For nest-cam v350 release

Bug: 259322762
diff --git a/AUTHORS b/AUTHORS
new file mode 100644
index 0000000..27993a2
--- /dev/null
+++ b/AUTHORS
@@ -0,0 +1,4 @@
+stunnel authors
+
+Michal Trojnara  <Michal.Trojnara@mirt.net>
+
diff --git a/BUGS b/BUGS
new file mode 100644
index 0000000..8b87d1f
--- /dev/null
+++ b/BUGS
@@ -0,0 +1,5 @@
+stunnel known bugs
+
+
+- Shared library for transparent proxy does not support IPv6.
+
diff --git a/COPYING b/COPYING
new file mode 100644
index 0000000..38b6cb9
--- /dev/null
+++ b/COPYING
@@ -0,0 +1,33 @@
+stunnel license (see COPYRIGHT.GPL for detailed GPL conditions)
+
+Copyright (C) 1998-2015 Michal Trojnara
+
+This program is free software; you can redistribute it and/or modify it under
+the terms of the GNU General Public License as published by the Free Software
+Foundation; either version 2 of the License, or (at your option) any later
+version.
+
+This program is distributed in the hope that it will be useful, but WITHOUT
+ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
+FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
+
+You should have received a copy of the GNU General Public License along with
+this program; if not, see <http://www.gnu.org/licenses>.
+
+Linking stunnel statically or dynamically with other modules is making
+a combined work based on stunnel. Thus, the terms and conditions of the
+GNU General Public License cover the whole combination.
+
+In addition, as a special exception, the copyright holder of stunnel gives you
+permission to combine stunnel with free software programs or libraries that
+are released under the GNU LGPL and with code included in the standard release
+of OpenSSL under the OpenSSL License (or modified versions of such code, with
+unchanged license). You may copy and distribute such a system following the
+terms of the GNU GPL for stunnel and the licenses of the other code concerned.
+
+Note that people who make modified versions of stunnel are not obligated to
+grant this special exception for their modified versions; it is their choice
+whether to do so. The GNU General Public License gives permission to release
+a modified version without this exception; this exception also makes it
+possible to release a modified version which carries forward this exception.
+
diff --git a/COPYRIGHT.GPL b/COPYRIGHT.GPL
new file mode 100644
index 0000000..f2def2a
--- /dev/null
+++ b/COPYRIGHT.GPL
@@ -0,0 +1,339 @@
+		    GNU GENERAL PUBLIC LICENSE
+		       Version 2, June 1991
+
+ Copyright (C) 1989, 1991 Free Software Foundation, Inc.
+ 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA.
+ Everyone is permitted to copy and distribute verbatim copies
+ of this license document, but changing it is not allowed.
+
+			    Preamble
+
+  The licenses for most software are designed to take away your
+freedom to share and change it.  By contrast, the GNU General Public
+License is intended to guarantee your freedom to share and change free
+software--to make sure the software is free for all its users.  This
+General Public License applies to most of the Free Software
+Foundation's software and to any other program whose authors commit to
+using it.  (Some other Free Software Foundation software is covered by
+the GNU Library General Public License instead.)  You can apply it to
+your programs, too.
+
+  When we speak of free software, we are referring to freedom, not
+price.  Our General Public Licenses are designed to make sure that you
+have the freedom to distribute copies of free software (and charge for
+this service if you wish), that you receive source code or can get it
+if you want it, that you can change the software or use pieces of it
+in new free programs; and that you know you can do these things.
+
+  To protect your rights, we need to make restrictions that forbid
+anyone to deny you these rights or to ask you to surrender the rights.
+These restrictions translate to certain responsibilities for you if you
+distribute copies of the software, or if you modify it.
+
+  For example, if you distribute copies of such a program, whether
+gratis or for a fee, you must give the recipients all the rights that
+you have.  You must make sure that they, too, receive or can get the
+source code.  And you must show them these terms so they know their
+rights.
+
+  We protect your rights with two steps: (1) copyright the software, and
+(2) offer you this license which gives you legal permission to copy,
+distribute and/or modify the software.
+
+  Also, for each author's protection and ours, we want to make certain
+that everyone understands that there is no warranty for this free
+software.  If the software is modified by someone else and passed on, we
+want its recipients to know that what they have is not the original, so
+that any problems introduced by others will not reflect on the original
+authors' reputations.
+
+  Finally, any free program is threatened constantly by software
+patents.  We wish to avoid the danger that redistributors of a free
+program will individually obtain patent licenses, in effect making the
+program proprietary.  To prevent this, we have made it clear that any
+patent must be licensed for everyone's free use or not licensed at all.
+
+  The precise terms and conditions for copying, distribution and
+modification follow.
+
+		    GNU GENERAL PUBLIC LICENSE
+   TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
+
+  0. This License applies to any program or other work which contains
+a notice placed by the copyright holder saying it may be distributed
+under the terms of this General Public License.  The "Program", below,
+refers to any such program or work, and a "work based on the Program"
+means either the Program or any derivative work under copyright law:
+that is to say, a work containing the Program or a portion of it,
+either verbatim or with modifications and/or translated into another
+language.  (Hereinafter, translation is included without limitation in
+the term "modification".)  Each licensee is addressed as "you".
+
+Activities other than copying, distribution and modification are not
+covered by this License; they are outside its scope.  The act of
+running the Program is not restricted, and the output from the Program
+is covered only if its contents constitute a work based on the
+Program (independent of having been made by running the Program).
+Whether that is true depends on what the Program does.
+
+  1. You may copy and distribute verbatim copies of the Program's
+source code as you receive it, in any medium, provided that you
+conspicuously and appropriately publish on each copy an appropriate
+copyright notice and disclaimer of warranty; keep intact all the
+notices that refer to this License and to the absence of any warranty;
+and give any other recipients of the Program a copy of this License
+along with the Program.
+
+You may charge a fee for the physical act of transferring a copy, and
+you may at your option offer warranty protection in exchange for a fee.
+
+  2. You may modify your copy or copies of the Program or any portion
+of it, thus forming a work based on the Program, and copy and
+distribute such modifications or work under the terms of Section 1
+above, provided that you also meet all of these conditions:
+
+    a) You must cause the modified files to carry prominent notices
+    stating that you changed the files and the date of any change.
+
+    b) You must cause any work that you distribute or publish, that in
+    whole or in part contains or is derived from the Program or any
+    part thereof, to be licensed as a whole at no charge to all third
+    parties under the terms of this License.
+
+    c) If the modified program normally reads commands interactively
+    when run, you must cause it, when started running for such
+    interactive use in the most ordinary way, to print or display an
+    announcement including an appropriate copyright notice and a
+    notice that there is no warranty (or else, saying that you provide
+    a warranty) and that users may redistribute the program under
+    these conditions, and telling the user how to view a copy of this
+    License.  (Exception: if the Program itself is interactive but
+    does not normally print such an announcement, your work based on
+    the Program is not required to print an announcement.)
+
+These requirements apply to the modified work as a whole.  If
+identifiable sections of that work are not derived from the Program,
+and can be reasonably considered independent and separate works in
+themselves, then this License, and its terms, do not apply to those
+sections when you distribute them as separate works.  But when you
+distribute the same sections as part of a whole which is a work based
+on the Program, the distribution of the whole must be on the terms of
+this License, whose permissions for other licensees extend to the
+entire whole, and thus to each and every part regardless of who wrote it.
+
+Thus, it is not the intent of this section to claim rights or contest
+your rights to work written entirely by you; rather, the intent is to
+exercise the right to control the distribution of derivative or
+collective works based on the Program.
+
+In addition, mere aggregation of another work not based on the Program
+with the Program (or with a work based on the Program) on a volume of
+a storage or distribution medium does not bring the other work under
+the scope of this License.
+
+  3. You may copy and distribute the Program (or a work based on it,
+under Section 2) in object code or executable form under the terms of
+Sections 1 and 2 above provided that you also do one of the following:
+
+    a) Accompany it with the complete corresponding machine-readable
+    source code, which must be distributed under the terms of Sections
+    1 and 2 above on a medium customarily used for software interchange; or,
+
+    b) Accompany it with a written offer, valid for at least three
+    years, to give any third party, for a charge no more than your
+    cost of physically performing source distribution, a complete
+    machine-readable copy of the corresponding source code, to be
+    distributed under the terms of Sections 1 and 2 above on a medium
+    customarily used for software interchange; or,
+
+    c) Accompany it with the information you received as to the offer
+    to distribute corresponding source code.  (This alternative is
+    allowed only for noncommercial distribution and only if you
+    received the program in object code or executable form with such
+    an offer, in accord with Subsection b above.)
+
+The source code for a work means the preferred form of the work for
+making modifications to it.  For an executable work, complete source
+code means all the source code for all modules it contains, plus any
+associated interface definition files, plus the scripts used to
+control compilation and installation of the executable.  However, as a
+special exception, the source code distributed need not include
+anything that is normally distributed (in either source or binary
+form) with the major components (compiler, kernel, and so on) of the
+operating system on which the executable runs, unless that component
+itself accompanies the executable.
+
+If distribution of executable or object code is made by offering
+access to copy from a designated place, then offering equivalent
+access to copy the source code from the same place counts as
+distribution of the source code, even though third parties are not
+compelled to copy the source along with the object code.
+
+  4. You may not copy, modify, sublicense, or distribute the Program
+except as expressly provided under this License.  Any attempt
+otherwise to copy, modify, sublicense or distribute the Program is
+void, and will automatically terminate your rights under this License.
+However, parties who have received copies, or rights, from you under
+this License will not have their licenses terminated so long as such
+parties remain in full compliance.
+
+  5. You are not required to accept this License, since you have not
+signed it.  However, nothing else grants you permission to modify or
+distribute the Program or its derivative works.  These actions are
+prohibited by law if you do not accept this License.  Therefore, by
+modifying or distributing the Program (or any work based on the
+Program), you indicate your acceptance of this License to do so, and
+all its terms and conditions for copying, distributing or modifying
+the Program or works based on it.
+
+  6. Each time you redistribute the Program (or any work based on the
+Program), the recipient automatically receives a license from the
+original licensor to copy, distribute or modify the Program subject to
+these terms and conditions.  You may not impose any further
+restrictions on the recipients' exercise of the rights granted herein.
+You are not responsible for enforcing compliance by third parties to
+this License.
+
+  7. If, as a consequence of a court judgment or allegation of patent
+infringement or for any other reason (not limited to patent issues),
+conditions are imposed on you (whether by court order, agreement or
+otherwise) that contradict the conditions of this License, they do not
+excuse you from the conditions of this License.  If you cannot
+distribute so as to satisfy simultaneously your obligations under this
+License and any other pertinent obligations, then as a consequence you
+may not distribute the Program at all.  For example, if a patent
+license would not permit royalty-free redistribution of the Program by
+all those who receive copies directly or indirectly through you, then
+the only way you could satisfy both it and this License would be to
+refrain entirely from distribution of the Program.
+
+If any portion of this section is held invalid or unenforceable under
+any particular circumstance, the balance of the section is intended to
+apply and the section as a whole is intended to apply in other
+circumstances.
+
+It is not the purpose of this section to induce you to infringe any
+patents or other property right claims or to contest validity of any
+such claims; this section has the sole purpose of protecting the
+integrity of the free software distribution system, which is
+implemented by public license practices.  Many people have made
+generous contributions to the wide range of software distributed
+through that system in reliance on consistent application of that
+system; it is up to the author/donor to decide if he or she is willing
+to distribute software through any other system and a licensee cannot
+impose that choice.
+
+This section is intended to make thoroughly clear what is believed to
+be a consequence of the rest of this License.
+
+  8. If the distribution and/or use of the Program is restricted in
+certain countries either by patents or by copyrighted interfaces, the
+original copyright holder who places the Program under this License
+may add an explicit geographical distribution limitation excluding
+those countries, so that distribution is permitted only in or among
+countries not thus excluded.  In such case, this License incorporates
+the limitation as if written in the body of this License.
+
+  9. The Free Software Foundation may publish revised and/or new versions
+of the General Public License from time to time.  Such new versions will
+be similar in spirit to the present version, but may differ in detail to
+address new problems or concerns.
+
+Each version is given a distinguishing version number.  If the Program
+specifies a version number of this License which applies to it and "any
+later version", you have the option of following the terms and conditions
+either of that version or of any later version published by the Free
+Software Foundation.  If the Program does not specify a version number of
+this License, you may choose any version ever published by the Free Software
+Foundation.
+
+  10. If you wish to incorporate parts of the Program into other free
+programs whose distribution conditions are different, write to the author
+to ask for permission.  For software which is copyrighted by the Free
+Software Foundation, write to the Free Software Foundation; we sometimes
+make exceptions for this.  Our decision will be guided by the two goals
+of preserving the free status of all derivatives of our free software and
+of promoting the sharing and reuse of software generally.
+
+			    NO WARRANTY
+
+  11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
+FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW.  EXCEPT WHEN
+OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
+PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED
+OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
+MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.  THE ENTIRE RISK AS
+TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU.  SHOULD THE
+PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING,
+REPAIR OR CORRECTION.
+
+  12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
+WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR
+REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
+INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING
+OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED
+TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY
+YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER
+PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE
+POSSIBILITY OF SUCH DAMAGES.
+
+		     END OF TERMS AND CONDITIONS
+
+	Appendix: How to Apply These Terms to Your New Programs
+
+  If you develop a new program, and you want it to be of the greatest
+possible use to the public, the best way to achieve this is to make it
+free software which everyone can redistribute and change under these terms.
+
+  To do so, attach the following notices to the program.  It is safest
+to attach them to the start of each source file to most effectively
+convey the exclusion of warranty; and each file should have at least
+the "copyright" line and a pointer to where the full notice is found.
+
+    <one line to give the program's name and a brief idea of what it does.>
+    Copyright (C) 19yy  <name of author>
+
+    This program is free software; you can redistribute it and/or modify
+    it under the terms of the GNU General Public License as published by
+    the Free Software Foundation; either version 2 of the License, or
+    (at your option) any later version.
+
+    This program is distributed in the hope that it will be useful,
+    but WITHOUT ANY WARRANTY; without even the implied warranty of
+    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+    GNU General Public License for more details.
+
+    You should have received a copy of the GNU General Public License
+    along with this program; if not, write to the Free Software
+    Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA.
+
+Also add information on how to contact you by electronic and paper mail.
+
+If the program is interactive, make it output a short notice like this
+when it starts in an interactive mode:
+
+    Gnomovision version 69, Copyright (C) 19yy name of author
+    Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
+    This is free software, and you are welcome to redistribute it
+    under certain conditions; type `show c' for details.
+
+The hypothetical commands `show w' and `show c' should show the appropriate
+parts of the General Public License.  Of course, the commands you use may
+be called something other than `show w' and `show c'; they could even be
+mouse-clicks or menu items--whatever suits your program.
+
+You should also get your employer (if you work as a programmer) or your
+school, if any, to sign a "copyright disclaimer" for the program, if
+necessary.  Here is a sample; alter the names:
+
+  Yoyodyne, Inc., hereby disclaims all copyright interest in the program
+  `Gnomovision' (which makes passes at compilers) written by James Hacker.
+
+  <signature of Ty Coon>, 1 April 1989
+  Ty Coon, President of Vice
+
+This General Public License does not permit incorporating your program into
+proprietary programs.  If your program is a subroutine library, you may
+consider it more useful to permit linking proprietary applications with the
+library.  If this is what you want to do, use the GNU Library General
+Public License instead of this License.
diff --git a/CREDITS b/CREDITS
new file mode 100644
index 0000000..c9ad66a
--- /dev/null
+++ b/CREDITS
@@ -0,0 +1,40 @@
+stunnel code contributions
+
+
+The code contributions are licensed as public domain unless stated otherwise.
+
+Several Win32 and WCE improvements and bugfixes:
+* Pierre Delaage <delaage.pierre@free.fr>
+
+systemd socket activation in version 5.05:
+Copyright (c) 2014 Mark Theunissen
+
+Permission is hereby granted, free of charge, to any person obtaining a copy of
+this software and associated documentation files (the "Software"), to deal in
+the Software without restriction, including without limitation the rights to
+use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies
+of the Software, and to permit persons to whom the Software is furnished to do
+so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+SOFTWARE.
+
+Several bugfixes and improvements mostly in versions 3.xx:
+* Brian Hatch <bri@stunnel.org>
+
+Initial PTY support in version 3.05:
+* Dirk O. Siebnich <dok@vossnet.de>
+
+Initial SSL support in versions 1.x:
+* Adam Hernik <adas@infocentrum.com>
+* Pawel Krawczyk <kravietz@ceti.com.pl>
+
+and many others...
diff --git a/ChangeLog b/ChangeLog
new file mode 100644
index 0000000..621fdbe
--- /dev/null
+++ b/ChangeLog
@@ -0,0 +1,1643 @@
+stunnel change log
+
+Version 5.22, 2015.07.30, urgency: HIGH
+* New features
+  - "OCSPaia = yes" added to the configuration file templates.
+  - Improved double free detection.
+* Bugfixes
+  - Fixed a number of OCSP bugs.  The most severe of those
+    bugs caused stunnel to treat OCSP responses that failed
+    OCSP_basic_verify() checks as if they were successful.
+  - Fixed the passive IPv6 resolver (broken in stunnel 5.21).
+
+Version 5.21, 2015.07.27, urgency: MEDIUM
+* New features
+  - Signal names are displayed instead of numbers.
+  - First resolve IPv4 addresses on passive resolver requests.
+    This speeds up stunnel startup on Win32 with a slow/defunct
+    DNS service.
+  - The "make check" target was modified to only build Win32
+    executables when stunnel is built from a git repository (thx
+    to Peter Pentchev).
+  - More elaborate descriptions were added to the warning about
+    using "verify = 2" without "checkHost" or "checkIP".
+  - Performance optimization was performed on the debug code.
+* Bugfixes
+  - Fixed the FORK and UCONTEXT threading support.
+  - Fixed "failover=prio" (broken since stunnel 5.15).
+  - Added a retry when sleep(3) was interrupted by a signal
+    in the cron thread scheduler.
+
+Version 5.20, 2015.07.09, urgency: HIGH 
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.2d.
+    https://www.openssl.org/news/secadv_20150709.txt
+* New features
+  - poll(2) re-enabled on MacOS X 10.5 and later.
+  - Xcode SDK is automatically used on MacOS X if no other
+    locally installed OpenSSL directory is found.
+  - The SSL library detection algorithm was made a bit smarter.
+  - Warnings about insecure authentication were modified to
+    include the name of the affected service section.
+  - A warning was added to stunnel.init if no pid file was
+    specified in the configuration file (thx to Peter Pentchev).
+  - Optional debugging symbols are included in the Win32 installer.
+  - Documentation updates (closes Debian bug #781669).
+* Bugfixes
+  - Signal pipe reinitialization added to prevent turning the
+    main accepting thread into a busy wait loop when an external
+    condition breaks the signal pipe.  This bug was found to
+    surface on Win32, but other platforms may also be affected.
+  - Fixed removing the disabled taskbar icon.
+  - Generated temporary DH parameters are used for configuration
+    reload instead of the static defaults.
+  - LSB compatibility fixes added to the stunnel.init script (thx
+    to Peter Pentchev).
+  - Fixed the manual page headers (thx to Gleydson Soares).
+
+Version 5.19, 2015.06.16, urgency: MEDIUM:
+* New features
+  - OpenSSL DLLs updated to version 1.0.2c.
+  - Added a runtime check whether COMP_zlib() method is implemented
+    in order to improve compatibility with the Debian OpenSSL build.
+* Bugfixes
+  - Improved socket error handling.
+  - Cron thread priority on Win32 platform changed to
+    THREAD_PRIORITY_LOWEST to improve portability.
+  - Makefile bugfixes for stunnel 5.18 regressions.
+  - Fixed some typos in docs and scripts (thx to Peter Pentchev).
+  - Fixed a log level check condition (thx to Peter Pentchev).
+
+Version 5.18, 2015.06.12, urgency: MEDIUM:
+* New features
+  - OpenSSL DLLs updated to version 1.0.2b.
+    https://www.openssl.org/news/secadv_20150611.txt
+  - Added "include" configuration file option to include all
+    configuration file parts located in a specified directory.
+  - Log file is reopened every 24 hours.  With "log = overwrite"
+    this feature can be used to prevent filling up disk space.
+  - Temporary DH parameters are refreshed every 24 hours, unless
+    static DH parameters were provided in the certificate file.
+  - Unique initial DH parameters are distributed with each release.
+  - Warnings are logged on potentially insecure authentication.
+  - Improved compatibility with the current OpenSSL 1.1.0-dev tree:
+    removed RLE compression support, etc.
+  - Updated stunnel.spec (thx to Bill Quayle).
+* Bugfixes
+  - Fixed handling of dynamic connect targets.
+  - Fixed handling of trailing whitespaces in the Content-Length
+    header of the NTLM authentication.
+  - Fixed --sysconfdir and --localstatedir handling (thx to
+    Dagobert Michelsen).
+
+Version 5.17, 2015.04.29, urgency: HIGH:
+* Bugfixes
+  - Fixed a NULL pointer dereference causing the service to crash.
+    This bug was introduced in stunnel 5.15.
+
+Version 5.16, 2015.04.19, urgency: MEDIUM:
+* Bugfixes
+  - Fixed compilation with old versions of gcc.
+
+Version 5.15, 2015.04.16, urgency: LOW:
+* New features
+  - Added new service-level options "checkHost", "checkEmail" and
+    "checkIP" for additional checks of the peer certificate subject.
+    These options require OpenSSL version 1.0.2 or higher.
+  - Win32 binary distribution now ships with the Mozilla root CA
+    bundle.  This bundle is intended be used together with the new
+    "checkHost" option to validate server certs accepted by Mozilla.
+  - New commandline options "-reload" to reload the configuration
+    file and "-reopen" to reopen the log file of stunnel running
+    as a Windows service (thx to Marc McLaughlin).
+  - Added session persistence based on negotiated TLS sessions.
+    https://en.wikipedia.org/wiki/Load_balancing_%28computing%29#Persistence
+    The current implementation does not support external TLS
+    session caching with sessiond.
+  - MEDIUM ciphers (currently SEED and RC4) are removed from the
+    default cipher list.
+  - The "redirect" option was improved to not only redirect sessions
+    established with an untrusted certificate, but also sessions
+    established without a client certificate.
+  - OpenSSL version checking modified to distinguish FIPS and
+    non-FIPS builds.
+  - Improved compatibility with the current OpenSSL 1.1.0-dev tree.
+  - Removed support for OpenSSL versions older than 0.9.7.
+    The final update for the OpenSSL 0.9.6 branch was 17 Mar 2004.
+  - "sessiond" support improved to also work in OpenSSL 0.9.7.
+  - Randomize the initial value of the round-robin counter.
+  - New stunnel.conf templates are provided for Windows and Unix.
+* Bugfixes
+  - Fixed compilation against old versions of OpenSSL.
+  - Fixed memory leaks in certificate verification.
+
+Version 5.14, 2015.03.25, urgency: HIGH:
+* Security bugfixes
+  - The "redirect" option now also redirects clients on SSL session
+    reuse.  In stunnel versions 5.00 to 5.13 reused sessions were
+    instead always connected hosts specified with the "connect"
+    option regardless of their certificate verification result.
+    This vulnerability was reported by Johan Olofsson.
+* New features
+  - Windows service is automatically restarted after upgrade.
+* Bugfixes
+  - Fixed a memory allocation error during Unix daemon shutdown.
+  - Fixed handling multiple connect/redirect destinations.
+  - OpenSSL FIPS builds are now correctly reported on startup.
+
+Version 5.13, 2015.03.20, urgency: MEDIUM:
+* New features
+  - The "service" option was modified to also control the syslog
+    service name.
+* Bugfixes
+  - Fixed Windows service crash.
+
+Version 5.12, 2015.03.19, urgency: HIGH:
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.2a.
+    https://www.openssl.org/news/secadv_20150319.txt
+* New features
+  - New service-level option "logId" to specify the
+    connection identifier type.  Currently supported types:
+    "sequential" (default), "unique", and "thread".
+  - New service-level option "debug" to individually control
+    logging verbosity of defined services.
+* Bugfixes
+  - OCSP fixed on Windows platform (thx to Alec Kosky).
+
+Version 5.11, 2015.03.11, urgency: LOW:
+* New features
+  - OpenSSL DLLs updated to version 1.0.2.
+  - Removed dereferences of internal OpenSSL data structures.
+  - PSK key lookup algorithm performance improved from
+    O(N) (linear) to O(log N) (logarithmic).
+* Bugfixes
+  - Fixed peer certificate list in the main window on Win32
+    (thx to @fyer for reporting it).
+  - Fixed console logging in tstunnel.exe.
+  - _tputenv_s() replaced with more portable _tputenv() on Win32.
+
+Version 5.10, 2015.01.22, urgency: LOW:
+* New features
+  - OCSP AIA (Authority Information Access) support.  This feature
+    can be enabled with the new service-level option "OCSPaia".
+  - Additional security features of the linker are enabled:
+    "-z relro", "-z now", "-z noexecstack".
+* Bugfixes
+  - OpenSSL DLLs updated to version 1.0.1l.
+    https://www.openssl.org/news/secadv_20150108.txt
+  - FIPS canister updated to version 2.0.9 in the Win32 binary
+    build.
+
+Version 5.09, 2015.01.02, urgency: LOW:
+* New features
+  - Added PSK authentication with two new service-level
+    configuration file options "PSKsecrets" and "PSKidentity".
+  - Added additional security checks to the OpenSSL memory
+    management functions.
+  - Added support for the OPENSSL_NO_OCSP and OPENSSL_NO_ENGINE
+    OpenSSL configuration flags.
+  - Added compatibility with the current OpenSSL 1.1.0-dev tree.
+* Bugfixes
+  - Removed defective s_poll_error() code occasionally causing
+    connections to be prematurely closed (truncated).
+    This bug was introduced in stunnel 4.34.
+  - Fixed ./configure systemd detection (thx to Kip Walraven).
+  - Fixed ./configure sysroot detection (thx to Kip Walraven).
+  - Fixed compilation against old versions of OpenSSL.
+  - Removed outdated French manual page.
+
+Version 5.08, 2014.12.09, urgency: MEDIUM:
+* New features
+  - Added SOCKS4/SOCKS4a protocol support.
+  - Added SOCKS5 protocol support.
+  - Added SOCKS RESOLVE [F0] TOR extension support.
+  - Updated automake to version 1.14.1.
+  - OpenSSL directory searching is now relative to the sysroot.
+* Bugfixes
+  - Fixed improper hangup condition handling.
+  - Fixed missing -pic linker option.  This is required for
+    Android 5.0 and improves security.
+
+Version 5.07, 2014.11.01, urgency: MEDIUM:
+* New features
+  - Several SMTP server protocol negotiation improvements.
+  - Added UTF-8 byte order marks to stunnel.conf templates.
+  - DH parameters are no longer generated by "make cert".
+    The hardcoded DH parameters are sufficiently secure,
+    and modern TLS implementations will use ECDH anyway.
+  - Updated manual for the "options" configuration file option.
+  - Added support for systemd 209 or later.
+  - New --disable-systemd ./configure option.
+  - setuid/setgid commented out in stunnel.conf-sample.
+* Bugfixes
+  - Added support for UTF-8 byte order mark in stunnel.conf.
+  - Compilation fix for OpenSSL with disabled SSLv2 or SSLv3.
+  - Non-blocking mode set on inetd and systemd descriptors.
+  - shfolder.h replaced with shlobj.h for compatibility
+    with modern Microsoft compilers.
+
+Version 5.06, 2014.10.15, urgency: HIGH:
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.1j.
+    https://www.openssl.org/news/secadv_20141015.txt
+  - The insecure SSLv2 protocol is now disabled by default.
+    It can be enabled with "options = -NO_SSLv2".
+  - The insecure SSLv3 protocol is now disabled by default.
+    It can be enabled with "options = -NO_SSLv3".
+  - Default sslVersion changed to "all" (also in FIPS mode)
+    to autonegotiate the highest supported TLS version.
+* New features
+  - Added missing SSL options to match OpenSSL 1.0.1j.
+  - New "-options" commandline option to display the list
+    of supported SSL options.
+* Bugfixes
+  - Fixed FORK threading build regression bug.
+  - Fixed missing periodic Win32 GUI log updates.
+
+Version 5.05, 2014.10.10, urgency: MEDIUM:
+* New features
+  - Asynchronous communication with the GUI thread for faster
+    logging on Win32.
+  - systemd socket activation (thx to Mark Theunissen).
+  - The parameter of "options" can now be prefixed with "-"
+    to clear an SSL option, for example:
+    "options = -LEGACY_SERVER_CONNECT".
+  - Improved "transparent = destination" manual page (thx to
+    Vadim Penzin).
+* Bugfixes
+  - Fixed POLLIN|POLLHUP condition handling error resulting
+    in prematurely closed (truncated) connection.
+  - Fixed a null pointer dereference regression bug in the
+    "transparent = destination" functionality (thx to
+    Vadim Penzin). This bug was introduced in stunnel 5.00.
+  - Fixed startup thread synchronization with Win32 GUI.
+  - Fixed erroneously closed stdin/stdout/stderr if specified
+    as the -fd commandline option parameter.
+  - A number of minor Win32 GUI bugfixes and improvements.
+  - Merged most of the Windows CE patches (thx to Pierre Delaage).
+  - Fixed incorrect CreateService() error message on Win32.
+  - Implemented a workaround for defective Cygwin file
+    descriptor passing breaking the libwrap support:
+    http://wiki.osdev.org/Cygwin_Issues#Passing_file_descriptors
+
+Version 5.04, 2014.09.21, urgency: LOW:
+* New features
+  - Support for local mode ("exec" option) on Win32.
+  - Support for UTF-8 config file and log file.
+  - Win32 UTF-16 build (thx to Pierre Delaage for support).
+  - Support for Unicode file names on Win32.
+  - A more explicit service description provided for the
+    Windows SCM (thx to Pierre Delaage).
+  - TCP/IP dependency added for NT service in order to prevent
+    initialization failure at boot time.
+  - FIPS canister updated to version 2.0.8 in the Win32 binary
+    build.
+* Bugfixes
+  - load_icon_default() modified to return copies of default icons
+    instead of the original resources to prevent the resources
+    from being destroyed.
+  - Partially merged Windows CE patches (thx to Pierre Delaage).
+  - Fixed typos in stunnel.init.in and vc.mak.
+  - Fixed incorrect memory allocation statistics update in
+    str_realloc().
+  - Missing REMOTE_PORT environmental variable is provided to
+    processes spawned with "exec" on Unix platforms.
+  - Taskbar icon is no longer disabled for NT service.
+  - Fixed taskbar icon initialization when commandline options are
+    specified.
+  - Reportedly more compatible values used for the dwDesiredAccess
+    parameter of the CreateFile() function (thx to Pierre Delaage).
+  - A number of minor Win32 GUI bugfixes and improvements.
+
+Version 5.03, 2014.08.07, urgency: HIGH:
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.1i.
+    See https://www.openssl.org/news/secadv_20140806.txt
+* New features
+  - FIPS autoconfiguration cleanup.
+  - FIPS canister updated to version 2.0.6.
+  - Improved SNI diagnostic logging.
+* Bugfixes
+  - Compilation fixes for old versions of OpenSSL.
+  - Fixed whitespace handling in the stunnel.init script.
+
+Version 5.02, 2014.06.09, urgency: HIGH:
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.1h.
+    See https://www.openssl.org/news/secadv_20140605.txt
+* New features
+  - Major rewrite of the protocol.c interface: it is now possible to add
+    protocol negotiations at multiple connection phases, protocols can
+    individually decide whether the remote connection will be
+    established before or after SSL/TLS is negotiated.
+  - Heap memory blocks are wiped before release.  This only works for
+    block allocated by stunnel, and not by OpenSSL or other libraries.
+  - The safe_memcmp() function implemented with execution time not
+    dependent on the compared data.
+  - Updated the stunnel.conf and stunnel.init templates.
+  - Added a client-mode example to the manual.
+* Bugfixes
+  - Fixed "failover = rr" broken since version 5.00.
+  - Fixed "taskbar = no" broken since version 5.00.
+  - Compilation fix for missing SSL_OP_MSIE_SSLV2_RSA_PADDING option.
+
+Version 5.01, 2014.04.08, urgency: HIGH:
+* Security bugfixes
+  - OpenSSL DLLs updated to version 1.0.1g.
+    This version mitigates TLS heartbeat read overrun (CVE-2014-0160).
+* New features
+  - X.509 extensions added to the created self-signed stunnel.pem.
+  - "FIPS = no" also allowed in non-FIPS builds of stunnel.
+  - Search all certificates with the same subject name for a matching
+    public key rather than only the first one (thx to Leon Winter).
+  - Create logs in the local application data folder if stunnel folder
+    is not writable on Win32.
+* Bugfixes
+  - close_notify not sent when SSL still has some data buffered.
+  - Protocol negotiation with server-side SNI fixed.
+  - A Mac OS X missing symbols fixed.
+  - Win32 configuration file reload crash fixed.
+  - Added s_pool_free() on exec+connect service retires.
+  - Line-buffering enforced on stderr output.
+
+stunnel 5.00 disables some features previously enabled by default.
+Users should review whether the new defaults are appropriate for their
+particular deployments.  Packages maintainers may consider prepending
+the old defaults for "fips" (if supported by their OpenSSL library),
+"pid" and "libwrap" to stunnel.conf during automated updates.
+
+Version 5.00, 2014.03.06, urgency: HIGH:
+* Security bugfixes
+  - Added PRNG state update in fork threading (CVE-2014-0016).
+* New global configuration file defaults
+  - Default "fips" option value is now "no", as FIPS mode is only
+    helpful for compliance, and never for actual security.
+  - Default "pid" is now "", i.e. not to create a pid file at startup.
+* New service-level configuration file defaults
+  - Default "ciphers" updated to "HIGH:MEDIUM:+3DES:+DH:!aNULL:!SSLv2"
+    due to AlFBPPS attack and bad performance of DH ciphersuites.
+  - Default "libwrap" setting is now "no" to improve performance.
+* New features
+  - OpenSSL DLLs updated to version 1.0.1f.
+  - zlib DLL updated to version 1.2.8.
+  - autoconf scripts upgraded to version 2.69.
+  - TLS 1.1 and TLS 1.2 are now allowed in the FIPS mode.
+  - New service-level option "redirect" to redirect SSL client
+    connections on authentication failures instead of rejecting them.
+  - New global "engineDefault" configuration file option to control
+    which OpenSSL tasks are delegated to the current engine.
+    Available tasks: ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS,
+    DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.
+  - New service-level configuration file option "engineId" to select
+    the engine by identifier, e.g. "engineId = capi".
+  - New global configuration file option "log" to control whether to
+    append (the default), or to overwrite log file while (re)opening.
+  - Different taskbar icon colors to indicate the service state.
+  - New global configuration file options "iconIdle", "iconActive",
+    and "iconError" to select status icon on GUI taskbar.
+  - Removed the limit of 63 stunnel.conf sections on Win32 platform.
+  - Installation of a sample certificate was moved to a separate "cert"
+    target in order to allow unattended (e.g. scripted) installations.
+  - Reduced length of the logged thread identifier.  It is still based
+    on the OS thread ID, and thus not unique over long periods of time.
+  - Improved readability of error messages printed when stunnel refuses
+    to start due to a critical error.
+* Bugfixes
+  - LD_PRELOAD Solaris compatibility bug fixed (thx to Norm Jacobs).
+  - CRYPTO_NUM_LOCKS replaced with CRYPTO_num_locks() to improve binary
+    compatibility with diverse builds of OpenSSL (thx to Norm Jacobs).
+  - Corrected round-robin failover behavior under heavy load.
+  - Numerous fixes in the engine support code.
+  - On Win32 platform .rnd file moved from c:\ to the stunnel folder.
+
+Version 4.57, 2015.04.01, urgency: HIGH:
+* Security bugfixes
+  - Added PRNG state update in fork threading (CVE-2014-0016).
+
+Version 4.56, 2013.03.22, urgency: HIGH:
+* New features
+  - Win32 installer automatically configures firewall exceptions.
+  - Win32 installer configures administrative shortcuts to invoke UAC.
+  - Improved Win32 GUI shutdown time.
+* Bugfixes
+  - Fixed a regression bug introduced in version 4.55 causing random
+    crashes on several platforms, including Windows 7.
+  - Fixed startup crashes on some Win32 systems.
+  - Fixed incorrect "stunnel -exit" process synchronisation.
+  - Fixed FIPS detection with new versions of the OpenSSL library.
+  - Failure to open the log file at startup is no longer ignored.
+
+Version 4.55, 2013.03.03, urgency: HIGH:
+* Security bugfixes
+  - Buffer overflow vulnerability fixed in the NTLM authentication
+    of the CONNECT protocol negotiation.
+    See https://www.stunnel.org/CVE-2013-1762.html for details.
+  - OpenSSL updated to version 1.0.1e in Win32/Android builds.
+* New features
+  - SNI wildcard matching in server mode.
+  - Terminal version of stunnel (tstunnel.exe) build for Win32.
+* Bugfixes
+  - Fixed write half-close handling in the transfer() function (thx to
+    Dustin Lundquist).
+  - Fixed EAGAIN error handling in the transfer() function (thx to Jan Bee).
+  - Restored default signal handlers before execvp() (thx to Michael Weiser).
+  - Fixed memory leaks in protocol negotiation (thx to Arthur Mesh).
+  - Fixed a file descriptor leak during configuration file reload (thx to
+    Arthur Mesh).
+  - Closed SSL sockets were removed from the transfer() c->fds poll.
+  - Minor fix in handling exotic inetd-mode configurations.
+  - WCE compilation fixes.
+  - IPv6 compilation fix in protocol.c.
+  - Windows installer fixes.
+
+Version 4.54, 2012.10.09, urgency: MEDIUM:
+* New Win32 features
+  - FIPS module updated to version 2.0.
+  - OpenSSL DLLs updated to version 1.0.1c.
+  - zlib DLL updated to version 1.2.7.
+  - Engine DLLs added: 4758cca, aep, atalla, capi, chil, cswift, gmp, gost,
+    nuron, padlock, sureware, ubsec.
+* Other new features
+  - "session" option renamed to more readable "sessionCacheTimeout".
+    The old name remains accepted for backward compatibility.
+  - New service-level "sessionCacheSize" option to control session cache size.
+  - New service-level option "reset" to control whether TCP RST flag is used
+    to indicate errors.  The default value is "reset = yes".
+  - New service-level option "renegotiation" to disable SSL renegotiation.
+    This feature is based on a public-domain patch by Janusz Dziemidowicz.
+  - New FreeBSD socket options: IP_FREEBIND, IP_BINDANY, IPV6_BINDANY (thx
+    to Janusz Dziemidowicz).
+  - New parameters to configure TLS v1.1/v1.2 with OpenSSL version 1.0.1
+    or higher (thx to Henrik Riomar).
+* Bugfixes
+  - Fixed "Application Failed to Initialize Properly (0xc0150002)" error.
+  - Fixed missing SSL state debug log entries.
+  - Fixed a race condition in libwrap code resulting in random stalls (thx
+    to Andrew Skalski).
+  - Session cache purged at configuration file reload to reduce memory leak.
+    Remaining leak of a few kilobytes per section is yet to be fixed.
+  - Fixed a regression bug in "transparent = destination" functionality (thx
+    to Stefan Lauterbach). This bug was introduced in stunnel 4.51.
+  - "transparent = destination" is now a valid endpoint in inetd mode.
+  - "delay = yes" fixed to work even if specified *after* "connect" option.
+  - Multiple "connect" targets fixed to also work with delayed resolver.
+  - The number of resolver retries of EAI_AGAIN error has been limited to 3
+    in order to prevent infinite loops.
+
+Version 4.53, 2012.03.19, urgency: MEDIUM:
+* New features
+  - Added client-mode "sni" option to directly control the value of
+    TLS Server Name Indication (RFC 3546) extension.
+  - Added support for IP_FREEBIND socket option with a pached Linux kernel.
+  - Glibc-specific dynamic allocation tuning was applied to help unused memory
+    deallocation.
+  - Non-blocking OCSP implementation.
+* Bugfixes
+  - Compilation fixes for old versions of OpenSSL (tested against 0.9.6).
+  - Usage of uninitialized variables fixed in exec+connect services.
+  - Occasional logging subsystem crash with exec+connect services.
+  - OpenBSD compilation fix (thx to Michele Orru').
+  - Session id context initialized with session name rather than a constant.
+  - Fixed handling of a rare inetd mode use case, where either stdin or stdout
+    is a socket, but not both of them at the same time.
+  - Fixed missing OPENSSL_Applink http://www.openssl.org/support/faq.html#PROG2
+  - Fixed crash on termination with FORK threading model.
+  - Fixed dead canary after configuration reload with open connections.
+  - Fixed missing file descriptors passed to local mode processes.
+  - Fixed required jmp_buf alignment on Itanium platform.
+  - Removed creating /dev/zero in the chroot jail on Solaris platform.
+  - Fixed detection of WSAECONNREFUSED Winsock error.
+  - Missing Microsoft.VC90.CRT.manifest added to Windows installer.
+
+Version 4.52, 2012.01.12, urgency: MEDIUM:
+* Bugfixes
+  - Fixed write closure notification for non-socket file descriptors.
+  - Removed a line logged to stderr in inetd mode.
+  - Fixed "Socket operation on non-socket" error in inetd mode on Mac OS X
+    platform.
+  - Removed direct access to the fields of the X509_STORE_CTX data structure.
+
+Version 4.51, 2012.01.09, urgency: MEDIUM:
+* New features
+  - Updated Win32 binary distribution OpenSSL DLLs to version 0.9.8s-fips.
+  - Updated Android binary OpenSSL to version 1.0.0f.
+  - Zlib support added to Win32 and Android binary builds.
+  - New "compression = deflate" global option to enable RFC 2246 compresion.
+    For compatibility with previous versions "compression = zlib" and
+    "compression = rle" also enable the deflate (RFC 2246) compression.
+  - Compression is disabled by default.
+  - Separate default ciphers and sslVersion for "fips = yes" and "fips = no".
+  - UAC support for editing configuration file with Windows GUI.
+* Bugfixes
+  - Fixed exec+connect sections.
+  - Added a workaround for broken Android getaddrinfo():
+    http://stackoverflow.com/questions/7818246/segmentation-fault-in-getaddrinfo
+
+Version 4.50, 2011.12.03, urgency: MEDIUM:
+* New features
+  - Added Android port.
+  - Updated INSTALL.FIPS.
+* Bugfixes
+  - Fixed internal memory allocation problem in inetd mode.
+  - Fixed FIPS mode on Microsoft Vista, Server 2008, and Windows 7.
+    This fix required to compile OpenSSL FIPS-compliant DLLs with MSVC 9.0,
+    instead of MSVC 10.0.  msvcr100.dll was replaced with msvcr90.dll.
+    GPL compatibility issues are explained in the GPL FAQ:
+    http://www.gnu.org/licenses/gpl-faq.html#WindowsRuntimeAndGPL
+  - POP3 server-side protocol negotiation updated to report STLS
+    capability (thx to Anthony Morgan).
+
+Version 4.49, 2011.11.28, urgency: MEDIUM:
+* Bugfixes
+  - Missing Microsoft Visual C++ Redistributable (msvcr100.dll) required
+    by FIPS-compliant OpenSSL library was added to the Windows installer.
+  - A bug was fixed causing crashes on MacOS X and some other platforms.
+
+Version 4.48, 2011.11.26, urgency: MEDIUM:
+* New features
+  - FIPS support on Win32 platform added.  OpenSSL 0.9.8r DLLs based on
+    FIPS 1.2.3 canister are included with this version of stunnel.  FIPS
+    mode can be disabled with "fips = no" configuration file option.
+* Bugfixes
+  - Fixed canary initialization problem on Win32 platform.
+
+Version 4.47, 2011.11.21, urgency: MEDIUM:
+* Internal improvements
+  - CVE-2010-3864 workaround improved to check runtime version of OpenSSL
+    rather than compiled version, and to allow OpenSSL 0.x.x >= 0.9.8p.
+  - Encoding of man page sources changed to UTF-8.
+* Bugfixes
+  - Handling of socket/SSL close in transfer() function was fixed.
+  - Logging was modified to save and restore system error codes.
+  - Option "service" was restricted to Unix, as since stunnel 4.42 it
+    wasn't doing anything useful on Windows platform.
+
+Version 4.46, 2011.11.04, urgency: LOW:
+* New features
+  - Added Unix socket support (e.g. "connect = /var/run/stunnel/socket").
+  - Added "verify = 4" mode to ignore CA chain and only verify peer certificate.
+  - Removed the limit of 16 IP addresses for a single 'connect' option.
+  - Removed the limit of 256 stunnel.conf sections in PTHREAD threading model.
+    It is still not possible have more than 63 sections on Win32 platform.
+    http://msdn.microsoft.com/en-us/library/windows/desktop/ms740141(v=vs.85).aspx
+* Optimizations
+  - Reduced per-connection memory usage.
+  - Performed a major refactoring of internal data structures.  Extensive
+    internal testing was performed, but some regression bugs are expected.
+* Bugfixes
+  - Fixed Win32 compilation with Mingw32.
+  - Fixed non-blocking API emulation layer in UCONTEXT threading model.
+  - Fixed signal handling in UCONTEXT threading model.
+
+Version 4.45, 2011.10.24, urgency: LOW:
+* New features
+  - "protocol = proxy" support to send original client IP address to haproxy:
+    http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt
+    This requires accept-proxy bind option of haproxy 1.5-dev3 or later.
+  - Added Win32 configuration reload without a valid configuration loaded.
+  - Added compatibility with LTS OpenSSL versions 0.9.6 and 0.9.7.
+    Some features are only available in OpenSSL 1.0.0 and later.
+* Performance optimizations
+  - Use SSL_MODE_RELEASE_BUFFERS if supported by the OpenSSL library.
+  - Libwrap helper processes are no longer started if libwrap is disabled
+    in all sections of the configuration file.
+* Internal improvements
+  - Protocol negotiation framework was rewritten to support additional
+    code to be executed after SSL_accept()/SSL_connect().
+  - Handling of memory allocation errors was rewritten to gracefully
+    terminate the process (thx to regenrecht for the idea).
+* Bugfixes
+  - Fixed -l option handling in stunnel3 script (thx to Kai Gülzau).
+  - Script to build default stunnel.pem was fixed (thx to Sebastian Kayser).
+  - MinGW compilation script (mingw.mak) was fixed (thx to Jose Alf).
+  - MSVC compilation script (vc.mak) was fixed.
+  - A number of problems in WINSOCK error handling were fixed.
+
+Version 4.44, 2011.09.17, urgency: MEDIUM:
+* New features
+  - Major automake/autoconf cleanup.
+  - Heap buffer overflow protection with canaries.
+  - Stack buffer overflow protection with -fstack-protector.
+* Bugfixes
+  - Fixed garbled error messages on errors with setuid/setgid options.
+  - SNI fixes (thx to Alexey Drozdov).
+  - Use after free in fdprintf() (thx to Alexey Drozdov).
+    This issue might cause GPF with "protocol" or "ident" options.
+
+Version 4.43, 2011.09.07, urgency: MEDIUM:
+* New features
+  - Updated Win32 DLLs for OpenSSL 1.0.0e.
+  - Major optimization of the logging subsystem.
+    Benchmarks indicate up to 15% stunnel performance improvement.
+* Bugfixes
+  - Fixed Win32 configuration file reload.
+  - Fixed FORK and UCONTEXT threading models.
+  - Corrected INSTALL.W32 file.
+
+Version 4.42, 2011.08.18, urgency: HIGH:
+* New features
+  - New verify level 0 to request and ignore peer certificate.  This
+    feature is useful with the new Windows GUI menu to save cached peer
+    certificate chains, as SSL client certificates are not sent by default.
+  - Manual page has been updated.
+  - Removed support for changing Windows Service name with "service" option.
+* Bugfixes
+  - Fixed a heap corruption vulnerability in versions 4.40 and 4.41.  It may
+    possibly be leveraged to perform DoS or remote code execution attacks.
+  - The -quiet commandline option was applied to *all* message boxes.
+  - Silent install (/S option) no longer attempts to create stunnel.pem.
+
+Version 4.41, 2011.07.25, urgency: MEDIUM:
+* Bugfixes
+  - Fixed Windows service crash of stunnel 4.40.
+
+Version 4.40, 2011.07.23, urgency: LOW:
+* New Win32 features
+  - Added a GUI menu to save cached peer certificate chains.
+  - Added comandline "-exit" option to stop stunnel *not* running
+    as a service.  This option may be useful for scripts.
+  - Added file version information to stunnel.exe.
+  - A number of other GUI improvements.
+* Other new features
+  - Hardcoded 2048-bit DH parameters are used as a fallback if DH parameters
+    are not provided in stunnel.pem.
+  - Default "ciphers" value updated to prefer ECDH:
+    "ALL:!SSLv2:!aNULL:!EXP:!LOW:-MEDIUM:RC4:+HIGH".
+  - Default ECDH curve updated to "prime256v1".
+  - Removed support for temporary RSA keys (used in obsolete export ciphers).
+
+Version 4.39, 2011.07.06, urgency: LOW:
+* New features
+  - New Win32 installer module to build self-signed stunnel.pem.
+  - Added configuration file editing with Windows GUI.
+  - Added log file reopening file editing with Windows GUI.
+    It might be useful to also implement log file rotation.
+  - Improved configuration file reload with Windows GUI.
+
+Version 4.38, 2011.06.28, urgency: MEDIUM:
+* New features
+  - Server-side SNI implemented (RFC 3546 section 3.1) with a new
+    service-level option "nsi".
+  - "socket" option also accepts "yes" and "no" for flags.
+  - Nagle's algorithm is now disabled by default for improved interactivity.
+* Bugfixes
+  - A compilation fix was added for OpenSSL version < 1.0.0.
+  - Signal pipe set to non-blocking mode.  This bug caused hangs of stunnel
+    features based on signals, e.g. local mode, FORK threading, or
+    configuration file reload on Unix.  Win32 platform was not affected.
+
+Version 4.37, 2011.06.17, urgency: MEDIUM:
+* New features
+  - Client-side SNI implemented (RFC 3546 section 3.1).
+  - Default "ciphers" changed from the OpenSSL default to a more secure
+    and faster "RC4-MD5:HIGH:!aNULL:!SSLv2".
+    A paranoid (and usually slower) setting would be "HIGH:!aNULL:!SSLv2".
+  - Recommended "options = NO_SSLv2" added to the sample stunnel.conf file.
+  - Default client method upgraded from SSLv3 to TLSv1.
+    To connect servers without TLS support use "sslVersion = SSLv3" option.
+  - Improved --enable-fips and --disable-fips ./configure option handling.
+  - On startup stunnel now compares the compiled version of OpenSSL against
+    the running version of OpenSSL. A warning is logged on mismatch.
+* Bugfixes
+  - Non-blocking socket handling in local mode fixed (Debian bug #626856).
+  - UCONTEXT threading mode fixed.
+  - Removed the use of gcc Thread-Local Storage for improved portability.
+  - va_copy macro defined for platforms that do not have it.
+  - Fixed "local" option parsing on IPv4 systems.
+  - Solaris compilation fix (redefinition of "STR").
+
+Version 4.36, 2011.05.03, urgency: LOW:
+* New features
+  - Updated Win32 DLLs for OpenSSL 1.0.0d.
+  - Dynamic memory management for strings manipulation:
+    no more static STRLEN limit, lower stack footprint.
+  - Strict public key comparison added for "verify = 3" certificate
+    checking mode (thx to Philipp Hartwig).
+  - Backlog parameter of listen(2) changed from 5 to SOMAXCONN:
+    improved behavior on heavy load.
+  - Example tools/stunnel.service file added for systemd service manager.
+* Bugfixes
+  - Missing pthread_attr_destroy() added to fix memory leak (thx to
+    Paul Allex and Peter Pentchev).
+  - Fixed the incorrect way of setting FD_CLOEXEC flag.
+  - Fixed --enable-libwrap option of ./configure script.
+  - /opt/local added to OpenSSL search path for MacPorts compatibility.
+  - Workaround implemented for signal handling on MacOS X.
+  - A trivial bug fixed in the stunnel.init script.
+  - Retry implemented on EAI_AGAIN error returned by resolver calls.
+
+Version 4.35, 2011.02.05, urgency: LOW:
+* New features
+  - Updated Win32 DLLs for OpenSSL 1.0.0c.
+  - Transparent source (non-local bind) added for FreeBSD 8.x.
+  - Transparent destination ("transparent = destination") added for Linux.
+* Bugfixes
+  - Fixed reload of FIPS-enabled stunnel.
+  - Compiler options are now auto-detected by ./configure script
+    in order to support obsolete versions of gcc.
+  - Async-signal-unsafe s_log() removed from SIGTERM/SIGQUIT/SIGINT handler.
+  - CLOEXEC file descriptor leaks fixed on Linux >= 2.6.28 with glibc >= 2.10.
+    Irreparable race condition leaks remain on other Unix platforms.
+    This issue may have security implications on some deployments:
+    http://udrepper.livejournal.com/20407.html
+  - Directory lib64 included in the OpenSSL library search path.
+  - Windows CE compilation fixes (thx to Pierre Delaage).
+  - Deprecated RSA_generate_key() replaced with RSA_generate_key_ex().
+* Domain name changes (courtesy of Bri Hatch)
+  - http://stunnel.mirt.net/ --> http://www.stunnel.org/
+  - ftp://stunnel.mirt.net/ --> http://ftp.stunnel.org/
+  - stunnel.mirt.net::stunnel --> rsync.stunnel.org::stunnel
+  - stunnel-users@mirt.net --> stunnel-users@stunnel.org
+  - stunnel-announce@mirt.net --> stunnel-announce@stunnel.org
+
+Version 4.34, 2010.09.19, urgency: LOW:
+* New features
+  - Updated Win32 DLLs for OpenSSL 1.0.0a.
+  - Updated Win32 DLLs for zlib 1.2.5.
+  - Updated automake to version 1.11.1
+  - Updated libtool to version 2.2.6b
+  - Added ECC support with a new service-level "curve" option.
+  - DH support is now enabled by default.
+  - Added support for OpenSSL builds with some algorithms disabled.
+  - ./configure modified to support cross-compilation.
+  - Sample stunnel.init updated based on Debian init script.
+* Bugfixes
+  - Implemented fixes in user interface to enter engine PIN.
+  - Fixed a transfer() loop issue on socket errors.
+  - Fixed missing Win32 taskbar icon while displaying a global option error.
+
+Version 4.33, 2010.04.05, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 1.0.0.
+    This library requires to c_rehash CApath/CRLpath directories on upgrade.
+  - Win32 DLLs for zlib 1.2.4.
+  - Experimental support for local mode on Win32 platform.
+    Try "exec = c:\windows\system32\cmd.exe".
+* Bugfixes
+  - Inetd mode fixed.
+
+Version 4.32, 2010.03.24, urgency: MEDIUM:
+* New features
+  - New service-level "libwrap" option for run-time control whether
+    /etc/hosts.allow and /etc/hosts.deny are used for access control.
+    Disabling libwrap significantly increases performance of stunnel.
+  - Win32 DLLs for OpenSSL 0.9.8m.
+* Bugfixes
+  - Fixed a transfer() loop issue with SSLv2 connections.
+  - Fixed a "setsockopt IP_TRANSPARENT" warning with "local" option.
+  - Logging subsystem bugfixes and cleanup.
+  - Installer bugfixes for Vista and later versions of Windows.
+  - FIPS mode can be enabled/disabled at runtime.
+
+Version 4.31, 2010.02.03, urgency: MEDIUM:
+* New features
+  - Log file reopen on USR1 signal was added.
+* Bugfixes
+  - Some regression issues introduced in 4.30 were fixed.
+
+Version 4.30, 2010.01.21, urgency: LOW/EXPERIMENTAL:
+* New features
+  - Graceful configuration reload with HUP signal on Unix
+    and with GUI on Windows.
+
+Version 4.29, 2009.12.02, urgency: MEDIUM:
+* New feature sponsored by Searchtech Limited http://www.astraweb.com/
+  - sessiond, a high performance SSL session cache was built for stunnel.
+    A new service-level "sessiond" option was added.  sessiond is
+    available for download on ftp://ftp.stunnel.org/stunnel/sessiond/ .
+    stunnel clusters will be a lot faster, now!
+* Bugfixes
+  - "execargs" defaults to the "exec" parameter (thx to Peter Pentchev).
+  - Compilation fixes added for AIX and old versions of OpenSSL.
+  - Missing "fips" option was added to the manual.
+
+Version 4.28, 2009.11.08, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 0.9.8l.
+  - Transparent proxy support on Linux kernels >=2.6.28.
+    See the manual for details.
+  - New socket options to control TCP keepalive on Linux:
+    TCP_KEEPCNT, TCP_KEEPIDLE, TCP_KEEPINTVL.
+  - SSL options updated for the recent version of OpenSSL library.
+* Bugfixes
+  - A serious bug in asynchronous shutdown code fixed.
+  - Data alignment updated in libwrap.c.
+  - Polish manual encoding fixed.
+  - Notes on compression implementation in OpenSSL added to the manual.
+
+Version 4.27, 2009.04.16, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 0.9.8k.
+  - FIPS support was updated for openssl-fips 1.2.
+  - New priority failover strategy for multiple "connect" targets,
+    controlled with "failover=rr" (default) or "failover=prio".
+  - pgsql protocol negotiation by Marko Kreen <markokr@gmail.com>.
+  - Building instructions were updated in INSTALL.W32 file.
+* Bugfixes
+  - Libwrap helper processes fixed to close standard
+    input/output/error file descriptors.
+  - OS2 compilation fixes.
+  - WCE fixes by Pierre Delaage <delaage.pierre@free.fr>.
+
+Version 4.26, 2008.09.20, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 0.9.8i.
+  - /etc/hosts.allow and /etc/hosts.deny no longer need to be
+    copied to the chrooted directory, as the libwrap processes
+    are no longer chrooted.
+  - A more informative error messages for invalid port number
+    specified in stunnel.conf file.
+  - Support for Microsoft Visual C++ 9.0 Express Edition.
+* Bugfixes
+  - Killing all libwrap processes at stunnel shutdown fixed.
+  - A minor bug in stunnel.init sample SysV startup file fixed.
+
+Version 4.25, 2008.06.01, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 0.9.8h.
+* Bugfixes
+  - Spawning libwrap processes delayed until privileges are dropped.
+  - Compilation fix for systems without struct msghdr.msg_control.
+
+Version 4.24, 2008.05.19, urgency: HIGH:
+* Bugfixes
+  - OCSP code was fixed to properly reject revoked certificates.
+
+Version 4.23, 2008.05.03, urgency: HIGH:
+* Bugfixes
+  - Local privilege escalation bug on Windows NT based
+    systems fixed.  A local user could exploit stunnel
+    running as a service to gain localsystem privileges.
+
+Version 4.22, 2008.03.28, urgency: MEDIUM:
+* New features
+  - Makefile was updated to use standard autoconf variables:
+    sysconfdir, localstatedir and pkglibdir.
+  - A new global option to control logging to syslog:
+      syslog = yes|no
+    Simultaneous logging to a file and the syslog is now possible.
+  - A new service-level option to control stack size:
+      stack = <number of bytes>
+* Bugfixes
+  - Restored chroot() to be executed after decoding numerical
+    userid and groupid values in drop_privileges().
+  - A few bugs fixed the in the new libwrap support code.
+  - TLSv1 method used by default in FIPS mode instead of
+    SSLv3 client and SSLv23 server methods.
+  - OpenSSL GPL license exception update based on
+    http://www.gnu.org/licenses/gpl-faq.html#GPLIncompatibleLibs
+
+Version 4.21, 2007.10.27, urgency: LOW/EXPERIMENTAL:
+* New features sponsored by Open-Source Software Institute
+  - Initial FIPS 140-2 support (see INSTALL.FIPS for details).
+    Win32 platform is not currently supported.
+* New features
+  - Experimental fast support for non-MT-safe libwrap is provided
+    with pre-spawned processes.
+  - Stunnel binary moved from /usr/local/sbin to /usr/local/bin
+    in order to meet FHS and LSB requirements.
+    Please delete the /usr/local/sbin/stunnel when upgrading.
+  - Added code to disallow compiling stunnel with pthreads when
+    OpenSSL is compiled without threads support.
+  - Win32 DLLs for OpenSSL 0.9.8g.
+  - Minor manual update.
+  - TODO file updated.
+* Bugfixes
+  - Dynamic locking callbacks added (needed by some engines to work).
+  - AC_ARG_ENABLE fixed in configure.am to accept yes/no arguments.
+  - On some systems libwrap requires yp_get_default_domain from libnsl,
+    additional checking for libnsl was added to the ./configure script.
+  - Sending a list of trusted CAs for the client to choose the right
+    certificate restored.
+  - Some compatibility issues with NTLM authentication fixed.
+  - Taskbar icon (unless there is a config file parsing error) and
+    "Save As" disabled in the service mode for local Win32 security
+    (it's much like Yeti -- some people claim they have seen it).
+
+Version 4.20, 2006.11.30, urgency: MEDIUM:
+* Release notes
+  - The new transfer() function has been well tested.
+    I recommend upgrading any previous version with this one.
+* Bugfixes
+  - Fixed support for encrypted passphrases on Unix (broken in 4.19).
+  - Reduced amount of debug logs.
+  - A minor man page update.
+
+Version 4.19, 2006.11.11, urgency: LOW/EXPERIMENTAL:
+* Release notes
+  - There are a lot of new features in this version.  I recommend
+    to test it well before upgrading your mission-critical systems.
+* New features
+  - New service-level option to specify OCSP server flag:
+    OCSPflag = <flag>
+  - "protocolCredentials" option changed to "protocolUsername"
+    and "protocolPassword"
+  - NTLM support to be enabled with the new service-level option:
+    protocolAuthentication = NTLM
+  - imap protocol negotiation support added.
+  - Passphrase cache was added so the user does not need to reenter
+    the same passphrase for each defined service any more.
+  - New service-level option to retry exec+connect section:
+    retry = yes|no
+  - Local IP and port is logged for each established connection.
+  - Win32 DLLs for OpenSSL 0.9.8d.
+* Bugfixes
+  - Serious problem with SSL_WANT_* retries fixed.
+    The new code requires extensive testing!
+
+Version 4.18, 2006.09.26, urgency: MEDIUM:
+* Bugfixes
+  - GPF on entering private key pass phrase on Win32 fixed.
+  - Updated OpenSSL Win32 DLLs.
+  - Minor configure script update.
+
+Version 4.17, 2006.09.10, urgency: MEDIUM:
+* New features
+  - Win32 DLLs for OpenSSL 0.9.8c.
+* Bugfixes
+  - Problem with detecting getaddrinfo() in ./configure fixed.
+  - Compilation problem due to misplaced #endif in ssl.c fixed.
+  - Duplicate 220 in smtp_server() function in protocol.c fixed.
+  - Minor os2.mak update.
+  - Minor update of safestring()/safename() macros.
+
+Version 4.16, 2006.08.31, urgency: MEDIUM:
+* New features sponsored by Hewlett-Packard
+  - A new global option to control engine:
+    engineCtrl = <command>[:<parameter>]
+  - A new service-level option to select engine to read private key:
+    engineNum = <engine number>
+  - OCSP support:
+    ocsp = <URL>
+* New features
+  - A new option to select version of SSL protocol:
+    sslVersion = all|SSLv2|SSLv3|TLSv1
+  - Visual Studio vc.mak by David Gillingham <dgillingham@gmail.com>.
+  - OS2 support by Paul Smedley (http://smedley.info)
+* Bugfixes
+  - An ordinary user can install stunnel again.
+  - Compilation problem with --enable-dh fixed.
+  - Some minor compilation warnings fixed.
+  - Service-level CRL cert store implemented.
+  - GPF on protocol negotiations fixed.
+  - Problem detecting addrinfo() on Tru64 fixed.
+  - Default group is now detected by configure script.
+  - Check for maximum number of defined services added.
+  - OpenSSL_add_all_algorithms() added to SSL initialization.
+  - configure script sections reordered to detect pthread library functions.
+  - RFC 2487 autodetection improved.  High resolution s_poll_wait()
+    not currently supported by UCONTEXT threading.
+  - More precise description of cert directory file names (thx to Muhammad
+    Muquit).
+* Other changes
+  - Maximum number of services increased from 64 to 256 when poll() is used.
+
+Version 4.15, 2006.03.11, urgency: LOW:
+* Release notes
+  - There are a lot of new features in this version.  I recommend
+    to test it well before upgrading your mission-critical systems.
+* Bugfixes
+  - Fix for pthreads on Solaris 10.
+  - Attempt to autodetect socklen_t type in configure script.
+  - Default threading model changed to pthread for better portability.
+  - DH parameters are not included in the certificate by default.
+* New features sponsored by Software House http://www.swhouse.com/
+  - Most SSL-related options (including client, cert, key) are now
+    available on service-level, so it is possible to have an SSL
+    client and an SSL server in a single stunnel process.
+  - Windows CE (version 3.0 and higher) support.
+* New features
+  - Client mode CONNECT protocol support (RFC 2817 section 5.2).
+    http://www.ietf.org/rfc/rfc2817.txt
+  - Retrying exec+connect services added.
+* File locations are more compliant to Filesystem Hierarchy Standard 2.3
+  - configuration and certificates are in $prefix/etc/stunnel/
+  - binaries are in $prefix/sbin/
+  - default pid file is $prefix/var/run/stunnel.pid
+  - manual is $prefix/man/man8/stunnel.8
+  - other docs are in $prefix/share/doc/stunnel/
+  - libstunnel is in $prefix/lib
+  - chroot directory is setup in $prefix/var/lib/stunnel/
+    this directory is chmoded 1770 and group nogroup
+
+Version 4.14, 2005.11.02, urgency: HIGH:
+* Bugfixes
+  - transfer() fixed to avoid random stalls introduced in version 4.12.
+  - poll() error handing bug fixed.
+  - Checking for dynamic loader libraries added again.
+  - Default pidfile changed from $localstatedir/run/stunnel.pid
+    to $localstatedir/stunnel/stunnel.pid.
+  - Basic SSL library initialization moved to the beginning of execution.
+* Release notes
+  - This is an important bugfix release.  Upgrade is recommended.
+
+Version 4.13, 2005.10.21, urgency: MEDIUM:
+* DLLs for OpenSSL 0.9.7i included because protection faults were reported
+  in 0.9.8 and 0.9.8a.
+* New features
+  - Libwrap code is executed as a separate process (no more delays due
+    to a global and potentially long critical section).
+* Bugfixes
+  - Problem with zombies in UCONTEXT threading fixed.
+  - Workaround for non-standard makecontext() uc_stack.ss_sp parameter
+    semantics on SGI IRIX.
+  - Protection fault in signals handling on IRIX fixed.
+  - Problem finding pthread library on AIX fixed.
+  - size_t printf() fixed in stack_info() (the previous fix didn't work).
+  - socklen_t is used instead of int where required.
+
+Version 4.12, 2005.09.29, urgency: MEDIUM:
+* New features
+  - Win32 installer added.
+  - New Win32 commandline options: -start and -stop.
+  - Log level and thread number are reported to syslog.
+  - DLLs for OpenSSL 0.9.8.
+  - stunnel.spec updated by neeo <neeo@irc.pl>.
+* Bugfixes
+  - Use of broken poll() is disabled on Mac OS X.
+  - Yet another transfer() infinite loop condition fixed.
+  - Workaround for a serious M$ bug (KB177346).
+  - IPv6 DLLs allocation problem resulting in GPF on W2K fixed.
+  - zlib added to shared libraries (OpenSSL may need it).
+  - size_t printf() fixed in stack_info().
+* Release notes
+  - This is a bugfix release.  Upgrade is recommended.
+
+Version 4.11, 2005.07.09, urgency: MEDIUM:
+* New features
+  - New ./configure option --with-threads to select thread model.
+  - ./configure option --with-tcp-wrappers renamed to --disable-libwrap.
+    I hope the meaning of the option is much more clear, now.
+* Bugfixes
+  - Workaround for non-standard makecontext() uc_stack.ss_sp parameter
+    semantics on Sparc/Solaris 9 and earlier.
+  - scan_waiting_queue() no longer drops contexts.
+  - Inetd mode GPFs with UCONTEXT fixed.
+  - Cleanup context is no longer used.
+  - Releasing memory of the current context is delayed.
+  - Win32 headers reordered for Visual Studio 7.
+  - Some Solaris compilation warnings fixed.
+  - Rejected inetd mode without 'connect' or 'exec'.
+* Release notes
+  - UCONTEXT threading seems stable, now.  Upgrade is recommended.
+
+Version 4.10, 2005.04.23, urgency: LOW/EXPERIMENTAL:
+* DLLs for OpenSSL 0.9.7g.
+* Bugfixes
+  - Missing locking on Win32 platform was added (thx to Yi Lin
+    <yi.lin@convergys.com>)
+  - Some problems with closing SSL fixed.
+* New features
+  - New UCONTEXT user-level non-preemptive threads model is used
+    on systems that support SYSV-compatible ucontext.h.
+  - Improved stunnel3 script with getopt-compatible syntax.
+* Release notes
+  - This version should be thoroughly tested before using it in the
+    mission-critical environment.
+
+Version 4.09, 2005.03.26, urgency: MEDIUM:
+* DLLs for OpenSSL 0.9.7f.
+* Bugfixes
+  - Compilation problem with undeclared socklen_t fixed.
+  - TIMEOUTclose is not used when there is any data in the buffers.
+  - Stunnel no longer relies on close_notify with SSL 2.0 connections,
+    since SSL 2.0 protocol does not have any alerts defined.
+  - Closing SSL socket when there is some data in SSL output buffer
+    is detected and reported as an error.
+  - Install/chmod race condition when installing default certificate fixed.
+  - Stunnel no longer installs signal_handler on ignored signals.
+
+Version 4.08, 2005.02.27, urgency: LOW:
+* New features
+  - New -quiet option was added to install NT service without a message box.
+* Bugfixes
+  - Using $(DESTDIR) in tools/Makefile.am.
+  - Define NI_NUMERICHOST and NI_NUMERICSERV when needed.
+  - Length of configuration file line increased from 256B to 16KB.
+  - Stunnel sends close_notify when a close_notify is received from SSL
+    peer and all remaining data is sent to SSL peer.
+  - Some fixes for bugs detected by the watchdog.
+* Release notes
+  - There were many changes in the transfer() function (the main loop).
+  - This version should be thoroughly tested before using it in the
+    mission-critical environment.
+
+Version 4.07, 2005.01.03, urgency: MEDIUM:
+* Bugfixes
+  - Problem with infinite poll() timeout negative, but not equal to -1 fixed.
+  - Problem with a file descriptor ready to be read just after a non-blocking
+    connect call fixed.
+  - Compile error with EAI_NODATA not defined or equal to EAI_NONAME fixed.
+  - IP address and TCP port textual representation length (IPLEN) increased
+    to 128 bytes.
+  - OpenSSL engine support is only used if engine.h header file exists.
+  - Broken NT Service mode on Win32 platform fixed.
+  - Support for IPv4-only Win32 machines restored.
+
+Version 4.06, 2004.12.26, urgency: LOW:
+* New feature sponsored by SURFnet http://www.surfnet.nl/
+  - IPv6 support (to be enabled with ./configure --enable-ipv6).
+* New features
+  - poll() support - no more FD_SETSIZE limit!
+  - Multiple connect=host:port options are allowed in a single service
+    section.  Remote hosts are connected using round-robin algorithm.
+    This feature is not compatible with delayed resolver.
+  - New 'compression' option to enable compression.  To use zlib
+    algorithm you have to enable it when building OpenSSL library.
+  - New 'engine' option to select a hardware engine.
+  - New 'TIMEOUTconnect' option with 10 seconds default added.
+  - stunnel3 perl script to emulate version 3.x command line options.
+  - French manual updated by Bernard Choppy <choppy AT free POINT fr>.
+  - A watchdog to detect transfer() infinite loops added.
+  - Configuration file comment character changed from '#' to ';'.
+    '#' will still be recognized to keep compatibility.
+  - MT-safe getaddrinfo() and getnameinfo() are used where available
+    to get better performance on resolver calls.
+  - Automake upgraded from 1.4-p4 to 1.7.9.
+* Bugfixes
+  - log() changed to s_log() to avoid conflicts on some systems.
+  - Common CRIT_INET critical section introduced instead of separate
+    CRIT_NTOA and CRIT_RESOLVER to avoid potential problems with
+    libwrap (TCP Wrappers) library.
+  - CreateThread() finally replaced with _beginthread() on Win32.
+  - make install creates $(localstatedir)/stunnel.
+    $(localstatedir)/stunnel/dev/zero is also created on Solaris.
+  - Race condition with client session cache fixed.
+  - Other minor bugfixes.
+* Release notes
+  - Win32 port requires Winsock2 to work.
+    Some Win95 systems may need a free update from Microsoft.
+    http://www.microsoft.com/windows95/downloads/
+  - Default is *not* to use IPv6 '::' for accept and '::1' for
+    connect.  For example to accept pop3s on IPv6 you could use:
+    'accept = :::995'.  I hope the new syntax is clear enough.
+
+Version 4.05, 2004.02.14, urgency: MEDIUM:
+* New feature sponsored by SURFnet http://www.surfnet.nl/
+  - Support for CIFS aka SMB protocol SSL negotiation.
+* New features
+  - CRL support with new CRLpath and CRLfile global options.
+  - New 'taskbar' option on Win32 (thx to Ken Mattsen
+    <ken.Mattsen@roxio.com>).
+  - New -fd command line parameter to read configuration
+    from a specified file descriptor instead of a file.
+  - accept is reported as error when no '[section]' is
+    defined (in stunnel 4.04 it was silently ignored causing
+    problems for lusers who did not read the fine manual).
+  - Use fcntl() instead of ioctlsocket() to set socket
+    nonblocking where it is supported.
+  - Basic support for hardware engines with OpenSSL >= 0.9.7.
+  - French manual by Bernard Choppy <choppy@imaginet.fr>.
+  - Thread stack size reduced to 64KB for maximum scalability.
+  - Added optional code to debug thread stack usage.
+  - Support for nsr-tandem-nsk (thx to Tom Bates <tom.bates@hp.com>).
+* Bugfixes
+  - TCP wrappers code moved to CRIT_NTOA critical section
+    since it uses static inet_ntoa() result buffer.
+  - SSL_ERROR_SYSCALL handling problems fixed.
+  - added code to retry nonblocking SSL_shutdown() calls.
+  - Use FD_SETSIZE instead of 16 file descriptors in inetd
+    mode.
+  - fdscanf groks lowercase protocol negotiation commands.
+  - Win32 taskbar GDI objects leak fixed.
+  - Libwrap detection bug in ./configure script fixed.
+  - grp.h header detection fixed for NetBSD and possibly
+    other systems.
+  - Some other minor updates.
+
+Version 4.04, 2003.01.12, urgency: MEDIUM:
+* New feature sponsored by SURFnet http://www.surfnet.nl/
+  - Encrypted private key can be used with Win32 GUI.
+* New features
+  - New 'options' configuration option to setup
+    OpenSSL library hacks with SSL_CTX_set_options().
+  - 'service' option also changes the name for
+    TCP Wrappers access control in inetd mode.
+  - Support for BeOS (thx to Mike I. Kozin <mik@sbor.net>)
+  - SSL is negotiated before connecting remote host
+    or spawning local process whenever possible.
+  - REMOTE_HOST variable is always placed in the
+    enrivonment of a process spawned with 'exec'.
+  - Whole SSL error stack is dumped on errors.
+  - 'make cert' rule is back (was missing since 4.00).
+  - Manual page updated (special thanks to Brian Hatch).
+  - TODO updated.
+* Bugfixes
+  - Major code cleanup (thx to Steve Grubb <linux_4ever@yahoo.com>).
+  - Unsafe functions are removed from SIGCHLD handler.
+  - Several bugs in auth_user() fixed.
+  - Incorrect port when using 'local' option fixed.
+  - OpenSSL tools '-rand' option is no longer directly
+    used with a device (like '/dev/urandom').
+    Temporary random file is created with 'dd' instead.
+* DLLs for OpenSSL 0.9.7.
+
+Version 4.03, 2002.10.27, urgency: HIGH:
+* NT Service (broken since 4.01) is operational again.
+* Memory leak in FORK environments fixed.
+* sigprocmask() mistake corrected.
+* struct timeval is reinitialized before select().
+* EAGAIN handled in client.c for AIX.
+* Manual page updated.
+
+Version 4.02, 2002.10.21, urgency: HIGH:
+* Serious bug in ECONNRESET handling fixed.
+
+Version 4.01, 2002.10.20, urgency: MEDIUM:
+* New features
+  - OpenVMS support.
+  - Polish manual and some manual updates.
+  - 'service' option added on Win32 platform.
+  - Obsolete FAQ has been removed.
+  - Log file is created with 0640 mode.
+  - exec->connect service sections (need more testing).
+* Bugfixes
+  - EINTR ingored in main select() loop.
+  - Fixed problem with stunnel closing connections on
+    TIMEOUTclose before all the data is sent.
+  - Fixed EWOULDBLOCK on writesocket problem.
+  - Potential DOS in Win32 GUI fixed.
+  - Solaris compilation problem fixed.
+  - Libtool configuration problems fixed.
+  - Signal mask is cleared just before exec in local mode.
+  - Accepting sockets and log file descriptors are no longer
+    leaked to the child processes.
+Special thanks to Steve Grubb for the source code audit.
+
+Version 4.00, 2002.08.30, urgency: LOW:
+* New features sponsored by MAXIMUS http://www.maximus.com/
+  - New user interface (config file).
+  - Single daemon can listen on multiple ports, now.
+  - Native Win32 GUI added.
+  - Native NT/2000/XP service added.
+  - Delayed DNS lookup added.
+* Other new features
+  - All the timeouts are now configurable including
+    TIMEOUTclose that can be set to 0 for MSIE and other
+    buggy clients that do not send close_notify.
+  - Stunnel process can be chrooted in a specified directory.
+  - Numerical values for setuid() and setgid() are allowed, now.
+  - Confusing code for setting certificate defaults introduced in
+    version 3.8p3 was removed to simplify stunnel setup.
+    There are no built-in defaults for CApath and CAfile options.
+  - Private key file for a certificate can be kept in a separate
+    file.  Default remains to keep it in the cert file.
+  - Manual page updated.
+  - New FHS-compatible build system based on automake and libtool.
+* Bugfixes
+  - `SSL socket closed on SSL_write' problem fixed.
+  - Problem with localtime() crashing Solaris 8 fixed.
+  - Problem with tcp wrappers library detection fixed.
+  - Cygwin (http://www.cygwin.com/) support added.
+  - __svr4__ macro defined for Sun C/C++ compiler.
+* DLLs for OpenSSL 0.9.6g.
+
+Version 3.22, 2001.12.20, urgency: HIGH:
+* Format string bug fixed in protocol.c
+  smtp, pop3 and nntp in client mode were affected.
+  (stunnel clients could be attacked by malicious servers)
+* Certificate chain can be supplied with -p option or in stunnel.pem.
+* Problem with -r and -l options used together fixed.
+* memmove() instead of memcpy() is used to move data in buffers.
+* More detailed information about negotiated ciphers is printed.
+* New ./configure options: '--enable-no-rsa' and '--enable-dh'.
+
+Version 3.21c, 2001.11.11, urgency: LOW:
+* autoconf scripts upgraded to version 2.52.
+* Problem with pthread_sigmask on Darwin fixed (I hope).
+* Some documentation typos corrected.
+* Attempt to ignore EINTR in transfer().
+* Shared library version reported on startup.
+* DLLs for OpenSSL 0.9.6b.
+
+Version 3.21b, 2001.11.03, urgency: MEDIUM:
+* File descriptor leak on failed connect() fixed.
+
+Version 3.21a, 2001.10.31, urgency: MEDIUM:
+* Small bug in Makefile fixed.
+
+Version 3.21, 2001.10.31, urgency: MEDIUM:
+* Problem with errno and posix threads fixed.
+* It is assumed that system has getopt() if it has getopt.h header file.
+* SSL_CLIENT_DN and SSL_CLIENT_I_DN environment variables set in local mode
+  (-l) process.  This feature doesn't work if
+  client mode (-c) or protocol negotiation (-n) is used.
+* Winsock error descriptions hardcoded (English version only).
+* SetConsoleCtrlHandler() used to handle CTRL+C, logoff and shutdown on Win32.
+* Stunnel always requests peer certificate with -v 0.
+* sysconf()/getrlimit() used to calculate number of clients allowed.
+* SSL mode changed for OpenSSL >= 0.9.6.
+* close-on-exec option used to avoid socket inheriting.
+* Buffer size increased from 8KB to 16KB.
+* fdscanf()/fdprintf() changes:
+   - non-blocking socket support,
+   - timeout after 1 minute of inactivity.
+* auth_user() redesigned to force 1 minute timeout.
+* Some source arrangement towards 4.x architecture.
+* No need for 'goto' any more.
+* New Makefile 'test' rule.  It performs basic test of
+  standalone/inetd, remote/local and server/client mode.
+* pop3 server mode support added.
+
+Version 3.20, 2001.08.15, urgency: LOW:
+* setsockopt() optlen set according to the optval for Solaris.
+* Minor NetBSD compatibility fixes by Martti Kuparinen.
+* Minor MSVC 6.0 compatibility fixes by Patrick Mayweg.
+* SSL close_notify timeout reduced to 10 seconds of inactivity.
+* Socket close instead of reset on close_notify timeout.
+* Some source arrangement and minor bugfixes.
+
+Version 3.19, 2001.08.10, urgency: MEDIUM:
+* Critical section added around non MT-safe TCP Wrappers code.
+* Problem with 'select: Interrupted system call' error fixed.
+* errno replaced with get_last_socket_error() for Win32.
+* Some FreeBSD/NetBSD patches to ./configure from Martti Kuparinen.
+* Local mode process pid logged.
+* Default FQDN (localhost) removed from stunnel.cnf
+* ./configure changed to recognize POSIX threads library on OSF.
+* New -O option to set socket options.
+
+Version 3.18, 2001.07.31, urgency: MEDIUM:
+* MAX_CLIENTS is calculated based on FD_SETSIZE, now.
+* Problems with closing SSL in transfer() fixed.
+* -I option to bind a static local IP address added.
+* Debug output of info_callback redesigned.
+
+Version 3.17, 2001.07.29, urgency: MEDIUM:
+* Problem with GPF on exit with active threads fixed.
+* Timeout for transfer() function added:
+   - 1 hour if socket is open for read
+   - 1 minute if socket is closed for read
+
+Version 3.16, 2001.07.22, urgency: MEDIUM:
+* Some transfer() bugfixes/improvements.
+* STDIN/STDOUT are no longer assumed to be non-socket descriptors.
+* Problem with --with-tcp-wrappers patch fixed.
+* pop3 and nntp support bug fixed by Martin Germann.
+* -o option to append log messages to a file added.
+* Changed error message for SSL error 0.
+
+Version 3.15, 2001.07.15, urgency: MEDIUM:
+* Serious bug resulting in random transfer() hangs fixed.
+* Separate file descriptors are used for inetd mode.
+* -f (foreground) logs are now stamped with time.
+* New ./configure option: --with-tcp-wrappers by Brian Hatch.
+* pop3 protocol client support (-n pop3) by Martin Germann.
+* nntp protocol client support (-n nntp) by Martin Germann.
+* RFC 2487 (smtp STARTTLS) client mode support.
+* Transparency support for Tru64 added.
+* Some #includes for AIX added.
+
+Version 3.14, 2001.02.21, urgency: LOW:
+* Pidfile creation algorithm has been changed.
+
+Version 3.13, 2001.01.25, urgency: MEDIUM:
+* pthread_sigmask() argument in sthreads.c corrected.
+* OOB data is now handled correctly.
+
+Version 3.12, 2001.01.24, urgency: LOW:
+* Attempted to fix problem with zombies in local mode.
+* Patch for 64-bit machines by Nalin Dahyabhai <nalin@redhat.com> applied.
+* Tiny bugfix for OSF cc by Dobrica Pavlinusic <dpavlin@rot13.org> added.
+* PORTS file updated.
+
+Version 3.11, 2000.12.21, urgency: MEDIUM:
+* New problem with zombies fixed.
+* Attempt to be integer-size independent.
+* SIGHUP handler added.
+
+Version 3.10, 2000.12.19, urgency: MEDIUM:
+* Internal thread synchronization code added.
+* libdl added to stunnel dependencies if it exists.
+* Manpage converted to sdf format.
+* stunnel deletes pid file before attempting to create it.
+* Documentation updates.
+* -D option now takes [facility].level as argument.  0-7 still supported.
+* Problems with occasional zombies in FORK mode fixed.
+* 'stunnel.exe' rule added to Makefile.
+  You can cross-compile stunnel.exe on Unix, now.
+  I'd like to be able to compile OpenSSL this way, too...
+
+Version 3.9, 2000.12.13, urgency: HIGH:
+* Updated temporary key generation:
+   - stunnel is now honoring requested key-lengths correctly,
+   - temporary key is changed every hour.
+* transfer() no longer hangs on some platforms.
+  Special thanks to Peter Wagemans for the patch.
+* Potential security problem with syslog() call fixed.
+
+Version 3.8p4, 2000.06.25  bri@stunnel.org:
+* fixes for Windows platform
+
+Version 3.8p3, 2000.06.24  bri@stunnel.org:
+* Compile time definitions for the following:
+    --with-cert-dir
+    --with-cert-file
+    --with-pem-dir
+    --enable-ssllib-cs
+* use daemon() function instead of daemonize, if available
+* fixed FreeBSD threads checking (patch from robertw@wojo.com)
+* added -S flag, allowing you to choose which default verify
+  sources to use
+* relocated service name output logging until after log_open.
+  (no longer outputs log info to inetd socket, causing bad SSL)
+* -V flag now outputs the default values used by stunnel
+* Removed DH param generation in Makefile.in
+* Moved stunnel.pem to sample.pem to keep people from blindly using it
+* Removed confusing stunnel.pem check from Makefile.
+
+* UPGRADE NOTE: this version seriously changes several previous stunnel
+  default behaviours.  There are no longer any default cert file/dirs
+  compiled into stunnel, you must use the --with-cert-dir and
+  --with-cert-file configure arguments to set these manually, if desired.
+  Stunnel does not use the underlying ssl library defaults by default
+  unless configured with --enable-ssllib-cs.  Note that these can always
+  be enabled at run time with the -A,-a, and -S flags.
+  Additionally, unless --with-pem-dir is specified at compile time,
+  stunnel will default to looking for stunnel.pem in the current directory.
+
+Version 3.8p2, 2000.06.13  bri@stunnel.org:
+* Fixes for Win32 platform
+* Minor output formatting changes
+* Fixed version number in files
+
+Version 3.8p1, 2000.06.11  bri@stunnel.org:
+* Added rigorous PRNG seeding
+* PID changes (and related security-fix)
+* Man page fixes
+* Client SSL Session-IDs now used
+* -N flag to specify tcpwrapper service name
+
+Version 3.8, 2000.02.24:
+* Checking for threads in c_r library for FreeBSD.
+* Some compatibility fixes for Ultrix.
+* configure.in has been cleaned up.
+  Separate directories for SSL certs and SSL libraries/headers
+  are no longer supported.  SSL ports maintainers should create
+  softlinks in the main openssl directory if necessary.
+* Added --with-ssl option to specify SSL directory.
+* Added setgid (-g) option.
+  (Special thanks to Brian Hatch for his feedback and support)
+* Added pty.c based on a Public Domain code by Tatu Ylonen
+* Distribution files are now signed with GnuPG
+
+Version 3.7, 2000.02.10:
+* /usr/pkg added to list of possible SSL directories for pkgsrc installs
+  of OpenSSL under NetBSD.
+* Added the -s option, which setuid()s to the specified user when running
+  in daemon mode. Useful for cyrus imapd.
+  (both based on patch by George Coulouris)
+* PTY code ported to Solaris.  The port needs some more testing.
+* Added handler for SIGINT.
+* Added --with-random option to ./configure script.
+* Fixed some problems with autoconfiguration on Solaris and others.
+  It doesn't use config.h any more.
+* /var/run changed to @localstatedir@/stunnel for better portability.
+  The directory is chmoded a=rwx,+t.
+* FAQ has been updated.
+
+3.6 2000.02.03
+* Automatic RFC 2487 detection based on patch by Pascual Perez and Borja Perez.
+* Non-blocking sockets not used by default.
+* DH support is disabled by default.
+* (both can be enabled in ssl.c)
+
+3.5 2000.02.02
+* Support for openssl 0.9.4 added.
+* /usr/ssl added to configure by Christian Zuckschwerdt.
+* Added tunneling for PPP through the addition of PTY handling.
+* Added some documentation.
+
+3.4a 1999.07.13 (bugfix release)
+* Problem with cipher negotiation fixed.
+* setenv changed to putenv.
+
+3.4 1999.07.12
+* Local transparent proxy added with LD_PRELOADed shared library.
+* DH code rewritten.
+* Added -C option to set cipher list.
+* stderr fflushed after fprintf().
+* Minor portability bugfixes.
+* Manual updated (but still not perfect).
+
+3.3 1999.06.18
+* Support for openssl 0.9.3 added.
+* Generic support for protocol negotiation added (protocol.c).
+* SMTP protocol negotiation support for Netscape client added.
+* Transparent proxy mode (currently works on Linux only).
+* SO_REUSEADDR enabled on listening socket in daemon mode.
+* ./configure now accepts --prefix parameter.
+* -Wall is only used with gcc compiler.
+* Makefile.in and configure.in updated.
+* SSL-related functions moved to a separate file.
+* vsprintf changed to vsnprintf in log.c on systems have it.
+* Pidfile in /var/run added for daemon mode.
+* RSAref support fix (not tested).
+* Some compatibility fixes for Solaris and NetBSD added.
+
+3.2 1999.04.28
+* RSAref support (not tested).
+* Added full duplex with non-blocking sockets.
+* RST sent instead of FIN on peer error (on error peer
+  socket is reset - not just closed).
+* RSA temporary key length changed back to 512 bits to fix
+  a problem with Netscape.
+* Added NO_RSA for US citizens having problems with patents.
+
+3.1 1999.04.22
+* Changed -l syntax (first argument specified is now argv[0]).
+* Fixed problem with options passed to locally executed daemon.
+* Fixed problem with ':' passed to libwrap in a service name:
+  - ':' has been changed to '.';
+  - user can specify his own service name as an argument.
+* RSA temporary key length changed from 512 to 1024 bits.
+* Added safecopy to avoid buffer overflows in stunnel.c.
+* Fixed problems with GPF after unsuccessful resolver call
+  and incorrect parameters passed to getopt() in Win32.
+* FAQ updated.
+
+3.0 1999.04.19
+* Some bugfixes.
+* FAQ added.
+
+3.0b7 1999.04.14
+* Win32 native port fixed (looks quite stable).
+* New transfer() function algorithm.
+* New 'make cert' to be compatible with openssl-0.9.2b.
+* Removed support for memory leaks debugging.
+
+3.0b6 1999.04.01
+* Fixed problems with session cache (by Adam).
+* Added client mode session cache.
+* Source structure, autoconf script and Makefile changed.
+* Added -D option to set debug level.
+* Added support for memory leaks debugging
+  (SSL library needs to be compiled with -DMFUNC).
+
+3.0b5 1999.03.25
+* Lots of changes to make threads work.
+* Peer (client and server) authentication works!
+* Added -V option to display version.
+
+3.0b4 1999.03.22
+* Early POSIX threads implementation.
+* Work on porting to native Win32 application started.
+
+3.0b3 1999.03.05
+* Improved behavior on heavy load.
+
+3.0b2 1999.03.04
+* Fixed -v parsing bug.
+
+3.0b1 1999.01.18
+* New user interface.
+* Client mode added.
+* Peer certificate verification added (=strong authentication).
+* Win32 port added.
+* Other minor problems fixed.
+
+2.1 1998.06.01
+* Few bugs fixed.
+
+2.0 1998.05.25
+* Remote mode added!
+* Standalone mode added!
+* tcpd functionality added by libwrap utilization.
+* DH callbacks removed by kravietZ.
+* bind loopback on Intel and other bugs fixed by kravietZ.
+* New manual page by kravietZ & myself.
+
+1.6 1998.02.24
+* Linux bind fix.
+* New TODO ideas!
+
+1.5 1998.02.24
+* make_sockets() implemented with Internet sockets instead
+  of Unix sockets for better compatibility.
+  (i.e. to avoid random data returned by getpeername(2))
+  This feature can be disabled in stunnel.c.
+
+1.4 1998.02.16
+* Ported to HP-UX, Solaris and probably other UNIXes.
+* Autoconfiguration added.
+
+1.3 1998.02.14
+* Man page by Pawel Krawczyk <kravietz@ceti.com.pl> added!
+* Copyrights added.
+* Minor errors corrected.
+
+1.2 1998.02.14
+* Separate certificate for each service added.
+* Connection logging support.
+
+1.1 1998.02.14
+* Callback functions added by Pawel Krawczyk <kravietz@ceti.com.pl>.
+
+1.0 1998.02.11
+* First version with SSL support
+  - special thx to Adam Hernik <adas@infocentrum.com>.
+
+0.1 1998.02.10
+* Testing skeleton.
+
diff --git a/INSTALL b/INSTALL
new file mode 100644
index 0000000..2099840
--- /dev/null
+++ b/INSTALL
@@ -0,0 +1,370 @@
+Installation Instructions
+*************************
+
+Copyright (C) 1994-1996, 1999-2002, 2004-2013 Free Software Foundation,
+Inc.
+
+   Copying and distribution of this file, with or without modification,
+are permitted in any medium without royalty provided the copyright
+notice and this notice are preserved.  This file is offered as-is,
+without warranty of any kind.
+
+Basic Installation
+==================
+
+   Briefly, the shell command `./configure && make && make install'
+should configure, build, and install this package.  The following
+more-detailed instructions are generic; see the `README' file for
+instructions specific to this package.  Some packages provide this
+`INSTALL' file but do not implement all of the features documented
+below.  The lack of an optional feature in a given package is not
+necessarily a bug.  More recommendations for GNU packages can be found
+in *note Makefile Conventions: (standards)Makefile Conventions.
+
+   The `configure' shell script attempts to guess correct values for
+various system-dependent variables used during compilation.  It uses
+those values to create a `Makefile' in each directory of the package.
+It may also create one or more `.h' files containing system-dependent
+definitions.  Finally, it creates a shell script `config.status' that
+you can run in the future to recreate the current configuration, and a
+file `config.log' containing compiler output (useful mainly for
+debugging `configure').
+
+   It can also use an optional file (typically called `config.cache'
+and enabled with `--cache-file=config.cache' or simply `-C') that saves
+the results of its tests to speed up reconfiguring.  Caching is
+disabled by default to prevent problems with accidental use of stale
+cache files.
+
+   If you need to do unusual things to compile the package, please try
+to figure out how `configure' could check whether to do them, and mail
+diffs or instructions to the address given in the `README' so they can
+be considered for the next release.  If you are using the cache, and at
+some point `config.cache' contains results you don't want to keep, you
+may remove or edit it.
+
+   The file `configure.ac' (or `configure.in') is used to create
+`configure' by a program called `autoconf'.  You need `configure.ac' if
+you want to change it or regenerate `configure' using a newer version
+of `autoconf'.
+
+   The simplest way to compile this package is:
+
+  1. `cd' to the directory containing the package's source code and type
+     `./configure' to configure the package for your system.
+
+     Running `configure' might take a while.  While running, it prints
+     some messages telling which features it is checking for.
+
+  2. Type `make' to compile the package.
+
+  3. Optionally, type `make check' to run any self-tests that come with
+     the package, generally using the just-built uninstalled binaries.
+
+  4. Type `make install' to install the programs and any data files and
+     documentation.  When installing into a prefix owned by root, it is
+     recommended that the package be configured and built as a regular
+     user, and only the `make install' phase executed with root
+     privileges.
+
+  5. Optionally, type `make installcheck' to repeat any self-tests, but
+     this time using the binaries in their final installed location.
+     This target does not install anything.  Running this target as a
+     regular user, particularly if the prior `make install' required
+     root privileges, verifies that the installation completed
+     correctly.
+
+  6. You can remove the program binaries and object files from the
+     source code directory by typing `make clean'.  To also remove the
+     files that `configure' created (so you can compile the package for
+     a different kind of computer), type `make distclean'.  There is
+     also a `make maintainer-clean' target, but that is intended mainly
+     for the package's developers.  If you use it, you may have to get
+     all sorts of other programs in order to regenerate files that came
+     with the distribution.
+
+  7. Often, you can also type `make uninstall' to remove the installed
+     files again.  In practice, not all packages have tested that
+     uninstallation works correctly, even though it is required by the
+     GNU Coding Standards.
+
+  8. Some packages, particularly those that use Automake, provide `make
+     distcheck', which can by used by developers to test that all other
+     targets like `make install' and `make uninstall' work correctly.
+     This target is generally not run by end users.
+
+Compilers and Options
+=====================
+
+   Some systems require unusual options for compilation or linking that
+the `configure' script does not know about.  Run `./configure --help'
+for details on some of the pertinent environment variables.
+
+   You can give `configure' initial values for configuration parameters
+by setting variables in the command line or in the environment.  Here
+is an example:
+
+     ./configure CC=c99 CFLAGS=-g LIBS=-lposix
+
+   *Note Defining Variables::, for more details.
+
+Compiling For Multiple Architectures
+====================================
+
+   You can compile the package for more than one kind of computer at the
+same time, by placing the object files for each architecture in their
+own directory.  To do this, you can use GNU `make'.  `cd' to the
+directory where you want the object files and executables to go and run
+the `configure' script.  `configure' automatically checks for the
+source code in the directory that `configure' is in and in `..'.  This
+is known as a "VPATH" build.
+
+   With a non-GNU `make', it is safer to compile the package for one
+architecture at a time in the source code directory.  After you have
+installed the package for one architecture, use `make distclean' before
+reconfiguring for another architecture.
+
+   On MacOS X 10.5 and later systems, you can create libraries and
+executables that work on multiple system types--known as "fat" or
+"universal" binaries--by specifying multiple `-arch' options to the
+compiler but only a single `-arch' option to the preprocessor.  Like
+this:
+
+     ./configure CC="gcc -arch i386 -arch x86_64 -arch ppc -arch ppc64" \
+                 CXX="g++ -arch i386 -arch x86_64 -arch ppc -arch ppc64" \
+                 CPP="gcc -E" CXXCPP="g++ -E"
+
+   This is not guaranteed to produce working output in all cases, you
+may have to build one architecture at a time and combine the results
+using the `lipo' tool if you have problems.
+
+Installation Names
+==================
+
+   By default, `make install' installs the package's commands under
+`/usr/local/bin', include files under `/usr/local/include', etc.  You
+can specify an installation prefix other than `/usr/local' by giving
+`configure' the option `--prefix=PREFIX', where PREFIX must be an
+absolute file name.
+
+   You can specify separate installation prefixes for
+architecture-specific files and architecture-independent files.  If you
+pass the option `--exec-prefix=PREFIX' to `configure', the package uses
+PREFIX as the prefix for installing programs and libraries.
+Documentation and other data files still use the regular prefix.
+
+   In addition, if you use an unusual directory layout you can give
+options like `--bindir=DIR' to specify different values for particular
+kinds of files.  Run `configure --help' for a list of the directories
+you can set and what kinds of files go in them.  In general, the
+default for these options is expressed in terms of `${prefix}', so that
+specifying just `--prefix' will affect all of the other directory
+specifications that were not explicitly provided.
+
+   The most portable way to affect installation locations is to pass the
+correct locations to `configure'; however, many packages provide one or
+both of the following shortcuts of passing variable assignments to the
+`make install' command line to change installation locations without
+having to reconfigure or recompile.
+
+   The first method involves providing an override variable for each
+affected directory.  For example, `make install
+prefix=/alternate/directory' will choose an alternate location for all
+directory configuration variables that were expressed in terms of
+`${prefix}'.  Any directories that were specified during `configure',
+but not in terms of `${prefix}', must each be overridden at install
+time for the entire installation to be relocated.  The approach of
+makefile variable overrides for each directory variable is required by
+the GNU Coding Standards, and ideally causes no recompilation.
+However, some platforms have known limitations with the semantics of
+shared libraries that end up requiring recompilation when using this
+method, particularly noticeable in packages that use GNU Libtool.
+
+   The second method involves providing the `DESTDIR' variable.  For
+example, `make install DESTDIR=/alternate/directory' will prepend
+`/alternate/directory' before all installation names.  The approach of
+`DESTDIR' overrides is not required by the GNU Coding Standards, and
+does not work on platforms that have drive letters.  On the other hand,
+it does better at avoiding recompilation issues, and works well even
+when some directory options were not specified in terms of `${prefix}'
+at `configure' time.
+
+Optional Features
+=================
+
+   If the package supports it, you can cause programs to be installed
+with an extra prefix or suffix on their names by giving `configure' the
+option `--program-prefix=PREFIX' or `--program-suffix=SUFFIX'.
+
+   Some packages pay attention to `--enable-FEATURE' options to
+`configure', where FEATURE indicates an optional part of the package.
+They may also pay attention to `--with-PACKAGE' options, where PACKAGE
+is something like `gnu-as' or `x' (for the X Window System).  The
+`README' should mention any `--enable-' and `--with-' options that the
+package recognizes.
+
+   For packages that use the X Window System, `configure' can usually
+find the X include and library files automatically, but if it doesn't,
+you can use the `configure' options `--x-includes=DIR' and
+`--x-libraries=DIR' to specify their locations.
+
+   Some packages offer the ability to configure how verbose the
+execution of `make' will be.  For these packages, running `./configure
+--enable-silent-rules' sets the default to minimal output, which can be
+overridden with `make V=1'; while running `./configure
+--disable-silent-rules' sets the default to verbose, which can be
+overridden with `make V=0'.
+
+Particular systems
+==================
+
+   On HP-UX, the default C compiler is not ANSI C compatible.  If GNU
+CC is not installed, it is recommended to use the following options in
+order to use an ANSI C compiler:
+
+     ./configure CC="cc -Ae -D_XOPEN_SOURCE=500"
+
+and if that doesn't work, install pre-built binaries of GCC for HP-UX.
+
+   HP-UX `make' updates targets which have the same time stamps as
+their prerequisites, which makes it generally unusable when shipped
+generated files such as `configure' are involved.  Use GNU `make'
+instead.
+
+   On OSF/1 a.k.a. Tru64, some versions of the default C compiler cannot
+parse its `<wchar.h>' header file.  The option `-nodtk' can be used as
+a workaround.  If GNU CC is not installed, it is therefore recommended
+to try
+
+     ./configure CC="cc"
+
+and if that doesn't work, try
+
+     ./configure CC="cc -nodtk"
+
+   On Solaris, don't put `/usr/ucb' early in your `PATH'.  This
+directory contains several dysfunctional programs; working variants of
+these programs are available in `/usr/bin'.  So, if you need `/usr/ucb'
+in your `PATH', put it _after_ `/usr/bin'.
+
+   On Haiku, software installed for all users goes in `/boot/common',
+not `/usr/local'.  It is recommended to use the following options:
+
+     ./configure --prefix=/boot/common
+
+Specifying the System Type
+==========================
+
+   There may be some features `configure' cannot figure out
+automatically, but needs to determine by the type of machine the package
+will run on.  Usually, assuming the package is built to be run on the
+_same_ architectures, `configure' can figure that out, but if it prints
+a message saying it cannot guess the machine type, give it the
+`--build=TYPE' option.  TYPE can either be a short name for the system
+type, such as `sun4', or a canonical name which has the form:
+
+     CPU-COMPANY-SYSTEM
+
+where SYSTEM can have one of these forms:
+
+     OS
+     KERNEL-OS
+
+   See the file `config.sub' for the possible values of each field.  If
+`config.sub' isn't included in this package, then this package doesn't
+need to know the machine type.
+
+   If you are _building_ compiler tools for cross-compiling, you should
+use the option `--target=TYPE' to select the type of system they will
+produce code for.
+
+   If you want to _use_ a cross compiler, that generates code for a
+platform different from the build platform, you should specify the
+"host" platform (i.e., that on which the generated programs will
+eventually be run) with `--host=TYPE'.
+
+Sharing Defaults
+================
+
+   If you want to set default values for `configure' scripts to share,
+you can create a site shell script called `config.site' that gives
+default values for variables like `CC', `cache_file', and `prefix'.
+`configure' looks for `PREFIX/share/config.site' if it exists, then
+`PREFIX/etc/config.site' if it exists.  Or, you can set the
+`CONFIG_SITE' environment variable to the location of the site script.
+A warning: not all `configure' scripts look for a site script.
+
+Defining Variables
+==================
+
+   Variables not defined in a site shell script can be set in the
+environment passed to `configure'.  However, some packages may run
+configure again during the build, and the customized values of these
+variables may be lost.  In order to avoid this problem, you should set
+them in the `configure' command line, using `VAR=value'.  For example:
+
+     ./configure CC=/usr/local2/bin/gcc
+
+causes the specified `gcc' to be used as the C compiler (unless it is
+overridden in the site shell script).
+
+Unfortunately, this technique does not work for `CONFIG_SHELL' due to
+an Autoconf limitation.  Until the limitation is lifted, you can use
+this workaround:
+
+     CONFIG_SHELL=/bin/bash ./configure CONFIG_SHELL=/bin/bash
+
+`configure' Invocation
+======================
+
+   `configure' recognizes the following options to control how it
+operates.
+
+`--help'
+`-h'
+     Print a summary of all of the options to `configure', and exit.
+
+`--help=short'
+`--help=recursive'
+     Print a summary of the options unique to this package's
+     `configure', and exit.  The `short' variant lists options used
+     only in the top level, while the `recursive' variant lists options
+     also present in any nested packages.
+
+`--version'
+`-V'
+     Print the version of Autoconf used to generate the `configure'
+     script, and exit.
+
+`--cache-file=FILE'
+     Enable the cache: use and save the results of the tests in FILE,
+     traditionally `config.cache'.  FILE defaults to `/dev/null' to
+     disable caching.
+
+`--config-cache'
+`-C'
+     Alias for `--cache-file=config.cache'.
+
+`--quiet'
+`--silent'
+`-q'
+     Do not print messages saying which checks are being made.  To
+     suppress all normal output, redirect it to `/dev/null' (any error
+     messages will still be shown).
+
+`--srcdir=DIR'
+     Look for the package's source code in directory DIR.  Usually
+     `configure' can determine that directory automatically.
+
+`--prefix=DIR'
+     Use DIR as the installation prefix.  *note Installation Names::
+     for more details, including other options available for fine-tuning
+     the installation locations.
+
+`--no-create'
+`-n'
+     Run the configure checks, but stop before creating any output
+     files.
+
+`configure' also accepts some other, not widely useful, options.  Run
+`configure --help' for more details.
diff --git a/INSTALL.FIPS b/INSTALL.FIPS
new file mode 100644
index 0000000..247e025
--- /dev/null
+++ b/INSTALL.FIPS
@@ -0,0 +1,25 @@
+stunnel FIPS install notes
+
+
+Unix HOWTO:
+* Only dynamic linking of the FIPS-enabled OpenSSL is currently supported,
+  i.e. FIPS-enabled OpenSSL has to be configured with "shared" parameter.
+* FIPS mode is autodetected if possible.  It can be forced with:
+    ./configure --enable-fips
+  or disable with:
+    ./configure --disable-fips
+
+WIN32 HOWTO:
+* On 32-bit Windows install one of the following compilers:
+  - MSVC 8.0 (VS 2005) Standard or Professional Edition
+  - MSVC 9.0 (VS 2008) any edition including Express Edition
+* On 64-bit Windows install one of the following compilers:
+  - MSVC 8.0 (VS 2005) Standard or Professional Edition
+  - MSVC 9.0 (VS 2008) Standard or Professional Edition
+* Build FIPS-compliant OpenSSL DLLS according to:
+  https://www.openssl.org/docs/fips/UserGuide-2.0.pdf
+* Build stunnel normally with MSVC or Mingw.
+  Mingw build requires DLL stubs.  Stubs can be built with:
+  dlltool --def ms/libeay32.def --output-lib libcrypto.a
+  dlltool --def ms/ssleay32.def --output-lib libssl.a
+
diff --git a/INSTALL.W32 b/INSTALL.W32
new file mode 100644
index 0000000..1c98920
--- /dev/null
+++ b/INSTALL.W32
@@ -0,0 +1,51 @@
+stunnel Windows install notes

+

+

+Building stunnel from source (optional):

+

+ 1) Install mingw32 cross-compiler o a Unix/Linux machine.

+    In Debian all you need is:

+      apt-get install gcc-mingw-w64-i686

+    Native compilation on a Windows machine is possible, but not supported.

+

+ 2) Download the recent zlib from http://www.zlib.net/

+    Update the following definitions in win32/Makefile.gcc file:

+      SHARED_MODE=1

+      PREFIX = i686-w64-mingw32-

+    then build zlib with:

+      make -f win32/Makefile.gcc

+    and install it in mingw32 tree:

+      sudo BINARY_PATH=~/ \

+        INCLUDE_PATH=/usr/i686-w64-mingw32/include/ \

+        LIBRARY_PATH=/usr/i686-w64-mingw32/lib/ \

+        make -f win32/Makefile.gcc install

+

+ 3) Download the recent OpenSSL in unpack it to /usr/src/ directory.

+      cd /usr/src

+      tar zvxf ~/openssl-(version).tar.gz

+      mv openssl-(version) openssl-(version)-i686

+

+ 4) Build OpenSSL.

+      ./Configure --cross-compile-prefix=i686-w64-mingw32- mingw shared zlib-dynamic

+      make

+

+ 5) Download and unpack stunnel-(version).tar.gz.

+

+ 6) Configure stunnel.

+      cd stunnel-(version)

+      ./configure --with-ssl=/path/to/openssl-(version)

+

+ 7) Build windows executable.

+      cd src

+      make stunnel.exe

+

+

+Installing stunnel:

+

+ 1) run installer to install precompiled binaries or copy stunnel.exe and

+    OpenSSL DLLs into a directory

+

+ 2) read the manual (stunnel.html)

+

+ 3) create/edit stunnel.conf configuration file

+

diff --git a/INSTALL.WCE b/INSTALL.WCE
new file mode 100644
index 0000000..9f7aa63
--- /dev/null
+++ b/INSTALL.WCE
@@ -0,0 +1,45 @@
+stunnel Windows CE install notes

+

+

+Two stunnel executables are available for Windows CE platform:

+

+  1) stunnel.exe - version with interactive GUI

+

+  2) tstunnel.exe - non-iteractive version for headless devices

+

+

+Building stunnel from source (optional):

+

+  1) install the following tools:

+     evt2002web_min.exe from http://www.microsoft.com/

+     ActivePerl from http://www.activestate.com/Products/ActivePerl/

+     unzip.exe (file needs to be renamed) from

+       http://www.mirrorservice.org/sites/ftp.info-zip.org/pub/infozip/WIN32/

+

+  2) download the OpenSSL source files (the whole directory):

+     ftp://ftp.stunnel.org/stunnel/openssl/ce/

+  

+  3) your directory should look like this:

+     build.bat

+     build.pl

+     unzip.exe

+     src\openssl-0.9.8a.zip

+     src\wcecompat-1.2.zip

+

+  4) type "build" to build OpenSSL

+

+  5) download and unpack stunnel-(version).tar.gz

+

+  4) enter "stunnel-(version)\src" subdirectory

+

+  5) type "makece" to build stunnel

+

+

+Installing stunnel:

+

+  1) copy OpenSSL DLLs and stunnel.exe or tstunnel.exe into \stunnel directory

+

+  2) read the manual (stunnel.html)

+

+  3) create/edit stunnel.conf configuration file

+

diff --git a/Makefile.am b/Makefile.am
new file mode 100644
index 0000000..5d6f444
--- /dev/null
+++ b/Makefile.am
@@ -0,0 +1,56 @@
+## Process this file with automake to produce Makefile.in
+
+ACLOCAL_AMFLAGS = -I m4
+
+SUBDIRS = src doc tools
+
+LIBTOOL_DEPS = @LIBTOOL_DEPS@
+libtool: $(LIBTOOL_DEPS)
+	$(SHELL) ./config.status libtool
+
+EXTRA_DIST = PORTS BUGS COPYRIGHT.GPL CREDITS
+EXTRA_DIST += INSTALL.W32 INSTALL.WCE INSTALL.FIPS
+EXTRA_DIST += build-android.sh
+
+docdir = $(datadir)/doc/stunnel
+doc_DATA = INSTALL README TODO COPYING AUTHORS ChangeLog
+doc_DATA += PORTS BUGS COPYRIGHT.GPL CREDITS
+doc_DATA += INSTALL.W32 INSTALL.WCE INSTALL.FIPS
+
+distcleancheck_listfiles = find -type f -exec sh -c 'test -f $(srcdir)/{} || echo {}' ';'
+
+distclean-local:
+	rm -rf autom4te.cache
+#	rm -f $(distdir)-installer.exe
+
+#dist-hook:
+#	makensis -NOCD -DVERSION=${VERSION} -DSRCDIR=$(srcdir) \
+#		-DOPENSSL=/usr/src/openssl-0.9.8u-fips/out32dll \
+#		-DZLIB=/usr/src/zlib-1.2.8-i586 \
+#		$(srcdir)/tools/stunnel.nsi
+
+
+sign: dist
+	cp -f $(distdir).tar.gz $(distdir)-installer.exe $(distdir)-android.zip ../dist
+	gpg-agent --daemon /bin/sh -c "cd ../dist; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir).tar.gz; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir)-installer.exe; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir)-android.zip"
+	sha256sum $(distdir).tar.gz >../dist/$(distdir).tar.gz.sha256
+	sha256sum $(distdir)-installer.exe >../dist/$(distdir)-installer.exe.sha256
+	sha256sum $(distdir)-android.zip >../dist/$(distdir)-android.zip.sha256
+	cat ../dist/$(distdir)*.sha256 | tac
+
+cert:
+	$(MAKE) -C tools cert
+
+install-data-hook:
+	@echo "*********************************************************"
+	@echo "* Type 'make cert' to also install a sample certificate *"
+	@echo "*********************************************************"
+
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g'
+
+stunnel.pod: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.pod: $(srcdir)/stunnel.pod
diff --git a/Makefile.in b/Makefile.in
new file mode 100644
index 0000000..afe880a
--- /dev/null
+++ b/Makefile.in
@@ -0,0 +1,895 @@
+# Makefile.in generated by automake 1.14.1 from Makefile.am.
+# @configure_input@
+
+# Copyright (C) 1994-2013 Free Software Foundation, Inc.
+
+# This Makefile.in is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+@SET_MAKE@
+
+VPATH = @srcdir@
+am__is_gnu_make = test -n '$(MAKEFILE_LIST)' && test -n '$(MAKELEVEL)'
+am__make_running_with_option = \
+  case $${target_option-} in \
+      ?) ;; \
+      *) echo "am__make_running_with_option: internal error: invalid" \
+              "target option '$${target_option-}' specified" >&2; \
+         exit 1;; \
+  esac; \
+  has_opt=no; \
+  sane_makeflags=$$MAKEFLAGS; \
+  if $(am__is_gnu_make); then \
+    sane_makeflags=$$MFLAGS; \
+  else \
+    case $$MAKEFLAGS in \
+      *\\[\ \	]*) \
+        bs=\\; \
+        sane_makeflags=`printf '%s\n' "$$MAKEFLAGS" \
+          | sed "s/$$bs$$bs[$$bs $$bs	]*//g"`;; \
+    esac; \
+  fi; \
+  skip_next=no; \
+  strip_trailopt () \
+  { \
+    flg=`printf '%s\n' "$$flg" | sed "s/$$1.*$$//"`; \
+  }; \
+  for flg in $$sane_makeflags; do \
+    test $$skip_next = yes && { skip_next=no; continue; }; \
+    case $$flg in \
+      *=*|--*) continue;; \
+        -*I) strip_trailopt 'I'; skip_next=yes;; \
+      -*I?*) strip_trailopt 'I';; \
+        -*O) strip_trailopt 'O'; skip_next=yes;; \
+      -*O?*) strip_trailopt 'O';; \
+        -*l) strip_trailopt 'l'; skip_next=yes;; \
+      -*l?*) strip_trailopt 'l';; \
+      -[dEDm]) skip_next=yes;; \
+      -[JT]) skip_next=yes;; \
+    esac; \
+    case $$flg in \
+      *$$target_option*) has_opt=yes; break;; \
+    esac; \
+  done; \
+  test $$has_opt = yes
+am__make_dryrun = (target_option=n; $(am__make_running_with_option))
+am__make_keepgoing = (target_option=k; $(am__make_running_with_option))
+pkgdatadir = $(datadir)/@PACKAGE@
+pkgincludedir = $(includedir)/@PACKAGE@
+pkglibdir = $(libdir)/@PACKAGE@
+pkglibexecdir = $(libexecdir)/@PACKAGE@
+am__cd = CDPATH="$${ZSH_VERSION+.}$(PATH_SEPARATOR)" && cd
+install_sh_DATA = $(install_sh) -c -m 644
+install_sh_PROGRAM = $(install_sh) -c
+install_sh_SCRIPT = $(install_sh) -c
+INSTALL_HEADER = $(INSTALL_DATA)
+transform = $(program_transform_name)
+NORMAL_INSTALL = :
+PRE_INSTALL = :
+POST_INSTALL = :
+NORMAL_UNINSTALL = :
+PRE_UNINSTALL = :
+POST_UNINSTALL = :
+build_triplet = @build@
+host_triplet = @host@
+subdir = .
+DIST_COMMON = INSTALL NEWS README AUTHORS ChangeLog \
+	$(srcdir)/Makefile.in $(srcdir)/Makefile.am \
+	$(top_srcdir)/configure $(am__configure_deps) COPYING TODO \
+	auto/compile auto/config.guess auto/config.sub auto/depcomp \
+	auto/install-sh auto/missing auto/ltmain.sh \
+	$(top_srcdir)/auto/compile $(top_srcdir)/auto/config.guess \
+	$(top_srcdir)/auto/config.sub $(top_srcdir)/auto/install-sh \
+	$(top_srcdir)/auto/ltmain.sh $(top_srcdir)/auto/missing
+ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
+am__aclocal_m4_deps = $(top_srcdir)/m4/ax_append_compile_flags.m4 \
+	$(top_srcdir)/m4/ax_append_flag.m4 \
+	$(top_srcdir)/m4/ax_append_link_flags.m4 \
+	$(top_srcdir)/m4/ax_check_compile_flag.m4 \
+	$(top_srcdir)/m4/ax_check_link_flag.m4 \
+	$(top_srcdir)/m4/ax_pthread.m4 \
+	$(top_srcdir)/m4/ax_require_defined.m4 \
+	$(top_srcdir)/m4/libtool.m4 $(top_srcdir)/m4/ltoptions.m4 \
+	$(top_srcdir)/m4/ltsugar.m4 $(top_srcdir)/m4/ltversion.m4 \
+	$(top_srcdir)/m4/lt~obsolete.m4 $(top_srcdir)/configure.ac
+am__configure_deps = $(am__aclocal_m4_deps) $(CONFIGURE_DEPENDENCIES) \
+	$(ACLOCAL_M4)
+am__CONFIG_DISTCLEAN_FILES = config.status config.cache config.log \
+ configure.lineno config.status.lineno
+mkinstalldirs = $(install_sh) -d
+CONFIG_HEADER = $(top_builddir)/src/config.h
+CONFIG_CLEAN_FILES =
+CONFIG_CLEAN_VPATH_FILES =
+AM_V_P = $(am__v_P_@AM_V@)
+am__v_P_ = $(am__v_P_@AM_DEFAULT_V@)
+am__v_P_0 = false
+am__v_P_1 = :
+AM_V_GEN = $(am__v_GEN_@AM_V@)
+am__v_GEN_ = $(am__v_GEN_@AM_DEFAULT_V@)
+am__v_GEN_0 = @echo "  GEN     " $@;
+am__v_GEN_1 = 
+AM_V_at = $(am__v_at_@AM_V@)
+am__v_at_ = $(am__v_at_@AM_DEFAULT_V@)
+am__v_at_0 = @
+am__v_at_1 = 
+SOURCES =
+DIST_SOURCES =
+RECURSIVE_TARGETS = all-recursive check-recursive cscopelist-recursive \
+	ctags-recursive dvi-recursive html-recursive info-recursive \
+	install-data-recursive install-dvi-recursive \
+	install-exec-recursive install-html-recursive \
+	install-info-recursive install-pdf-recursive \
+	install-ps-recursive install-recursive installcheck-recursive \
+	installdirs-recursive pdf-recursive ps-recursive \
+	tags-recursive uninstall-recursive
+am__can_run_installinfo = \
+  case $$AM_UPDATE_INFO_DIR in \
+    n|no|NO) false;; \
+    *) (install-info --version) >/dev/null 2>&1;; \
+  esac
+am__vpath_adj_setup = srcdirstrip=`echo "$(srcdir)" | sed 's|.|.|g'`;
+am__vpath_adj = case $$p in \
+    $(srcdir)/*) f=`echo "$$p" | sed "s|^$$srcdirstrip/||"`;; \
+    *) f=$$p;; \
+  esac;
+am__strip_dir = f=`echo $$p | sed -e 's|^.*/||'`;
+am__install_max = 40
+am__nobase_strip_setup = \
+  srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*|]/\\\\&/g'`
+am__nobase_strip = \
+  for p in $$list; do echo "$$p"; done | sed -e "s|$$srcdirstrip/||"
+am__nobase_list = $(am__nobase_strip_setup); \
+  for p in $$list; do echo "$$p $$p"; done | \
+  sed "s| $$srcdirstrip/| |;"' / .*\//!s/ .*/ ./; s,\( .*\)/[^/]*$$,\1,' | \
+  $(AWK) 'BEGIN { files["."] = "" } { files[$$2] = files[$$2] " " $$1; \
+    if (++n[$$2] == $(am__install_max)) \
+      { print $$2, files[$$2]; n[$$2] = 0; files[$$2] = "" } } \
+    END { for (dir in files) print dir, files[dir] }'
+am__base_list = \
+  sed '$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;s/\n/ /g' | \
+  sed '$$!N;$$!N;$$!N;$$!N;s/\n/ /g'
+am__uninstall_files_from_dir = { \
+  test -z "$$files" \
+    || { test ! -d "$$dir" && test ! -f "$$dir" && test ! -r "$$dir"; } \
+    || { echo " ( cd '$$dir' && rm -f" $$files ")"; \
+         $(am__cd) "$$dir" && rm -f $$files; }; \
+  }
+am__installdirs = "$(DESTDIR)$(docdir)"
+DATA = $(doc_DATA)
+RECURSIVE_CLEAN_TARGETS = mostlyclean-recursive clean-recursive	\
+  distclean-recursive maintainer-clean-recursive
+am__recursive_targets = \
+  $(RECURSIVE_TARGETS) \
+  $(RECURSIVE_CLEAN_TARGETS) \
+  $(am__extra_recursive_targets)
+AM_RECURSIVE_TARGETS = $(am__recursive_targets:-recursive=) TAGS CTAGS \
+	cscope distdir dist dist-all distcheck
+am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) $(LISP)
+# Read a list of newline-separated strings from the standard input,
+# and print each of them once, without duplicates.  Input order is
+# *not* preserved.
+am__uniquify_input = $(AWK) '\
+  BEGIN { nonempty = 0; } \
+  { items[$$0] = 1; nonempty = 1; } \
+  END { if (nonempty) { for (i in items) print i; }; } \
+'
+# Make sure the list of sources is unique.  This is necessary because,
+# e.g., the same source file might be shared among _SOURCES variables
+# for different programs/libraries.
+am__define_uniq_tagged_files = \
+  list='$(am__tagged_files)'; \
+  unique=`for i in $$list; do \
+    if test -f "$$i"; then echo $$i; else echo $(srcdir)/$$i; fi; \
+  done | $(am__uniquify_input)`
+ETAGS = etags
+CTAGS = ctags
+CSCOPE = cscope
+DIST_SUBDIRS = $(SUBDIRS)
+DISTFILES = $(DIST_COMMON) $(DIST_SOURCES) $(TEXINFOS) $(EXTRA_DIST)
+distdir = $(PACKAGE)-$(VERSION)
+top_distdir = $(distdir)
+am__remove_distdir = \
+  if test -d "$(distdir)"; then \
+    find "$(distdir)" -type d ! -perm -200 -exec chmod u+w {} ';' \
+      && rm -rf "$(distdir)" \
+      || { sleep 5 && rm -rf "$(distdir)"; }; \
+  else :; fi
+am__post_remove_distdir = $(am__remove_distdir)
+am__relativize = \
+  dir0=`pwd`; \
+  sed_first='s,^\([^/]*\)/.*$$,\1,'; \
+  sed_rest='s,^[^/]*/*,,'; \
+  sed_last='s,^.*/\([^/]*\)$$,\1,'; \
+  sed_butlast='s,/*[^/]*$$,,'; \
+  while test -n "$$dir1"; do \
+    first=`echo "$$dir1" | sed -e "$$sed_first"`; \
+    if test "$$first" != "."; then \
+      if test "$$first" = ".."; then \
+        dir2=`echo "$$dir0" | sed -e "$$sed_last"`/"$$dir2"; \
+        dir0=`echo "$$dir0" | sed -e "$$sed_butlast"`; \
+      else \
+        first2=`echo "$$dir2" | sed -e "$$sed_first"`; \
+        if test "$$first2" = "$$first"; then \
+          dir2=`echo "$$dir2" | sed -e "$$sed_rest"`; \
+        else \
+          dir2="../$$dir2"; \
+        fi; \
+        dir0="$$dir0"/"$$first"; \
+      fi; \
+    fi; \
+    dir1=`echo "$$dir1" | sed -e "$$sed_rest"`; \
+  done; \
+  reldir="$$dir2"
+DIST_ARCHIVES = $(distdir).tar.gz
+GZIP_ENV = --best
+DIST_TARGETS = dist-gzip
+distuninstallcheck_listfiles = find . -type f -print
+am__distuninstallcheck_listfiles = $(distuninstallcheck_listfiles) \
+  | sed 's|^\./|$(prefix)/|' | grep -v '$(infodir)/dir$$'
+ACLOCAL = @ACLOCAL@
+AMTAR = @AMTAR@
+AM_DEFAULT_VERBOSITY = @AM_DEFAULT_VERBOSITY@
+AR = @AR@
+AUTOCONF = @AUTOCONF@
+AUTOHEADER = @AUTOHEADER@
+AUTOMAKE = @AUTOMAKE@
+AWK = @AWK@
+CC = @CC@
+CCDEPMODE = @CCDEPMODE@
+CFLAGS = @CFLAGS@
+CPP = @CPP@
+CPPFLAGS = @CPPFLAGS@
+CYGPATH_W = @CYGPATH_W@
+DEFAULT_GROUP = @DEFAULT_GROUP@
+DEFS = @DEFS@
+DEPDIR = @DEPDIR@
+DLLTOOL = @DLLTOOL@
+DSYMUTIL = @DSYMUTIL@
+DUMPBIN = @DUMPBIN@
+ECHO_C = @ECHO_C@
+ECHO_N = @ECHO_N@
+ECHO_T = @ECHO_T@
+EGREP = @EGREP@
+EXEEXT = @EXEEXT@
+FGREP = @FGREP@
+GREP = @GREP@
+INSTALL = @INSTALL@
+INSTALL_DATA = @INSTALL_DATA@
+INSTALL_PROGRAM = @INSTALL_PROGRAM@
+INSTALL_SCRIPT = @INSTALL_SCRIPT@
+INSTALL_STRIP_PROGRAM = @INSTALL_STRIP_PROGRAM@
+LD = @LD@
+LDFLAGS = @LDFLAGS@
+LIBOBJS = @LIBOBJS@
+LIBS = @LIBS@
+LIBTOOL = @LIBTOOL@
+LIBTOOL_DEPS = @LIBTOOL_DEPS@
+LIPO = @LIPO@
+LN_S = @LN_S@
+LTLIBOBJS = @LTLIBOBJS@
+MAKEINFO = @MAKEINFO@
+MANIFEST_TOOL = @MANIFEST_TOOL@
+MKDIR_P = @MKDIR_P@
+NM = @NM@
+NMEDIT = @NMEDIT@
+OBJDUMP = @OBJDUMP@
+OBJEXT = @OBJEXT@
+OTOOL = @OTOOL@
+OTOOL64 = @OTOOL64@
+PACKAGE = @PACKAGE@
+PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
+PACKAGE_NAME = @PACKAGE_NAME@
+PACKAGE_STRING = @PACKAGE_STRING@
+PACKAGE_TARNAME = @PACKAGE_TARNAME@
+PACKAGE_URL = @PACKAGE_URL@
+PACKAGE_VERSION = @PACKAGE_VERSION@
+PATH_SEPARATOR = @PATH_SEPARATOR@
+PTHREAD_CC = @PTHREAD_CC@
+PTHREAD_CFLAGS = @PTHREAD_CFLAGS@
+PTHREAD_LIBS = @PTHREAD_LIBS@
+RANDOM_FILE = @RANDOM_FILE@
+RANLIB = @RANLIB@
+SED = @SED@
+SET_MAKE = @SET_MAKE@
+SHELL = @SHELL@
+SSLDIR = @SSLDIR@
+STRIP = @STRIP@
+VERSION = @VERSION@
+abs_builddir = @abs_builddir@
+abs_srcdir = @abs_srcdir@
+abs_top_builddir = @abs_top_builddir@
+abs_top_srcdir = @abs_top_srcdir@
+ac_ct_AR = @ac_ct_AR@
+ac_ct_CC = @ac_ct_CC@
+ac_ct_DUMPBIN = @ac_ct_DUMPBIN@
+am__include = @am__include@
+am__leading_dot = @am__leading_dot@
+am__quote = @am__quote@
+am__tar = @am__tar@
+am__untar = @am__untar@
+ax_pthread_config = @ax_pthread_config@
+bindir = @bindir@
+build = @build@
+build_alias = @build_alias@
+build_cpu = @build_cpu@
+build_os = @build_os@
+build_vendor = @build_vendor@
+builddir = @builddir@
+datadir = @datadir@
+datarootdir = @datarootdir@
+docdir = $(datadir)/doc/stunnel
+dvidir = @dvidir@
+exec_prefix = @exec_prefix@
+host = @host@
+host_alias = @host_alias@
+host_cpu = @host_cpu@
+host_os = @host_os@
+host_vendor = @host_vendor@
+htmldir = @htmldir@
+includedir = @includedir@
+infodir = @infodir@
+install_sh = @install_sh@
+libdir = @libdir@
+libexecdir = @libexecdir@
+localedir = @localedir@
+localstatedir = @localstatedir@
+mandir = @mandir@
+mkdir_p = @mkdir_p@
+oldincludedir = @oldincludedir@
+pdfdir = @pdfdir@
+prefix = @prefix@
+program_transform_name = @program_transform_name@
+psdir = @psdir@
+sbindir = @sbindir@
+sharedstatedir = @sharedstatedir@
+srcdir = @srcdir@
+sysconfdir = @sysconfdir@
+target_alias = @target_alias@
+top_build_prefix = @top_build_prefix@
+top_builddir = @top_builddir@
+top_srcdir = @top_srcdir@
+ACLOCAL_AMFLAGS = -I m4
+SUBDIRS = src doc tools
+EXTRA_DIST = PORTS BUGS COPYRIGHT.GPL CREDITS INSTALL.W32 INSTALL.WCE \
+	INSTALL.FIPS build-android.sh
+doc_DATA = INSTALL README TODO COPYING AUTHORS ChangeLog PORTS BUGS \
+	COPYRIGHT.GPL CREDITS INSTALL.W32 INSTALL.WCE INSTALL.FIPS
+distcleancheck_listfiles = find -type f -exec sh -c 'test -f $(srcdir)/{} || echo {}' ';'
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g'
+
+all: all-recursive
+
+.SUFFIXES:
+am--refresh: Makefile
+	@:
+$(srcdir)/Makefile.in:  $(srcdir)/Makefile.am  $(am__configure_deps)
+	@for dep in $?; do \
+	  case '$(am__configure_deps)' in \
+	    *$$dep*) \
+	      echo ' cd $(srcdir) && $(AUTOMAKE) --gnu'; \
+	      $(am__cd) $(srcdir) && $(AUTOMAKE) --gnu \
+		&& exit 0; \
+	      exit 1;; \
+	  esac; \
+	done; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu Makefile'; \
+	$(am__cd) $(top_srcdir) && \
+	  $(AUTOMAKE) --gnu Makefile
+.PRECIOUS: Makefile
+Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
+	@case '$?' in \
+	  *config.status*) \
+	    echo ' $(SHELL) ./config.status'; \
+	    $(SHELL) ./config.status;; \
+	  *) \
+	    echo ' cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__depfiles_maybe)'; \
+	    cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__depfiles_maybe);; \
+	esac;
+
+$(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES)
+	$(SHELL) ./config.status --recheck
+
+$(top_srcdir)/configure:  $(am__configure_deps)
+	$(am__cd) $(srcdir) && $(AUTOCONF)
+$(ACLOCAL_M4):  $(am__aclocal_m4_deps)
+	$(am__cd) $(srcdir) && $(ACLOCAL) $(ACLOCAL_AMFLAGS)
+$(am__aclocal_m4_deps):
+
+mostlyclean-libtool:
+	-rm -f *.lo
+
+clean-libtool:
+	-rm -rf .libs _libs
+
+distclean-libtool:
+	-rm -f libtool config.lt
+install-docDATA: $(doc_DATA)
+	@$(NORMAL_INSTALL)
+	@list='$(doc_DATA)'; test -n "$(docdir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(docdir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(docdir)" || exit 1; \
+	fi; \
+	for p in $$list; do \
+	  if test -f "$$p"; then d=; else d="$(srcdir)/"; fi; \
+	  echo "$$d$$p"; \
+	done | $(am__base_list) | \
+	while read files; do \
+	  echo " $(INSTALL_DATA) $$files '$(DESTDIR)$(docdir)'"; \
+	  $(INSTALL_DATA) $$files "$(DESTDIR)$(docdir)" || exit $$?; \
+	done
+
+uninstall-docDATA:
+	@$(NORMAL_UNINSTALL)
+	@list='$(doc_DATA)'; test -n "$(docdir)" || list=; \
+	files=`for p in $$list; do echo $$p; done | sed -e 's|^.*/||'`; \
+	dir='$(DESTDIR)$(docdir)'; $(am__uninstall_files_from_dir)
+
+# This directory's subdirectories are mostly independent; you can cd
+# into them and run 'make' without going through this Makefile.
+# To change the values of 'make' variables: instead of editing Makefiles,
+# (1) if the variable is set in 'config.status', edit 'config.status'
+#     (which will cause the Makefiles to be regenerated when you run 'make');
+# (2) otherwise, pass the desired values on the 'make' command line.
+$(am__recursive_targets):
+	@fail=; \
+	if $(am__make_keepgoing); then \
+	  failcom='fail=yes'; \
+	else \
+	  failcom='exit 1'; \
+	fi; \
+	dot_seen=no; \
+	target=`echo $@ | sed s/-recursive//`; \
+	case "$@" in \
+	  distclean-* | maintainer-clean-*) list='$(DIST_SUBDIRS)' ;; \
+	  *) list='$(SUBDIRS)' ;; \
+	esac; \
+	for subdir in $$list; do \
+	  echo "Making $$target in $$subdir"; \
+	  if test "$$subdir" = "."; then \
+	    dot_seen=yes; \
+	    local_target="$$target-am"; \
+	  else \
+	    local_target="$$target"; \
+	  fi; \
+	  ($(am__cd) $$subdir && $(MAKE) $(AM_MAKEFLAGS) $$local_target) \
+	  || eval $$failcom; \
+	done; \
+	if test "$$dot_seen" = "no"; then \
+	  $(MAKE) $(AM_MAKEFLAGS) "$$target-am" || exit 1; \
+	fi; test -z "$$fail"
+
+ID: $(am__tagged_files)
+	$(am__define_uniq_tagged_files); mkid -fID $$unique
+tags: tags-recursive
+TAGS: tags
+
+tags-am: $(TAGS_DEPENDENCIES) $(am__tagged_files)
+	set x; \
+	here=`pwd`; \
+	if ($(ETAGS) --etags-include --version) >/dev/null 2>&1; then \
+	  include_option=--etags-include; \
+	  empty_fix=.; \
+	else \
+	  include_option=--include; \
+	  empty_fix=; \
+	fi; \
+	list='$(SUBDIRS)'; for subdir in $$list; do \
+	  if test "$$subdir" = .; then :; else \
+	    test ! -f $$subdir/TAGS || \
+	      set "$$@" "$$include_option=$$here/$$subdir/TAGS"; \
+	  fi; \
+	done; \
+	$(am__define_uniq_tagged_files); \
+	shift; \
+	if test -z "$(ETAGS_ARGS)$$*$$unique"; then :; else \
+	  test -n "$$unique" || unique=$$empty_fix; \
+	  if test $$# -gt 0; then \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      "$$@" $$unique; \
+	  else \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      $$unique; \
+	  fi; \
+	fi
+ctags: ctags-recursive
+
+CTAGS: ctags
+ctags-am: $(TAGS_DEPENDENCIES) $(am__tagged_files)
+	$(am__define_uniq_tagged_files); \
+	test -z "$(CTAGS_ARGS)$$unique" \
+	  || $(CTAGS) $(CTAGSFLAGS) $(AM_CTAGSFLAGS) $(CTAGS_ARGS) \
+	     $$unique
+
+GTAGS:
+	here=`$(am__cd) $(top_builddir) && pwd` \
+	  && $(am__cd) $(top_srcdir) \
+	  && gtags -i $(GTAGS_ARGS) "$$here"
+cscope: cscope.files
+	test ! -s cscope.files \
+	  || $(CSCOPE) -b -q $(AM_CSCOPEFLAGS) $(CSCOPEFLAGS) -i cscope.files $(CSCOPE_ARGS)
+clean-cscope:
+	-rm -f cscope.files
+cscope.files: clean-cscope cscopelist
+cscopelist: cscopelist-recursive
+
+cscopelist-am: $(am__tagged_files)
+	list='$(am__tagged_files)'; \
+	case "$(srcdir)" in \
+	  [\\/]* | ?:[\\/]*) sdir="$(srcdir)" ;; \
+	  *) sdir=$(subdir)/$(srcdir) ;; \
+	esac; \
+	for i in $$list; do \
+	  if test -f "$$i"; then \
+	    echo "$(subdir)/$$i"; \
+	  else \
+	    echo "$$sdir/$$i"; \
+	  fi; \
+	done >> $(top_builddir)/cscope.files
+
+distclean-tags:
+	-rm -f TAGS ID GTAGS GRTAGS GSYMS GPATH tags
+	-rm -f cscope.out cscope.in.out cscope.po.out cscope.files
+
+distdir: $(DISTFILES)
+	$(am__remove_distdir)
+	test -d "$(distdir)" || mkdir "$(distdir)"
+	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	list='$(DISTFILES)'; \
+	  dist_files=`for file in $$list; do echo $$file; done | \
+	  sed -e "s|^$$srcdirstrip/||;t" \
+	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
+	case $$dist_files in \
+	  */*) $(MKDIR_P) `echo "$$dist_files" | \
+			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sort -u` ;; \
+	esac; \
+	for file in $$dist_files; do \
+	  if test -f $$file || test -d $$file; then d=.; else d=$(srcdir); fi; \
+	  if test -d $$d/$$file; then \
+	    dir=`echo "/$$file" | sed -e 's,/[^/]*$$,,'`; \
+	    if test -d "$(distdir)/$$file"; then \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    if test -d $(srcdir)/$$file && test $$d != $(srcdir); then \
+	      cp -fpR $(srcdir)/$$file "$(distdir)$$dir" || exit 1; \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    cp -fpR $$d/$$file "$(distdir)$$dir" || exit 1; \
+	  else \
+	    test -f "$(distdir)/$$file" \
+	    || cp -p $$d/$$file "$(distdir)/$$file" \
+	    || exit 1; \
+	  fi; \
+	done
+	@list='$(DIST_SUBDIRS)'; for subdir in $$list; do \
+	  if test "$$subdir" = .; then :; else \
+	    $(am__make_dryrun) \
+	      || test -d "$(distdir)/$$subdir" \
+	      || $(MKDIR_P) "$(distdir)/$$subdir" \
+	      || exit 1; \
+	    dir1=$$subdir; dir2="$(distdir)/$$subdir"; \
+	    $(am__relativize); \
+	    new_distdir=$$reldir; \
+	    dir1=$$subdir; dir2="$(top_distdir)"; \
+	    $(am__relativize); \
+	    new_top_distdir=$$reldir; \
+	    echo " (cd $$subdir && $(MAKE) $(AM_MAKEFLAGS) top_distdir="$$new_top_distdir" distdir="$$new_distdir" \\"; \
+	    echo "     am__remove_distdir=: am__skip_length_check=: am__skip_mode_fix=: distdir)"; \
+	    ($(am__cd) $$subdir && \
+	      $(MAKE) $(AM_MAKEFLAGS) \
+	        top_distdir="$$new_top_distdir" \
+	        distdir="$$new_distdir" \
+		am__remove_distdir=: \
+		am__skip_length_check=: \
+		am__skip_mode_fix=: \
+	        distdir) \
+	      || exit 1; \
+	  fi; \
+	done
+	-test -n "$(am__skip_mode_fix)" \
+	|| find "$(distdir)" -type d ! -perm -755 \
+		-exec chmod u+rwx,go+rx {} \; -o \
+	  ! -type d ! -perm -444 -links 1 -exec chmod a+r {} \; -o \
+	  ! -type d ! -perm -400 -exec chmod a+r {} \; -o \
+	  ! -type d ! -perm -444 -exec $(install_sh) -c -m a+r {} {} \; \
+	|| chmod -R a+r "$(distdir)"
+dist-gzip: distdir
+	tardir=$(distdir) && $(am__tar) | GZIP=$(GZIP_ENV) gzip -c >$(distdir).tar.gz
+	$(am__post_remove_distdir)
+
+dist-bzip2: distdir
+	tardir=$(distdir) && $(am__tar) | BZIP2=$${BZIP2--9} bzip2 -c >$(distdir).tar.bz2
+	$(am__post_remove_distdir)
+
+dist-lzip: distdir
+	tardir=$(distdir) && $(am__tar) | lzip -c $${LZIP_OPT--9} >$(distdir).tar.lz
+	$(am__post_remove_distdir)
+
+dist-xz: distdir
+	tardir=$(distdir) && $(am__tar) | XZ_OPT=$${XZ_OPT--e} xz -c >$(distdir).tar.xz
+	$(am__post_remove_distdir)
+
+dist-tarZ: distdir
+	@echo WARNING: "Support for shar distribution archives is" \
+	               "deprecated." >&2
+	@echo WARNING: "It will be removed altogether in Automake 2.0" >&2
+	tardir=$(distdir) && $(am__tar) | compress -c >$(distdir).tar.Z
+	$(am__post_remove_distdir)
+
+dist-shar: distdir
+	@echo WARNING: "Support for distribution archives compressed with" \
+		       "legacy program 'compress' is deprecated." >&2
+	@echo WARNING: "It will be removed altogether in Automake 2.0" >&2
+	shar $(distdir) | GZIP=$(GZIP_ENV) gzip -c >$(distdir).shar.gz
+	$(am__post_remove_distdir)
+
+dist-zip: distdir
+	-rm -f $(distdir).zip
+	zip -rq $(distdir).zip $(distdir)
+	$(am__post_remove_distdir)
+
+dist dist-all:
+	$(MAKE) $(AM_MAKEFLAGS) $(DIST_TARGETS) am__post_remove_distdir='@:'
+	$(am__post_remove_distdir)
+
+# This target untars the dist file and tries a VPATH configuration.  Then
+# it guarantees that the distribution is self-contained by making another
+# tarfile.
+distcheck: dist
+	case '$(DIST_ARCHIVES)' in \
+	*.tar.gz*) \
+	  GZIP=$(GZIP_ENV) gzip -dc $(distdir).tar.gz | $(am__untar) ;;\
+	*.tar.bz2*) \
+	  bzip2 -dc $(distdir).tar.bz2 | $(am__untar) ;;\
+	*.tar.lz*) \
+	  lzip -dc $(distdir).tar.lz | $(am__untar) ;;\
+	*.tar.xz*) \
+	  xz -dc $(distdir).tar.xz | $(am__untar) ;;\
+	*.tar.Z*) \
+	  uncompress -c $(distdir).tar.Z | $(am__untar) ;;\
+	*.shar.gz*) \
+	  GZIP=$(GZIP_ENV) gzip -dc $(distdir).shar.gz | unshar ;;\
+	*.zip*) \
+	  unzip $(distdir).zip ;;\
+	esac
+	chmod -R a-w $(distdir)
+	chmod u+w $(distdir)
+	mkdir $(distdir)/_build $(distdir)/_inst
+	chmod a-w $(distdir)
+	test -d $(distdir)/_build || exit 0; \
+	dc_install_base=`$(am__cd) $(distdir)/_inst && pwd | sed -e 's,^[^:\\/]:[\\/],/,'` \
+	  && dc_destdir="$${TMPDIR-/tmp}/am-dc-$$$$/" \
+	  && am__cwd=`pwd` \
+	  && $(am__cd) $(distdir)/_build \
+	  && ../configure \
+	    $(AM_DISTCHECK_CONFIGURE_FLAGS) \
+	    $(DISTCHECK_CONFIGURE_FLAGS) \
+	    --srcdir=.. --prefix="$$dc_install_base" \
+	  && $(MAKE) $(AM_MAKEFLAGS) \
+	  && $(MAKE) $(AM_MAKEFLAGS) dvi \
+	  && $(MAKE) $(AM_MAKEFLAGS) check \
+	  && $(MAKE) $(AM_MAKEFLAGS) install \
+	  && $(MAKE) $(AM_MAKEFLAGS) installcheck \
+	  && $(MAKE) $(AM_MAKEFLAGS) uninstall \
+	  && $(MAKE) $(AM_MAKEFLAGS) distuninstallcheck_dir="$$dc_install_base" \
+	        distuninstallcheck \
+	  && chmod -R a-w "$$dc_install_base" \
+	  && ({ \
+	       (cd ../.. && umask 077 && mkdir "$$dc_destdir") \
+	       && $(MAKE) $(AM_MAKEFLAGS) DESTDIR="$$dc_destdir" install \
+	       && $(MAKE) $(AM_MAKEFLAGS) DESTDIR="$$dc_destdir" uninstall \
+	       && $(MAKE) $(AM_MAKEFLAGS) DESTDIR="$$dc_destdir" \
+	            distuninstallcheck_dir="$$dc_destdir" distuninstallcheck; \
+	      } || { rm -rf "$$dc_destdir"; exit 1; }) \
+	  && rm -rf "$$dc_destdir" \
+	  && $(MAKE) $(AM_MAKEFLAGS) dist \
+	  && rm -rf $(DIST_ARCHIVES) \
+	  && $(MAKE) $(AM_MAKEFLAGS) distcleancheck \
+	  && cd "$$am__cwd" \
+	  || exit 1
+	$(am__post_remove_distdir)
+	@(echo "$(distdir) archives ready for distribution: "; \
+	  list='$(DIST_ARCHIVES)'; for i in $$list; do echo $$i; done) | \
+	  sed -e 1h -e 1s/./=/g -e 1p -e 1x -e '$$p' -e '$$x'
+distuninstallcheck:
+	@test -n '$(distuninstallcheck_dir)' || { \
+	  echo 'ERROR: trying to run $@ with an empty' \
+	       '$$(distuninstallcheck_dir)' >&2; \
+	  exit 1; \
+	}; \
+	$(am__cd) '$(distuninstallcheck_dir)' || { \
+	  echo 'ERROR: cannot chdir into $(distuninstallcheck_dir)' >&2; \
+	  exit 1; \
+	}; \
+	test `$(am__distuninstallcheck_listfiles) | wc -l` -eq 0 \
+	   || { echo "ERROR: files left after uninstall:" ; \
+	        if test -n "$(DESTDIR)"; then \
+	          echo "  (check DESTDIR support)"; \
+	        fi ; \
+	        $(distuninstallcheck_listfiles) ; \
+	        exit 1; } >&2
+distcleancheck: distclean
+	@if test '$(srcdir)' = . ; then \
+	  echo "ERROR: distcleancheck can only run from a VPATH build" ; \
+	  exit 1 ; \
+	fi
+	@test `$(distcleancheck_listfiles) | wc -l` -eq 0 \
+	  || { echo "ERROR: files left in build directory after distclean:" ; \
+	       $(distcleancheck_listfiles) ; \
+	       exit 1; } >&2
+check-am: all-am
+check: check-recursive
+all-am: Makefile $(DATA)
+installdirs: installdirs-recursive
+installdirs-am:
+	for dir in "$(DESTDIR)$(docdir)"; do \
+	  test -z "$$dir" || $(MKDIR_P) "$$dir"; \
+	done
+install: install-recursive
+install-exec: install-exec-recursive
+install-data: install-data-recursive
+uninstall: uninstall-recursive
+
+install-am: all-am
+	@$(MAKE) $(AM_MAKEFLAGS) install-exec-am install-data-am
+
+installcheck: installcheck-recursive
+install-strip:
+	if test -z '$(STRIP)'; then \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	      install; \
+	else \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	    "INSTALL_PROGRAM_ENV=STRIPPROG='$(STRIP)'" install; \
+	fi
+mostlyclean-generic:
+
+clean-generic:
+
+distclean-generic:
+	-test -z "$(CONFIG_CLEAN_FILES)" || rm -f $(CONFIG_CLEAN_FILES)
+	-test . = "$(srcdir)" || test -z "$(CONFIG_CLEAN_VPATH_FILES)" || rm -f $(CONFIG_CLEAN_VPATH_FILES)
+
+maintainer-clean-generic:
+	@echo "This command is intended for maintainers to use"
+	@echo "it deletes files that may require special tools to rebuild."
+clean: clean-recursive
+
+clean-am: clean-generic clean-libtool mostlyclean-am
+
+distclean: distclean-recursive
+	-rm -f $(am__CONFIG_DISTCLEAN_FILES)
+	-rm -f Makefile
+distclean-am: clean-am distclean-generic distclean-libtool \
+	distclean-local distclean-tags
+
+dvi: dvi-recursive
+
+dvi-am:
+
+html: html-recursive
+
+html-am:
+
+info: info-recursive
+
+info-am:
+
+install-data-am: install-docDATA
+	@$(NORMAL_INSTALL)
+	$(MAKE) $(AM_MAKEFLAGS) install-data-hook
+install-dvi: install-dvi-recursive
+
+install-dvi-am:
+
+install-exec-am:
+
+install-html: install-html-recursive
+
+install-html-am:
+
+install-info: install-info-recursive
+
+install-info-am:
+
+install-man:
+
+install-pdf: install-pdf-recursive
+
+install-pdf-am:
+
+install-ps: install-ps-recursive
+
+install-ps-am:
+
+installcheck-am:
+
+maintainer-clean: maintainer-clean-recursive
+	-rm -f $(am__CONFIG_DISTCLEAN_FILES)
+	-rm -rf $(top_srcdir)/autom4te.cache
+	-rm -f Makefile
+maintainer-clean-am: distclean-am maintainer-clean-generic
+
+mostlyclean: mostlyclean-recursive
+
+mostlyclean-am: mostlyclean-generic mostlyclean-libtool
+
+pdf: pdf-recursive
+
+pdf-am:
+
+ps: ps-recursive
+
+ps-am:
+
+uninstall-am: uninstall-docDATA
+
+.MAKE: $(am__recursive_targets) install-am install-data-am \
+	install-strip
+
+.PHONY: $(am__recursive_targets) CTAGS GTAGS TAGS all all-am \
+	am--refresh check check-am clean clean-cscope clean-generic \
+	clean-libtool cscope cscopelist-am ctags ctags-am dist \
+	dist-all dist-bzip2 dist-gzip dist-lzip dist-shar dist-tarZ \
+	dist-xz dist-zip distcheck distclean distclean-generic \
+	distclean-libtool distclean-local distclean-tags \
+	distcleancheck distdir distuninstallcheck dvi dvi-am html \
+	html-am info info-am install install-am install-data \
+	install-data-am install-data-hook install-docDATA install-dvi \
+	install-dvi-am install-exec install-exec-am install-html \
+	install-html-am install-info install-info-am install-man \
+	install-pdf install-pdf-am install-ps install-ps-am \
+	install-strip installcheck installcheck-am installdirs \
+	installdirs-am maintainer-clean maintainer-clean-generic \
+	mostlyclean mostlyclean-generic mostlyclean-libtool pdf pdf-am \
+	ps ps-am tags tags-am uninstall uninstall-am uninstall-docDATA
+
+libtool: $(LIBTOOL_DEPS)
+	$(SHELL) ./config.status libtool
+
+distclean-local:
+	rm -rf autom4te.cache
+#	rm -f $(distdir)-installer.exe
+
+#dist-hook:
+#	makensis -NOCD -DVERSION=${VERSION} -DSRCDIR=$(srcdir) \
+#		-DOPENSSL=/usr/src/openssl-0.9.8u-fips/out32dll \
+#		-DZLIB=/usr/src/zlib-1.2.8-i586 \
+#		$(srcdir)/tools/stunnel.nsi
+
+sign: dist
+	cp -f $(distdir).tar.gz $(distdir)-installer.exe $(distdir)-android.zip ../dist
+	gpg-agent --daemon /bin/sh -c "cd ../dist; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir).tar.gz; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir)-installer.exe; gpg --yes --armor --detach-sign --force-v3-sigs $(distdir)-android.zip"
+	sha256sum $(distdir).tar.gz >../dist/$(distdir).tar.gz.sha256
+	sha256sum $(distdir)-installer.exe >../dist/$(distdir)-installer.exe.sha256
+	sha256sum $(distdir)-android.zip >../dist/$(distdir)-android.zip.sha256
+	cat ../dist/$(distdir)*.sha256 | tac
+
+cert:
+	$(MAKE) -C tools cert
+
+install-data-hook:
+	@echo "*********************************************************"
+	@echo "* Type 'make cert' to also install a sample certificate *"
+	@echo "*********************************************************"
+
+stunnel.pod: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.pod: $(srcdir)/stunnel.pod
+
+# Tell versions [3.59,3.63) of GNU make to not export all variables.
+# Otherwise a system limit (for SysV at least) may be exceeded.
+.NOEXPORT:
diff --git a/NEWS b/NEWS
new file mode 100644
index 0000000..1384d3c
--- /dev/null
+++ b/NEWS
@@ -0,0 +1 @@
+See the ChangeLog file for the latest news.
diff --git a/PORTS b/PORTS
new file mode 100644
index 0000000..ae71173
--- /dev/null
+++ b/PORTS
@@ -0,0 +1,24 @@
+stunnel known port maintainers
+
+
+* AmigaOS
+  - Diego Casorran <dcr8520@amiga.org>
+* Cygwin
+  - Andrew Schulman <andrex@alumni.utexas.net>
+* Debian GNU/Linux
+  - Peter Pentchev <roam@ringlet.net>
+* FreeBSD
+  - Ryan Steinmetz <zi@FreeBSD.org>
+* NetBSD
+  - Martti Kuparinen <martti.kuparinen@iki.fi>
+* OpenBSD
+  - Gleydson Soares <gsoares@openbsd.org>
+* OpenCSW Solaris
+  - Dagobert Michelsen <dam@opencsw.org>
+* OpenSolaris
+  - Mark Fenwick <Mark.Fenwick@sun.com>
+* OS/2
+  - Paul Smedley <paul@smedley.info>
+* RedHat Linux
+  - Damien Miller <dmiller@ilogic.com.au>
+
diff --git a/README b/README
new file mode 100644
index 0000000..b66a3ed
--- /dev/null
+++ b/README
@@ -0,0 +1,30 @@
+stunnel overview
+
+Short description
+
+     The stunnel program is designed to work as an SSL encryption
+     wrapper between remote client and local (inetd-startable) or
+     remote servers. The goal is to facilitate SSL encryption and
+     authentication for non-SSL-aware programs.
+
+     stunnel can be used to add  SSL  functionality  to  commonly
+     used  inetd  daemons  like  POP-2,  POP-3  and  IMAP servers
+     without any changes in the programs' code.
+
+Compile instructions
+
+     See INSTALL file.
+
+License
+
+     See COPYING file.
+
+Other files you should read
+
+     Changelog      What I did
+     TODO           What I'm going to do
+
+Reporting problems and other contacts
+
+     See FAQ file.
+
diff --git a/TODO b/TODO
new file mode 100644
index 0000000..f0a4bb8
--- /dev/null
+++ b/TODO
@@ -0,0 +1,49 @@
+stunnel TODO
+
+
+High priority features.  They will likely be supported some day.
+A sponsor could allocate my time to get them faster.
+* Add an Apparmor profile.
+* Optional line-buffering of the log file.
+* Log rotation on Windows.
+* Configuration file option to limit the number of concurrent connections.
+* Implement reference counting of the SERVICE_OPTIONS structure
+  - Add 'leastconn' failover strategy to order defined 'connect' targets
+    by the number of active connections.
+  - Add '-status' command line option reporting the number of clients
+    connected to each service.
+  - Deallocate SERVICE_OPTIONS structure when the configuration file
+    is reloaded *and* old connections are closed.
+* Command-line server control interface on both Unix and Windows.
+* Separate GUI process running as current user on Windows.
+* An Android GUI.
+* Indirect CRL support (RFC 3280, section 5).
+* Provide 64-bit Windows builds (besides 32-bit builds).
+  This requires either Microsoft Visual Studio Standard Edition or Microsoft
+  Visual Studio Professional Edition in order to retain FIPS compliance.
+* MSI installer for Windows.
+* Database and/or directory interface for retrieving PSK secrets.
+* Extend session tickets and/or sessiond to also serialize
+  application data ("redirect" state and session persistence).
+* Add user-defined headers to proxy requests in order to impersonate
+  other software (e.g. web browsers).
+
+Low priority features.  They will unlikely ever be supported.
+* Support static FIPS-enabled build.
+* Service-level logging destination.
+* Enforce key renegotiation (re-handshake) for long connections.
+* Logging to NT EventLog on Windows.
+* Internationalization of logged messages (i18n).
+* Generic scripting engine instead or static protocol.c.
+
+Features I won't support, unless convinced otherwise by a wealthy sponsor.
+* Support for adding X-Forwarded-For to HTTP request headers.
+  This feature is less useful since PROXY protocol support is available.
+* Support for adding X-Forwarded-For to SMTP email headers.
+  This feature is most likely to be implemented as a separate proxy.
+* Additional certificate checks (including wildcard comparison) based on:
+  - O (Organization), and
+  - OU (Organizational Unit).
+* Set processes title that appear on the ps(1) and top(1) commands.
+  I could not find a portable *and* non-copyleft library for it.
+
diff --git a/aclocal.m4 b/aclocal.m4
new file mode 100644
index 0000000..3a180fa
--- /dev/null
+++ b/aclocal.m4
@@ -0,0 +1,1161 @@
+# generated automatically by aclocal 1.14.1 -*- Autoconf -*-
+
+# Copyright (C) 1996-2013 Free Software Foundation, Inc.
+
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+m4_ifndef([AC_CONFIG_MACRO_DIRS], [m4_defun([_AM_CONFIG_MACRO_DIRS], [])m4_defun([AC_CONFIG_MACRO_DIRS], [_AM_CONFIG_MACRO_DIRS($@)])])
+m4_ifndef([AC_AUTOCONF_VERSION],
+  [m4_copy([m4_PACKAGE_VERSION], [AC_AUTOCONF_VERSION])])dnl
+m4_if(m4_defn([AC_AUTOCONF_VERSION]), [2.69],,
+[m4_warning([this file was generated for autoconf 2.69.
+You have another version of autoconf.  It may work, but is not guaranteed to.
+If you have problems, you may need to regenerate the build system entirely.
+To do so, use the procedure documented by the package, typically 'autoreconf'.])])
+
+# Copyright (C) 2002-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_AUTOMAKE_VERSION(VERSION)
+# ----------------------------
+# Automake X.Y traces this macro to ensure aclocal.m4 has been
+# generated from the m4 files accompanying Automake X.Y.
+# (This private macro should not be called outside this file.)
+AC_DEFUN([AM_AUTOMAKE_VERSION],
+[am__api_version='1.14'
+dnl Some users find AM_AUTOMAKE_VERSION and mistake it for a way to
+dnl require some minimum version.  Point them to the right macro.
+m4_if([$1], [1.14.1], [],
+      [AC_FATAL([Do not call $0, use AM_INIT_AUTOMAKE([$1]).])])dnl
+])
+
+# _AM_AUTOCONF_VERSION(VERSION)
+# -----------------------------
+# aclocal traces this macro to find the Autoconf version.
+# This is a private macro too.  Using m4_define simplifies
+# the logic in aclocal, which can simply ignore this definition.
+m4_define([_AM_AUTOCONF_VERSION], [])
+
+# AM_SET_CURRENT_AUTOMAKE_VERSION
+# -------------------------------
+# Call AM_AUTOMAKE_VERSION and AM_AUTOMAKE_VERSION so they can be traced.
+# This function is AC_REQUIREd by AM_INIT_AUTOMAKE.
+AC_DEFUN([AM_SET_CURRENT_AUTOMAKE_VERSION],
+[AM_AUTOMAKE_VERSION([1.14.1])dnl
+m4_ifndef([AC_AUTOCONF_VERSION],
+  [m4_copy([m4_PACKAGE_VERSION], [AC_AUTOCONF_VERSION])])dnl
+_AM_AUTOCONF_VERSION(m4_defn([AC_AUTOCONF_VERSION]))])
+
+# AM_AUX_DIR_EXPAND                                         -*- Autoconf -*-
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# For projects using AC_CONFIG_AUX_DIR([foo]), Autoconf sets
+# $ac_aux_dir to '$srcdir/foo'.  In other projects, it is set to
+# '$srcdir', '$srcdir/..', or '$srcdir/../..'.
+#
+# Of course, Automake must honor this variable whenever it calls a
+# tool from the auxiliary directory.  The problem is that $srcdir (and
+# therefore $ac_aux_dir as well) can be either absolute or relative,
+# depending on how configure is run.  This is pretty annoying, since
+# it makes $ac_aux_dir quite unusable in subdirectories: in the top
+# source directory, any form will work fine, but in subdirectories a
+# relative path needs to be adjusted first.
+#
+# $ac_aux_dir/missing
+#    fails when called from a subdirectory if $ac_aux_dir is relative
+# $top_srcdir/$ac_aux_dir/missing
+#    fails if $ac_aux_dir is absolute,
+#    fails when called from a subdirectory in a VPATH build with
+#          a relative $ac_aux_dir
+#
+# The reason of the latter failure is that $top_srcdir and $ac_aux_dir
+# are both prefixed by $srcdir.  In an in-source build this is usually
+# harmless because $srcdir is '.', but things will broke when you
+# start a VPATH build or use an absolute $srcdir.
+#
+# So we could use something similar to $top_srcdir/$ac_aux_dir/missing,
+# iff we strip the leading $srcdir from $ac_aux_dir.  That would be:
+#   am_aux_dir='\$(top_srcdir)/'`expr "$ac_aux_dir" : "$srcdir//*\(.*\)"`
+# and then we would define $MISSING as
+#   MISSING="\${SHELL} $am_aux_dir/missing"
+# This will work as long as MISSING is not called from configure, because
+# unfortunately $(top_srcdir) has no meaning in configure.
+# However there are other variables, like CC, which are often used in
+# configure, and could therefore not use this "fixed" $ac_aux_dir.
+#
+# Another solution, used here, is to always expand $ac_aux_dir to an
+# absolute PATH.  The drawback is that using absolute paths prevent a
+# configured tree to be moved without reconfiguration.
+
+AC_DEFUN([AM_AUX_DIR_EXPAND],
+[AC_REQUIRE([AC_CONFIG_AUX_DIR_DEFAULT])dnl
+# Expand $ac_aux_dir to an absolute path.
+am_aux_dir=`cd "$ac_aux_dir" && pwd`
+])
+
+# AM_CONDITIONAL                                            -*- Autoconf -*-
+
+# Copyright (C) 1997-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_CONDITIONAL(NAME, SHELL-CONDITION)
+# -------------------------------------
+# Define a conditional.
+AC_DEFUN([AM_CONDITIONAL],
+[AC_PREREQ([2.52])dnl
+ m4_if([$1], [TRUE],  [AC_FATAL([$0: invalid condition: $1])],
+       [$1], [FALSE], [AC_FATAL([$0: invalid condition: $1])])dnl
+AC_SUBST([$1_TRUE])dnl
+AC_SUBST([$1_FALSE])dnl
+_AM_SUBST_NOTMAKE([$1_TRUE])dnl
+_AM_SUBST_NOTMAKE([$1_FALSE])dnl
+m4_define([_AM_COND_VALUE_$1], [$2])dnl
+if $2; then
+  $1_TRUE=
+  $1_FALSE='#'
+else
+  $1_TRUE='#'
+  $1_FALSE=
+fi
+AC_CONFIG_COMMANDS_PRE(
+[if test -z "${$1_TRUE}" && test -z "${$1_FALSE}"; then
+  AC_MSG_ERROR([[conditional "$1" was never defined.
+Usually this means the macro was only invoked conditionally.]])
+fi])])
+
+# Copyright (C) 1999-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+
+# There are a few dirty hacks below to avoid letting 'AC_PROG_CC' be
+# written in clear, in which case automake, when reading aclocal.m4,
+# will think it sees a *use*, and therefore will trigger all it's
+# C support machinery.  Also note that it means that autoscan, seeing
+# CC etc. in the Makefile, will ask for an AC_PROG_CC use...
+
+
+# _AM_DEPENDENCIES(NAME)
+# ----------------------
+# See how the compiler implements dependency checking.
+# NAME is "CC", "CXX", "OBJC", "OBJCXX", "UPC", or "GJC".
+# We try a few techniques and use that to set a single cache variable.
+#
+# We don't AC_REQUIRE the corresponding AC_PROG_CC since the latter was
+# modified to invoke _AM_DEPENDENCIES(CC); we would have a circular
+# dependency, and given that the user is not expected to run this macro,
+# just rely on AC_PROG_CC.
+AC_DEFUN([_AM_DEPENDENCIES],
+[AC_REQUIRE([AM_SET_DEPDIR])dnl
+AC_REQUIRE([AM_OUTPUT_DEPENDENCY_COMMANDS])dnl
+AC_REQUIRE([AM_MAKE_INCLUDE])dnl
+AC_REQUIRE([AM_DEP_TRACK])dnl
+
+m4_if([$1], [CC],   [depcc="$CC"   am_compiler_list=],
+      [$1], [CXX],  [depcc="$CXX"  am_compiler_list=],
+      [$1], [OBJC], [depcc="$OBJC" am_compiler_list='gcc3 gcc'],
+      [$1], [OBJCXX], [depcc="$OBJCXX" am_compiler_list='gcc3 gcc'],
+      [$1], [UPC],  [depcc="$UPC"  am_compiler_list=],
+      [$1], [GCJ],  [depcc="$GCJ"  am_compiler_list='gcc3 gcc'],
+                    [depcc="$$1"   am_compiler_list=])
+
+AC_CACHE_CHECK([dependency style of $depcc],
+               [am_cv_$1_dependencies_compiler_type],
+[if test -z "$AMDEP_TRUE" && test -f "$am_depcomp"; then
+  # We make a subdir and do the tests there.  Otherwise we can end up
+  # making bogus files that we don't know about and never remove.  For
+  # instance it was reported that on HP-UX the gcc test will end up
+  # making a dummy file named 'D' -- because '-MD' means "put the output
+  # in D".
+  rm -rf conftest.dir
+  mkdir conftest.dir
+  # Copy depcomp to subdir because otherwise we won't find it if we're
+  # using a relative directory.
+  cp "$am_depcomp" conftest.dir
+  cd conftest.dir
+  # We will build objects and dependencies in a subdirectory because
+  # it helps to detect inapplicable dependency modes.  For instance
+  # both Tru64's cc and ICC support -MD to output dependencies as a
+  # side effect of compilation, but ICC will put the dependencies in
+  # the current directory while Tru64 will put them in the object
+  # directory.
+  mkdir sub
+
+  am_cv_$1_dependencies_compiler_type=none
+  if test "$am_compiler_list" = ""; then
+     am_compiler_list=`sed -n ['s/^#*\([a-zA-Z0-9]*\))$/\1/p'] < ./depcomp`
+  fi
+  am__universal=false
+  m4_case([$1], [CC],
+    [case " $depcc " in #(
+     *\ -arch\ *\ -arch\ *) am__universal=true ;;
+     esac],
+    [CXX],
+    [case " $depcc " in #(
+     *\ -arch\ *\ -arch\ *) am__universal=true ;;
+     esac])
+
+  for depmode in $am_compiler_list; do
+    # Setup a source with many dependencies, because some compilers
+    # like to wrap large dependency lists on column 80 (with \), and
+    # we should not choose a depcomp mode which is confused by this.
+    #
+    # We need to recreate these files for each test, as the compiler may
+    # overwrite some of them when testing with obscure command lines.
+    # This happens at least with the AIX C compiler.
+    : > sub/conftest.c
+    for i in 1 2 3 4 5 6; do
+      echo '#include "conftst'$i'.h"' >> sub/conftest.c
+      # Using ": > sub/conftst$i.h" creates only sub/conftst1.h with
+      # Solaris 10 /bin/sh.
+      echo '/* dummy */' > sub/conftst$i.h
+    done
+    echo "${am__include} ${am__quote}sub/conftest.Po${am__quote}" > confmf
+
+    # We check with '-c' and '-o' for the sake of the "dashmstdout"
+    # mode.  It turns out that the SunPro C++ compiler does not properly
+    # handle '-M -o', and we need to detect this.  Also, some Intel
+    # versions had trouble with output in subdirs.
+    am__obj=sub/conftest.${OBJEXT-o}
+    am__minus_obj="-o $am__obj"
+    case $depmode in
+    gcc)
+      # This depmode causes a compiler race in universal mode.
+      test "$am__universal" = false || continue
+      ;;
+    nosideeffect)
+      # After this tag, mechanisms are not by side-effect, so they'll
+      # only be used when explicitly requested.
+      if test "x$enable_dependency_tracking" = xyes; then
+	continue
+      else
+	break
+      fi
+      ;;
+    msvc7 | msvc7msys | msvisualcpp | msvcmsys)
+      # This compiler won't grok '-c -o', but also, the minuso test has
+      # not run yet.  These depmodes are late enough in the game, and
+      # so weak that their functioning should not be impacted.
+      am__obj=conftest.${OBJEXT-o}
+      am__minus_obj=
+      ;;
+    none) break ;;
+    esac
+    if depmode=$depmode \
+       source=sub/conftest.c object=$am__obj \
+       depfile=sub/conftest.Po tmpdepfile=sub/conftest.TPo \
+       $SHELL ./depcomp $depcc -c $am__minus_obj sub/conftest.c \
+         >/dev/null 2>conftest.err &&
+       grep sub/conftst1.h sub/conftest.Po > /dev/null 2>&1 &&
+       grep sub/conftst6.h sub/conftest.Po > /dev/null 2>&1 &&
+       grep $am__obj sub/conftest.Po > /dev/null 2>&1 &&
+       ${MAKE-make} -s -f confmf > /dev/null 2>&1; then
+      # icc doesn't choke on unknown options, it will just issue warnings
+      # or remarks (even with -Werror).  So we grep stderr for any message
+      # that says an option was ignored or not supported.
+      # When given -MP, icc 7.0 and 7.1 complain thusly:
+      #   icc: Command line warning: ignoring option '-M'; no argument required
+      # The diagnosis changed in icc 8.0:
+      #   icc: Command line remark: option '-MP' not supported
+      if (grep 'ignoring option' conftest.err ||
+          grep 'not supported' conftest.err) >/dev/null 2>&1; then :; else
+        am_cv_$1_dependencies_compiler_type=$depmode
+        break
+      fi
+    fi
+  done
+
+  cd ..
+  rm -rf conftest.dir
+else
+  am_cv_$1_dependencies_compiler_type=none
+fi
+])
+AC_SUBST([$1DEPMODE], [depmode=$am_cv_$1_dependencies_compiler_type])
+AM_CONDITIONAL([am__fastdep$1], [
+  test "x$enable_dependency_tracking" != xno \
+  && test "$am_cv_$1_dependencies_compiler_type" = gcc3])
+])
+
+
+# AM_SET_DEPDIR
+# -------------
+# Choose a directory name for dependency files.
+# This macro is AC_REQUIREd in _AM_DEPENDENCIES.
+AC_DEFUN([AM_SET_DEPDIR],
+[AC_REQUIRE([AM_SET_LEADING_DOT])dnl
+AC_SUBST([DEPDIR], ["${am__leading_dot}deps"])dnl
+])
+
+
+# AM_DEP_TRACK
+# ------------
+AC_DEFUN([AM_DEP_TRACK],
+[AC_ARG_ENABLE([dependency-tracking], [dnl
+AS_HELP_STRING(
+  [--enable-dependency-tracking],
+  [do not reject slow dependency extractors])
+AS_HELP_STRING(
+  [--disable-dependency-tracking],
+  [speeds up one-time build])])
+if test "x$enable_dependency_tracking" != xno; then
+  am_depcomp="$ac_aux_dir/depcomp"
+  AMDEPBACKSLASH='\'
+  am__nodep='_no'
+fi
+AM_CONDITIONAL([AMDEP], [test "x$enable_dependency_tracking" != xno])
+AC_SUBST([AMDEPBACKSLASH])dnl
+_AM_SUBST_NOTMAKE([AMDEPBACKSLASH])dnl
+AC_SUBST([am__nodep])dnl
+_AM_SUBST_NOTMAKE([am__nodep])dnl
+])
+
+# Generate code to set up dependency tracking.              -*- Autoconf -*-
+
+# Copyright (C) 1999-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+
+# _AM_OUTPUT_DEPENDENCY_COMMANDS
+# ------------------------------
+AC_DEFUN([_AM_OUTPUT_DEPENDENCY_COMMANDS],
+[{
+  # Older Autoconf quotes --file arguments for eval, but not when files
+  # are listed without --file.  Let's play safe and only enable the eval
+  # if we detect the quoting.
+  case $CONFIG_FILES in
+  *\'*) eval set x "$CONFIG_FILES" ;;
+  *)   set x $CONFIG_FILES ;;
+  esac
+  shift
+  for mf
+  do
+    # Strip MF so we end up with the name of the file.
+    mf=`echo "$mf" | sed -e 's/:.*$//'`
+    # Check whether this is an Automake generated Makefile or not.
+    # We used to match only the files named 'Makefile.in', but
+    # some people rename them; so instead we look at the file content.
+    # Grep'ing the first line is not enough: some people post-process
+    # each Makefile.in and add a new line on top of each file to say so.
+    # Grep'ing the whole file is not good either: AIX grep has a line
+    # limit of 2048, but all sed's we know have understand at least 4000.
+    if sed -n 's,^#.*generated by automake.*,X,p' "$mf" | grep X >/dev/null 2>&1; then
+      dirpart=`AS_DIRNAME("$mf")`
+    else
+      continue
+    fi
+    # Extract the definition of DEPDIR, am__include, and am__quote
+    # from the Makefile without running 'make'.
+    DEPDIR=`sed -n 's/^DEPDIR = //p' < "$mf"`
+    test -z "$DEPDIR" && continue
+    am__include=`sed -n 's/^am__include = //p' < "$mf"`
+    test -z "$am__include" && continue
+    am__quote=`sed -n 's/^am__quote = //p' < "$mf"`
+    # Find all dependency output files, they are included files with
+    # $(DEPDIR) in their names.  We invoke sed twice because it is the
+    # simplest approach to changing $(DEPDIR) to its actual value in the
+    # expansion.
+    for file in `sed -n "
+      s/^$am__include $am__quote\(.*(DEPDIR).*\)$am__quote"'$/\1/p' <"$mf" | \
+	 sed -e 's/\$(DEPDIR)/'"$DEPDIR"'/g'`; do
+      # Make sure the directory exists.
+      test -f "$dirpart/$file" && continue
+      fdir=`AS_DIRNAME(["$file"])`
+      AS_MKDIR_P([$dirpart/$fdir])
+      # echo "creating $dirpart/$file"
+      echo '# dummy' > "$dirpart/$file"
+    done
+  done
+}
+])# _AM_OUTPUT_DEPENDENCY_COMMANDS
+
+
+# AM_OUTPUT_DEPENDENCY_COMMANDS
+# -----------------------------
+# This macro should only be invoked once -- use via AC_REQUIRE.
+#
+# This code is only required when automatic dependency tracking
+# is enabled.  FIXME.  This creates each '.P' file that we will
+# need in order to bootstrap the dependency handling code.
+AC_DEFUN([AM_OUTPUT_DEPENDENCY_COMMANDS],
+[AC_CONFIG_COMMANDS([depfiles],
+     [test x"$AMDEP_TRUE" != x"" || _AM_OUTPUT_DEPENDENCY_COMMANDS],
+     [AMDEP_TRUE="$AMDEP_TRUE" ac_aux_dir="$ac_aux_dir"])
+])
+
+# Do all the work for Automake.                             -*- Autoconf -*-
+
+# Copyright (C) 1996-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This macro actually does too much.  Some checks are only needed if
+# your package does certain things.  But this isn't really a big deal.
+
+dnl Redefine AC_PROG_CC to automatically invoke _AM_PROG_CC_C_O.
+m4_define([AC_PROG_CC],
+m4_defn([AC_PROG_CC])
+[_AM_PROG_CC_C_O
+])
+
+# AM_INIT_AUTOMAKE(PACKAGE, VERSION, [NO-DEFINE])
+# AM_INIT_AUTOMAKE([OPTIONS])
+# -----------------------------------------------
+# The call with PACKAGE and VERSION arguments is the old style
+# call (pre autoconf-2.50), which is being phased out.  PACKAGE
+# and VERSION should now be passed to AC_INIT and removed from
+# the call to AM_INIT_AUTOMAKE.
+# We support both call styles for the transition.  After
+# the next Automake release, Autoconf can make the AC_INIT
+# arguments mandatory, and then we can depend on a new Autoconf
+# release and drop the old call support.
+AC_DEFUN([AM_INIT_AUTOMAKE],
+[AC_PREREQ([2.65])dnl
+dnl Autoconf wants to disallow AM_ names.  We explicitly allow
+dnl the ones we care about.
+m4_pattern_allow([^AM_[A-Z]+FLAGS$])dnl
+AC_REQUIRE([AM_SET_CURRENT_AUTOMAKE_VERSION])dnl
+AC_REQUIRE([AC_PROG_INSTALL])dnl
+if test "`cd $srcdir && pwd`" != "`pwd`"; then
+  # Use -I$(srcdir) only when $(srcdir) != ., so that make's output
+  # is not polluted with repeated "-I."
+  AC_SUBST([am__isrc], [' -I$(srcdir)'])_AM_SUBST_NOTMAKE([am__isrc])dnl
+  # test to see if srcdir already configured
+  if test -f $srcdir/config.status; then
+    AC_MSG_ERROR([source directory already configured; run "make distclean" there first])
+  fi
+fi
+
+# test whether we have cygpath
+if test -z "$CYGPATH_W"; then
+  if (cygpath --version) >/dev/null 2>/dev/null; then
+    CYGPATH_W='cygpath -w'
+  else
+    CYGPATH_W=echo
+  fi
+fi
+AC_SUBST([CYGPATH_W])
+
+# Define the identity of the package.
+dnl Distinguish between old-style and new-style calls.
+m4_ifval([$2],
+[AC_DIAGNOSE([obsolete],
+             [$0: two- and three-arguments forms are deprecated.])
+m4_ifval([$3], [_AM_SET_OPTION([no-define])])dnl
+ AC_SUBST([PACKAGE], [$1])dnl
+ AC_SUBST([VERSION], [$2])],
+[_AM_SET_OPTIONS([$1])dnl
+dnl Diagnose old-style AC_INIT with new-style AM_AUTOMAKE_INIT.
+m4_if(
+  m4_ifdef([AC_PACKAGE_NAME], [ok]):m4_ifdef([AC_PACKAGE_VERSION], [ok]),
+  [ok:ok],,
+  [m4_fatal([AC_INIT should be called with package and version arguments])])dnl
+ AC_SUBST([PACKAGE], ['AC_PACKAGE_TARNAME'])dnl
+ AC_SUBST([VERSION], ['AC_PACKAGE_VERSION'])])dnl
+
+_AM_IF_OPTION([no-define],,
+[AC_DEFINE_UNQUOTED([PACKAGE], ["$PACKAGE"], [Name of package])
+ AC_DEFINE_UNQUOTED([VERSION], ["$VERSION"], [Version number of package])])dnl
+
+# Some tools Automake needs.
+AC_REQUIRE([AM_SANITY_CHECK])dnl
+AC_REQUIRE([AC_ARG_PROGRAM])dnl
+AM_MISSING_PROG([ACLOCAL], [aclocal-${am__api_version}])
+AM_MISSING_PROG([AUTOCONF], [autoconf])
+AM_MISSING_PROG([AUTOMAKE], [automake-${am__api_version}])
+AM_MISSING_PROG([AUTOHEADER], [autoheader])
+AM_MISSING_PROG([MAKEINFO], [makeinfo])
+AC_REQUIRE([AM_PROG_INSTALL_SH])dnl
+AC_REQUIRE([AM_PROG_INSTALL_STRIP])dnl
+AC_REQUIRE([AC_PROG_MKDIR_P])dnl
+# For better backward compatibility.  To be removed once Automake 1.9.x
+# dies out for good.  For more background, see:
+# <http://lists.gnu.org/archive/html/automake/2012-07/msg00001.html>
+# <http://lists.gnu.org/archive/html/automake/2012-07/msg00014.html>
+AC_SUBST([mkdir_p], ['$(MKDIR_P)'])
+# We need awk for the "check" target.  The system "awk" is bad on
+# some platforms.
+AC_REQUIRE([AC_PROG_AWK])dnl
+AC_REQUIRE([AC_PROG_MAKE_SET])dnl
+AC_REQUIRE([AM_SET_LEADING_DOT])dnl
+_AM_IF_OPTION([tar-ustar], [_AM_PROG_TAR([ustar])],
+	      [_AM_IF_OPTION([tar-pax], [_AM_PROG_TAR([pax])],
+			     [_AM_PROG_TAR([v7])])])
+_AM_IF_OPTION([no-dependencies],,
+[AC_PROVIDE_IFELSE([AC_PROG_CC],
+		  [_AM_DEPENDENCIES([CC])],
+		  [m4_define([AC_PROG_CC],
+			     m4_defn([AC_PROG_CC])[_AM_DEPENDENCIES([CC])])])dnl
+AC_PROVIDE_IFELSE([AC_PROG_CXX],
+		  [_AM_DEPENDENCIES([CXX])],
+		  [m4_define([AC_PROG_CXX],
+			     m4_defn([AC_PROG_CXX])[_AM_DEPENDENCIES([CXX])])])dnl
+AC_PROVIDE_IFELSE([AC_PROG_OBJC],
+		  [_AM_DEPENDENCIES([OBJC])],
+		  [m4_define([AC_PROG_OBJC],
+			     m4_defn([AC_PROG_OBJC])[_AM_DEPENDENCIES([OBJC])])])dnl
+AC_PROVIDE_IFELSE([AC_PROG_OBJCXX],
+		  [_AM_DEPENDENCIES([OBJCXX])],
+		  [m4_define([AC_PROG_OBJCXX],
+			     m4_defn([AC_PROG_OBJCXX])[_AM_DEPENDENCIES([OBJCXX])])])dnl
+])
+AC_REQUIRE([AM_SILENT_RULES])dnl
+dnl The testsuite driver may need to know about EXEEXT, so add the
+dnl 'am__EXEEXT' conditional if _AM_COMPILER_EXEEXT was seen.  This
+dnl macro is hooked onto _AC_COMPILER_EXEEXT early, see below.
+AC_CONFIG_COMMANDS_PRE(dnl
+[m4_provide_if([_AM_COMPILER_EXEEXT],
+  [AM_CONDITIONAL([am__EXEEXT], [test -n "$EXEEXT"])])])dnl
+
+# POSIX will say in a future version that running "rm -f" with no argument
+# is OK; and we want to be able to make that assumption in our Makefile
+# recipes.  So use an aggressive probe to check that the usage we want is
+# actually supported "in the wild" to an acceptable degree.
+# See automake bug#10828.
+# To make any issue more visible, cause the running configure to be aborted
+# by default if the 'rm' program in use doesn't match our expectations; the
+# user can still override this though.
+if rm -f && rm -fr && rm -rf; then : OK; else
+  cat >&2 <<'END'
+Oops!
+
+Your 'rm' program seems unable to run without file operands specified
+on the command line, even when the '-f' option is present.  This is contrary
+to the behaviour of most rm programs out there, and not conforming with
+the upcoming POSIX standard: <http://austingroupbugs.net/view.php?id=542>
+
+Please tell bug-automake@gnu.org about your system, including the value
+of your $PATH and any error possibly output before this message.  This
+can help us improve future automake versions.
+
+END
+  if test x"$ACCEPT_INFERIOR_RM_PROGRAM" = x"yes"; then
+    echo 'Configuration will proceed anyway, since you have set the' >&2
+    echo 'ACCEPT_INFERIOR_RM_PROGRAM variable to "yes"' >&2
+    echo >&2
+  else
+    cat >&2 <<'END'
+Aborting the configuration process, to ensure you take notice of the issue.
+
+You can download and install GNU coreutils to get an 'rm' implementation
+that behaves properly: <http://www.gnu.org/software/coreutils/>.
+
+If you want to complete the configuration process using your problematic
+'rm' anyway, export the environment variable ACCEPT_INFERIOR_RM_PROGRAM
+to "yes", and re-run configure.
+
+END
+    AC_MSG_ERROR([Your 'rm' program is bad, sorry.])
+  fi
+fi
+])
+
+dnl Hook into '_AC_COMPILER_EXEEXT' early to learn its expansion.  Do not
+dnl add the conditional right here, as _AC_COMPILER_EXEEXT may be further
+dnl mangled by Autoconf and run in a shell conditional statement.
+m4_define([_AC_COMPILER_EXEEXT],
+m4_defn([_AC_COMPILER_EXEEXT])[m4_provide([_AM_COMPILER_EXEEXT])])
+
+# When config.status generates a header, we must update the stamp-h file.
+# This file resides in the same directory as the config header
+# that is generated.  The stamp files are numbered to have different names.
+
+# Autoconf calls _AC_AM_CONFIG_HEADER_HOOK (when defined) in the
+# loop where config.status creates the headers, so we can generate
+# our stamp files there.
+AC_DEFUN([_AC_AM_CONFIG_HEADER_HOOK],
+[# Compute $1's index in $config_headers.
+_am_arg=$1
+_am_stamp_count=1
+for _am_header in $config_headers :; do
+  case $_am_header in
+    $_am_arg | $_am_arg:* )
+      break ;;
+    * )
+      _am_stamp_count=`expr $_am_stamp_count + 1` ;;
+  esac
+done
+echo "timestamp for $_am_arg" >`AS_DIRNAME(["$_am_arg"])`/stamp-h[]$_am_stamp_count])
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_PROG_INSTALL_SH
+# ------------------
+# Define $install_sh.
+AC_DEFUN([AM_PROG_INSTALL_SH],
+[AC_REQUIRE([AM_AUX_DIR_EXPAND])dnl
+if test x"${install_sh}" != xset; then
+  case $am_aux_dir in
+  *\ * | *\	*)
+    install_sh="\${SHELL} '$am_aux_dir/install-sh'" ;;
+  *)
+    install_sh="\${SHELL} $am_aux_dir/install-sh"
+  esac
+fi
+AC_SUBST([install_sh])])
+
+# Copyright (C) 2003-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# Check whether the underlying file-system supports filenames
+# with a leading dot.  For instance MS-DOS doesn't.
+AC_DEFUN([AM_SET_LEADING_DOT],
+[rm -rf .tst 2>/dev/null
+mkdir .tst 2>/dev/null
+if test -d .tst; then
+  am__leading_dot=.
+else
+  am__leading_dot=_
+fi
+rmdir .tst 2>/dev/null
+AC_SUBST([am__leading_dot])])
+
+# Check to see how 'make' treats includes.	            -*- Autoconf -*-
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_MAKE_INCLUDE()
+# -----------------
+# Check to see how make treats includes.
+AC_DEFUN([AM_MAKE_INCLUDE],
+[am_make=${MAKE-make}
+cat > confinc << 'END'
+am__doit:
+	@echo this is the am__doit target
+.PHONY: am__doit
+END
+# If we don't find an include directive, just comment out the code.
+AC_MSG_CHECKING([for style of include used by $am_make])
+am__include="#"
+am__quote=
+_am_result=none
+# First try GNU make style include.
+echo "include confinc" > confmf
+# Ignore all kinds of additional output from 'make'.
+case `$am_make -s -f confmf 2> /dev/null` in #(
+*the\ am__doit\ target*)
+  am__include=include
+  am__quote=
+  _am_result=GNU
+  ;;
+esac
+# Now try BSD make style include.
+if test "$am__include" = "#"; then
+   echo '.include "confinc"' > confmf
+   case `$am_make -s -f confmf 2> /dev/null` in #(
+   *the\ am__doit\ target*)
+     am__include=.include
+     am__quote="\""
+     _am_result=BSD
+     ;;
+   esac
+fi
+AC_SUBST([am__include])
+AC_SUBST([am__quote])
+AC_MSG_RESULT([$_am_result])
+rm -f confinc confmf
+])
+
+# Fake the existence of programs that GNU maintainers use.  -*- Autoconf -*-
+
+# Copyright (C) 1997-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_MISSING_PROG(NAME, PROGRAM)
+# ------------------------------
+AC_DEFUN([AM_MISSING_PROG],
+[AC_REQUIRE([AM_MISSING_HAS_RUN])
+$1=${$1-"${am_missing_run}$2"}
+AC_SUBST($1)])
+
+# AM_MISSING_HAS_RUN
+# ------------------
+# Define MISSING if not defined so far and test if it is modern enough.
+# If it is, set am_missing_run to use it, otherwise, to nothing.
+AC_DEFUN([AM_MISSING_HAS_RUN],
+[AC_REQUIRE([AM_AUX_DIR_EXPAND])dnl
+AC_REQUIRE_AUX_FILE([missing])dnl
+if test x"${MISSING+set}" != xset; then
+  case $am_aux_dir in
+  *\ * | *\	*)
+    MISSING="\${SHELL} \"$am_aux_dir/missing\"" ;;
+  *)
+    MISSING="\${SHELL} $am_aux_dir/missing" ;;
+  esac
+fi
+# Use eval to expand $SHELL
+if eval "$MISSING --is-lightweight"; then
+  am_missing_run="$MISSING "
+else
+  am_missing_run=
+  AC_MSG_WARN(['missing' script is too old or missing])
+fi
+])
+
+# Helper functions for option handling.                     -*- Autoconf -*-
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# _AM_MANGLE_OPTION(NAME)
+# -----------------------
+AC_DEFUN([_AM_MANGLE_OPTION],
+[[_AM_OPTION_]m4_bpatsubst($1, [[^a-zA-Z0-9_]], [_])])
+
+# _AM_SET_OPTION(NAME)
+# --------------------
+# Set option NAME.  Presently that only means defining a flag for this option.
+AC_DEFUN([_AM_SET_OPTION],
+[m4_define(_AM_MANGLE_OPTION([$1]), [1])])
+
+# _AM_SET_OPTIONS(OPTIONS)
+# ------------------------
+# OPTIONS is a space-separated list of Automake options.
+AC_DEFUN([_AM_SET_OPTIONS],
+[m4_foreach_w([_AM_Option], [$1], [_AM_SET_OPTION(_AM_Option)])])
+
+# _AM_IF_OPTION(OPTION, IF-SET, [IF-NOT-SET])
+# -------------------------------------------
+# Execute IF-SET if OPTION is set, IF-NOT-SET otherwise.
+AC_DEFUN([_AM_IF_OPTION],
+[m4_ifset(_AM_MANGLE_OPTION([$1]), [$2], [$3])])
+
+# Copyright (C) 1999-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# _AM_PROG_CC_C_O
+# ---------------
+# Like AC_PROG_CC_C_O, but changed for automake.  We rewrite AC_PROG_CC
+# to automatically call this.
+AC_DEFUN([_AM_PROG_CC_C_O],
+[AC_REQUIRE([AM_AUX_DIR_EXPAND])dnl
+AC_REQUIRE_AUX_FILE([compile])dnl
+AC_LANG_PUSH([C])dnl
+AC_CACHE_CHECK(
+  [whether $CC understands -c and -o together],
+  [am_cv_prog_cc_c_o],
+  [AC_LANG_CONFTEST([AC_LANG_PROGRAM([])])
+  # Make sure it works both with $CC and with simple cc.
+  # Following AC_PROG_CC_C_O, we do the test twice because some
+  # compilers refuse to overwrite an existing .o file with -o,
+  # though they will create one.
+  am_cv_prog_cc_c_o=yes
+  for am_i in 1 2; do
+    if AM_RUN_LOG([$CC -c conftest.$ac_ext -o conftest2.$ac_objext]) \
+         && test -f conftest2.$ac_objext; then
+      : OK
+    else
+      am_cv_prog_cc_c_o=no
+      break
+    fi
+  done
+  rm -f core conftest*
+  unset am_i])
+if test "$am_cv_prog_cc_c_o" != yes; then
+   # Losing compiler, so override with the script.
+   # FIXME: It is wrong to rewrite CC.
+   # But if we don't then we get into trouble of one sort or another.
+   # A longer-term fix would be to have automake use am__CC in this case,
+   # and then we could set am__CC="\$(top_srcdir)/compile \$(CC)"
+   CC="$am_aux_dir/compile $CC"
+fi
+AC_LANG_POP([C])])
+
+# For backward compatibility.
+AC_DEFUN_ONCE([AM_PROG_CC_C_O], [AC_REQUIRE([AC_PROG_CC])])
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_RUN_LOG(COMMAND)
+# -------------------
+# Run COMMAND, save the exit status in ac_status, and log it.
+# (This has been adapted from Autoconf's _AC_RUN_LOG macro.)
+AC_DEFUN([AM_RUN_LOG],
+[{ echo "$as_me:$LINENO: $1" >&AS_MESSAGE_LOG_FD
+   ($1) >&AS_MESSAGE_LOG_FD 2>&AS_MESSAGE_LOG_FD
+   ac_status=$?
+   echo "$as_me:$LINENO: \$? = $ac_status" >&AS_MESSAGE_LOG_FD
+   (exit $ac_status); }])
+
+# Check to make sure that the build environment is sane.    -*- Autoconf -*-
+
+# Copyright (C) 1996-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_SANITY_CHECK
+# ---------------
+AC_DEFUN([AM_SANITY_CHECK],
+[AC_MSG_CHECKING([whether build environment is sane])
+# Reject unsafe characters in $srcdir or the absolute working directory
+# name.  Accept space and tab only in the latter.
+am_lf='
+'
+case `pwd` in
+  *[[\\\"\#\$\&\'\`$am_lf]]*)
+    AC_MSG_ERROR([unsafe absolute working directory name]);;
+esac
+case $srcdir in
+  *[[\\\"\#\$\&\'\`$am_lf\ \	]]*)
+    AC_MSG_ERROR([unsafe srcdir value: '$srcdir']);;
+esac
+
+# Do 'set' in a subshell so we don't clobber the current shell's
+# arguments.  Must try -L first in case configure is actually a
+# symlink; some systems play weird games with the mod time of symlinks
+# (eg FreeBSD returns the mod time of the symlink's containing
+# directory).
+if (
+   am_has_slept=no
+   for am_try in 1 2; do
+     echo "timestamp, slept: $am_has_slept" > conftest.file
+     set X `ls -Lt "$srcdir/configure" conftest.file 2> /dev/null`
+     if test "$[*]" = "X"; then
+	# -L didn't work.
+	set X `ls -t "$srcdir/configure" conftest.file`
+     fi
+     if test "$[*]" != "X $srcdir/configure conftest.file" \
+	&& test "$[*]" != "X conftest.file $srcdir/configure"; then
+
+	# If neither matched, then we have a broken ls.  This can happen
+	# if, for instance, CONFIG_SHELL is bash and it inherits a
+	# broken ls alias from the environment.  This has actually
+	# happened.  Such a system could not be considered "sane".
+	AC_MSG_ERROR([ls -t appears to fail.  Make sure there is not a broken
+  alias in your environment])
+     fi
+     if test "$[2]" = conftest.file || test $am_try -eq 2; then
+       break
+     fi
+     # Just in case.
+     sleep 1
+     am_has_slept=yes
+   done
+   test "$[2]" = conftest.file
+   )
+then
+   # Ok.
+   :
+else
+   AC_MSG_ERROR([newly created file is older than distributed files!
+Check your system clock])
+fi
+AC_MSG_RESULT([yes])
+# If we didn't sleep, we still need to ensure time stamps of config.status and
+# generated files are strictly newer.
+am_sleep_pid=
+if grep 'slept: no' conftest.file >/dev/null 2>&1; then
+  ( sleep 1 ) &
+  am_sleep_pid=$!
+fi
+AC_CONFIG_COMMANDS_PRE(
+  [AC_MSG_CHECKING([that generated files are newer than configure])
+   if test -n "$am_sleep_pid"; then
+     # Hide warnings about reused PIDs.
+     wait $am_sleep_pid 2>/dev/null
+   fi
+   AC_MSG_RESULT([done])])
+rm -f conftest.file
+])
+
+# Copyright (C) 2009-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_SILENT_RULES([DEFAULT])
+# --------------------------
+# Enable less verbose build rules; with the default set to DEFAULT
+# ("yes" being less verbose, "no" or empty being verbose).
+AC_DEFUN([AM_SILENT_RULES],
+[AC_ARG_ENABLE([silent-rules], [dnl
+AS_HELP_STRING(
+  [--enable-silent-rules],
+  [less verbose build output (undo: "make V=1")])
+AS_HELP_STRING(
+  [--disable-silent-rules],
+  [verbose build output (undo: "make V=0")])dnl
+])
+case $enable_silent_rules in @%:@ (((
+  yes) AM_DEFAULT_VERBOSITY=0;;
+   no) AM_DEFAULT_VERBOSITY=1;;
+    *) AM_DEFAULT_VERBOSITY=m4_if([$1], [yes], [0], [1]);;
+esac
+dnl
+dnl A few 'make' implementations (e.g., NonStop OS and NextStep)
+dnl do not support nested variable expansions.
+dnl See automake bug#9928 and bug#10237.
+am_make=${MAKE-make}
+AC_CACHE_CHECK([whether $am_make supports nested variables],
+   [am_cv_make_support_nested_variables],
+   [if AS_ECHO([['TRUE=$(BAR$(V))
+BAR0=false
+BAR1=true
+V=1
+am__doit:
+	@$(TRUE)
+.PHONY: am__doit']]) | $am_make -f - >/dev/null 2>&1; then
+  am_cv_make_support_nested_variables=yes
+else
+  am_cv_make_support_nested_variables=no
+fi])
+if test $am_cv_make_support_nested_variables = yes; then
+  dnl Using '$V' instead of '$(V)' breaks IRIX make.
+  AM_V='$(V)'
+  AM_DEFAULT_V='$(AM_DEFAULT_VERBOSITY)'
+else
+  AM_V=$AM_DEFAULT_VERBOSITY
+  AM_DEFAULT_V=$AM_DEFAULT_VERBOSITY
+fi
+AC_SUBST([AM_V])dnl
+AM_SUBST_NOTMAKE([AM_V])dnl
+AC_SUBST([AM_DEFAULT_V])dnl
+AM_SUBST_NOTMAKE([AM_DEFAULT_V])dnl
+AC_SUBST([AM_DEFAULT_VERBOSITY])dnl
+AM_BACKSLASH='\'
+AC_SUBST([AM_BACKSLASH])dnl
+_AM_SUBST_NOTMAKE([AM_BACKSLASH])dnl
+])
+
+# Copyright (C) 2001-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# AM_PROG_INSTALL_STRIP
+# ---------------------
+# One issue with vendor 'install' (even GNU) is that you can't
+# specify the program used to strip binaries.  This is especially
+# annoying in cross-compiling environments, where the build's strip
+# is unlikely to handle the host's binaries.
+# Fortunately install-sh will honor a STRIPPROG variable, so we
+# always use install-sh in "make install-strip", and initialize
+# STRIPPROG with the value of the STRIP variable (set by the user).
+AC_DEFUN([AM_PROG_INSTALL_STRIP],
+[AC_REQUIRE([AM_PROG_INSTALL_SH])dnl
+# Installed binaries are usually stripped using 'strip' when the user
+# run "make install-strip".  However 'strip' might not be the right
+# tool to use in cross-compilation environments, therefore Automake
+# will honor the 'STRIP' environment variable to overrule this program.
+dnl Don't test for $cross_compiling = yes, because it might be 'maybe'.
+if test "$cross_compiling" != no; then
+  AC_CHECK_TOOL([STRIP], [strip], :)
+fi
+INSTALL_STRIP_PROGRAM="\$(install_sh) -c -s"
+AC_SUBST([INSTALL_STRIP_PROGRAM])])
+
+# Copyright (C) 2006-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# _AM_SUBST_NOTMAKE(VARIABLE)
+# ---------------------------
+# Prevent Automake from outputting VARIABLE = @VARIABLE@ in Makefile.in.
+# This macro is traced by Automake.
+AC_DEFUN([_AM_SUBST_NOTMAKE])
+
+# AM_SUBST_NOTMAKE(VARIABLE)
+# --------------------------
+# Public sister of _AM_SUBST_NOTMAKE.
+AC_DEFUN([AM_SUBST_NOTMAKE], [_AM_SUBST_NOTMAKE($@)])
+
+# Check how to create a tarball.                            -*- Autoconf -*-
+
+# Copyright (C) 2004-2013 Free Software Foundation, Inc.
+#
+# This file is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# _AM_PROG_TAR(FORMAT)
+# --------------------
+# Check how to create a tarball in format FORMAT.
+# FORMAT should be one of 'v7', 'ustar', or 'pax'.
+#
+# Substitute a variable $(am__tar) that is a command
+# writing to stdout a FORMAT-tarball containing the directory
+# $tardir.
+#     tardir=directory && $(am__tar) > result.tar
+#
+# Substitute a variable $(am__untar) that extract such
+# a tarball read from stdin.
+#     $(am__untar) < result.tar
+#
+AC_DEFUN([_AM_PROG_TAR],
+[# Always define AMTAR for backward compatibility.  Yes, it's still used
+# in the wild :-(  We should find a proper way to deprecate it ...
+AC_SUBST([AMTAR], ['$${TAR-tar}'])
+
+# We'll loop over all known methods to create a tar archive until one works.
+_am_tools='gnutar m4_if([$1], [ustar], [plaintar]) pax cpio none'
+
+m4_if([$1], [v7],
+  [am__tar='$${TAR-tar} chof - "$$tardir"' am__untar='$${TAR-tar} xf -'],
+
+  [m4_case([$1],
+    [ustar],
+     [# The POSIX 1988 'ustar' format is defined with fixed-size fields.
+      # There is notably a 21 bits limit for the UID and the GID.  In fact,
+      # the 'pax' utility can hang on bigger UID/GID (see automake bug#8343
+      # and bug#13588).
+      am_max_uid=2097151 # 2^21 - 1
+      am_max_gid=$am_max_uid
+      # The $UID and $GID variables are not portable, so we need to resort
+      # to the POSIX-mandated id(1) utility.  Errors in the 'id' calls
+      # below are definitely unexpected, so allow the users to see them
+      # (that is, avoid stderr redirection).
+      am_uid=`id -u || echo unknown`
+      am_gid=`id -g || echo unknown`
+      AC_MSG_CHECKING([whether UID '$am_uid' is supported by ustar format])
+      if test $am_uid -le $am_max_uid; then
+         AC_MSG_RESULT([yes])
+      else
+         AC_MSG_RESULT([no])
+         _am_tools=none
+      fi
+      AC_MSG_CHECKING([whether GID '$am_gid' is supported by ustar format])
+      if test $am_gid -le $am_max_gid; then
+         AC_MSG_RESULT([yes])
+      else
+        AC_MSG_RESULT([no])
+        _am_tools=none
+      fi],
+
+  [pax],
+    [],
+
+  [m4_fatal([Unknown tar format])])
+
+  AC_MSG_CHECKING([how to create a $1 tar archive])
+
+  # Go ahead even if we have the value already cached.  We do so because we
+  # need to set the values for the 'am__tar' and 'am__untar' variables.
+  _am_tools=${am_cv_prog_tar_$1-$_am_tools}
+
+  for _am_tool in $_am_tools; do
+    case $_am_tool in
+    gnutar)
+      for _am_tar in tar gnutar gtar; do
+        AM_RUN_LOG([$_am_tar --version]) && break
+      done
+      am__tar="$_am_tar --format=m4_if([$1], [pax], [posix], [$1]) -chf - "'"$$tardir"'
+      am__tar_="$_am_tar --format=m4_if([$1], [pax], [posix], [$1]) -chf - "'"$tardir"'
+      am__untar="$_am_tar -xf -"
+      ;;
+    plaintar)
+      # Must skip GNU tar: if it does not support --format= it doesn't create
+      # ustar tarball either.
+      (tar --version) >/dev/null 2>&1 && continue
+      am__tar='tar chf - "$$tardir"'
+      am__tar_='tar chf - "$tardir"'
+      am__untar='tar xf -'
+      ;;
+    pax)
+      am__tar='pax -L -x $1 -w "$$tardir"'
+      am__tar_='pax -L -x $1 -w "$tardir"'
+      am__untar='pax -r'
+      ;;
+    cpio)
+      am__tar='find "$$tardir" -print | cpio -o -H $1 -L'
+      am__tar_='find "$tardir" -print | cpio -o -H $1 -L'
+      am__untar='cpio -i -H $1 -d'
+      ;;
+    none)
+      am__tar=false
+      am__tar_=false
+      am__untar=false
+      ;;
+    esac
+
+    # If the value was cached, stop now.  We just wanted to have am__tar
+    # and am__untar set.
+    test -n "${am_cv_prog_tar_$1}" && break
+
+    # tar/untar a dummy directory, and stop if the command works.
+    rm -rf conftest.dir
+    mkdir conftest.dir
+    echo GrepMe > conftest.dir/file
+    AM_RUN_LOG([tardir=conftest.dir && eval $am__tar_ >conftest.tar])
+    rm -rf conftest.dir
+    if test -s conftest.tar; then
+      AM_RUN_LOG([$am__untar <conftest.tar])
+      AM_RUN_LOG([cat conftest.dir/file])
+      grep GrepMe conftest.dir/file >/dev/null 2>&1 && break
+    fi
+  done
+  rm -rf conftest.dir
+
+  AC_CACHE_VAL([am_cv_prog_tar_$1], [am_cv_prog_tar_$1=$_am_tool])
+  AC_MSG_RESULT([$am_cv_prog_tar_$1])])
+
+AC_SUBST([am__tar])
+AC_SUBST([am__untar])
+]) # _AM_PROG_TAR
+
+m4_include([m4/ax_append_compile_flags.m4])
+m4_include([m4/ax_append_flag.m4])
+m4_include([m4/ax_append_link_flags.m4])
+m4_include([m4/ax_check_compile_flag.m4])
+m4_include([m4/ax_check_link_flag.m4])
+m4_include([m4/ax_pthread.m4])
+m4_include([m4/ax_require_defined.m4])
+m4_include([m4/libtool.m4])
+m4_include([m4/ltoptions.m4])
+m4_include([m4/ltsugar.m4])
+m4_include([m4/ltversion.m4])
+m4_include([m4/lt~obsolete.m4])
diff --git a/auto/compile b/auto/compile
new file mode 100755
index 0000000..531136b
--- /dev/null
+++ b/auto/compile
@@ -0,0 +1,347 @@
+#! /bin/sh
+# Wrapper for compilers which do not understand '-c -o'.
+
+scriptversion=2012-10-14.11; # UTC
+
+# Copyright (C) 1999-2013 Free Software Foundation, Inc.
+# Written by Tom Tromey <tromey@cygnus.com>.
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2, or (at your option)
+# any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program.  If not, see <http://www.gnu.org/licenses/>.
+
+# As a special exception to the GNU General Public License, if you
+# distribute this file as part of a program that contains a
+# configuration script generated by Autoconf, you may include it under
+# the same distribution terms that you use for the rest of that program.
+
+# This file is maintained in Automake, please report
+# bugs to <bug-automake@gnu.org> or send patches to
+# <automake-patches@gnu.org>.
+
+nl='
+'
+
+# We need space, tab and new line, in precisely that order.  Quoting is
+# there to prevent tools from complaining about whitespace usage.
+IFS=" ""	$nl"
+
+file_conv=
+
+# func_file_conv build_file lazy
+# Convert a $build file to $host form and store it in $file
+# Currently only supports Windows hosts. If the determined conversion
+# type is listed in (the comma separated) LAZY, no conversion will
+# take place.
+func_file_conv ()
+{
+  file=$1
+  case $file in
+    / | /[!/]*) # absolute file, and not a UNC file
+      if test -z "$file_conv"; then
+	# lazily determine how to convert abs files
+	case `uname -s` in
+	  MINGW*)
+	    file_conv=mingw
+	    ;;
+	  CYGWIN*)
+	    file_conv=cygwin
+	    ;;
+	  *)
+	    file_conv=wine
+	    ;;
+	esac
+      fi
+      case $file_conv/,$2, in
+	*,$file_conv,*)
+	  ;;
+	mingw/*)
+	  file=`cmd //C echo "$file " | sed -e 's/"\(.*\) " *$/\1/'`
+	  ;;
+	cygwin/*)
+	  file=`cygpath -m "$file" || echo "$file"`
+	  ;;
+	wine/*)
+	  file=`winepath -w "$file" || echo "$file"`
+	  ;;
+      esac
+      ;;
+  esac
+}
+
+# func_cl_dashL linkdir
+# Make cl look for libraries in LINKDIR
+func_cl_dashL ()
+{
+  func_file_conv "$1"
+  if test -z "$lib_path"; then
+    lib_path=$file
+  else
+    lib_path="$lib_path;$file"
+  fi
+  linker_opts="$linker_opts -LIBPATH:$file"
+}
+
+# func_cl_dashl library
+# Do a library search-path lookup for cl
+func_cl_dashl ()
+{
+  lib=$1
+  found=no
+  save_IFS=$IFS
+  IFS=';'
+  for dir in $lib_path $LIB
+  do
+    IFS=$save_IFS
+    if $shared && test -f "$dir/$lib.dll.lib"; then
+      found=yes
+      lib=$dir/$lib.dll.lib
+      break
+    fi
+    if test -f "$dir/$lib.lib"; then
+      found=yes
+      lib=$dir/$lib.lib
+      break
+    fi
+    if test -f "$dir/lib$lib.a"; then
+      found=yes
+      lib=$dir/lib$lib.a
+      break
+    fi
+  done
+  IFS=$save_IFS
+
+  if test "$found" != yes; then
+    lib=$lib.lib
+  fi
+}
+
+# func_cl_wrapper cl arg...
+# Adjust compile command to suit cl
+func_cl_wrapper ()
+{
+  # Assume a capable shell
+  lib_path=
+  shared=:
+  linker_opts=
+  for arg
+  do
+    if test -n "$eat"; then
+      eat=
+    else
+      case $1 in
+	-o)
+	  # configure might choose to run compile as 'compile cc -o foo foo.c'.
+	  eat=1
+	  case $2 in
+	    *.o | *.[oO][bB][jJ])
+	      func_file_conv "$2"
+	      set x "$@" -Fo"$file"
+	      shift
+	      ;;
+	    *)
+	      func_file_conv "$2"
+	      set x "$@" -Fe"$file"
+	      shift
+	      ;;
+	  esac
+	  ;;
+	-I)
+	  eat=1
+	  func_file_conv "$2" mingw
+	  set x "$@" -I"$file"
+	  shift
+	  ;;
+	-I*)
+	  func_file_conv "${1#-I}" mingw
+	  set x "$@" -I"$file"
+	  shift
+	  ;;
+	-l)
+	  eat=1
+	  func_cl_dashl "$2"
+	  set x "$@" "$lib"
+	  shift
+	  ;;
+	-l*)
+	  func_cl_dashl "${1#-l}"
+	  set x "$@" "$lib"
+	  shift
+	  ;;
+	-L)
+	  eat=1
+	  func_cl_dashL "$2"
+	  ;;
+	-L*)
+	  func_cl_dashL "${1#-L}"
+	  ;;
+	-static)
+	  shared=false
+	  ;;
+	-Wl,*)
+	  arg=${1#-Wl,}
+	  save_ifs="$IFS"; IFS=','
+	  for flag in $arg; do
+	    IFS="$save_ifs"
+	    linker_opts="$linker_opts $flag"
+	  done
+	  IFS="$save_ifs"
+	  ;;
+	-Xlinker)
+	  eat=1
+	  linker_opts="$linker_opts $2"
+	  ;;
+	-*)
+	  set x "$@" "$1"
+	  shift
+	  ;;
+	*.cc | *.CC | *.cxx | *.CXX | *.[cC]++)
+	  func_file_conv "$1"
+	  set x "$@" -Tp"$file"
+	  shift
+	  ;;
+	*.c | *.cpp | *.CPP | *.lib | *.LIB | *.Lib | *.OBJ | *.obj | *.[oO])
+	  func_file_conv "$1" mingw
+	  set x "$@" "$file"
+	  shift
+	  ;;
+	*)
+	  set x "$@" "$1"
+	  shift
+	  ;;
+      esac
+    fi
+    shift
+  done
+  if test -n "$linker_opts"; then
+    linker_opts="-link$linker_opts"
+  fi
+  exec "$@" $linker_opts
+  exit 1
+}
+
+eat=
+
+case $1 in
+  '')
+     echo "$0: No command.  Try '$0 --help' for more information." 1>&2
+     exit 1;
+     ;;
+  -h | --h*)
+    cat <<\EOF
+Usage: compile [--help] [--version] PROGRAM [ARGS]
+
+Wrapper for compilers which do not understand '-c -o'.
+Remove '-o dest.o' from ARGS, run PROGRAM with the remaining
+arguments, and rename the output as expected.
+
+If you are trying to build a whole package this is not the
+right script to run: please start by reading the file 'INSTALL'.
+
+Report bugs to <bug-automake@gnu.org>.
+EOF
+    exit $?
+    ;;
+  -v | --v*)
+    echo "compile $scriptversion"
+    exit $?
+    ;;
+  cl | *[/\\]cl | cl.exe | *[/\\]cl.exe )
+    func_cl_wrapper "$@"      # Doesn't return...
+    ;;
+esac
+
+ofile=
+cfile=
+
+for arg
+do
+  if test -n "$eat"; then
+    eat=
+  else
+    case $1 in
+      -o)
+	# configure might choose to run compile as 'compile cc -o foo foo.c'.
+	# So we strip '-o arg' only if arg is an object.
+	eat=1
+	case $2 in
+	  *.o | *.obj)
+	    ofile=$2
+	    ;;
+	  *)
+	    set x "$@" -o "$2"
+	    shift
+	    ;;
+	esac
+	;;
+      *.c)
+	cfile=$1
+	set x "$@" "$1"
+	shift
+	;;
+      *)
+	set x "$@" "$1"
+	shift
+	;;
+    esac
+  fi
+  shift
+done
+
+if test -z "$ofile" || test -z "$cfile"; then
+  # If no '-o' option was seen then we might have been invoked from a
+  # pattern rule where we don't need one.  That is ok -- this is a
+  # normal compilation that the losing compiler can handle.  If no
+  # '.c' file was seen then we are probably linking.  That is also
+  # ok.
+  exec "$@"
+fi
+
+# Name of file we expect compiler to create.
+cofile=`echo "$cfile" | sed 's|^.*[\\/]||; s|^[a-zA-Z]:||; s/\.c$/.o/'`
+
+# Create the lock directory.
+# Note: use '[/\\:.-]' here to ensure that we don't use the same name
+# that we are using for the .o file.  Also, base the name on the expected
+# object file name, since that is what matters with a parallel build.
+lockdir=`echo "$cofile" | sed -e 's|[/\\:.-]|_|g'`.d
+while true; do
+  if mkdir "$lockdir" >/dev/null 2>&1; then
+    break
+  fi
+  sleep 1
+done
+# FIXME: race condition here if user kills between mkdir and trap.
+trap "rmdir '$lockdir'; exit 1" 1 2 15
+
+# Run the compile.
+"$@"
+ret=$?
+
+if test -f "$cofile"; then
+  test "$cofile" = "$ofile" || mv "$cofile" "$ofile"
+elif test -f "${cofile}bj"; then
+  test "${cofile}bj" = "$ofile" || mv "${cofile}bj" "$ofile"
+fi
+
+rmdir "$lockdir"
+exit $ret
+
+# Local Variables:
+# mode: shell-script
+# sh-indentation: 2
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "scriptversion="
+# time-stamp-format: "%:y-%02m-%02d.%02H"
+# time-stamp-time-zone: "UTC"
+# time-stamp-end: "; # UTC"
+# End:
diff --git a/auto/config.guess b/auto/config.guess
new file mode 100755
index 0000000..1f5c50c
--- /dev/null
+++ b/auto/config.guess
@@ -0,0 +1,1420 @@
+#! /bin/sh
+# Attempt to guess a canonical system name.
+#   Copyright 1992-2014 Free Software Foundation, Inc.
+
+timestamp='2014-03-23'
+
+# This file is free software; you can redistribute it and/or modify it
+# under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful, but
+# WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+# General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, see <http://www.gnu.org/licenses/>.
+#
+# As a special exception to the GNU General Public License, if you
+# distribute this file as part of a program that contains a
+# configuration script generated by Autoconf, you may include it under
+# the same distribution terms that you use for the rest of that
+# program.  This Exception is an additional permission under section 7
+# of the GNU General Public License, version 3 ("GPLv3").
+#
+# Originally written by Per Bothner.
+#
+# You can get the latest version of this script from:
+# http://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD
+#
+# Please send patches with a ChangeLog entry to config-patches@gnu.org.
+
+
+me=`echo "$0" | sed -e 's,.*/,,'`
+
+usage="\
+Usage: $0 [OPTION]
+
+Output the configuration name of the system \`$me' is run on.
+
+Operation modes:
+  -h, --help         print this help, then exit
+  -t, --time-stamp   print date of last modification, then exit
+  -v, --version      print version number, then exit
+
+Report bugs and patches to <config-patches@gnu.org>."
+
+version="\
+GNU config.guess ($timestamp)
+
+Originally written by Per Bothner.
+Copyright 1992-2014 Free Software Foundation, Inc.
+
+This is free software; see the source for copying conditions.  There is NO
+warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE."
+
+help="
+Try \`$me --help' for more information."
+
+# Parse command line
+while test $# -gt 0 ; do
+  case $1 in
+    --time-stamp | --time* | -t )
+       echo "$timestamp" ; exit ;;
+    --version | -v )
+       echo "$version" ; exit ;;
+    --help | --h* | -h )
+       echo "$usage"; exit ;;
+    -- )     # Stop option processing
+       shift; break ;;
+    - )	# Use stdin as input.
+       break ;;
+    -* )
+       echo "$me: invalid option $1$help" >&2
+       exit 1 ;;
+    * )
+       break ;;
+  esac
+done
+
+if test $# != 0; then
+  echo "$me: too many arguments$help" >&2
+  exit 1
+fi
+
+trap 'exit 1' 1 2 15
+
+# CC_FOR_BUILD -- compiler used by this script. Note that the use of a
+# compiler to aid in system detection is discouraged as it requires
+# temporary files to be created and, as you can see below, it is a
+# headache to deal with in a portable fashion.
+
+# Historically, `CC_FOR_BUILD' used to be named `HOST_CC'. We still
+# use `HOST_CC' if defined, but it is deprecated.
+
+# Portable tmp directory creation inspired by the Autoconf team.
+
+set_cc_for_build='
+trap "exitcode=\$?; (rm -f \$tmpfiles 2>/dev/null; rmdir \$tmp 2>/dev/null) && exit \$exitcode" 0 ;
+trap "rm -f \$tmpfiles 2>/dev/null; rmdir \$tmp 2>/dev/null; exit 1" 1 2 13 15 ;
+: ${TMPDIR=/tmp} ;
+ { tmp=`(umask 077 && mktemp -d "$TMPDIR/cgXXXXXX") 2>/dev/null` && test -n "$tmp" && test -d "$tmp" ; } ||
+ { test -n "$RANDOM" && tmp=$TMPDIR/cg$$-$RANDOM && (umask 077 && mkdir $tmp) ; } ||
+ { tmp=$TMPDIR/cg-$$ && (umask 077 && mkdir $tmp) && echo "Warning: creating insecure temp directory" >&2 ; } ||
+ { echo "$me: cannot create a temporary directory in $TMPDIR" >&2 ; exit 1 ; } ;
+dummy=$tmp/dummy ;
+tmpfiles="$dummy.c $dummy.o $dummy.rel $dummy" ;
+case $CC_FOR_BUILD,$HOST_CC,$CC in
+ ,,)    echo "int x;" > $dummy.c ;
+	for c in cc gcc c89 c99 ; do
+	  if ($c -c -o $dummy.o $dummy.c) >/dev/null 2>&1 ; then
+	     CC_FOR_BUILD="$c"; break ;
+	  fi ;
+	done ;
+	if test x"$CC_FOR_BUILD" = x ; then
+	  CC_FOR_BUILD=no_compiler_found ;
+	fi
+	;;
+ ,,*)   CC_FOR_BUILD=$CC ;;
+ ,*,*)  CC_FOR_BUILD=$HOST_CC ;;
+esac ; set_cc_for_build= ;'
+
+# This is needed to find uname on a Pyramid OSx when run in the BSD universe.
+# (ghazi@noc.rutgers.edu 1994-08-24)
+if (test -f /.attbin/uname) >/dev/null 2>&1 ; then
+	PATH=$PATH:/.attbin ; export PATH
+fi
+
+UNAME_MACHINE=`(uname -m) 2>/dev/null` || UNAME_MACHINE=unknown
+UNAME_RELEASE=`(uname -r) 2>/dev/null` || UNAME_RELEASE=unknown
+UNAME_SYSTEM=`(uname -s) 2>/dev/null`  || UNAME_SYSTEM=unknown
+UNAME_VERSION=`(uname -v) 2>/dev/null` || UNAME_VERSION=unknown
+
+case "${UNAME_SYSTEM}" in
+Linux|GNU|GNU/*)
+	# If the system lacks a compiler, then just pick glibc.
+	# We could probably try harder.
+	LIBC=gnu
+
+	eval $set_cc_for_build
+	cat <<-EOF > $dummy.c
+	#include <features.h>
+	#if defined(__UCLIBC__)
+	LIBC=uclibc
+	#elif defined(__dietlibc__)
+	LIBC=dietlibc
+	#else
+	LIBC=gnu
+	#endif
+	EOF
+	eval `$CC_FOR_BUILD -E $dummy.c 2>/dev/null | grep '^LIBC' | sed 's, ,,g'`
+	;;
+esac
+
+# Note: order is significant - the case branches are not exclusive.
+
+case "${UNAME_MACHINE}:${UNAME_SYSTEM}:${UNAME_RELEASE}:${UNAME_VERSION}" in
+    *:NetBSD:*:*)
+	# NetBSD (nbsd) targets should (where applicable) match one or
+	# more of the tuples: *-*-netbsdelf*, *-*-netbsdaout*,
+	# *-*-netbsdecoff* and *-*-netbsd*.  For targets that recently
+	# switched to ELF, *-*-netbsd* would select the old
+	# object file format.  This provides both forward
+	# compatibility and a consistent mechanism for selecting the
+	# object file format.
+	#
+	# Note: NetBSD doesn't particularly care about the vendor
+	# portion of the name.  We always set it to "unknown".
+	sysctl="sysctl -n hw.machine_arch"
+	UNAME_MACHINE_ARCH=`(/sbin/$sysctl 2>/dev/null || \
+	    /usr/sbin/$sysctl 2>/dev/null || echo unknown)`
+	case "${UNAME_MACHINE_ARCH}" in
+	    armeb) machine=armeb-unknown ;;
+	    arm*) machine=arm-unknown ;;
+	    sh3el) machine=shl-unknown ;;
+	    sh3eb) machine=sh-unknown ;;
+	    sh5el) machine=sh5le-unknown ;;
+	    *) machine=${UNAME_MACHINE_ARCH}-unknown ;;
+	esac
+	# The Operating System including object format, if it has switched
+	# to ELF recently, or will in the future.
+	case "${UNAME_MACHINE_ARCH}" in
+	    arm*|i386|m68k|ns32k|sh3*|sparc|vax)
+		eval $set_cc_for_build
+		if echo __ELF__ | $CC_FOR_BUILD -E - 2>/dev/null \
+			| grep -q __ELF__
+		then
+		    # Once all utilities can be ECOFF (netbsdecoff) or a.out (netbsdaout).
+		    # Return netbsd for either.  FIX?
+		    os=netbsd
+		else
+		    os=netbsdelf
+		fi
+		;;
+	    *)
+		os=netbsd
+		;;
+	esac
+	# The OS release
+	# Debian GNU/NetBSD machines have a different userland, and
+	# thus, need a distinct triplet. However, they do not need
+	# kernel version information, so it can be replaced with a
+	# suitable tag, in the style of linux-gnu.
+	case "${UNAME_VERSION}" in
+	    Debian*)
+		release='-gnu'
+		;;
+	    *)
+		release=`echo ${UNAME_RELEASE}|sed -e 's/[-_].*/\./'`
+		;;
+	esac
+	# Since CPU_TYPE-MANUFACTURER-KERNEL-OPERATING_SYSTEM:
+	# contains redundant information, the shorter form:
+	# CPU_TYPE-MANUFACTURER-OPERATING_SYSTEM is used.
+	echo "${machine}-${os}${release}"
+	exit ;;
+    *:Bitrig:*:*)
+	UNAME_MACHINE_ARCH=`arch | sed 's/Bitrig.//'`
+	echo ${UNAME_MACHINE_ARCH}-unknown-bitrig${UNAME_RELEASE}
+	exit ;;
+    *:OpenBSD:*:*)
+	UNAME_MACHINE_ARCH=`arch | sed 's/OpenBSD.//'`
+	echo ${UNAME_MACHINE_ARCH}-unknown-openbsd${UNAME_RELEASE}
+	exit ;;
+    *:ekkoBSD:*:*)
+	echo ${UNAME_MACHINE}-unknown-ekkobsd${UNAME_RELEASE}
+	exit ;;
+    *:SolidBSD:*:*)
+	echo ${UNAME_MACHINE}-unknown-solidbsd${UNAME_RELEASE}
+	exit ;;
+    macppc:MirBSD:*:*)
+	echo powerpc-unknown-mirbsd${UNAME_RELEASE}
+	exit ;;
+    *:MirBSD:*:*)
+	echo ${UNAME_MACHINE}-unknown-mirbsd${UNAME_RELEASE}
+	exit ;;
+    alpha:OSF1:*:*)
+	case $UNAME_RELEASE in
+	*4.0)
+		UNAME_RELEASE=`/usr/sbin/sizer -v | awk '{print $3}'`
+		;;
+	*5.*)
+		UNAME_RELEASE=`/usr/sbin/sizer -v | awk '{print $4}'`
+		;;
+	esac
+	# According to Compaq, /usr/sbin/psrinfo has been available on
+	# OSF/1 and Tru64 systems produced since 1995.  I hope that
+	# covers most systems running today.  This code pipes the CPU
+	# types through head -n 1, so we only detect the type of CPU 0.
+	ALPHA_CPU_TYPE=`/usr/sbin/psrinfo -v | sed -n -e 's/^  The alpha \(.*\) processor.*$/\1/p' | head -n 1`
+	case "$ALPHA_CPU_TYPE" in
+	    "EV4 (21064)")
+		UNAME_MACHINE="alpha" ;;
+	    "EV4.5 (21064)")
+		UNAME_MACHINE="alpha" ;;
+	    "LCA4 (21066/21068)")
+		UNAME_MACHINE="alpha" ;;
+	    "EV5 (21164)")
+		UNAME_MACHINE="alphaev5" ;;
+	    "EV5.6 (21164A)")
+		UNAME_MACHINE="alphaev56" ;;
+	    "EV5.6 (21164PC)")
+		UNAME_MACHINE="alphapca56" ;;
+	    "EV5.7 (21164PC)")
+		UNAME_MACHINE="alphapca57" ;;
+	    "EV6 (21264)")
+		UNAME_MACHINE="alphaev6" ;;
+	    "EV6.7 (21264A)")
+		UNAME_MACHINE="alphaev67" ;;
+	    "EV6.8CB (21264C)")
+		UNAME_MACHINE="alphaev68" ;;
+	    "EV6.8AL (21264B)")
+		UNAME_MACHINE="alphaev68" ;;
+	    "EV6.8CX (21264D)")
+		UNAME_MACHINE="alphaev68" ;;
+	    "EV6.9A (21264/EV69A)")
+		UNAME_MACHINE="alphaev69" ;;
+	    "EV7 (21364)")
+		UNAME_MACHINE="alphaev7" ;;
+	    "EV7.9 (21364A)")
+		UNAME_MACHINE="alphaev79" ;;
+	esac
+	# A Pn.n version is a patched version.
+	# A Vn.n version is a released version.
+	# A Tn.n version is a released field test version.
+	# A Xn.n version is an unreleased experimental baselevel.
+	# 1.2 uses "1.2" for uname -r.
+	echo ${UNAME_MACHINE}-dec-osf`echo ${UNAME_RELEASE} | sed -e 's/^[PVTX]//' | tr 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' 'abcdefghijklmnopqrstuvwxyz'`
+	# Reset EXIT trap before exiting to avoid spurious non-zero exit code.
+	exitcode=$?
+	trap '' 0
+	exit $exitcode ;;
+    Alpha\ *:Windows_NT*:*)
+	# How do we know it's Interix rather than the generic POSIX subsystem?
+	# Should we change UNAME_MACHINE based on the output of uname instead
+	# of the specific Alpha model?
+	echo alpha-pc-interix
+	exit ;;
+    21064:Windows_NT:50:3)
+	echo alpha-dec-winnt3.5
+	exit ;;
+    Amiga*:UNIX_System_V:4.0:*)
+	echo m68k-unknown-sysv4
+	exit ;;
+    *:[Aa]miga[Oo][Ss]:*:*)
+	echo ${UNAME_MACHINE}-unknown-amigaos
+	exit ;;
+    *:[Mm]orph[Oo][Ss]:*:*)
+	echo ${UNAME_MACHINE}-unknown-morphos
+	exit ;;
+    *:OS/390:*:*)
+	echo i370-ibm-openedition
+	exit ;;
+    *:z/VM:*:*)
+	echo s390-ibm-zvmoe
+	exit ;;
+    *:OS400:*:*)
+	echo powerpc-ibm-os400
+	exit ;;
+    arm:RISC*:1.[012]*:*|arm:riscix:1.[012]*:*)
+	echo arm-acorn-riscix${UNAME_RELEASE}
+	exit ;;
+    arm*:riscos:*:*|arm*:RISCOS:*:*)
+	echo arm-unknown-riscos
+	exit ;;
+    SR2?01:HI-UX/MPP:*:* | SR8000:HI-UX/MPP:*:*)
+	echo hppa1.1-hitachi-hiuxmpp
+	exit ;;
+    Pyramid*:OSx*:*:* | MIS*:OSx*:*:* | MIS*:SMP_DC-OSx*:*:*)
+	# akee@wpdis03.wpafb.af.mil (Earle F. Ake) contributed MIS and NILE.
+	if test "`(/bin/universe) 2>/dev/null`" = att ; then
+		echo pyramid-pyramid-sysv3
+	else
+		echo pyramid-pyramid-bsd
+	fi
+	exit ;;
+    NILE*:*:*:dcosx)
+	echo pyramid-pyramid-svr4
+	exit ;;
+    DRS?6000:unix:4.0:6*)
+	echo sparc-icl-nx6
+	exit ;;
+    DRS?6000:UNIX_SV:4.2*:7* | DRS?6000:isis:4.2*:7*)
+	case `/usr/bin/uname -p` in
+	    sparc) echo sparc-icl-nx7; exit ;;
+	esac ;;
+    s390x:SunOS:*:*)
+	echo ${UNAME_MACHINE}-ibm-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    sun4H:SunOS:5.*:*)
+	echo sparc-hal-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    sun4*:SunOS:5.*:* | tadpole*:SunOS:5.*:*)
+	echo sparc-sun-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    i86pc:AuroraUX:5.*:* | i86xen:AuroraUX:5.*:*)
+	echo i386-pc-auroraux${UNAME_RELEASE}
+	exit ;;
+    i86pc:SunOS:5.*:* | i86xen:SunOS:5.*:*)
+	eval $set_cc_for_build
+	SUN_ARCH="i386"
+	# If there is a compiler, see if it is configured for 64-bit objects.
+	# Note that the Sun cc does not turn __LP64__ into 1 like gcc does.
+	# This test works for both compilers.
+	if [ "$CC_FOR_BUILD" != 'no_compiler_found' ]; then
+	    if (echo '#ifdef __amd64'; echo IS_64BIT_ARCH; echo '#endif') | \
+		(CCOPTS= $CC_FOR_BUILD -E - 2>/dev/null) | \
+		grep IS_64BIT_ARCH >/dev/null
+	    then
+		SUN_ARCH="x86_64"
+	    fi
+	fi
+	echo ${SUN_ARCH}-pc-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    sun4*:SunOS:6*:*)
+	# According to config.sub, this is the proper way to canonicalize
+	# SunOS6.  Hard to guess exactly what SunOS6 will be like, but
+	# it's likely to be more like Solaris than SunOS4.
+	echo sparc-sun-solaris3`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    sun4*:SunOS:*:*)
+	case "`/usr/bin/arch -k`" in
+	    Series*|S4*)
+		UNAME_RELEASE=`uname -v`
+		;;
+	esac
+	# Japanese Language versions have a version number like `4.1.3-JL'.
+	echo sparc-sun-sunos`echo ${UNAME_RELEASE}|sed -e 's/-/_/'`
+	exit ;;
+    sun3*:SunOS:*:*)
+	echo m68k-sun-sunos${UNAME_RELEASE}
+	exit ;;
+    sun*:*:4.2BSD:*)
+	UNAME_RELEASE=`(sed 1q /etc/motd | awk '{print substr($5,1,3)}') 2>/dev/null`
+	test "x${UNAME_RELEASE}" = "x" && UNAME_RELEASE=3
+	case "`/bin/arch`" in
+	    sun3)
+		echo m68k-sun-sunos${UNAME_RELEASE}
+		;;
+	    sun4)
+		echo sparc-sun-sunos${UNAME_RELEASE}
+		;;
+	esac
+	exit ;;
+    aushp:SunOS:*:*)
+	echo sparc-auspex-sunos${UNAME_RELEASE}
+	exit ;;
+    # The situation for MiNT is a little confusing.  The machine name
+    # can be virtually everything (everything which is not
+    # "atarist" or "atariste" at least should have a processor
+    # > m68000).  The system name ranges from "MiNT" over "FreeMiNT"
+    # to the lowercase version "mint" (or "freemint").  Finally
+    # the system name "TOS" denotes a system which is actually not
+    # MiNT.  But MiNT is downward compatible to TOS, so this should
+    # be no problem.
+    atarist[e]:*MiNT:*:* | atarist[e]:*mint:*:* | atarist[e]:*TOS:*:*)
+	echo m68k-atari-mint${UNAME_RELEASE}
+	exit ;;
+    atari*:*MiNT:*:* | atari*:*mint:*:* | atarist[e]:*TOS:*:*)
+	echo m68k-atari-mint${UNAME_RELEASE}
+	exit ;;
+    *falcon*:*MiNT:*:* | *falcon*:*mint:*:* | *falcon*:*TOS:*:*)
+	echo m68k-atari-mint${UNAME_RELEASE}
+	exit ;;
+    milan*:*MiNT:*:* | milan*:*mint:*:* | *milan*:*TOS:*:*)
+	echo m68k-milan-mint${UNAME_RELEASE}
+	exit ;;
+    hades*:*MiNT:*:* | hades*:*mint:*:* | *hades*:*TOS:*:*)
+	echo m68k-hades-mint${UNAME_RELEASE}
+	exit ;;
+    *:*MiNT:*:* | *:*mint:*:* | *:*TOS:*:*)
+	echo m68k-unknown-mint${UNAME_RELEASE}
+	exit ;;
+    m68k:machten:*:*)
+	echo m68k-apple-machten${UNAME_RELEASE}
+	exit ;;
+    powerpc:machten:*:*)
+	echo powerpc-apple-machten${UNAME_RELEASE}
+	exit ;;
+    RISC*:Mach:*:*)
+	echo mips-dec-mach_bsd4.3
+	exit ;;
+    RISC*:ULTRIX:*:*)
+	echo mips-dec-ultrix${UNAME_RELEASE}
+	exit ;;
+    VAX*:ULTRIX*:*:*)
+	echo vax-dec-ultrix${UNAME_RELEASE}
+	exit ;;
+    2020:CLIX:*:* | 2430:CLIX:*:*)
+	echo clipper-intergraph-clix${UNAME_RELEASE}
+	exit ;;
+    mips:*:*:UMIPS | mips:*:*:RISCos)
+	eval $set_cc_for_build
+	sed 's/^	//' << EOF >$dummy.c
+#ifdef __cplusplus
+#include <stdio.h>  /* for printf() prototype */
+	int main (int argc, char *argv[]) {
+#else
+	int main (argc, argv) int argc; char *argv[]; {
+#endif
+	#if defined (host_mips) && defined (MIPSEB)
+	#if defined (SYSTYPE_SYSV)
+	  printf ("mips-mips-riscos%ssysv\n", argv[1]); exit (0);
+	#endif
+	#if defined (SYSTYPE_SVR4)
+	  printf ("mips-mips-riscos%ssvr4\n", argv[1]); exit (0);
+	#endif
+	#if defined (SYSTYPE_BSD43) || defined(SYSTYPE_BSD)
+	  printf ("mips-mips-riscos%sbsd\n", argv[1]); exit (0);
+	#endif
+	#endif
+	  exit (-1);
+	}
+EOF
+	$CC_FOR_BUILD -o $dummy $dummy.c &&
+	  dummyarg=`echo "${UNAME_RELEASE}" | sed -n 's/\([0-9]*\).*/\1/p'` &&
+	  SYSTEM_NAME=`$dummy $dummyarg` &&
+	    { echo "$SYSTEM_NAME"; exit; }
+	echo mips-mips-riscos${UNAME_RELEASE}
+	exit ;;
+    Motorola:PowerMAX_OS:*:*)
+	echo powerpc-motorola-powermax
+	exit ;;
+    Motorola:*:4.3:PL8-*)
+	echo powerpc-harris-powermax
+	exit ;;
+    Night_Hawk:*:*:PowerMAX_OS | Synergy:PowerMAX_OS:*:*)
+	echo powerpc-harris-powermax
+	exit ;;
+    Night_Hawk:Power_UNIX:*:*)
+	echo powerpc-harris-powerunix
+	exit ;;
+    m88k:CX/UX:7*:*)
+	echo m88k-harris-cxux7
+	exit ;;
+    m88k:*:4*:R4*)
+	echo m88k-motorola-sysv4
+	exit ;;
+    m88k:*:3*:R3*)
+	echo m88k-motorola-sysv3
+	exit ;;
+    AViiON:dgux:*:*)
+	# DG/UX returns AViiON for all architectures
+	UNAME_PROCESSOR=`/usr/bin/uname -p`
+	if [ $UNAME_PROCESSOR = mc88100 ] || [ $UNAME_PROCESSOR = mc88110 ]
+	then
+	    if [ ${TARGET_BINARY_INTERFACE}x = m88kdguxelfx ] || \
+	       [ ${TARGET_BINARY_INTERFACE}x = x ]
+	    then
+		echo m88k-dg-dgux${UNAME_RELEASE}
+	    else
+		echo m88k-dg-dguxbcs${UNAME_RELEASE}
+	    fi
+	else
+	    echo i586-dg-dgux${UNAME_RELEASE}
+	fi
+	exit ;;
+    M88*:DolphinOS:*:*)	# DolphinOS (SVR3)
+	echo m88k-dolphin-sysv3
+	exit ;;
+    M88*:*:R3*:*)
+	# Delta 88k system running SVR3
+	echo m88k-motorola-sysv3
+	exit ;;
+    XD88*:*:*:*) # Tektronix XD88 system running UTekV (SVR3)
+	echo m88k-tektronix-sysv3
+	exit ;;
+    Tek43[0-9][0-9]:UTek:*:*) # Tektronix 4300 system running UTek (BSD)
+	echo m68k-tektronix-bsd
+	exit ;;
+    *:IRIX*:*:*)
+	echo mips-sgi-irix`echo ${UNAME_RELEASE}|sed -e 's/-/_/g'`
+	exit ;;
+    ????????:AIX?:[12].1:2)   # AIX 2.2.1 or AIX 2.1.1 is RT/PC AIX.
+	echo romp-ibm-aix     # uname -m gives an 8 hex-code CPU id
+	exit ;;               # Note that: echo "'`uname -s`'" gives 'AIX '
+    i*86:AIX:*:*)
+	echo i386-ibm-aix
+	exit ;;
+    ia64:AIX:*:*)
+	if [ -x /usr/bin/oslevel ] ; then
+		IBM_REV=`/usr/bin/oslevel`
+	else
+		IBM_REV=${UNAME_VERSION}.${UNAME_RELEASE}
+	fi
+	echo ${UNAME_MACHINE}-ibm-aix${IBM_REV}
+	exit ;;
+    *:AIX:2:3)
+	if grep bos325 /usr/include/stdio.h >/dev/null 2>&1; then
+		eval $set_cc_for_build
+		sed 's/^		//' << EOF >$dummy.c
+		#include <sys/systemcfg.h>
+
+		main()
+			{
+			if (!__power_pc())
+				exit(1);
+			puts("powerpc-ibm-aix3.2.5");
+			exit(0);
+			}
+EOF
+		if $CC_FOR_BUILD -o $dummy $dummy.c && SYSTEM_NAME=`$dummy`
+		then
+			echo "$SYSTEM_NAME"
+		else
+			echo rs6000-ibm-aix3.2.5
+		fi
+	elif grep bos324 /usr/include/stdio.h >/dev/null 2>&1; then
+		echo rs6000-ibm-aix3.2.4
+	else
+		echo rs6000-ibm-aix3.2
+	fi
+	exit ;;
+    *:AIX:*:[4567])
+	IBM_CPU_ID=`/usr/sbin/lsdev -C -c processor -S available | sed 1q | awk '{ print $1 }'`
+	if /usr/sbin/lsattr -El ${IBM_CPU_ID} | grep ' POWER' >/dev/null 2>&1; then
+		IBM_ARCH=rs6000
+	else
+		IBM_ARCH=powerpc
+	fi
+	if [ -x /usr/bin/oslevel ] ; then
+		IBM_REV=`/usr/bin/oslevel`
+	else
+		IBM_REV=${UNAME_VERSION}.${UNAME_RELEASE}
+	fi
+	echo ${IBM_ARCH}-ibm-aix${IBM_REV}
+	exit ;;
+    *:AIX:*:*)
+	echo rs6000-ibm-aix
+	exit ;;
+    ibmrt:4.4BSD:*|romp-ibm:BSD:*)
+	echo romp-ibm-bsd4.4
+	exit ;;
+    ibmrt:*BSD:*|romp-ibm:BSD:*)            # covers RT/PC BSD and
+	echo romp-ibm-bsd${UNAME_RELEASE}   # 4.3 with uname added to
+	exit ;;                             # report: romp-ibm BSD 4.3
+    *:BOSX:*:*)
+	echo rs6000-bull-bosx
+	exit ;;
+    DPX/2?00:B.O.S.:*:*)
+	echo m68k-bull-sysv3
+	exit ;;
+    9000/[34]??:4.3bsd:1.*:*)
+	echo m68k-hp-bsd
+	exit ;;
+    hp300:4.4BSD:*:* | 9000/[34]??:4.3bsd:2.*:*)
+	echo m68k-hp-bsd4.4
+	exit ;;
+    9000/[34678]??:HP-UX:*:*)
+	HPUX_REV=`echo ${UNAME_RELEASE}|sed -e 's/[^.]*.[0B]*//'`
+	case "${UNAME_MACHINE}" in
+	    9000/31? )            HP_ARCH=m68000 ;;
+	    9000/[34]?? )         HP_ARCH=m68k ;;
+	    9000/[678][0-9][0-9])
+		if [ -x /usr/bin/getconf ]; then
+		    sc_cpu_version=`/usr/bin/getconf SC_CPU_VERSION 2>/dev/null`
+		    sc_kernel_bits=`/usr/bin/getconf SC_KERNEL_BITS 2>/dev/null`
+		    case "${sc_cpu_version}" in
+		      523) HP_ARCH="hppa1.0" ;; # CPU_PA_RISC1_0
+		      528) HP_ARCH="hppa1.1" ;; # CPU_PA_RISC1_1
+		      532)                      # CPU_PA_RISC2_0
+			case "${sc_kernel_bits}" in
+			  32) HP_ARCH="hppa2.0n" ;;
+			  64) HP_ARCH="hppa2.0w" ;;
+			  '') HP_ARCH="hppa2.0" ;;   # HP-UX 10.20
+			esac ;;
+		    esac
+		fi
+		if [ "${HP_ARCH}" = "" ]; then
+		    eval $set_cc_for_build
+		    sed 's/^		//' << EOF >$dummy.c
+
+		#define _HPUX_SOURCE
+		#include <stdlib.h>
+		#include <unistd.h>
+
+		int main ()
+		{
+		#if defined(_SC_KERNEL_BITS)
+		    long bits = sysconf(_SC_KERNEL_BITS);
+		#endif
+		    long cpu  = sysconf (_SC_CPU_VERSION);
+
+		    switch (cpu)
+			{
+			case CPU_PA_RISC1_0: puts ("hppa1.0"); break;
+			case CPU_PA_RISC1_1: puts ("hppa1.1"); break;
+			case CPU_PA_RISC2_0:
+		#if defined(_SC_KERNEL_BITS)
+			    switch (bits)
+				{
+				case 64: puts ("hppa2.0w"); break;
+				case 32: puts ("hppa2.0n"); break;
+				default: puts ("hppa2.0"); break;
+				} break;
+		#else  /* !defined(_SC_KERNEL_BITS) */
+			    puts ("hppa2.0"); break;
+		#endif
+			default: puts ("hppa1.0"); break;
+			}
+		    exit (0);
+		}
+EOF
+		    (CCOPTS= $CC_FOR_BUILD -o $dummy $dummy.c 2>/dev/null) && HP_ARCH=`$dummy`
+		    test -z "$HP_ARCH" && HP_ARCH=hppa
+		fi ;;
+	esac
+	if [ ${HP_ARCH} = "hppa2.0w" ]
+	then
+	    eval $set_cc_for_build
+
+	    # hppa2.0w-hp-hpux* has a 64-bit kernel and a compiler generating
+	    # 32-bit code.  hppa64-hp-hpux* has the same kernel and a compiler
+	    # generating 64-bit code.  GNU and HP use different nomenclature:
+	    #
+	    # $ CC_FOR_BUILD=cc ./config.guess
+	    # => hppa2.0w-hp-hpux11.23
+	    # $ CC_FOR_BUILD="cc +DA2.0w" ./config.guess
+	    # => hppa64-hp-hpux11.23
+
+	    if echo __LP64__ | (CCOPTS= $CC_FOR_BUILD -E - 2>/dev/null) |
+		grep -q __LP64__
+	    then
+		HP_ARCH="hppa2.0w"
+	    else
+		HP_ARCH="hppa64"
+	    fi
+	fi
+	echo ${HP_ARCH}-hp-hpux${HPUX_REV}
+	exit ;;
+    ia64:HP-UX:*:*)
+	HPUX_REV=`echo ${UNAME_RELEASE}|sed -e 's/[^.]*.[0B]*//'`
+	echo ia64-hp-hpux${HPUX_REV}
+	exit ;;
+    3050*:HI-UX:*:*)
+	eval $set_cc_for_build
+	sed 's/^	//' << EOF >$dummy.c
+	#include <unistd.h>
+	int
+	main ()
+	{
+	  long cpu = sysconf (_SC_CPU_VERSION);
+	  /* The order matters, because CPU_IS_HP_MC68K erroneously returns
+	     true for CPU_PA_RISC1_0.  CPU_IS_PA_RISC returns correct
+	     results, however.  */
+	  if (CPU_IS_PA_RISC (cpu))
+	    {
+	      switch (cpu)
+		{
+		  case CPU_PA_RISC1_0: puts ("hppa1.0-hitachi-hiuxwe2"); break;
+		  case CPU_PA_RISC1_1: puts ("hppa1.1-hitachi-hiuxwe2"); break;
+		  case CPU_PA_RISC2_0: puts ("hppa2.0-hitachi-hiuxwe2"); break;
+		  default: puts ("hppa-hitachi-hiuxwe2"); break;
+		}
+	    }
+	  else if (CPU_IS_HP_MC68K (cpu))
+	    puts ("m68k-hitachi-hiuxwe2");
+	  else puts ("unknown-hitachi-hiuxwe2");
+	  exit (0);
+	}
+EOF
+	$CC_FOR_BUILD -o $dummy $dummy.c && SYSTEM_NAME=`$dummy` &&
+		{ echo "$SYSTEM_NAME"; exit; }
+	echo unknown-hitachi-hiuxwe2
+	exit ;;
+    9000/7??:4.3bsd:*:* | 9000/8?[79]:4.3bsd:*:* )
+	echo hppa1.1-hp-bsd
+	exit ;;
+    9000/8??:4.3bsd:*:*)
+	echo hppa1.0-hp-bsd
+	exit ;;
+    *9??*:MPE/iX:*:* | *3000*:MPE/iX:*:*)
+	echo hppa1.0-hp-mpeix
+	exit ;;
+    hp7??:OSF1:*:* | hp8?[79]:OSF1:*:* )
+	echo hppa1.1-hp-osf
+	exit ;;
+    hp8??:OSF1:*:*)
+	echo hppa1.0-hp-osf
+	exit ;;
+    i*86:OSF1:*:*)
+	if [ -x /usr/sbin/sysversion ] ; then
+	    echo ${UNAME_MACHINE}-unknown-osf1mk
+	else
+	    echo ${UNAME_MACHINE}-unknown-osf1
+	fi
+	exit ;;
+    parisc*:Lites*:*:*)
+	echo hppa1.1-hp-lites
+	exit ;;
+    C1*:ConvexOS:*:* | convex:ConvexOS:C1*:*)
+	echo c1-convex-bsd
+	exit ;;
+    C2*:ConvexOS:*:* | convex:ConvexOS:C2*:*)
+	if getsysinfo -f scalar_acc
+	then echo c32-convex-bsd
+	else echo c2-convex-bsd
+	fi
+	exit ;;
+    C34*:ConvexOS:*:* | convex:ConvexOS:C34*:*)
+	echo c34-convex-bsd
+	exit ;;
+    C38*:ConvexOS:*:* | convex:ConvexOS:C38*:*)
+	echo c38-convex-bsd
+	exit ;;
+    C4*:ConvexOS:*:* | convex:ConvexOS:C4*:*)
+	echo c4-convex-bsd
+	exit ;;
+    CRAY*Y-MP:*:*:*)
+	echo ymp-cray-unicos${UNAME_RELEASE} | sed -e 's/\.[^.]*$/.X/'
+	exit ;;
+    CRAY*[A-Z]90:*:*:*)
+	echo ${UNAME_MACHINE}-cray-unicos${UNAME_RELEASE} \
+	| sed -e 's/CRAY.*\([A-Z]90\)/\1/' \
+	      -e y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/ \
+	      -e 's/\.[^.]*$/.X/'
+	exit ;;
+    CRAY*TS:*:*:*)
+	echo t90-cray-unicos${UNAME_RELEASE} | sed -e 's/\.[^.]*$/.X/'
+	exit ;;
+    CRAY*T3E:*:*:*)
+	echo alphaev5-cray-unicosmk${UNAME_RELEASE} | sed -e 's/\.[^.]*$/.X/'
+	exit ;;
+    CRAY*SV1:*:*:*)
+	echo sv1-cray-unicos${UNAME_RELEASE} | sed -e 's/\.[^.]*$/.X/'
+	exit ;;
+    *:UNICOS/mp:*:*)
+	echo craynv-cray-unicosmp${UNAME_RELEASE} | sed -e 's/\.[^.]*$/.X/'
+	exit ;;
+    F30[01]:UNIX_System_V:*:* | F700:UNIX_System_V:*:*)
+	FUJITSU_PROC=`uname -m | tr 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' 'abcdefghijklmnopqrstuvwxyz'`
+	FUJITSU_SYS=`uname -p | tr 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' 'abcdefghijklmnopqrstuvwxyz' | sed -e 's/\///'`
+	FUJITSU_REL=`echo ${UNAME_RELEASE} | sed -e 's/ /_/'`
+	echo "${FUJITSU_PROC}-fujitsu-${FUJITSU_SYS}${FUJITSU_REL}"
+	exit ;;
+    5000:UNIX_System_V:4.*:*)
+	FUJITSU_SYS=`uname -p | tr 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' 'abcdefghijklmnopqrstuvwxyz' | sed -e 's/\///'`
+	FUJITSU_REL=`echo ${UNAME_RELEASE} | tr 'ABCDEFGHIJKLMNOPQRSTUVWXYZ' 'abcdefghijklmnopqrstuvwxyz' | sed -e 's/ /_/'`
+	echo "sparc-fujitsu-${FUJITSU_SYS}${FUJITSU_REL}"
+	exit ;;
+    i*86:BSD/386:*:* | i*86:BSD/OS:*:* | *:Ascend\ Embedded/OS:*:*)
+	echo ${UNAME_MACHINE}-pc-bsdi${UNAME_RELEASE}
+	exit ;;
+    sparc*:BSD/OS:*:*)
+	echo sparc-unknown-bsdi${UNAME_RELEASE}
+	exit ;;
+    *:BSD/OS:*:*)
+	echo ${UNAME_MACHINE}-unknown-bsdi${UNAME_RELEASE}
+	exit ;;
+    *:FreeBSD:*:*)
+	UNAME_PROCESSOR=`/usr/bin/uname -p`
+	case ${UNAME_PROCESSOR} in
+	    amd64)
+		echo x86_64-unknown-freebsd`echo ${UNAME_RELEASE}|sed -e 's/[-(].*//'` ;;
+	    *)
+		echo ${UNAME_PROCESSOR}-unknown-freebsd`echo ${UNAME_RELEASE}|sed -e 's/[-(].*//'` ;;
+	esac
+	exit ;;
+    i*:CYGWIN*:*)
+	echo ${UNAME_MACHINE}-pc-cygwin
+	exit ;;
+    *:MINGW64*:*)
+	echo ${UNAME_MACHINE}-pc-mingw64
+	exit ;;
+    *:MINGW*:*)
+	echo ${UNAME_MACHINE}-pc-mingw32
+	exit ;;
+    *:MSYS*:*)
+	echo ${UNAME_MACHINE}-pc-msys
+	exit ;;
+    i*:windows32*:*)
+	# uname -m includes "-pc" on this system.
+	echo ${UNAME_MACHINE}-mingw32
+	exit ;;
+    i*:PW*:*)
+	echo ${UNAME_MACHINE}-pc-pw32
+	exit ;;
+    *:Interix*:*)
+	case ${UNAME_MACHINE} in
+	    x86)
+		echo i586-pc-interix${UNAME_RELEASE}
+		exit ;;
+	    authenticamd | genuineintel | EM64T)
+		echo x86_64-unknown-interix${UNAME_RELEASE}
+		exit ;;
+	    IA64)
+		echo ia64-unknown-interix${UNAME_RELEASE}
+		exit ;;
+	esac ;;
+    [345]86:Windows_95:* | [345]86:Windows_98:* | [345]86:Windows_NT:*)
+	echo i${UNAME_MACHINE}-pc-mks
+	exit ;;
+    8664:Windows_NT:*)
+	echo x86_64-pc-mks
+	exit ;;
+    i*:Windows_NT*:* | Pentium*:Windows_NT*:*)
+	# How do we know it's Interix rather than the generic POSIX subsystem?
+	# It also conflicts with pre-2.0 versions of AT&T UWIN. Should we
+	# UNAME_MACHINE based on the output of uname instead of i386?
+	echo i586-pc-interix
+	exit ;;
+    i*:UWIN*:*)
+	echo ${UNAME_MACHINE}-pc-uwin
+	exit ;;
+    amd64:CYGWIN*:*:* | x86_64:CYGWIN*:*:*)
+	echo x86_64-unknown-cygwin
+	exit ;;
+    p*:CYGWIN*:*)
+	echo powerpcle-unknown-cygwin
+	exit ;;
+    prep*:SunOS:5.*:*)
+	echo powerpcle-unknown-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
+    *:GNU:*:*)
+	# the GNU system
+	echo `echo ${UNAME_MACHINE}|sed -e 's,[-/].*$,,'`-unknown-${LIBC}`echo ${UNAME_RELEASE}|sed -e 's,/.*$,,'`
+	exit ;;
+    *:GNU/*:*:*)
+	# other systems with GNU libc and userland
+	echo ${UNAME_MACHINE}-unknown-`echo ${UNAME_SYSTEM} | sed 's,^[^/]*/,,' | tr '[A-Z]' '[a-z]'``echo ${UNAME_RELEASE}|sed -e 's/[-(].*//'`-${LIBC}
+	exit ;;
+    i*86:Minix:*:*)
+	echo ${UNAME_MACHINE}-pc-minix
+	exit ;;
+    aarch64:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    aarch64_be:Linux:*:*)
+	UNAME_MACHINE=aarch64_be
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    alpha:Linux:*:*)
+	case `sed -n '/^cpu model/s/^.*: \(.*\)/\1/p' < /proc/cpuinfo` in
+	  EV5)   UNAME_MACHINE=alphaev5 ;;
+	  EV56)  UNAME_MACHINE=alphaev56 ;;
+	  PCA56) UNAME_MACHINE=alphapca56 ;;
+	  PCA57) UNAME_MACHINE=alphapca56 ;;
+	  EV6)   UNAME_MACHINE=alphaev6 ;;
+	  EV67)  UNAME_MACHINE=alphaev67 ;;
+	  EV68*) UNAME_MACHINE=alphaev68 ;;
+	esac
+	objdump --private-headers /bin/sh | grep -q ld.so.1
+	if test "$?" = 0 ; then LIBC="gnulibc1" ; fi
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    arc:Linux:*:* | arceb:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    arm*:Linux:*:*)
+	eval $set_cc_for_build
+	if echo __ARM_EABI__ | $CC_FOR_BUILD -E - 2>/dev/null \
+	    | grep -q __ARM_EABI__
+	then
+	    echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	else
+	    if echo __ARM_PCS_VFP | $CC_FOR_BUILD -E - 2>/dev/null \
+		| grep -q __ARM_PCS_VFP
+	    then
+		echo ${UNAME_MACHINE}-unknown-linux-${LIBC}eabi
+	    else
+		echo ${UNAME_MACHINE}-unknown-linux-${LIBC}eabihf
+	    fi
+	fi
+	exit ;;
+    avr32*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    cris:Linux:*:*)
+	echo ${UNAME_MACHINE}-axis-linux-${LIBC}
+	exit ;;
+    crisv32:Linux:*:*)
+	echo ${UNAME_MACHINE}-axis-linux-${LIBC}
+	exit ;;
+    frv:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    hexagon:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    i*86:Linux:*:*)
+	echo ${UNAME_MACHINE}-pc-linux-${LIBC}
+	exit ;;
+    ia64:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    m32r*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    m68*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    mips:Linux:*:* | mips64:Linux:*:*)
+	eval $set_cc_for_build
+	sed 's/^	//' << EOF >$dummy.c
+	#undef CPU
+	#undef ${UNAME_MACHINE}
+	#undef ${UNAME_MACHINE}el
+	#if defined(__MIPSEL__) || defined(__MIPSEL) || defined(_MIPSEL) || defined(MIPSEL)
+	CPU=${UNAME_MACHINE}el
+	#else
+	#if defined(__MIPSEB__) || defined(__MIPSEB) || defined(_MIPSEB) || defined(MIPSEB)
+	CPU=${UNAME_MACHINE}
+	#else
+	CPU=
+	#endif
+	#endif
+EOF
+	eval `$CC_FOR_BUILD -E $dummy.c 2>/dev/null | grep '^CPU'`
+	test x"${CPU}" != x && { echo "${CPU}-unknown-linux-${LIBC}"; exit; }
+	;;
+    openrisc*:Linux:*:*)
+	echo or1k-unknown-linux-${LIBC}
+	exit ;;
+    or32:Linux:*:* | or1k*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    padre:Linux:*:*)
+	echo sparc-unknown-linux-${LIBC}
+	exit ;;
+    parisc64:Linux:*:* | hppa64:Linux:*:*)
+	echo hppa64-unknown-linux-${LIBC}
+	exit ;;
+    parisc:Linux:*:* | hppa:Linux:*:*)
+	# Look for CPU level
+	case `grep '^cpu[^a-z]*:' /proc/cpuinfo 2>/dev/null | cut -d' ' -f2` in
+	  PA7*) echo hppa1.1-unknown-linux-${LIBC} ;;
+	  PA8*) echo hppa2.0-unknown-linux-${LIBC} ;;
+	  *)    echo hppa-unknown-linux-${LIBC} ;;
+	esac
+	exit ;;
+    ppc64:Linux:*:*)
+	echo powerpc64-unknown-linux-${LIBC}
+	exit ;;
+    ppc:Linux:*:*)
+	echo powerpc-unknown-linux-${LIBC}
+	exit ;;
+    ppc64le:Linux:*:*)
+	echo powerpc64le-unknown-linux-${LIBC}
+	exit ;;
+    ppcle:Linux:*:*)
+	echo powerpcle-unknown-linux-${LIBC}
+	exit ;;
+    s390:Linux:*:* | s390x:Linux:*:*)
+	echo ${UNAME_MACHINE}-ibm-linux-${LIBC}
+	exit ;;
+    sh64*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    sh*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    sparc:Linux:*:* | sparc64:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    tile*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    vax:Linux:*:*)
+	echo ${UNAME_MACHINE}-dec-linux-${LIBC}
+	exit ;;
+    x86_64:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    xtensa*:Linux:*:*)
+	echo ${UNAME_MACHINE}-unknown-linux-${LIBC}
+	exit ;;
+    i*86:DYNIX/ptx:4*:*)
+	# ptx 4.0 does uname -s correctly, with DYNIX/ptx in there.
+	# earlier versions are messed up and put the nodename in both
+	# sysname and nodename.
+	echo i386-sequent-sysv4
+	exit ;;
+    i*86:UNIX_SV:4.2MP:2.*)
+	# Unixware is an offshoot of SVR4, but it has its own version
+	# number series starting with 2...
+	# I am not positive that other SVR4 systems won't match this,
+	# I just have to hope.  -- rms.
+	# Use sysv4.2uw... so that sysv4* matches it.
+	echo ${UNAME_MACHINE}-pc-sysv4.2uw${UNAME_VERSION}
+	exit ;;
+    i*86:OS/2:*:*)
+	# If we were able to find `uname', then EMX Unix compatibility
+	# is probably installed.
+	echo ${UNAME_MACHINE}-pc-os2-emx
+	exit ;;
+    i*86:XTS-300:*:STOP)
+	echo ${UNAME_MACHINE}-unknown-stop
+	exit ;;
+    i*86:atheos:*:*)
+	echo ${UNAME_MACHINE}-unknown-atheos
+	exit ;;
+    i*86:syllable:*:*)
+	echo ${UNAME_MACHINE}-pc-syllable
+	exit ;;
+    i*86:LynxOS:2.*:* | i*86:LynxOS:3.[01]*:* | i*86:LynxOS:4.[02]*:*)
+	echo i386-unknown-lynxos${UNAME_RELEASE}
+	exit ;;
+    i*86:*DOS:*:*)
+	echo ${UNAME_MACHINE}-pc-msdosdjgpp
+	exit ;;
+    i*86:*:4.*:* | i*86:SYSTEM_V:4.*:*)
+	UNAME_REL=`echo ${UNAME_RELEASE} | sed 's/\/MP$//'`
+	if grep Novell /usr/include/link.h >/dev/null 2>/dev/null; then
+		echo ${UNAME_MACHINE}-univel-sysv${UNAME_REL}
+	else
+		echo ${UNAME_MACHINE}-pc-sysv${UNAME_REL}
+	fi
+	exit ;;
+    i*86:*:5:[678]*)
+	# UnixWare 7.x, OpenUNIX and OpenServer 6.
+	case `/bin/uname -X | grep "^Machine"` in
+	    *486*)	     UNAME_MACHINE=i486 ;;
+	    *Pentium)	     UNAME_MACHINE=i586 ;;
+	    *Pent*|*Celeron) UNAME_MACHINE=i686 ;;
+	esac
+	echo ${UNAME_MACHINE}-unknown-sysv${UNAME_RELEASE}${UNAME_SYSTEM}${UNAME_VERSION}
+	exit ;;
+    i*86:*:3.2:*)
+	if test -f /usr/options/cb.name; then
+		UNAME_REL=`sed -n 's/.*Version //p' </usr/options/cb.name`
+		echo ${UNAME_MACHINE}-pc-isc$UNAME_REL
+	elif /bin/uname -X 2>/dev/null >/dev/null ; then
+		UNAME_REL=`(/bin/uname -X|grep Release|sed -e 's/.*= //')`
+		(/bin/uname -X|grep i80486 >/dev/null) && UNAME_MACHINE=i486
+		(/bin/uname -X|grep '^Machine.*Pentium' >/dev/null) \
+			&& UNAME_MACHINE=i586
+		(/bin/uname -X|grep '^Machine.*Pent *II' >/dev/null) \
+			&& UNAME_MACHINE=i686
+		(/bin/uname -X|grep '^Machine.*Pentium Pro' >/dev/null) \
+			&& UNAME_MACHINE=i686
+		echo ${UNAME_MACHINE}-pc-sco$UNAME_REL
+	else
+		echo ${UNAME_MACHINE}-pc-sysv32
+	fi
+	exit ;;
+    pc:*:*:*)
+	# Left here for compatibility:
+	# uname -m prints for DJGPP always 'pc', but it prints nothing about
+	# the processor, so we play safe by assuming i586.
+	# Note: whatever this is, it MUST be the same as what config.sub
+	# prints for the "djgpp" host, or else GDB configury will decide that
+	# this is a cross-build.
+	echo i586-pc-msdosdjgpp
+	exit ;;
+    Intel:Mach:3*:*)
+	echo i386-pc-mach3
+	exit ;;
+    paragon:*:*:*)
+	echo i860-intel-osf1
+	exit ;;
+    i860:*:4.*:*) # i860-SVR4
+	if grep Stardent /usr/include/sys/uadmin.h >/dev/null 2>&1 ; then
+	  echo i860-stardent-sysv${UNAME_RELEASE} # Stardent Vistra i860-SVR4
+	else # Add other i860-SVR4 vendors below as they are discovered.
+	  echo i860-unknown-sysv${UNAME_RELEASE}  # Unknown i860-SVR4
+	fi
+	exit ;;
+    mini*:CTIX:SYS*5:*)
+	# "miniframe"
+	echo m68010-convergent-sysv
+	exit ;;
+    mc68k:UNIX:SYSTEM5:3.51m)
+	echo m68k-convergent-sysv
+	exit ;;
+    M680?0:D-NIX:5.3:*)
+	echo m68k-diab-dnix
+	exit ;;
+    M68*:*:R3V[5678]*:*)
+	test -r /sysV68 && { echo 'm68k-motorola-sysv'; exit; } ;;
+    3[345]??:*:4.0:3.0 | 3[34]??A:*:4.0:3.0 | 3[34]??,*:*:4.0:3.0 | 3[34]??/*:*:4.0:3.0 | 4400:*:4.0:3.0 | 4850:*:4.0:3.0 | SKA40:*:4.0:3.0 | SDS2:*:4.0:3.0 | SHG2:*:4.0:3.0 | S7501*:*:4.0:3.0)
+	OS_REL=''
+	test -r /etc/.relid \
+	&& OS_REL=.`sed -n 's/[^ ]* [^ ]* \([0-9][0-9]\).*/\1/p' < /etc/.relid`
+	/bin/uname -p 2>/dev/null | grep 86 >/dev/null \
+	  && { echo i486-ncr-sysv4.3${OS_REL}; exit; }
+	/bin/uname -p 2>/dev/null | /bin/grep entium >/dev/null \
+	  && { echo i586-ncr-sysv4.3${OS_REL}; exit; } ;;
+    3[34]??:*:4.0:* | 3[34]??,*:*:4.0:*)
+	/bin/uname -p 2>/dev/null | grep 86 >/dev/null \
+	  && { echo i486-ncr-sysv4; exit; } ;;
+    NCR*:*:4.2:* | MPRAS*:*:4.2:*)
+	OS_REL='.3'
+	test -r /etc/.relid \
+	    && OS_REL=.`sed -n 's/[^ ]* [^ ]* \([0-9][0-9]\).*/\1/p' < /etc/.relid`
+	/bin/uname -p 2>/dev/null | grep 86 >/dev/null \
+	    && { echo i486-ncr-sysv4.3${OS_REL}; exit; }
+	/bin/uname -p 2>/dev/null | /bin/grep entium >/dev/null \
+	    && { echo i586-ncr-sysv4.3${OS_REL}; exit; }
+	/bin/uname -p 2>/dev/null | /bin/grep pteron >/dev/null \
+	    && { echo i586-ncr-sysv4.3${OS_REL}; exit; } ;;
+    m68*:LynxOS:2.*:* | m68*:LynxOS:3.0*:*)
+	echo m68k-unknown-lynxos${UNAME_RELEASE}
+	exit ;;
+    mc68030:UNIX_System_V:4.*:*)
+	echo m68k-atari-sysv4
+	exit ;;
+    TSUNAMI:LynxOS:2.*:*)
+	echo sparc-unknown-lynxos${UNAME_RELEASE}
+	exit ;;
+    rs6000:LynxOS:2.*:*)
+	echo rs6000-unknown-lynxos${UNAME_RELEASE}
+	exit ;;
+    PowerPC:LynxOS:2.*:* | PowerPC:LynxOS:3.[01]*:* | PowerPC:LynxOS:4.[02]*:*)
+	echo powerpc-unknown-lynxos${UNAME_RELEASE}
+	exit ;;
+    SM[BE]S:UNIX_SV:*:*)
+	echo mips-dde-sysv${UNAME_RELEASE}
+	exit ;;
+    RM*:ReliantUNIX-*:*:*)
+	echo mips-sni-sysv4
+	exit ;;
+    RM*:SINIX-*:*:*)
+	echo mips-sni-sysv4
+	exit ;;
+    *:SINIX-*:*:*)
+	if uname -p 2>/dev/null >/dev/null ; then
+		UNAME_MACHINE=`(uname -p) 2>/dev/null`
+		echo ${UNAME_MACHINE}-sni-sysv4
+	else
+		echo ns32k-sni-sysv
+	fi
+	exit ;;
+    PENTIUM:*:4.0*:*)	# Unisys `ClearPath HMP IX 4000' SVR4/MP effort
+			# says <Richard.M.Bartel@ccMail.Census.GOV>
+	echo i586-unisys-sysv4
+	exit ;;
+    *:UNIX_System_V:4*:FTX*)
+	# From Gerald Hewes <hewes@openmarket.com>.
+	# How about differentiating between stratus architectures? -djm
+	echo hppa1.1-stratus-sysv4
+	exit ;;
+    *:*:*:FTX*)
+	# From seanf@swdc.stratus.com.
+	echo i860-stratus-sysv4
+	exit ;;
+    i*86:VOS:*:*)
+	# From Paul.Green@stratus.com.
+	echo ${UNAME_MACHINE}-stratus-vos
+	exit ;;
+    *:VOS:*:*)
+	# From Paul.Green@stratus.com.
+	echo hppa1.1-stratus-vos
+	exit ;;
+    mc68*:A/UX:*:*)
+	echo m68k-apple-aux${UNAME_RELEASE}
+	exit ;;
+    news*:NEWS-OS:6*:*)
+	echo mips-sony-newsos6
+	exit ;;
+    R[34]000:*System_V*:*:* | R4000:UNIX_SYSV:*:* | R*000:UNIX_SV:*:*)
+	if [ -d /usr/nec ]; then
+		echo mips-nec-sysv${UNAME_RELEASE}
+	else
+		echo mips-unknown-sysv${UNAME_RELEASE}
+	fi
+	exit ;;
+    BeBox:BeOS:*:*)	# BeOS running on hardware made by Be, PPC only.
+	echo powerpc-be-beos
+	exit ;;
+    BeMac:BeOS:*:*)	# BeOS running on Mac or Mac clone, PPC only.
+	echo powerpc-apple-beos
+	exit ;;
+    BePC:BeOS:*:*)	# BeOS running on Intel PC compatible.
+	echo i586-pc-beos
+	exit ;;
+    BePC:Haiku:*:*)	# Haiku running on Intel PC compatible.
+	echo i586-pc-haiku
+	exit ;;
+    x86_64:Haiku:*:*)
+	echo x86_64-unknown-haiku
+	exit ;;
+    SX-4:SUPER-UX:*:*)
+	echo sx4-nec-superux${UNAME_RELEASE}
+	exit ;;
+    SX-5:SUPER-UX:*:*)
+	echo sx5-nec-superux${UNAME_RELEASE}
+	exit ;;
+    SX-6:SUPER-UX:*:*)
+	echo sx6-nec-superux${UNAME_RELEASE}
+	exit ;;
+    SX-7:SUPER-UX:*:*)
+	echo sx7-nec-superux${UNAME_RELEASE}
+	exit ;;
+    SX-8:SUPER-UX:*:*)
+	echo sx8-nec-superux${UNAME_RELEASE}
+	exit ;;
+    SX-8R:SUPER-UX:*:*)
+	echo sx8r-nec-superux${UNAME_RELEASE}
+	exit ;;
+    Power*:Rhapsody:*:*)
+	echo powerpc-apple-rhapsody${UNAME_RELEASE}
+	exit ;;
+    *:Rhapsody:*:*)
+	echo ${UNAME_MACHINE}-apple-rhapsody${UNAME_RELEASE}
+	exit ;;
+    *:Darwin:*:*)
+	UNAME_PROCESSOR=`uname -p` || UNAME_PROCESSOR=unknown
+	eval $set_cc_for_build
+	if test "$UNAME_PROCESSOR" = unknown ; then
+	    UNAME_PROCESSOR=powerpc
+	fi
+	if test `echo "$UNAME_RELEASE" | sed -e 's/\..*//'` -le 10 ; then
+	    if [ "$CC_FOR_BUILD" != 'no_compiler_found' ]; then
+		if (echo '#ifdef __LP64__'; echo IS_64BIT_ARCH; echo '#endif') | \
+		    (CCOPTS= $CC_FOR_BUILD -E - 2>/dev/null) | \
+		    grep IS_64BIT_ARCH >/dev/null
+		then
+		    case $UNAME_PROCESSOR in
+			i386) UNAME_PROCESSOR=x86_64 ;;
+			powerpc) UNAME_PROCESSOR=powerpc64 ;;
+		    esac
+		fi
+	    fi
+	elif test "$UNAME_PROCESSOR" = i386 ; then
+	    # Avoid executing cc on OS X 10.9, as it ships with a stub
+	    # that puts up a graphical alert prompting to install
+	    # developer tools.  Any system running Mac OS X 10.7 or
+	    # later (Darwin 11 and later) is required to have a 64-bit
+	    # processor. This is not true of the ARM version of Darwin
+	    # that Apple uses in portable devices.
+	    UNAME_PROCESSOR=x86_64
+	fi
+	echo ${UNAME_PROCESSOR}-apple-darwin${UNAME_RELEASE}
+	exit ;;
+    *:procnto*:*:* | *:QNX:[0123456789]*:*)
+	UNAME_PROCESSOR=`uname -p`
+	if test "$UNAME_PROCESSOR" = "x86"; then
+		UNAME_PROCESSOR=i386
+		UNAME_MACHINE=pc
+	fi
+	echo ${UNAME_PROCESSOR}-${UNAME_MACHINE}-nto-qnx${UNAME_RELEASE}
+	exit ;;
+    *:QNX:*:4*)
+	echo i386-pc-qnx
+	exit ;;
+    NEO-?:NONSTOP_KERNEL:*:*)
+	echo neo-tandem-nsk${UNAME_RELEASE}
+	exit ;;
+    NSE-*:NONSTOP_KERNEL:*:*)
+	echo nse-tandem-nsk${UNAME_RELEASE}
+	exit ;;
+    NSR-?:NONSTOP_KERNEL:*:*)
+	echo nsr-tandem-nsk${UNAME_RELEASE}
+	exit ;;
+    *:NonStop-UX:*:*)
+	echo mips-compaq-nonstopux
+	exit ;;
+    BS2000:POSIX*:*:*)
+	echo bs2000-siemens-sysv
+	exit ;;
+    DS/*:UNIX_System_V:*:*)
+	echo ${UNAME_MACHINE}-${UNAME_SYSTEM}-${UNAME_RELEASE}
+	exit ;;
+    *:Plan9:*:*)
+	# "uname -m" is not consistent, so use $cputype instead. 386
+	# is converted to i386 for consistency with other x86
+	# operating systems.
+	if test "$cputype" = "386"; then
+	    UNAME_MACHINE=i386
+	else
+	    UNAME_MACHINE="$cputype"
+	fi
+	echo ${UNAME_MACHINE}-unknown-plan9
+	exit ;;
+    *:TOPS-10:*:*)
+	echo pdp10-unknown-tops10
+	exit ;;
+    *:TENEX:*:*)
+	echo pdp10-unknown-tenex
+	exit ;;
+    KS10:TOPS-20:*:* | KL10:TOPS-20:*:* | TYPE4:TOPS-20:*:*)
+	echo pdp10-dec-tops20
+	exit ;;
+    XKL-1:TOPS-20:*:* | TYPE5:TOPS-20:*:*)
+	echo pdp10-xkl-tops20
+	exit ;;
+    *:TOPS-20:*:*)
+	echo pdp10-unknown-tops20
+	exit ;;
+    *:ITS:*:*)
+	echo pdp10-unknown-its
+	exit ;;
+    SEI:*:*:SEIUX)
+	echo mips-sei-seiux${UNAME_RELEASE}
+	exit ;;
+    *:DragonFly:*:*)
+	echo ${UNAME_MACHINE}-unknown-dragonfly`echo ${UNAME_RELEASE}|sed -e 's/[-(].*//'`
+	exit ;;
+    *:*VMS:*:*)
+	UNAME_MACHINE=`(uname -p) 2>/dev/null`
+	case "${UNAME_MACHINE}" in
+	    A*) echo alpha-dec-vms ; exit ;;
+	    I*) echo ia64-dec-vms ; exit ;;
+	    V*) echo vax-dec-vms ; exit ;;
+	esac ;;
+    *:XENIX:*:SysV)
+	echo i386-pc-xenix
+	exit ;;
+    i*86:skyos:*:*)
+	echo ${UNAME_MACHINE}-pc-skyos`echo ${UNAME_RELEASE}` | sed -e 's/ .*$//'
+	exit ;;
+    i*86:rdos:*:*)
+	echo ${UNAME_MACHINE}-pc-rdos
+	exit ;;
+    i*86:AROS:*:*)
+	echo ${UNAME_MACHINE}-pc-aros
+	exit ;;
+    x86_64:VMkernel:*:*)
+	echo ${UNAME_MACHINE}-unknown-esx
+	exit ;;
+esac
+
+cat >&2 <<EOF
+$0: unable to guess system type
+
+This script, last modified $timestamp, has failed to recognize
+the operating system you are using. It is advised that you
+download the most up to date version of the config scripts from
+
+  http://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.guess;hb=HEAD
+and
+  http://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.sub;hb=HEAD
+
+If the version you run ($0) is already up to date, please
+send the following data and any information you think might be
+pertinent to <config-patches@gnu.org> in order to provide the needed
+information to handle your system.
+
+config.guess timestamp = $timestamp
+
+uname -m = `(uname -m) 2>/dev/null || echo unknown`
+uname -r = `(uname -r) 2>/dev/null || echo unknown`
+uname -s = `(uname -s) 2>/dev/null || echo unknown`
+uname -v = `(uname -v) 2>/dev/null || echo unknown`
+
+/usr/bin/uname -p = `(/usr/bin/uname -p) 2>/dev/null`
+/bin/uname -X     = `(/bin/uname -X) 2>/dev/null`
+
+hostinfo               = `(hostinfo) 2>/dev/null`
+/bin/universe          = `(/bin/universe) 2>/dev/null`
+/usr/bin/arch -k       = `(/usr/bin/arch -k) 2>/dev/null`
+/bin/arch              = `(/bin/arch) 2>/dev/null`
+/usr/bin/oslevel       = `(/usr/bin/oslevel) 2>/dev/null`
+/usr/convex/getsysinfo = `(/usr/convex/getsysinfo) 2>/dev/null`
+
+UNAME_MACHINE = ${UNAME_MACHINE}
+UNAME_RELEASE = ${UNAME_RELEASE}
+UNAME_SYSTEM  = ${UNAME_SYSTEM}
+UNAME_VERSION = ${UNAME_VERSION}
+EOF
+
+exit 1
+
+# Local variables:
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "timestamp='"
+# time-stamp-format: "%:y-%02m-%02d"
+# time-stamp-end: "'"
+# End:
diff --git a/auto/config.sub b/auto/config.sub
new file mode 100755
index 0000000..bba4efb
--- /dev/null
+++ b/auto/config.sub
@@ -0,0 +1,1799 @@
+#! /bin/sh
+# Configuration validation subroutine script.
+#   Copyright 1992-2014 Free Software Foundation, Inc.
+
+timestamp='2014-09-11'
+
+# This file is free software; you can redistribute it and/or modify it
+# under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful, but
+# WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+# General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, see <http://www.gnu.org/licenses/>.
+#
+# As a special exception to the GNU General Public License, if you
+# distribute this file as part of a program that contains a
+# configuration script generated by Autoconf, you may include it under
+# the same distribution terms that you use for the rest of that
+# program.  This Exception is an additional permission under section 7
+# of the GNU General Public License, version 3 ("GPLv3").
+
+
+# Please send patches with a ChangeLog entry to config-patches@gnu.org.
+#
+# Configuration subroutine to validate and canonicalize a configuration type.
+# Supply the specified configuration type as an argument.
+# If it is invalid, we print an error message on stderr and exit with code 1.
+# Otherwise, we print the canonical config type on stdout and succeed.
+
+# You can get the latest version of this script from:
+# http://git.savannah.gnu.org/gitweb/?p=config.git;a=blob_plain;f=config.sub;hb=HEAD
+
+# This file is supposed to be the same for all GNU packages
+# and recognize all the CPU types, system types and aliases
+# that are meaningful with *any* GNU software.
+# Each package is responsible for reporting which valid configurations
+# it does not support.  The user should be able to distinguish
+# a failure to support a valid configuration from a meaningless
+# configuration.
+
+# The goal of this file is to map all the various variations of a given
+# machine specification into a single specification in the form:
+#	CPU_TYPE-MANUFACTURER-OPERATING_SYSTEM
+# or in some cases, the newer four-part form:
+#	CPU_TYPE-MANUFACTURER-KERNEL-OPERATING_SYSTEM
+# It is wrong to echo any other type of specification.
+
+me=`echo "$0" | sed -e 's,.*/,,'`
+
+usage="\
+Usage: $0 [OPTION] CPU-MFR-OPSYS
+       $0 [OPTION] ALIAS
+
+Canonicalize a configuration name.
+
+Operation modes:
+  -h, --help         print this help, then exit
+  -t, --time-stamp   print date of last modification, then exit
+  -v, --version      print version number, then exit
+
+Report bugs and patches to <config-patches@gnu.org>."
+
+version="\
+GNU config.sub ($timestamp)
+
+Copyright 1992-2014 Free Software Foundation, Inc.
+
+This is free software; see the source for copying conditions.  There is NO
+warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE."
+
+help="
+Try \`$me --help' for more information."
+
+# Parse command line
+while test $# -gt 0 ; do
+  case $1 in
+    --time-stamp | --time* | -t )
+       echo "$timestamp" ; exit ;;
+    --version | -v )
+       echo "$version" ; exit ;;
+    --help | --h* | -h )
+       echo "$usage"; exit ;;
+    -- )     # Stop option processing
+       shift; break ;;
+    - )	# Use stdin as input.
+       break ;;
+    -* )
+       echo "$me: invalid option $1$help"
+       exit 1 ;;
+
+    *local*)
+       # First pass through any local machine types.
+       echo $1
+       exit ;;
+
+    * )
+       break ;;
+  esac
+done
+
+case $# in
+ 0) echo "$me: missing argument$help" >&2
+    exit 1;;
+ 1) ;;
+ *) echo "$me: too many arguments$help" >&2
+    exit 1;;
+esac
+
+# Separate what the user gave into CPU-COMPANY and OS or KERNEL-OS (if any).
+# Here we must recognize all the valid KERNEL-OS combinations.
+maybe_os=`echo $1 | sed 's/^\(.*\)-\([^-]*-[^-]*\)$/\2/'`
+case $maybe_os in
+  nto-qnx* | linux-gnu* | linux-android* | linux-dietlibc | linux-newlib* | \
+  linux-musl* | linux-uclibc* | uclinux-uclibc* | uclinux-gnu* | kfreebsd*-gnu* | \
+  knetbsd*-gnu* | netbsd*-gnu* | \
+  kopensolaris*-gnu* | \
+  storm-chaos* | os2-emx* | rtmk-nova*)
+    os=-$maybe_os
+    basic_machine=`echo $1 | sed 's/^\(.*\)-\([^-]*-[^-]*\)$/\1/'`
+    ;;
+  android-linux)
+    os=-linux-android
+    basic_machine=`echo $1 | sed 's/^\(.*\)-\([^-]*-[^-]*\)$/\1/'`-unknown
+    ;;
+  *)
+    basic_machine=`echo $1 | sed 's/-[^-]*$//'`
+    if [ $basic_machine != $1 ]
+    then os=`echo $1 | sed 's/.*-/-/'`
+    else os=; fi
+    ;;
+esac
+
+### Let's recognize common machines as not being operating systems so
+### that things like config.sub decstation-3100 work.  We also
+### recognize some manufacturers as not being operating systems, so we
+### can provide default operating systems below.
+case $os in
+	-sun*os*)
+		# Prevent following clause from handling this invalid input.
+		;;
+	-dec* | -mips* | -sequent* | -encore* | -pc532* | -sgi* | -sony* | \
+	-att* | -7300* | -3300* | -delta* | -motorola* | -sun[234]* | \
+	-unicom* | -ibm* | -next | -hp | -isi* | -apollo | -altos* | \
+	-convergent* | -ncr* | -news | -32* | -3600* | -3100* | -hitachi* |\
+	-c[123]* | -convex* | -sun | -crds | -omron* | -dg | -ultra | -tti* | \
+	-harris | -dolphin | -highlevel | -gould | -cbm | -ns | -masscomp | \
+	-apple | -axis | -knuth | -cray | -microblaze*)
+		os=
+		basic_machine=$1
+		;;
+	-bluegene*)
+		os=-cnk
+		;;
+	-sim | -cisco | -oki | -wec | -winbond)
+		os=
+		basic_machine=$1
+		;;
+	-scout)
+		;;
+	-wrs)
+		os=-vxworks
+		basic_machine=$1
+		;;
+	-chorusos*)
+		os=-chorusos
+		basic_machine=$1
+		;;
+	-chorusrdb)
+		os=-chorusrdb
+		basic_machine=$1
+		;;
+	-hiux*)
+		os=-hiuxwe2
+		;;
+	-sco6)
+		os=-sco5v6
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco5)
+		os=-sco3.2v5
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco4)
+		os=-sco3.2v4
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco3.2.[4-9]*)
+		os=`echo $os | sed -e 's/sco3.2./sco3.2v/'`
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco3.2v[4-9]*)
+		# Don't forget version if it is 3.2v4 or newer.
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco5v6*)
+		# Don't forget version if it is 3.2v4 or newer.
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-sco*)
+		os=-sco3.2v2
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-udk*)
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-isc)
+		os=-isc2.2
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-clix*)
+		basic_machine=clipper-intergraph
+		;;
+	-isc*)
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-pc/'`
+		;;
+	-lynx*178)
+		os=-lynxos178
+		;;
+	-lynx*5)
+		os=-lynxos5
+		;;
+	-lynx*)
+		os=-lynxos
+		;;
+	-ptx*)
+		basic_machine=`echo $1 | sed -e 's/86-.*/86-sequent/'`
+		;;
+	-windowsnt*)
+		os=`echo $os | sed -e 's/windowsnt/winnt/'`
+		;;
+	-psos*)
+		os=-psos
+		;;
+	-mint | -mint[0-9]*)
+		basic_machine=m68k-atari
+		os=-mint
+		;;
+esac
+
+# Decode aliases for certain CPU-COMPANY combinations.
+case $basic_machine in
+	# Recognize the basic CPU types without company name.
+	# Some are omitted here because they have special meanings below.
+	1750a | 580 \
+	| a29k \
+	| aarch64 | aarch64_be \
+	| alpha | alphaev[4-8] | alphaev56 | alphaev6[78] | alphapca5[67] \
+	| alpha64 | alpha64ev[4-8] | alpha64ev56 | alpha64ev6[78] | alpha64pca5[67] \
+	| am33_2.0 \
+	| arc | arceb \
+	| arm | arm[bl]e | arme[lb] | armv[2-8] | armv[3-8][lb] | armv7[arm] \
+	| avr | avr32 \
+	| be32 | be64 \
+	| bfin \
+	| c4x | c8051 | clipper \
+	| d10v | d30v | dlx | dsp16xx \
+	| epiphany \
+	| fido | fr30 | frv \
+	| h8300 | h8500 | hppa | hppa1.[01] | hppa2.0 | hppa2.0[nw] | hppa64 \
+	| hexagon \
+	| i370 | i860 | i960 | ia64 \
+	| ip2k | iq2000 \
+	| k1om \
+	| le32 | le64 \
+	| lm32 \
+	| m32c | m32r | m32rle | m68000 | m68k | m88k \
+	| maxq | mb | microblaze | microblazeel | mcore | mep | metag \
+	| mips | mipsbe | mipseb | mipsel | mipsle \
+	| mips16 \
+	| mips64 | mips64el \
+	| mips64octeon | mips64octeonel \
+	| mips64orion | mips64orionel \
+	| mips64r5900 | mips64r5900el \
+	| mips64vr | mips64vrel \
+	| mips64vr4100 | mips64vr4100el \
+	| mips64vr4300 | mips64vr4300el \
+	| mips64vr5000 | mips64vr5000el \
+	| mips64vr5900 | mips64vr5900el \
+	| mipsisa32 | mipsisa32el \
+	| mipsisa32r2 | mipsisa32r2el \
+	| mipsisa32r6 | mipsisa32r6el \
+	| mipsisa64 | mipsisa64el \
+	| mipsisa64r2 | mipsisa64r2el \
+	| mipsisa64r6 | mipsisa64r6el \
+	| mipsisa64sb1 | mipsisa64sb1el \
+	| mipsisa64sr71k | mipsisa64sr71kel \
+	| mipsr5900 | mipsr5900el \
+	| mipstx39 | mipstx39el \
+	| mn10200 | mn10300 \
+	| moxie \
+	| mt \
+	| msp430 \
+	| nds32 | nds32le | nds32be \
+	| nios | nios2 | nios2eb | nios2el \
+	| ns16k | ns32k \
+	| open8 | or1k | or1knd | or32 \
+	| pdp10 | pdp11 | pj | pjl \
+	| powerpc | powerpc64 | powerpc64le | powerpcle \
+	| pyramid \
+	| riscv32 | riscv64 \
+	| rl78 | rx \
+	| score \
+	| sh | sh[1234] | sh[24]a | sh[24]aeb | sh[23]e | sh[34]eb | sheb | shbe | shle | sh[1234]le | sh3ele \
+	| sh64 | sh64le \
+	| sparc | sparc64 | sparc64b | sparc64v | sparc86x | sparclet | sparclite \
+	| sparcv8 | sparcv9 | sparcv9b | sparcv9v \
+	| spu \
+	| tahoe | tic4x | tic54x | tic55x | tic6x | tic80 | tron \
+	| ubicom32 \
+	| v850 | v850e | v850e1 | v850e2 | v850es | v850e2v3 \
+	| we32k \
+	| x86 | xc16x | xstormy16 | xtensa \
+	| z8k | z80)
+		basic_machine=$basic_machine-unknown
+		;;
+	c54x)
+		basic_machine=tic54x-unknown
+		;;
+	c55x)
+		basic_machine=tic55x-unknown
+		;;
+	c6x)
+		basic_machine=tic6x-unknown
+		;;
+	m6811 | m68hc11 | m6812 | m68hc12 | m68hcs12x | nvptx | picochip)
+		basic_machine=$basic_machine-unknown
+		os=-none
+		;;
+	m88110 | m680[12346]0 | m683?2 | m68360 | m5200 | v70 | w65 | z8k)
+		;;
+	ms1)
+		basic_machine=mt-unknown
+		;;
+
+	strongarm | thumb | xscale)
+		basic_machine=arm-unknown
+		;;
+	xgate)
+		basic_machine=$basic_machine-unknown
+		os=-none
+		;;
+	xscaleeb)
+		basic_machine=armeb-unknown
+		;;
+
+	xscaleel)
+		basic_machine=armel-unknown
+		;;
+
+	# We use `pc' rather than `unknown'
+	# because (1) that's what they normally are, and
+	# (2) the word "unknown" tends to confuse beginning users.
+	i*86 | x86_64)
+	  basic_machine=$basic_machine-pc
+	  ;;
+	# Object if more than one company name word.
+	*-*-*)
+		echo Invalid configuration \`$1\': machine \`$basic_machine\' not recognized 1>&2
+		exit 1
+		;;
+	# Recognize the basic CPU types with company name.
+	580-* \
+	| a29k-* \
+	| aarch64-* | aarch64_be-* \
+	| alpha-* | alphaev[4-8]-* | alphaev56-* | alphaev6[78]-* \
+	| alpha64-* | alpha64ev[4-8]-* | alpha64ev56-* | alpha64ev6[78]-* \
+	| alphapca5[67]-* | alpha64pca5[67]-* | arc-* | arceb-* \
+	| arm-*  | armbe-* | armle-* | armeb-* | armv*-* \
+	| avr-* | avr32-* \
+	| be32-* | be64-* \
+	| bfin-* | bs2000-* \
+	| c[123]* | c30-* | [cjt]90-* | c4x-* \
+	| c8051-* | clipper-* | craynv-* | cydra-* \
+	| d10v-* | d30v-* | dlx-* \
+	| elxsi-* \
+	| f30[01]-* | f700-* | fido-* | fr30-* | frv-* | fx80-* \
+	| h8300-* | h8500-* \
+	| hppa-* | hppa1.[01]-* | hppa2.0-* | hppa2.0[nw]-* | hppa64-* \
+	| hexagon-* \
+	| i*86-* | i860-* | i960-* | ia64-* \
+	| ip2k-* | iq2000-* \
+	| k1om-* \
+	| le32-* | le64-* \
+	| lm32-* \
+	| m32c-* | m32r-* | m32rle-* \
+	| m68000-* | m680[012346]0-* | m68360-* | m683?2-* | m68k-* \
+	| m88110-* | m88k-* | maxq-* | mcore-* | metag-* \
+	| microblaze-* | microblazeel-* \
+	| mips-* | mipsbe-* | mipseb-* | mipsel-* | mipsle-* \
+	| mips16-* \
+	| mips64-* | mips64el-* \
+	| mips64octeon-* | mips64octeonel-* \
+	| mips64orion-* | mips64orionel-* \
+	| mips64r5900-* | mips64r5900el-* \
+	| mips64vr-* | mips64vrel-* \
+	| mips64vr4100-* | mips64vr4100el-* \
+	| mips64vr4300-* | mips64vr4300el-* \
+	| mips64vr5000-* | mips64vr5000el-* \
+	| mips64vr5900-* | mips64vr5900el-* \
+	| mipsisa32-* | mipsisa32el-* \
+	| mipsisa32r2-* | mipsisa32r2el-* \
+	| mipsisa32r6-* | mipsisa32r6el-* \
+	| mipsisa64-* | mipsisa64el-* \
+	| mipsisa64r2-* | mipsisa64r2el-* \
+	| mipsisa64r6-* | mipsisa64r6el-* \
+	| mipsisa64sb1-* | mipsisa64sb1el-* \
+	| mipsisa64sr71k-* | mipsisa64sr71kel-* \
+	| mipsr5900-* | mipsr5900el-* \
+	| mipstx39-* | mipstx39el-* \
+	| mmix-* \
+	| mt-* \
+	| msp430-* \
+	| nds32-* | nds32le-* | nds32be-* \
+	| nios-* | nios2-* | nios2eb-* | nios2el-* \
+	| none-* | np1-* | ns16k-* | ns32k-* \
+	| open8-* \
+	| or1k*-* \
+	| orion-* \
+	| pdp10-* | pdp11-* | pj-* | pjl-* | pn-* | power-* \
+	| powerpc-* | powerpc64-* | powerpc64le-* | powerpcle-* \
+	| pyramid-* \
+	| rl78-* | romp-* | rs6000-* | rx-* \
+	| sh-* | sh[1234]-* | sh[24]a-* | sh[24]aeb-* | sh[23]e-* | sh[34]eb-* | sheb-* | shbe-* \
+	| shle-* | sh[1234]le-* | sh3ele-* | sh64-* | sh64le-* \
+	| sparc-* | sparc64-* | sparc64b-* | sparc64v-* | sparc86x-* | sparclet-* \
+	| sparclite-* \
+	| sparcv8-* | sparcv9-* | sparcv9b-* | sparcv9v-* | sv1-* | sx?-* \
+	| tahoe-* \
+	| tic30-* | tic4x-* | tic54x-* | tic55x-* | tic6x-* | tic80-* \
+	| tile*-* \
+	| tron-* \
+	| ubicom32-* \
+	| v850-* | v850e-* | v850e1-* | v850es-* | v850e2-* | v850e2v3-* \
+	| vax-* \
+	| we32k-* \
+	| x86-* | x86_64-* | xc16x-* | xps100-* \
+	| xstormy16-* | xtensa*-* \
+	| ymp-* \
+	| z8k-* | z80-*)
+		;;
+	# Recognize the basic CPU types without company name, with glob match.
+	xtensa*)
+		basic_machine=$basic_machine-unknown
+		;;
+	# Recognize the various machine names and aliases which stand
+	# for a CPU type and a company and sometimes even an OS.
+	386bsd)
+		basic_machine=i386-unknown
+		os=-bsd
+		;;
+	3b1 | 7300 | 7300-att | att-7300 | pc7300 | safari | unixpc)
+		basic_machine=m68000-att
+		;;
+	3b*)
+		basic_machine=we32k-att
+		;;
+	a29khif)
+		basic_machine=a29k-amd
+		os=-udi
+		;;
+	abacus)
+		basic_machine=abacus-unknown
+		;;
+	adobe68k)
+		basic_machine=m68010-adobe
+		os=-scout
+		;;
+	alliant | fx80)
+		basic_machine=fx80-alliant
+		;;
+	altos | altos3068)
+		basic_machine=m68k-altos
+		;;
+	am29k)
+		basic_machine=a29k-none
+		os=-bsd
+		;;
+	amd64)
+		basic_machine=x86_64-pc
+		;;
+	amd64-*)
+		basic_machine=x86_64-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	amdahl)
+		basic_machine=580-amdahl
+		os=-sysv
+		;;
+	amiga | amiga-*)
+		basic_machine=m68k-unknown
+		;;
+	amigaos | amigados)
+		basic_machine=m68k-unknown
+		os=-amigaos
+		;;
+	amigaunix | amix)
+		basic_machine=m68k-unknown
+		os=-sysv4
+		;;
+	apollo68)
+		basic_machine=m68k-apollo
+		os=-sysv
+		;;
+	apollo68bsd)
+		basic_machine=m68k-apollo
+		os=-bsd
+		;;
+	aros)
+		basic_machine=i386-pc
+		os=-aros
+		;;
+	aux)
+		basic_machine=m68k-apple
+		os=-aux
+		;;
+	balance)
+		basic_machine=ns32k-sequent
+		os=-dynix
+		;;
+	blackfin)
+		basic_machine=bfin-unknown
+		os=-linux
+		;;
+	blackfin-*)
+		basic_machine=bfin-`echo $basic_machine | sed 's/^[^-]*-//'`
+		os=-linux
+		;;
+	bluegene*)
+		basic_machine=powerpc-ibm
+		os=-cnk
+		;;
+	c54x-*)
+		basic_machine=tic54x-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	c55x-*)
+		basic_machine=tic55x-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	c6x-*)
+		basic_machine=tic6x-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	c90)
+		basic_machine=c90-cray
+		os=-unicos
+		;;
+	cegcc)
+		basic_machine=arm-unknown
+		os=-cegcc
+		;;
+	convex-c1)
+		basic_machine=c1-convex
+		os=-bsd
+		;;
+	convex-c2)
+		basic_machine=c2-convex
+		os=-bsd
+		;;
+	convex-c32)
+		basic_machine=c32-convex
+		os=-bsd
+		;;
+	convex-c34)
+		basic_machine=c34-convex
+		os=-bsd
+		;;
+	convex-c38)
+		basic_machine=c38-convex
+		os=-bsd
+		;;
+	cray | j90)
+		basic_machine=j90-cray
+		os=-unicos
+		;;
+	craynv)
+		basic_machine=craynv-cray
+		os=-unicosmp
+		;;
+	cr16 | cr16-*)
+		basic_machine=cr16-unknown
+		os=-elf
+		;;
+	crds | unos)
+		basic_machine=m68k-crds
+		;;
+	crisv32 | crisv32-* | etraxfs*)
+		basic_machine=crisv32-axis
+		;;
+	cris | cris-* | etrax*)
+		basic_machine=cris-axis
+		;;
+	crx)
+		basic_machine=crx-unknown
+		os=-elf
+		;;
+	da30 | da30-*)
+		basic_machine=m68k-da30
+		;;
+	decstation | decstation-3100 | pmax | pmax-* | pmin | dec3100 | decstatn)
+		basic_machine=mips-dec
+		;;
+	decsystem10* | dec10*)
+		basic_machine=pdp10-dec
+		os=-tops10
+		;;
+	decsystem20* | dec20*)
+		basic_machine=pdp10-dec
+		os=-tops20
+		;;
+	delta | 3300 | motorola-3300 | motorola-delta \
+	      | 3300-motorola | delta-motorola)
+		basic_machine=m68k-motorola
+		;;
+	delta88)
+		basic_machine=m88k-motorola
+		os=-sysv3
+		;;
+	dicos)
+		basic_machine=i686-pc
+		os=-dicos
+		;;
+	djgpp)
+		basic_machine=i586-pc
+		os=-msdosdjgpp
+		;;
+	dpx20 | dpx20-*)
+		basic_machine=rs6000-bull
+		os=-bosx
+		;;
+	dpx2* | dpx2*-bull)
+		basic_machine=m68k-bull
+		os=-sysv3
+		;;
+	ebmon29k)
+		basic_machine=a29k-amd
+		os=-ebmon
+		;;
+	elxsi)
+		basic_machine=elxsi-elxsi
+		os=-bsd
+		;;
+	encore | umax | mmax)
+		basic_machine=ns32k-encore
+		;;
+	es1800 | OSE68k | ose68k | ose | OSE)
+		basic_machine=m68k-ericsson
+		os=-ose
+		;;
+	fx2800)
+		basic_machine=i860-alliant
+		;;
+	genix)
+		basic_machine=ns32k-ns
+		;;
+	gmicro)
+		basic_machine=tron-gmicro
+		os=-sysv
+		;;
+	go32)
+		basic_machine=i386-pc
+		os=-go32
+		;;
+	h3050r* | hiux*)
+		basic_machine=hppa1.1-hitachi
+		os=-hiuxwe2
+		;;
+	h8300hms)
+		basic_machine=h8300-hitachi
+		os=-hms
+		;;
+	h8300xray)
+		basic_machine=h8300-hitachi
+		os=-xray
+		;;
+	h8500hms)
+		basic_machine=h8500-hitachi
+		os=-hms
+		;;
+	harris)
+		basic_machine=m88k-harris
+		os=-sysv3
+		;;
+	hp300-*)
+		basic_machine=m68k-hp
+		;;
+	hp300bsd)
+		basic_machine=m68k-hp
+		os=-bsd
+		;;
+	hp300hpux)
+		basic_machine=m68k-hp
+		os=-hpux
+		;;
+	hp3k9[0-9][0-9] | hp9[0-9][0-9])
+		basic_machine=hppa1.0-hp
+		;;
+	hp9k2[0-9][0-9] | hp9k31[0-9])
+		basic_machine=m68000-hp
+		;;
+	hp9k3[2-9][0-9])
+		basic_machine=m68k-hp
+		;;
+	hp9k6[0-9][0-9] | hp6[0-9][0-9])
+		basic_machine=hppa1.0-hp
+		;;
+	hp9k7[0-79][0-9] | hp7[0-79][0-9])
+		basic_machine=hppa1.1-hp
+		;;
+	hp9k78[0-9] | hp78[0-9])
+		# FIXME: really hppa2.0-hp
+		basic_machine=hppa1.1-hp
+		;;
+	hp9k8[67]1 | hp8[67]1 | hp9k80[24] | hp80[24] | hp9k8[78]9 | hp8[78]9 | hp9k893 | hp893)
+		# FIXME: really hppa2.0-hp
+		basic_machine=hppa1.1-hp
+		;;
+	hp9k8[0-9][13679] | hp8[0-9][13679])
+		basic_machine=hppa1.1-hp
+		;;
+	hp9k8[0-9][0-9] | hp8[0-9][0-9])
+		basic_machine=hppa1.0-hp
+		;;
+	hppa-next)
+		os=-nextstep3
+		;;
+	hppaosf)
+		basic_machine=hppa1.1-hp
+		os=-osf
+		;;
+	hppro)
+		basic_machine=hppa1.1-hp
+		os=-proelf
+		;;
+	i370-ibm* | ibm*)
+		basic_machine=i370-ibm
+		;;
+	i*86v32)
+		basic_machine=`echo $1 | sed -e 's/86.*/86-pc/'`
+		os=-sysv32
+		;;
+	i*86v4*)
+		basic_machine=`echo $1 | sed -e 's/86.*/86-pc/'`
+		os=-sysv4
+		;;
+	i*86v)
+		basic_machine=`echo $1 | sed -e 's/86.*/86-pc/'`
+		os=-sysv
+		;;
+	i*86sol2)
+		basic_machine=`echo $1 | sed -e 's/86.*/86-pc/'`
+		os=-solaris2
+		;;
+	i386mach)
+		basic_machine=i386-mach
+		os=-mach
+		;;
+	i386-vsta | vsta)
+		basic_machine=i386-unknown
+		os=-vsta
+		;;
+	iris | iris4d)
+		basic_machine=mips-sgi
+		case $os in
+		    -irix*)
+			;;
+		    *)
+			os=-irix4
+			;;
+		esac
+		;;
+	isi68 | isi)
+		basic_machine=m68k-isi
+		os=-sysv
+		;;
+	m68knommu)
+		basic_machine=m68k-unknown
+		os=-linux
+		;;
+	m68knommu-*)
+		basic_machine=m68k-`echo $basic_machine | sed 's/^[^-]*-//'`
+		os=-linux
+		;;
+	m88k-omron*)
+		basic_machine=m88k-omron
+		;;
+	magnum | m3230)
+		basic_machine=mips-mips
+		os=-sysv
+		;;
+	merlin)
+		basic_machine=ns32k-utek
+		os=-sysv
+		;;
+	microblaze*)
+		basic_machine=microblaze-xilinx
+		;;
+	mingw64)
+		basic_machine=x86_64-pc
+		os=-mingw64
+		;;
+	mingw32)
+		basic_machine=i686-pc
+		os=-mingw32
+		;;
+	mingw32ce)
+		basic_machine=arm-unknown
+		os=-mingw32ce
+		;;
+	miniframe)
+		basic_machine=m68000-convergent
+		;;
+	*mint | -mint[0-9]* | *MiNT | *MiNT[0-9]*)
+		basic_machine=m68k-atari
+		os=-mint
+		;;
+	mips3*-*)
+		basic_machine=`echo $basic_machine | sed -e 's/mips3/mips64/'`
+		;;
+	mips3*)
+		basic_machine=`echo $basic_machine | sed -e 's/mips3/mips64/'`-unknown
+		;;
+	monitor)
+		basic_machine=m68k-rom68k
+		os=-coff
+		;;
+	morphos)
+		basic_machine=powerpc-unknown
+		os=-morphos
+		;;
+	moxiebox)
+		basic_machine=moxie-unknown
+		os=-moxiebox
+		;;
+	msdos)
+		basic_machine=i386-pc
+		os=-msdos
+		;;
+	ms1-*)
+		basic_machine=`echo $basic_machine | sed -e 's/ms1-/mt-/'`
+		;;
+	msys)
+		basic_machine=i686-pc
+		os=-msys
+		;;
+	mvs)
+		basic_machine=i370-ibm
+		os=-mvs
+		;;
+	nacl)
+		basic_machine=le32-unknown
+		os=-nacl
+		;;
+	ncr3000)
+		basic_machine=i486-ncr
+		os=-sysv4
+		;;
+	netbsd386)
+		basic_machine=i386-unknown
+		os=-netbsd
+		;;
+	netwinder)
+		basic_machine=armv4l-rebel
+		os=-linux
+		;;
+	news | news700 | news800 | news900)
+		basic_machine=m68k-sony
+		os=-newsos
+		;;
+	news1000)
+		basic_machine=m68030-sony
+		os=-newsos
+		;;
+	news-3600 | risc-news)
+		basic_machine=mips-sony
+		os=-newsos
+		;;
+	necv70)
+		basic_machine=v70-nec
+		os=-sysv
+		;;
+	next | m*-next )
+		basic_machine=m68k-next
+		case $os in
+		    -nextstep* )
+			;;
+		    -ns2*)
+		      os=-nextstep2
+			;;
+		    *)
+		      os=-nextstep3
+			;;
+		esac
+		;;
+	nh3000)
+		basic_machine=m68k-harris
+		os=-cxux
+		;;
+	nh[45]000)
+		basic_machine=m88k-harris
+		os=-cxux
+		;;
+	nindy960)
+		basic_machine=i960-intel
+		os=-nindy
+		;;
+	mon960)
+		basic_machine=i960-intel
+		os=-mon960
+		;;
+	nonstopux)
+		basic_machine=mips-compaq
+		os=-nonstopux
+		;;
+	np1)
+		basic_machine=np1-gould
+		;;
+	neo-tandem)
+		basic_machine=neo-tandem
+		;;
+	nse-tandem)
+		basic_machine=nse-tandem
+		;;
+	nsr-tandem)
+		basic_machine=nsr-tandem
+		;;
+	op50n-* | op60c-*)
+		basic_machine=hppa1.1-oki
+		os=-proelf
+		;;
+	openrisc | openrisc-*)
+		basic_machine=or32-unknown
+		;;
+	os400)
+		basic_machine=powerpc-ibm
+		os=-os400
+		;;
+	OSE68000 | ose68000)
+		basic_machine=m68000-ericsson
+		os=-ose
+		;;
+	os68k)
+		basic_machine=m68k-none
+		os=-os68k
+		;;
+	pa-hitachi)
+		basic_machine=hppa1.1-hitachi
+		os=-hiuxwe2
+		;;
+	paragon)
+		basic_machine=i860-intel
+		os=-osf
+		;;
+	parisc)
+		basic_machine=hppa-unknown
+		os=-linux
+		;;
+	parisc-*)
+		basic_machine=hppa-`echo $basic_machine | sed 's/^[^-]*-//'`
+		os=-linux
+		;;
+	pbd)
+		basic_machine=sparc-tti
+		;;
+	pbb)
+		basic_machine=m68k-tti
+		;;
+	pc532 | pc532-*)
+		basic_machine=ns32k-pc532
+		;;
+	pc98)
+		basic_machine=i386-pc
+		;;
+	pc98-*)
+		basic_machine=i386-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	pentium | p5 | k5 | k6 | nexgen | viac3)
+		basic_machine=i586-pc
+		;;
+	pentiumpro | p6 | 6x86 | athlon | athlon_*)
+		basic_machine=i686-pc
+		;;
+	pentiumii | pentium2 | pentiumiii | pentium3)
+		basic_machine=i686-pc
+		;;
+	pentium4)
+		basic_machine=i786-pc
+		;;
+	pentium-* | p5-* | k5-* | k6-* | nexgen-* | viac3-*)
+		basic_machine=i586-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	pentiumpro-* | p6-* | 6x86-* | athlon-*)
+		basic_machine=i686-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	pentiumii-* | pentium2-* | pentiumiii-* | pentium3-*)
+		basic_machine=i686-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	pentium4-*)
+		basic_machine=i786-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	pn)
+		basic_machine=pn-gould
+		;;
+	power)	basic_machine=power-ibm
+		;;
+	ppc | ppcbe)	basic_machine=powerpc-unknown
+		;;
+	ppc-* | ppcbe-*)
+		basic_machine=powerpc-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	ppcle | powerpclittle | ppc-le | powerpc-little)
+		basic_machine=powerpcle-unknown
+		;;
+	ppcle-* | powerpclittle-*)
+		basic_machine=powerpcle-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	ppc64)	basic_machine=powerpc64-unknown
+		;;
+	ppc64-*) basic_machine=powerpc64-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	ppc64le | powerpc64little | ppc64-le | powerpc64-little)
+		basic_machine=powerpc64le-unknown
+		;;
+	ppc64le-* | powerpc64little-*)
+		basic_machine=powerpc64le-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	ps2)
+		basic_machine=i386-ibm
+		;;
+	pw32)
+		basic_machine=i586-unknown
+		os=-pw32
+		;;
+	rdos | rdos64)
+		basic_machine=x86_64-pc
+		os=-rdos
+		;;
+	rdos32)
+		basic_machine=i386-pc
+		os=-rdos
+		;;
+	rom68k)
+		basic_machine=m68k-rom68k
+		os=-coff
+		;;
+	rm[46]00)
+		basic_machine=mips-siemens
+		;;
+	rtpc | rtpc-*)
+		basic_machine=romp-ibm
+		;;
+	s390 | s390-*)
+		basic_machine=s390-ibm
+		;;
+	s390x | s390x-*)
+		basic_machine=s390x-ibm
+		;;
+	sa29200)
+		basic_machine=a29k-amd
+		os=-udi
+		;;
+	sb1)
+		basic_machine=mipsisa64sb1-unknown
+		;;
+	sb1el)
+		basic_machine=mipsisa64sb1el-unknown
+		;;
+	sde)
+		basic_machine=mipsisa32-sde
+		os=-elf
+		;;
+	sei)
+		basic_machine=mips-sei
+		os=-seiux
+		;;
+	sequent)
+		basic_machine=i386-sequent
+		;;
+	sh)
+		basic_machine=sh-hitachi
+		os=-hms
+		;;
+	sh5el)
+		basic_machine=sh5le-unknown
+		;;
+	sh64)
+		basic_machine=sh64-unknown
+		;;
+	sparclite-wrs | simso-wrs)
+		basic_machine=sparclite-wrs
+		os=-vxworks
+		;;
+	sps7)
+		basic_machine=m68k-bull
+		os=-sysv2
+		;;
+	spur)
+		basic_machine=spur-unknown
+		;;
+	st2000)
+		basic_machine=m68k-tandem
+		;;
+	stratus)
+		basic_machine=i860-stratus
+		os=-sysv4
+		;;
+	strongarm-* | thumb-*)
+		basic_machine=arm-`echo $basic_machine | sed 's/^[^-]*-//'`
+		;;
+	sun2)
+		basic_machine=m68000-sun
+		;;
+	sun2os3)
+		basic_machine=m68000-sun
+		os=-sunos3
+		;;
+	sun2os4)
+		basic_machine=m68000-sun
+		os=-sunos4
+		;;
+	sun3os3)
+		basic_machine=m68k-sun
+		os=-sunos3
+		;;
+	sun3os4)
+		basic_machine=m68k-sun
+		os=-sunos4
+		;;
+	sun4os3)
+		basic_machine=sparc-sun
+		os=-sunos3
+		;;
+	sun4os4)
+		basic_machine=sparc-sun
+		os=-sunos4
+		;;
+	sun4sol2)
+		basic_machine=sparc-sun
+		os=-solaris2
+		;;
+	sun3 | sun3-*)
+		basic_machine=m68k-sun
+		;;
+	sun4)
+		basic_machine=sparc-sun
+		;;
+	sun386 | sun386i | roadrunner)
+		basic_machine=i386-sun
+		;;
+	sv1)
+		basic_machine=sv1-cray
+		os=-unicos
+		;;
+	symmetry)
+		basic_machine=i386-sequent
+		os=-dynix
+		;;
+	t3e)
+		basic_machine=alphaev5-cray
+		os=-unicos
+		;;
+	t90)
+		basic_machine=t90-cray
+		os=-unicos
+		;;
+	tile*)
+		basic_machine=$basic_machine-unknown
+		os=-linux-gnu
+		;;
+	tx39)
+		basic_machine=mipstx39-unknown
+		;;
+	tx39el)
+		basic_machine=mipstx39el-unknown
+		;;
+	toad1)
+		basic_machine=pdp10-xkl
+		os=-tops20
+		;;
+	tower | tower-32)
+		basic_machine=m68k-ncr
+		;;
+	tpf)
+		basic_machine=s390x-ibm
+		os=-tpf
+		;;
+	udi29k)
+		basic_machine=a29k-amd
+		os=-udi
+		;;
+	ultra3)
+		basic_machine=a29k-nyu
+		os=-sym1
+		;;
+	v810 | necv810)
+		basic_machine=v810-nec
+		os=-none
+		;;
+	vaxv)
+		basic_machine=vax-dec
+		os=-sysv
+		;;
+	vms)
+		basic_machine=vax-dec
+		os=-vms
+		;;
+	vpp*|vx|vx-*)
+		basic_machine=f301-fujitsu
+		;;
+	vxworks960)
+		basic_machine=i960-wrs
+		os=-vxworks
+		;;
+	vxworks68)
+		basic_machine=m68k-wrs
+		os=-vxworks
+		;;
+	vxworks29k)
+		basic_machine=a29k-wrs
+		os=-vxworks
+		;;
+	w65*)
+		basic_machine=w65-wdc
+		os=-none
+		;;
+	w89k-*)
+		basic_machine=hppa1.1-winbond
+		os=-proelf
+		;;
+	xbox)
+		basic_machine=i686-pc
+		os=-mingw32
+		;;
+	xps | xps100)
+		basic_machine=xps100-honeywell
+		;;
+	xscale-* | xscalee[bl]-*)
+		basic_machine=`echo $basic_machine | sed 's/^xscale/arm/'`
+		;;
+	ymp)
+		basic_machine=ymp-cray
+		os=-unicos
+		;;
+	z8k-*-coff)
+		basic_machine=z8k-unknown
+		os=-sim
+		;;
+	z80-*-coff)
+		basic_machine=z80-unknown
+		os=-sim
+		;;
+	none)
+		basic_machine=none-none
+		os=-none
+		;;
+
+# Here we handle the default manufacturer of certain CPU types.  It is in
+# some cases the only manufacturer, in others, it is the most popular.
+	w89k)
+		basic_machine=hppa1.1-winbond
+		;;
+	op50n)
+		basic_machine=hppa1.1-oki
+		;;
+	op60c)
+		basic_machine=hppa1.1-oki
+		;;
+	romp)
+		basic_machine=romp-ibm
+		;;
+	mmix)
+		basic_machine=mmix-knuth
+		;;
+	rs6000)
+		basic_machine=rs6000-ibm
+		;;
+	vax)
+		basic_machine=vax-dec
+		;;
+	pdp10)
+		# there are many clones, so DEC is not a safe bet
+		basic_machine=pdp10-unknown
+		;;
+	pdp11)
+		basic_machine=pdp11-dec
+		;;
+	we32k)
+		basic_machine=we32k-att
+		;;
+	sh[1234] | sh[24]a | sh[24]aeb | sh[34]eb | sh[1234]le | sh[23]ele)
+		basic_machine=sh-unknown
+		;;
+	sparc | sparcv8 | sparcv9 | sparcv9b | sparcv9v)
+		basic_machine=sparc-sun
+		;;
+	cydra)
+		basic_machine=cydra-cydrome
+		;;
+	orion)
+		basic_machine=orion-highlevel
+		;;
+	orion105)
+		basic_machine=clipper-highlevel
+		;;
+	mac | mpw | mac-mpw)
+		basic_machine=m68k-apple
+		;;
+	pmac | pmac-mpw)
+		basic_machine=powerpc-apple
+		;;
+	*-unknown)
+		# Make sure to match an already-canonicalized machine name.
+		;;
+	*)
+		echo Invalid configuration \`$1\': machine \`$basic_machine\' not recognized 1>&2
+		exit 1
+		;;
+esac
+
+# Here we canonicalize certain aliases for manufacturers.
+case $basic_machine in
+	*-digital*)
+		basic_machine=`echo $basic_machine | sed 's/digital.*/dec/'`
+		;;
+	*-commodore*)
+		basic_machine=`echo $basic_machine | sed 's/commodore.*/cbm/'`
+		;;
+	*)
+		;;
+esac
+
+# Decode manufacturer-specific aliases for certain operating systems.
+
+if [ x"$os" != x"" ]
+then
+case $os in
+	# First match some system type aliases
+	# that might get confused with valid system types.
+	# -solaris* is a basic system type, with this one exception.
+	-auroraux)
+		os=-auroraux
+		;;
+	-solaris1 | -solaris1.*)
+		os=`echo $os | sed -e 's|solaris1|sunos4|'`
+		;;
+	-solaris)
+		os=-solaris2
+		;;
+	-svr4*)
+		os=-sysv4
+		;;
+	-unixware*)
+		os=-sysv4.2uw
+		;;
+	-gnu/linux*)
+		os=`echo $os | sed -e 's|gnu/linux|linux-gnu|'`
+		;;
+	# First accept the basic system types.
+	# The portable systems comes first.
+	# Each alternative MUST END IN A *, to match a version number.
+	# -sysv* is not here because it comes later, after sysvr4.
+	-gnu* | -bsd* | -mach* | -minix* | -genix* | -ultrix* | -irix* \
+	      | -*vms* | -sco* | -esix* | -isc* | -aix* | -cnk* | -sunos | -sunos[34]*\
+	      | -hpux* | -unos* | -osf* | -luna* | -dgux* | -auroraux* | -solaris* \
+	      | -sym* | -kopensolaris* | -plan9* \
+	      | -amigaos* | -amigados* | -msdos* | -newsos* | -unicos* | -aof* \
+	      | -aos* | -aros* \
+	      | -nindy* | -vxsim* | -vxworks* | -ebmon* | -hms* | -mvs* \
+	      | -clix* | -riscos* | -uniplus* | -iris* | -rtu* | -xenix* \
+	      | -hiux* | -386bsd* | -knetbsd* | -mirbsd* | -netbsd* \
+	      | -bitrig* | -openbsd* | -solidbsd* \
+	      | -ekkobsd* | -kfreebsd* | -freebsd* | -riscix* | -lynxos* \
+	      | -bosx* | -nextstep* | -cxux* | -aout* | -elf* | -oabi* \
+	      | -ptx* | -coff* | -ecoff* | -winnt* | -domain* | -vsta* \
+	      | -udi* | -eabi* | -lites* | -ieee* | -go32* | -aux* \
+	      | -chorusos* | -chorusrdb* | -cegcc* \
+	      | -cygwin* | -msys* | -pe* | -psos* | -moss* | -proelf* | -rtems* \
+	      | -mingw32* | -mingw64* | -linux-gnu* | -linux-android* \
+	      | -linux-newlib* | -linux-musl* | -linux-uclibc* \
+	      | -uxpv* | -beos* | -mpeix* | -udk* | -moxiebox* \
+	      | -interix* | -uwin* | -mks* | -rhapsody* | -darwin* | -opened* \
+	      | -openstep* | -oskit* | -conix* | -pw32* | -nonstopux* \
+	      | -storm-chaos* | -tops10* | -tenex* | -tops20* | -its* \
+	      | -os2* | -vos* | -palmos* | -uclinux* | -nucleus* \
+	      | -morphos* | -superux* | -rtmk* | -rtmk-nova* | -windiss* \
+	      | -powermax* | -dnix* | -nx6 | -nx7 | -sei* | -dragonfly* \
+	      | -skyos* | -haiku* | -rdos* | -toppers* | -drops* | -es* | -tirtos*)
+	# Remember, each alternative MUST END IN *, to match a version number.
+		;;
+	-qnx*)
+		case $basic_machine in
+		    x86-* | i*86-*)
+			;;
+		    *)
+			os=-nto$os
+			;;
+		esac
+		;;
+	-nto-qnx*)
+		;;
+	-nto*)
+		os=`echo $os | sed -e 's|nto|nto-qnx|'`
+		;;
+	-sim | -es1800* | -hms* | -xray | -os68k* | -none* | -v88r* \
+	      | -windows* | -osx | -abug | -netware* | -os9* | -beos* | -haiku* \
+	      | -macos* | -mpw* | -magic* | -mmixware* | -mon960* | -lnews*)
+		;;
+	-mac*)
+		os=`echo $os | sed -e 's|mac|macos|'`
+		;;
+	-linux-dietlibc)
+		os=-linux-dietlibc
+		;;
+	-linux*)
+		os=`echo $os | sed -e 's|linux|linux-gnu|'`
+		;;
+	-sunos5*)
+		os=`echo $os | sed -e 's|sunos5|solaris2|'`
+		;;
+	-sunos6*)
+		os=`echo $os | sed -e 's|sunos6|solaris3|'`
+		;;
+	-opened*)
+		os=-openedition
+		;;
+	-os400*)
+		os=-os400
+		;;
+	-wince*)
+		os=-wince
+		;;
+	-osfrose*)
+		os=-osfrose
+		;;
+	-osf*)
+		os=-osf
+		;;
+	-utek*)
+		os=-bsd
+		;;
+	-dynix*)
+		os=-bsd
+		;;
+	-acis*)
+		os=-aos
+		;;
+	-atheos*)
+		os=-atheos
+		;;
+	-syllable*)
+		os=-syllable
+		;;
+	-386bsd)
+		os=-bsd
+		;;
+	-ctix* | -uts*)
+		os=-sysv
+		;;
+	-nova*)
+		os=-rtmk-nova
+		;;
+	-ns2 )
+		os=-nextstep2
+		;;
+	-nsk*)
+		os=-nsk
+		;;
+	# Preserve the version number of sinix5.
+	-sinix5.*)
+		os=`echo $os | sed -e 's|sinix|sysv|'`
+		;;
+	-sinix*)
+		os=-sysv4
+		;;
+	-tpf*)
+		os=-tpf
+		;;
+	-triton*)
+		os=-sysv3
+		;;
+	-oss*)
+		os=-sysv3
+		;;
+	-svr4)
+		os=-sysv4
+		;;
+	-svr3)
+		os=-sysv3
+		;;
+	-sysvr4)
+		os=-sysv4
+		;;
+	# This must come after -sysvr4.
+	-sysv*)
+		;;
+	-ose*)
+		os=-ose
+		;;
+	-es1800*)
+		os=-ose
+		;;
+	-xenix)
+		os=-xenix
+		;;
+	-*mint | -mint[0-9]* | -*MiNT | -MiNT[0-9]*)
+		os=-mint
+		;;
+	-aros*)
+		os=-aros
+		;;
+	-zvmoe)
+		os=-zvmoe
+		;;
+	-dicos*)
+		os=-dicos
+		;;
+	-nacl*)
+		;;
+	-none)
+		;;
+	*)
+		# Get rid of the `-' at the beginning of $os.
+		os=`echo $os | sed 's/[^-]*-//'`
+		echo Invalid configuration \`$1\': system \`$os\' not recognized 1>&2
+		exit 1
+		;;
+esac
+else
+
+# Here we handle the default operating systems that come with various machines.
+# The value should be what the vendor currently ships out the door with their
+# machine or put another way, the most popular os provided with the machine.
+
+# Note that if you're going to try to match "-MANUFACTURER" here (say,
+# "-sun"), then you have to tell the case statement up towards the top
+# that MANUFACTURER isn't an operating system.  Otherwise, code above
+# will signal an error saying that MANUFACTURER isn't an operating
+# system, and we'll never get to this point.
+
+case $basic_machine in
+	score-*)
+		os=-elf
+		;;
+	spu-*)
+		os=-elf
+		;;
+	*-acorn)
+		os=-riscix1.2
+		;;
+	arm*-rebel)
+		os=-linux
+		;;
+	arm*-semi)
+		os=-aout
+		;;
+	c4x-* | tic4x-*)
+		os=-coff
+		;;
+	c8051-*)
+		os=-elf
+		;;
+	hexagon-*)
+		os=-elf
+		;;
+	tic54x-*)
+		os=-coff
+		;;
+	tic55x-*)
+		os=-coff
+		;;
+	tic6x-*)
+		os=-coff
+		;;
+	# This must come before the *-dec entry.
+	pdp10-*)
+		os=-tops20
+		;;
+	pdp11-*)
+		os=-none
+		;;
+	*-dec | vax-*)
+		os=-ultrix4.2
+		;;
+	m68*-apollo)
+		os=-domain
+		;;
+	i386-sun)
+		os=-sunos4.0.2
+		;;
+	m68000-sun)
+		os=-sunos3
+		;;
+	m68*-cisco)
+		os=-aout
+		;;
+	mep-*)
+		os=-elf
+		;;
+	mips*-cisco)
+		os=-elf
+		;;
+	mips*-*)
+		os=-elf
+		;;
+	or32-*)
+		os=-coff
+		;;
+	*-tti)	# must be before sparc entry or we get the wrong os.
+		os=-sysv3
+		;;
+	sparc-* | *-sun)
+		os=-sunos4.1.1
+		;;
+	*-be)
+		os=-beos
+		;;
+	*-haiku)
+		os=-haiku
+		;;
+	*-ibm)
+		os=-aix
+		;;
+	*-knuth)
+		os=-mmixware
+		;;
+	*-wec)
+		os=-proelf
+		;;
+	*-winbond)
+		os=-proelf
+		;;
+	*-oki)
+		os=-proelf
+		;;
+	*-hp)
+		os=-hpux
+		;;
+	*-hitachi)
+		os=-hiux
+		;;
+	i860-* | *-att | *-ncr | *-altos | *-motorola | *-convergent)
+		os=-sysv
+		;;
+	*-cbm)
+		os=-amigaos
+		;;
+	*-dg)
+		os=-dgux
+		;;
+	*-dolphin)
+		os=-sysv3
+		;;
+	m68k-ccur)
+		os=-rtu
+		;;
+	m88k-omron*)
+		os=-luna
+		;;
+	*-next )
+		os=-nextstep
+		;;
+	*-sequent)
+		os=-ptx
+		;;
+	*-crds)
+		os=-unos
+		;;
+	*-ns)
+		os=-genix
+		;;
+	i370-*)
+		os=-mvs
+		;;
+	*-next)
+		os=-nextstep3
+		;;
+	*-gould)
+		os=-sysv
+		;;
+	*-highlevel)
+		os=-bsd
+		;;
+	*-encore)
+		os=-bsd
+		;;
+	*-sgi)
+		os=-irix
+		;;
+	*-siemens)
+		os=-sysv4
+		;;
+	*-masscomp)
+		os=-rtu
+		;;
+	f30[01]-fujitsu | f700-fujitsu)
+		os=-uxpv
+		;;
+	*-rom68k)
+		os=-coff
+		;;
+	*-*bug)
+		os=-coff
+		;;
+	*-apple)
+		os=-macos
+		;;
+	*-atari*)
+		os=-mint
+		;;
+	*)
+		os=-none
+		;;
+esac
+fi
+
+# Here we handle the case where we know the os, and the CPU type, but not the
+# manufacturer.  We pick the logical manufacturer.
+vendor=unknown
+case $basic_machine in
+	*-unknown)
+		case $os in
+			-riscix*)
+				vendor=acorn
+				;;
+			-sunos*)
+				vendor=sun
+				;;
+			-cnk*|-aix*)
+				vendor=ibm
+				;;
+			-beos*)
+				vendor=be
+				;;
+			-hpux*)
+				vendor=hp
+				;;
+			-mpeix*)
+				vendor=hp
+				;;
+			-hiux*)
+				vendor=hitachi
+				;;
+			-unos*)
+				vendor=crds
+				;;
+			-dgux*)
+				vendor=dg
+				;;
+			-luna*)
+				vendor=omron
+				;;
+			-genix*)
+				vendor=ns
+				;;
+			-mvs* | -opened*)
+				vendor=ibm
+				;;
+			-os400*)
+				vendor=ibm
+				;;
+			-ptx*)
+				vendor=sequent
+				;;
+			-tpf*)
+				vendor=ibm
+				;;
+			-vxsim* | -vxworks* | -windiss*)
+				vendor=wrs
+				;;
+			-aux*)
+				vendor=apple
+				;;
+			-hms*)
+				vendor=hitachi
+				;;
+			-mpw* | -macos*)
+				vendor=apple
+				;;
+			-*mint | -mint[0-9]* | -*MiNT | -MiNT[0-9]*)
+				vendor=atari
+				;;
+			-vos*)
+				vendor=stratus
+				;;
+		esac
+		basic_machine=`echo $basic_machine | sed "s/unknown/$vendor/"`
+		;;
+esac
+
+echo $basic_machine$os
+exit
+
+# Local variables:
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "timestamp='"
+# time-stamp-format: "%:y-%02m-%02d"
+# time-stamp-end: "'"
+# End:
diff --git a/auto/depcomp b/auto/depcomp
new file mode 100755
index 0000000..4ebd5b3
--- /dev/null
+++ b/auto/depcomp
@@ -0,0 +1,791 @@
+#! /bin/sh
+# depcomp - compile a program generating dependencies as side-effects
+
+scriptversion=2013-05-30.07; # UTC
+
+# Copyright (C) 1999-2013 Free Software Foundation, Inc.
+
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2, or (at your option)
+# any later version.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+
+# You should have received a copy of the GNU General Public License
+# along with this program.  If not, see <http://www.gnu.org/licenses/>.
+
+# As a special exception to the GNU General Public License, if you
+# distribute this file as part of a program that contains a
+# configuration script generated by Autoconf, you may include it under
+# the same distribution terms that you use for the rest of that program.
+
+# Originally written by Alexandre Oliva <oliva@dcc.unicamp.br>.
+
+case $1 in
+  '')
+    echo "$0: No command.  Try '$0 --help' for more information." 1>&2
+    exit 1;
+    ;;
+  -h | --h*)
+    cat <<\EOF
+Usage: depcomp [--help] [--version] PROGRAM [ARGS]
+
+Run PROGRAMS ARGS to compile a file, generating dependencies
+as side-effects.
+
+Environment variables:
+  depmode     Dependency tracking mode.
+  source      Source file read by 'PROGRAMS ARGS'.
+  object      Object file output by 'PROGRAMS ARGS'.
+  DEPDIR      directory where to store dependencies.
+  depfile     Dependency file to output.
+  tmpdepfile  Temporary file to use when outputting dependencies.
+  libtool     Whether libtool is used (yes/no).
+
+Report bugs to <bug-automake@gnu.org>.
+EOF
+    exit $?
+    ;;
+  -v | --v*)
+    echo "depcomp $scriptversion"
+    exit $?
+    ;;
+esac
+
+# Get the directory component of the given path, and save it in the
+# global variables '$dir'.  Note that this directory component will
+# be either empty or ending with a '/' character.  This is deliberate.
+set_dir_from ()
+{
+  case $1 in
+    */*) dir=`echo "$1" | sed -e 's|/[^/]*$|/|'`;;
+      *) dir=;;
+  esac
+}
+
+# Get the suffix-stripped basename of the given path, and save it the
+# global variable '$base'.
+set_base_from ()
+{
+  base=`echo "$1" | sed -e 's|^.*/||' -e 's/\.[^.]*$//'`
+}
+
+# If no dependency file was actually created by the compiler invocation,
+# we still have to create a dummy depfile, to avoid errors with the
+# Makefile "include basename.Plo" scheme.
+make_dummy_depfile ()
+{
+  echo "#dummy" > "$depfile"
+}
+
+# Factor out some common post-processing of the generated depfile.
+# Requires the auxiliary global variable '$tmpdepfile' to be set.
+aix_post_process_depfile ()
+{
+  # If the compiler actually managed to produce a dependency file,
+  # post-process it.
+  if test -f "$tmpdepfile"; then
+    # Each line is of the form 'foo.o: dependency.h'.
+    # Do two passes, one to just change these to
+    #   $object: dependency.h
+    # and one to simply output
+    #   dependency.h:
+    # which is needed to avoid the deleted-header problem.
+    { sed -e "s,^.*\.[$lower]*:,$object:," < "$tmpdepfile"
+      sed -e "s,^.*\.[$lower]*:[$tab ]*,," -e 's,$,:,' < "$tmpdepfile"
+    } > "$depfile"
+    rm -f "$tmpdepfile"
+  else
+    make_dummy_depfile
+  fi
+}
+
+# A tabulation character.
+tab='	'
+# A newline character.
+nl='
+'
+# Character ranges might be problematic outside the C locale.
+# These definitions help.
+upper=ABCDEFGHIJKLMNOPQRSTUVWXYZ
+lower=abcdefghijklmnopqrstuvwxyz
+digits=0123456789
+alpha=${upper}${lower}
+
+if test -z "$depmode" || test -z "$source" || test -z "$object"; then
+  echo "depcomp: Variables source, object and depmode must be set" 1>&2
+  exit 1
+fi
+
+# Dependencies for sub/bar.o or sub/bar.obj go into sub/.deps/bar.Po.
+depfile=${depfile-`echo "$object" |
+  sed 's|[^\\/]*$|'${DEPDIR-.deps}'/&|;s|\.\([^.]*\)$|.P\1|;s|Pobj$|Po|'`}
+tmpdepfile=${tmpdepfile-`echo "$depfile" | sed 's/\.\([^.]*\)$/.T\1/'`}
+
+rm -f "$tmpdepfile"
+
+# Avoid interferences from the environment.
+gccflag= dashmflag=
+
+# Some modes work just like other modes, but use different flags.  We
+# parameterize here, but still list the modes in the big case below,
+# to make depend.m4 easier to write.  Note that we *cannot* use a case
+# here, because this file can only contain one case statement.
+if test "$depmode" = hp; then
+  # HP compiler uses -M and no extra arg.
+  gccflag=-M
+  depmode=gcc
+fi
+
+if test "$depmode" = dashXmstdout; then
+  # This is just like dashmstdout with a different argument.
+  dashmflag=-xM
+  depmode=dashmstdout
+fi
+
+cygpath_u="cygpath -u -f -"
+if test "$depmode" = msvcmsys; then
+  # This is just like msvisualcpp but w/o cygpath translation.
+  # Just convert the backslash-escaped backslashes to single forward
+  # slashes to satisfy depend.m4
+  cygpath_u='sed s,\\\\,/,g'
+  depmode=msvisualcpp
+fi
+
+if test "$depmode" = msvc7msys; then
+  # This is just like msvc7 but w/o cygpath translation.
+  # Just convert the backslash-escaped backslashes to single forward
+  # slashes to satisfy depend.m4
+  cygpath_u='sed s,\\\\,/,g'
+  depmode=msvc7
+fi
+
+if test "$depmode" = xlc; then
+  # IBM C/C++ Compilers xlc/xlC can output gcc-like dependency information.
+  gccflag=-qmakedep=gcc,-MF
+  depmode=gcc
+fi
+
+case "$depmode" in
+gcc3)
+## gcc 3 implements dependency tracking that does exactly what
+## we want.  Yay!  Note: for some reason libtool 1.4 doesn't like
+## it if -MD -MP comes after the -MF stuff.  Hmm.
+## Unfortunately, FreeBSD c89 acceptance of flags depends upon
+## the command line argument order; so add the flags where they
+## appear in depend2.am.  Note that the slowdown incurred here
+## affects only configure: in makefiles, %FASTDEP% shortcuts this.
+  for arg
+  do
+    case $arg in
+    -c) set fnord "$@" -MT "$object" -MD -MP -MF "$tmpdepfile" "$arg" ;;
+    *)  set fnord "$@" "$arg" ;;
+    esac
+    shift # fnord
+    shift # $arg
+  done
+  "$@"
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  mv "$tmpdepfile" "$depfile"
+  ;;
+
+gcc)
+## Note that this doesn't just cater to obsosete pre-3.x GCC compilers.
+## but also to in-use compilers like IMB xlc/xlC and the HP C compiler.
+## (see the conditional assignment to $gccflag above).
+## There are various ways to get dependency output from gcc.  Here's
+## why we pick this rather obscure method:
+## - Don't want to use -MD because we'd like the dependencies to end
+##   up in a subdir.  Having to rename by hand is ugly.
+##   (We might end up doing this anyway to support other compilers.)
+## - The DEPENDENCIES_OUTPUT environment variable makes gcc act like
+##   -MM, not -M (despite what the docs say).  Also, it might not be
+##   supported by the other compilers which use the 'gcc' depmode.
+## - Using -M directly means running the compiler twice (even worse
+##   than renaming).
+  if test -z "$gccflag"; then
+    gccflag=-MD,
+  fi
+  "$@" -Wp,"$gccflag$tmpdepfile"
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  rm -f "$depfile"
+  echo "$object : \\" > "$depfile"
+  # The second -e expression handles DOS-style file names with drive
+  # letters.
+  sed -e 's/^[^:]*: / /' \
+      -e 's/^['$alpha']:\/[^:]*: / /' < "$tmpdepfile" >> "$depfile"
+## This next piece of magic avoids the "deleted header file" problem.
+## The problem is that when a header file which appears in a .P file
+## is deleted, the dependency causes make to die (because there is
+## typically no way to rebuild the header).  We avoid this by adding
+## dummy dependencies for each header file.  Too bad gcc doesn't do
+## this for us directly.
+## Some versions of gcc put a space before the ':'.  On the theory
+## that the space means something, we add a space to the output as
+## well.  hp depmode also adds that space, but also prefixes the VPATH
+## to the object.  Take care to not repeat it in the output.
+## Some versions of the HPUX 10.20 sed can't process this invocation
+## correctly.  Breaking it into two sed invocations is a workaround.
+  tr ' ' "$nl" < "$tmpdepfile" \
+    | sed -e 's/^\\$//' -e '/^$/d' -e "s|.*$object$||" -e '/:$/d' \
+    | sed -e 's/$/ :/' >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+hp)
+  # This case exists only to let depend.m4 do its work.  It works by
+  # looking at the text of this script.  This case will never be run,
+  # since it is checked for above.
+  exit 1
+  ;;
+
+sgi)
+  if test "$libtool" = yes; then
+    "$@" "-Wp,-MDupdate,$tmpdepfile"
+  else
+    "$@" -MDupdate "$tmpdepfile"
+  fi
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  rm -f "$depfile"
+
+  if test -f "$tmpdepfile"; then  # yes, the sourcefile depend on other files
+    echo "$object : \\" > "$depfile"
+    # Clip off the initial element (the dependent).  Don't try to be
+    # clever and replace this with sed code, as IRIX sed won't handle
+    # lines with more than a fixed number of characters (4096 in
+    # IRIX 6.2 sed, 8192 in IRIX 6.5).  We also remove comment lines;
+    # the IRIX cc adds comments like '#:fec' to the end of the
+    # dependency line.
+    tr ' ' "$nl" < "$tmpdepfile" \
+      | sed -e 's/^.*\.o://' -e 's/#.*$//' -e '/^$/ d' \
+      | tr "$nl" ' ' >> "$depfile"
+    echo >> "$depfile"
+    # The second pass generates a dummy entry for each header file.
+    tr ' ' "$nl" < "$tmpdepfile" \
+      | sed -e 's/^.*\.o://' -e 's/#.*$//' -e '/^$/ d' -e 's/$/:/' \
+      >> "$depfile"
+  else
+    make_dummy_depfile
+  fi
+  rm -f "$tmpdepfile"
+  ;;
+
+xlc)
+  # This case exists only to let depend.m4 do its work.  It works by
+  # looking at the text of this script.  This case will never be run,
+  # since it is checked for above.
+  exit 1
+  ;;
+
+aix)
+  # The C for AIX Compiler uses -M and outputs the dependencies
+  # in a .u file.  In older versions, this file always lives in the
+  # current directory.  Also, the AIX compiler puts '$object:' at the
+  # start of each line; $object doesn't have directory information.
+  # Version 6 uses the directory in both cases.
+  set_dir_from "$object"
+  set_base_from "$object"
+  if test "$libtool" = yes; then
+    tmpdepfile1=$dir$base.u
+    tmpdepfile2=$base.u
+    tmpdepfile3=$dir.libs/$base.u
+    "$@" -Wc,-M
+  else
+    tmpdepfile1=$dir$base.u
+    tmpdepfile2=$dir$base.u
+    tmpdepfile3=$dir$base.u
+    "$@" -M
+  fi
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile1" "$tmpdepfile2" "$tmpdepfile3"
+    exit $stat
+  fi
+
+  for tmpdepfile in "$tmpdepfile1" "$tmpdepfile2" "$tmpdepfile3"
+  do
+    test -f "$tmpdepfile" && break
+  done
+  aix_post_process_depfile
+  ;;
+
+tcc)
+  # tcc (Tiny C Compiler) understand '-MD -MF file' since version 0.9.26
+  # FIXME: That version still under development at the moment of writing.
+  #        Make that this statement remains true also for stable, released
+  #        versions.
+  # It will wrap lines (doesn't matter whether long or short) with a
+  # trailing '\', as in:
+  #
+  #   foo.o : \
+  #    foo.c \
+  #    foo.h \
+  #
+  # It will put a trailing '\' even on the last line, and will use leading
+  # spaces rather than leading tabs (at least since its commit 0394caf7
+  # "Emit spaces for -MD").
+  "$@" -MD -MF "$tmpdepfile"
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  rm -f "$depfile"
+  # Each non-empty line is of the form 'foo.o : \' or ' dep.h \'.
+  # We have to change lines of the first kind to '$object: \'.
+  sed -e "s|.*:|$object :|" < "$tmpdepfile" > "$depfile"
+  # And for each line of the second kind, we have to emit a 'dep.h:'
+  # dummy dependency, to avoid the deleted-header problem.
+  sed -n -e 's|^  *\(.*\) *\\$|\1:|p' < "$tmpdepfile" >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+## The order of this option in the case statement is important, since the
+## shell code in configure will try each of these formats in the order
+## listed in this file.  A plain '-MD' option would be understood by many
+## compilers, so we must ensure this comes after the gcc and icc options.
+pgcc)
+  # Portland's C compiler understands '-MD'.
+  # Will always output deps to 'file.d' where file is the root name of the
+  # source file under compilation, even if file resides in a subdirectory.
+  # The object file name does not affect the name of the '.d' file.
+  # pgcc 10.2 will output
+  #    foo.o: sub/foo.c sub/foo.h
+  # and will wrap long lines using '\' :
+  #    foo.o: sub/foo.c ... \
+  #     sub/foo.h ... \
+  #     ...
+  set_dir_from "$object"
+  # Use the source, not the object, to determine the base name, since
+  # that's sadly what pgcc will do too.
+  set_base_from "$source"
+  tmpdepfile=$base.d
+
+  # For projects that build the same source file twice into different object
+  # files, the pgcc approach of using the *source* file root name can cause
+  # problems in parallel builds.  Use a locking strategy to avoid stomping on
+  # the same $tmpdepfile.
+  lockdir=$base.d-lock
+  trap "
+    echo '$0: caught signal, cleaning up...' >&2
+    rmdir '$lockdir'
+    exit 1
+  " 1 2 13 15
+  numtries=100
+  i=$numtries
+  while test $i -gt 0; do
+    # mkdir is a portable test-and-set.
+    if mkdir "$lockdir" 2>/dev/null; then
+      # This process acquired the lock.
+      "$@" -MD
+      stat=$?
+      # Release the lock.
+      rmdir "$lockdir"
+      break
+    else
+      # If the lock is being held by a different process, wait
+      # until the winning process is done or we timeout.
+      while test -d "$lockdir" && test $i -gt 0; do
+        sleep 1
+        i=`expr $i - 1`
+      done
+    fi
+    i=`expr $i - 1`
+  done
+  trap - 1 2 13 15
+  if test $i -le 0; then
+    echo "$0: failed to acquire lock after $numtries attempts" >&2
+    echo "$0: check lockdir '$lockdir'" >&2
+    exit 1
+  fi
+
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  rm -f "$depfile"
+  # Each line is of the form `foo.o: dependent.h',
+  # or `foo.o: dep1.h dep2.h \', or ` dep3.h dep4.h \'.
+  # Do two passes, one to just change these to
+  # `$object: dependent.h' and one to simply `dependent.h:'.
+  sed "s,^[^:]*:,$object :," < "$tmpdepfile" > "$depfile"
+  # Some versions of the HPUX 10.20 sed can't process this invocation
+  # correctly.  Breaking it into two sed invocations is a workaround.
+  sed 's,^[^:]*: \(.*\)$,\1,;s/^\\$//;/^$/d;/:$/d' < "$tmpdepfile" \
+    | sed -e 's/$/ :/' >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+hp2)
+  # The "hp" stanza above does not work with aCC (C++) and HP's ia64
+  # compilers, which have integrated preprocessors.  The correct option
+  # to use with these is +Maked; it writes dependencies to a file named
+  # 'foo.d', which lands next to the object file, wherever that
+  # happens to be.
+  # Much of this is similar to the tru64 case; see comments there.
+  set_dir_from  "$object"
+  set_base_from "$object"
+  if test "$libtool" = yes; then
+    tmpdepfile1=$dir$base.d
+    tmpdepfile2=$dir.libs/$base.d
+    "$@" -Wc,+Maked
+  else
+    tmpdepfile1=$dir$base.d
+    tmpdepfile2=$dir$base.d
+    "$@" +Maked
+  fi
+  stat=$?
+  if test $stat -ne 0; then
+     rm -f "$tmpdepfile1" "$tmpdepfile2"
+     exit $stat
+  fi
+
+  for tmpdepfile in "$tmpdepfile1" "$tmpdepfile2"
+  do
+    test -f "$tmpdepfile" && break
+  done
+  if test -f "$tmpdepfile"; then
+    sed -e "s,^.*\.[$lower]*:,$object:," "$tmpdepfile" > "$depfile"
+    # Add 'dependent.h:' lines.
+    sed -ne '2,${
+               s/^ *//
+               s/ \\*$//
+               s/$/:/
+               p
+             }' "$tmpdepfile" >> "$depfile"
+  else
+    make_dummy_depfile
+  fi
+  rm -f "$tmpdepfile" "$tmpdepfile2"
+  ;;
+
+tru64)
+  # The Tru64 compiler uses -MD to generate dependencies as a side
+  # effect.  'cc -MD -o foo.o ...' puts the dependencies into 'foo.o.d'.
+  # At least on Alpha/Redhat 6.1, Compaq CCC V6.2-504 seems to put
+  # dependencies in 'foo.d' instead, so we check for that too.
+  # Subdirectories are respected.
+  set_dir_from  "$object"
+  set_base_from "$object"
+
+  if test "$libtool" = yes; then
+    # Libtool generates 2 separate objects for the 2 libraries.  These
+    # two compilations output dependencies in $dir.libs/$base.o.d and
+    # in $dir$base.o.d.  We have to check for both files, because
+    # one of the two compilations can be disabled.  We should prefer
+    # $dir$base.o.d over $dir.libs/$base.o.d because the latter is
+    # automatically cleaned when .libs/ is deleted, while ignoring
+    # the former would cause a distcleancheck panic.
+    tmpdepfile1=$dir$base.o.d          # libtool 1.5
+    tmpdepfile2=$dir.libs/$base.o.d    # Likewise.
+    tmpdepfile3=$dir.libs/$base.d      # Compaq CCC V6.2-504
+    "$@" -Wc,-MD
+  else
+    tmpdepfile1=$dir$base.d
+    tmpdepfile2=$dir$base.d
+    tmpdepfile3=$dir$base.d
+    "$@" -MD
+  fi
+
+  stat=$?
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile1" "$tmpdepfile2" "$tmpdepfile3"
+    exit $stat
+  fi
+
+  for tmpdepfile in "$tmpdepfile1" "$tmpdepfile2" "$tmpdepfile3"
+  do
+    test -f "$tmpdepfile" && break
+  done
+  # Same post-processing that is required for AIX mode.
+  aix_post_process_depfile
+  ;;
+
+msvc7)
+  if test "$libtool" = yes; then
+    showIncludes=-Wc,-showIncludes
+  else
+    showIncludes=-showIncludes
+  fi
+  "$@" $showIncludes > "$tmpdepfile"
+  stat=$?
+  grep -v '^Note: including file: ' "$tmpdepfile"
+  if test $stat -ne 0; then
+    rm -f "$tmpdepfile"
+    exit $stat
+  fi
+  rm -f "$depfile"
+  echo "$object : \\" > "$depfile"
+  # The first sed program below extracts the file names and escapes
+  # backslashes for cygpath.  The second sed program outputs the file
+  # name when reading, but also accumulates all include files in the
+  # hold buffer in order to output them again at the end.  This only
+  # works with sed implementations that can handle large buffers.
+  sed < "$tmpdepfile" -n '
+/^Note: including file:  *\(.*\)/ {
+  s//\1/
+  s/\\/\\\\/g
+  p
+}' | $cygpath_u | sort -u | sed -n '
+s/ /\\ /g
+s/\(.*\)/'"$tab"'\1 \\/p
+s/.\(.*\) \\/\1:/
+H
+$ {
+  s/.*/'"$tab"'/
+  G
+  p
+}' >> "$depfile"
+  echo >> "$depfile" # make sure the fragment doesn't end with a backslash
+  rm -f "$tmpdepfile"
+  ;;
+
+msvc7msys)
+  # This case exists only to let depend.m4 do its work.  It works by
+  # looking at the text of this script.  This case will never be run,
+  # since it is checked for above.
+  exit 1
+  ;;
+
+#nosideeffect)
+  # This comment above is used by automake to tell side-effect
+  # dependency tracking mechanisms from slower ones.
+
+dashmstdout)
+  # Important note: in order to support this mode, a compiler *must*
+  # always write the preprocessed file to stdout, regardless of -o.
+  "$@" || exit $?
+
+  # Remove the call to Libtool.
+  if test "$libtool" = yes; then
+    while test "X$1" != 'X--mode=compile'; do
+      shift
+    done
+    shift
+  fi
+
+  # Remove '-o $object'.
+  IFS=" "
+  for arg
+  do
+    case $arg in
+    -o)
+      shift
+      ;;
+    $object)
+      shift
+      ;;
+    *)
+      set fnord "$@" "$arg"
+      shift # fnord
+      shift # $arg
+      ;;
+    esac
+  done
+
+  test -z "$dashmflag" && dashmflag=-M
+  # Require at least two characters before searching for ':'
+  # in the target name.  This is to cope with DOS-style filenames:
+  # a dependency such as 'c:/foo/bar' could be seen as target 'c' otherwise.
+  "$@" $dashmflag |
+    sed "s|^[$tab ]*[^:$tab ][^:][^:]*:[$tab ]*|$object: |" > "$tmpdepfile"
+  rm -f "$depfile"
+  cat < "$tmpdepfile" > "$depfile"
+  # Some versions of the HPUX 10.20 sed can't process this sed invocation
+  # correctly.  Breaking it into two sed invocations is a workaround.
+  tr ' ' "$nl" < "$tmpdepfile" \
+    | sed -e 's/^\\$//' -e '/^$/d' -e '/:$/d' \
+    | sed -e 's/$/ :/' >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+dashXmstdout)
+  # This case only exists to satisfy depend.m4.  It is never actually
+  # run, as this mode is specially recognized in the preamble.
+  exit 1
+  ;;
+
+makedepend)
+  "$@" || exit $?
+  # Remove any Libtool call
+  if test "$libtool" = yes; then
+    while test "X$1" != 'X--mode=compile'; do
+      shift
+    done
+    shift
+  fi
+  # X makedepend
+  shift
+  cleared=no eat=no
+  for arg
+  do
+    case $cleared in
+    no)
+      set ""; shift
+      cleared=yes ;;
+    esac
+    if test $eat = yes; then
+      eat=no
+      continue
+    fi
+    case "$arg" in
+    -D*|-I*)
+      set fnord "$@" "$arg"; shift ;;
+    # Strip any option that makedepend may not understand.  Remove
+    # the object too, otherwise makedepend will parse it as a source file.
+    -arch)
+      eat=yes ;;
+    -*|$object)
+      ;;
+    *)
+      set fnord "$@" "$arg"; shift ;;
+    esac
+  done
+  obj_suffix=`echo "$object" | sed 's/^.*\././'`
+  touch "$tmpdepfile"
+  ${MAKEDEPEND-makedepend} -o"$obj_suffix" -f"$tmpdepfile" "$@"
+  rm -f "$depfile"
+  # makedepend may prepend the VPATH from the source file name to the object.
+  # No need to regex-escape $object, excess matching of '.' is harmless.
+  sed "s|^.*\($object *:\)|\1|" "$tmpdepfile" > "$depfile"
+  # Some versions of the HPUX 10.20 sed can't process the last invocation
+  # correctly.  Breaking it into two sed invocations is a workaround.
+  sed '1,2d' "$tmpdepfile" \
+    | tr ' ' "$nl" \
+    | sed -e 's/^\\$//' -e '/^$/d' -e '/:$/d' \
+    | sed -e 's/$/ :/' >> "$depfile"
+  rm -f "$tmpdepfile" "$tmpdepfile".bak
+  ;;
+
+cpp)
+  # Important note: in order to support this mode, a compiler *must*
+  # always write the preprocessed file to stdout.
+  "$@" || exit $?
+
+  # Remove the call to Libtool.
+  if test "$libtool" = yes; then
+    while test "X$1" != 'X--mode=compile'; do
+      shift
+    done
+    shift
+  fi
+
+  # Remove '-o $object'.
+  IFS=" "
+  for arg
+  do
+    case $arg in
+    -o)
+      shift
+      ;;
+    $object)
+      shift
+      ;;
+    *)
+      set fnord "$@" "$arg"
+      shift # fnord
+      shift # $arg
+      ;;
+    esac
+  done
+
+  "$@" -E \
+    | sed -n -e '/^# [0-9][0-9]* "\([^"]*\)".*/ s:: \1 \\:p' \
+             -e '/^#line [0-9][0-9]* "\([^"]*\)".*/ s:: \1 \\:p' \
+    | sed '$ s: \\$::' > "$tmpdepfile"
+  rm -f "$depfile"
+  echo "$object : \\" > "$depfile"
+  cat < "$tmpdepfile" >> "$depfile"
+  sed < "$tmpdepfile" '/^$/d;s/^ //;s/ \\$//;s/$/ :/' >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+msvisualcpp)
+  # Important note: in order to support this mode, a compiler *must*
+  # always write the preprocessed file to stdout.
+  "$@" || exit $?
+
+  # Remove the call to Libtool.
+  if test "$libtool" = yes; then
+    while test "X$1" != 'X--mode=compile'; do
+      shift
+    done
+    shift
+  fi
+
+  IFS=" "
+  for arg
+  do
+    case "$arg" in
+    -o)
+      shift
+      ;;
+    $object)
+      shift
+      ;;
+    "-Gm"|"/Gm"|"-Gi"|"/Gi"|"-ZI"|"/ZI")
+        set fnord "$@"
+        shift
+        shift
+        ;;
+    *)
+        set fnord "$@" "$arg"
+        shift
+        shift
+        ;;
+    esac
+  done
+  "$@" -E 2>/dev/null |
+  sed -n '/^#line [0-9][0-9]* "\([^"]*\)"/ s::\1:p' | $cygpath_u | sort -u > "$tmpdepfile"
+  rm -f "$depfile"
+  echo "$object : \\" > "$depfile"
+  sed < "$tmpdepfile" -n -e 's% %\\ %g' -e '/^\(.*\)$/ s::'"$tab"'\1 \\:p' >> "$depfile"
+  echo "$tab" >> "$depfile"
+  sed < "$tmpdepfile" -n -e 's% %\\ %g' -e '/^\(.*\)$/ s::\1\::p' >> "$depfile"
+  rm -f "$tmpdepfile"
+  ;;
+
+msvcmsys)
+  # This case exists only to let depend.m4 do its work.  It works by
+  # looking at the text of this script.  This case will never be run,
+  # since it is checked for above.
+  exit 1
+  ;;
+
+none)
+  exec "$@"
+  ;;
+
+*)
+  echo "Unknown depmode $depmode" 1>&2
+  exit 1
+  ;;
+esac
+
+exit 0
+
+# Local Variables:
+# mode: shell-script
+# sh-indentation: 2
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "scriptversion="
+# time-stamp-format: "%:y-%02m-%02d.%02H"
+# time-stamp-time-zone: "UTC"
+# time-stamp-end: "; # UTC"
+# End:
diff --git a/auto/install-sh b/auto/install-sh
new file mode 100755
index 0000000..377bb86
--- /dev/null
+++ b/auto/install-sh
@@ -0,0 +1,527 @@
+#!/bin/sh
+# install - install a program, script, or datafile
+
+scriptversion=2011-11-20.07; # UTC
+
+# This originates from X11R5 (mit/util/scripts/install.sh), which was
+# later released in X11R6 (xc/config/util/install.sh) with the
+# following copyright and license.
+#
+# Copyright (C) 1994 X Consortium
+#
+# Permission is hereby granted, free of charge, to any person obtaining a copy
+# of this software and associated documentation files (the "Software"), to
+# deal in the Software without restriction, including without limitation the
+# rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
+# sell copies of the Software, and to permit persons to whom the Software is
+# furnished to do so, subject to the following conditions:
+#
+# The above copyright notice and this permission notice shall be included in
+# all copies or substantial portions of the Software.
+#
+# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.  IN NO EVENT SHALL THE
+# X CONSORTIUM BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
+# AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNEC-
+# TION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+#
+# Except as contained in this notice, the name of the X Consortium shall not
+# be used in advertising or otherwise to promote the sale, use or other deal-
+# ings in this Software without prior written authorization from the X Consor-
+# tium.
+#
+#
+# FSF changes to this file are in the public domain.
+#
+# Calling this script install-sh is preferred over install.sh, to prevent
+# 'make' implicit rules from creating a file called install from it
+# when there is no Makefile.
+#
+# This script is compatible with the BSD install script, but was written
+# from scratch.
+
+nl='
+'
+IFS=" ""	$nl"
+
+# set DOITPROG to echo to test this script
+
+# Don't use :- since 4.3BSD and earlier shells don't like it.
+doit=${DOITPROG-}
+if test -z "$doit"; then
+  doit_exec=exec
+else
+  doit_exec=$doit
+fi
+
+# Put in absolute file names if you don't have them in your path;
+# or use environment vars.
+
+chgrpprog=${CHGRPPROG-chgrp}
+chmodprog=${CHMODPROG-chmod}
+chownprog=${CHOWNPROG-chown}
+cmpprog=${CMPPROG-cmp}
+cpprog=${CPPROG-cp}
+mkdirprog=${MKDIRPROG-mkdir}
+mvprog=${MVPROG-mv}
+rmprog=${RMPROG-rm}
+stripprog=${STRIPPROG-strip}
+
+posix_glob='?'
+initialize_posix_glob='
+  test "$posix_glob" != "?" || {
+    if (set -f) 2>/dev/null; then
+      posix_glob=
+    else
+      posix_glob=:
+    fi
+  }
+'
+
+posix_mkdir=
+
+# Desired mode of installed file.
+mode=0755
+
+chgrpcmd=
+chmodcmd=$chmodprog
+chowncmd=
+mvcmd=$mvprog
+rmcmd="$rmprog -f"
+stripcmd=
+
+src=
+dst=
+dir_arg=
+dst_arg=
+
+copy_on_change=false
+no_target_directory=
+
+usage="\
+Usage: $0 [OPTION]... [-T] SRCFILE DSTFILE
+   or: $0 [OPTION]... SRCFILES... DIRECTORY
+   or: $0 [OPTION]... -t DIRECTORY SRCFILES...
+   or: $0 [OPTION]... -d DIRECTORIES...
+
+In the 1st form, copy SRCFILE to DSTFILE.
+In the 2nd and 3rd, copy all SRCFILES to DIRECTORY.
+In the 4th, create DIRECTORIES.
+
+Options:
+     --help     display this help and exit.
+     --version  display version info and exit.
+
+  -c            (ignored)
+  -C            install only if different (preserve the last data modification time)
+  -d            create directories instead of installing files.
+  -g GROUP      $chgrpprog installed files to GROUP.
+  -m MODE       $chmodprog installed files to MODE.
+  -o USER       $chownprog installed files to USER.
+  -s            $stripprog installed files.
+  -t DIRECTORY  install into DIRECTORY.
+  -T            report an error if DSTFILE is a directory.
+
+Environment variables override the default commands:
+  CHGRPPROG CHMODPROG CHOWNPROG CMPPROG CPPROG MKDIRPROG MVPROG
+  RMPROG STRIPPROG
+"
+
+while test $# -ne 0; do
+  case $1 in
+    -c) ;;
+
+    -C) copy_on_change=true;;
+
+    -d) dir_arg=true;;
+
+    -g) chgrpcmd="$chgrpprog $2"
+	shift;;
+
+    --help) echo "$usage"; exit $?;;
+
+    -m) mode=$2
+	case $mode in
+	  *' '* | *'	'* | *'
+'*	  | *'*'* | *'?'* | *'['*)
+	    echo "$0: invalid mode: $mode" >&2
+	    exit 1;;
+	esac
+	shift;;
+
+    -o) chowncmd="$chownprog $2"
+	shift;;
+
+    -s) stripcmd=$stripprog;;
+
+    -t) dst_arg=$2
+	# Protect names problematic for 'test' and other utilities.
+	case $dst_arg in
+	  -* | [=\(\)!]) dst_arg=./$dst_arg;;
+	esac
+	shift;;
+
+    -T) no_target_directory=true;;
+
+    --version) echo "$0 $scriptversion"; exit $?;;
+
+    --)	shift
+	break;;
+
+    -*)	echo "$0: invalid option: $1" >&2
+	exit 1;;
+
+    *)  break;;
+  esac
+  shift
+done
+
+if test $# -ne 0 && test -z "$dir_arg$dst_arg"; then
+  # When -d is used, all remaining arguments are directories to create.
+  # When -t is used, the destination is already specified.
+  # Otherwise, the last argument is the destination.  Remove it from $@.
+  for arg
+  do
+    if test -n "$dst_arg"; then
+      # $@ is not empty: it contains at least $arg.
+      set fnord "$@" "$dst_arg"
+      shift # fnord
+    fi
+    shift # arg
+    dst_arg=$arg
+    # Protect names problematic for 'test' and other utilities.
+    case $dst_arg in
+      -* | [=\(\)!]) dst_arg=./$dst_arg;;
+    esac
+  done
+fi
+
+if test $# -eq 0; then
+  if test -z "$dir_arg"; then
+    echo "$0: no input file specified." >&2
+    exit 1
+  fi
+  # It's OK to call 'install-sh -d' without argument.
+  # This can happen when creating conditional directories.
+  exit 0
+fi
+
+if test -z "$dir_arg"; then
+  do_exit='(exit $ret); exit $ret'
+  trap "ret=129; $do_exit" 1
+  trap "ret=130; $do_exit" 2
+  trap "ret=141; $do_exit" 13
+  trap "ret=143; $do_exit" 15
+
+  # Set umask so as not to create temps with too-generous modes.
+  # However, 'strip' requires both read and write access to temps.
+  case $mode in
+    # Optimize common cases.
+    *644) cp_umask=133;;
+    *755) cp_umask=22;;
+
+    *[0-7])
+      if test -z "$stripcmd"; then
+	u_plus_rw=
+      else
+	u_plus_rw='% 200'
+      fi
+      cp_umask=`expr '(' 777 - $mode % 1000 ')' $u_plus_rw`;;
+    *)
+      if test -z "$stripcmd"; then
+	u_plus_rw=
+      else
+	u_plus_rw=,u+rw
+      fi
+      cp_umask=$mode$u_plus_rw;;
+  esac
+fi
+
+for src
+do
+  # Protect names problematic for 'test' and other utilities.
+  case $src in
+    -* | [=\(\)!]) src=./$src;;
+  esac
+
+  if test -n "$dir_arg"; then
+    dst=$src
+    dstdir=$dst
+    test -d "$dstdir"
+    dstdir_status=$?
+  else
+
+    # Waiting for this to be detected by the "$cpprog $src $dsttmp" command
+    # might cause directories to be created, which would be especially bad
+    # if $src (and thus $dsttmp) contains '*'.
+    if test ! -f "$src" && test ! -d "$src"; then
+      echo "$0: $src does not exist." >&2
+      exit 1
+    fi
+
+    if test -z "$dst_arg"; then
+      echo "$0: no destination specified." >&2
+      exit 1
+    fi
+    dst=$dst_arg
+
+    # If destination is a directory, append the input filename; won't work
+    # if double slashes aren't ignored.
+    if test -d "$dst"; then
+      if test -n "$no_target_directory"; then
+	echo "$0: $dst_arg: Is a directory" >&2
+	exit 1
+      fi
+      dstdir=$dst
+      dst=$dstdir/`basename "$src"`
+      dstdir_status=0
+    else
+      # Prefer dirname, but fall back on a substitute if dirname fails.
+      dstdir=`
+	(dirname "$dst") 2>/dev/null ||
+	expr X"$dst" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	     X"$dst" : 'X\(//\)[^/]' \| \
+	     X"$dst" : 'X\(//\)$' \| \
+	     X"$dst" : 'X\(/\)' \| . 2>/dev/null ||
+	echo X"$dst" |
+	    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+		   s//\1/
+		   q
+		 }
+		 /^X\(\/\/\)[^/].*/{
+		   s//\1/
+		   q
+		 }
+		 /^X\(\/\/\)$/{
+		   s//\1/
+		   q
+		 }
+		 /^X\(\/\).*/{
+		   s//\1/
+		   q
+		 }
+		 s/.*/./; q'
+      `
+
+      test -d "$dstdir"
+      dstdir_status=$?
+    fi
+  fi
+
+  obsolete_mkdir_used=false
+
+  if test $dstdir_status != 0; then
+    case $posix_mkdir in
+      '')
+	# Create intermediate dirs using mode 755 as modified by the umask.
+	# This is like FreeBSD 'install' as of 1997-10-28.
+	umask=`umask`
+	case $stripcmd.$umask in
+	  # Optimize common cases.
+	  *[2367][2367]) mkdir_umask=$umask;;
+	  .*0[02][02] | .[02][02] | .[02]) mkdir_umask=22;;
+
+	  *[0-7])
+	    mkdir_umask=`expr $umask + 22 \
+	      - $umask % 100 % 40 + $umask % 20 \
+	      - $umask % 10 % 4 + $umask % 2
+	    `;;
+	  *) mkdir_umask=$umask,go-w;;
+	esac
+
+	# With -d, create the new directory with the user-specified mode.
+	# Otherwise, rely on $mkdir_umask.
+	if test -n "$dir_arg"; then
+	  mkdir_mode=-m$mode
+	else
+	  mkdir_mode=
+	fi
+
+	posix_mkdir=false
+	case $umask in
+	  *[123567][0-7][0-7])
+	    # POSIX mkdir -p sets u+wx bits regardless of umask, which
+	    # is incompatible with FreeBSD 'install' when (umask & 300) != 0.
+	    ;;
+	  *)
+	    tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$
+	    trap 'ret=$?; rmdir "$tmpdir/d" "$tmpdir" 2>/dev/null; exit $ret' 0
+
+	    if (umask $mkdir_umask &&
+		exec $mkdirprog $mkdir_mode -p -- "$tmpdir/d") >/dev/null 2>&1
+	    then
+	      if test -z "$dir_arg" || {
+		   # Check for POSIX incompatibilities with -m.
+		   # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or
+		   # other-writable bit of parent directory when it shouldn't.
+		   # FreeBSD 6.1 mkdir -m -p sets mode of existing directory.
+		   ls_ld_tmpdir=`ls -ld "$tmpdir"`
+		   case $ls_ld_tmpdir in
+		     d????-?r-*) different_mode=700;;
+		     d????-?--*) different_mode=755;;
+		     *) false;;
+		   esac &&
+		   $mkdirprog -m$different_mode -p -- "$tmpdir" && {
+		     ls_ld_tmpdir_1=`ls -ld "$tmpdir"`
+		     test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1"
+		   }
+		 }
+	      then posix_mkdir=:
+	      fi
+	      rmdir "$tmpdir/d" "$tmpdir"
+	    else
+	      # Remove any dirs left behind by ancient mkdir implementations.
+	      rmdir ./$mkdir_mode ./-p ./-- 2>/dev/null
+	    fi
+	    trap '' 0;;
+	esac;;
+    esac
+
+    if
+      $posix_mkdir && (
+	umask $mkdir_umask &&
+	$doit_exec $mkdirprog $mkdir_mode -p -- "$dstdir"
+      )
+    then :
+    else
+
+      # The umask is ridiculous, or mkdir does not conform to POSIX,
+      # or it failed possibly due to a race condition.  Create the
+      # directory the slow way, step by step, checking for races as we go.
+
+      case $dstdir in
+	/*) prefix='/';;
+	[-=\(\)!]*) prefix='./';;
+	*)  prefix='';;
+      esac
+
+      eval "$initialize_posix_glob"
+
+      oIFS=$IFS
+      IFS=/
+      $posix_glob set -f
+      set fnord $dstdir
+      shift
+      $posix_glob set +f
+      IFS=$oIFS
+
+      prefixes=
+
+      for d
+      do
+	test X"$d" = X && continue
+
+	prefix=$prefix$d
+	if test -d "$prefix"; then
+	  prefixes=
+	else
+	  if $posix_mkdir; then
+	    (umask=$mkdir_umask &&
+	     $doit_exec $mkdirprog $mkdir_mode -p -- "$dstdir") && break
+	    # Don't fail if two instances are running concurrently.
+	    test -d "$prefix" || exit 1
+	  else
+	    case $prefix in
+	      *\'*) qprefix=`echo "$prefix" | sed "s/'/'\\\\\\\\''/g"`;;
+	      *) qprefix=$prefix;;
+	    esac
+	    prefixes="$prefixes '$qprefix'"
+	  fi
+	fi
+	prefix=$prefix/
+      done
+
+      if test -n "$prefixes"; then
+	# Don't fail if two instances are running concurrently.
+	(umask $mkdir_umask &&
+	 eval "\$doit_exec \$mkdirprog $prefixes") ||
+	  test -d "$dstdir" || exit 1
+	obsolete_mkdir_used=true
+      fi
+    fi
+  fi
+
+  if test -n "$dir_arg"; then
+    { test -z "$chowncmd" || $doit $chowncmd "$dst"; } &&
+    { test -z "$chgrpcmd" || $doit $chgrpcmd "$dst"; } &&
+    { test "$obsolete_mkdir_used$chowncmd$chgrpcmd" = false ||
+      test -z "$chmodcmd" || $doit $chmodcmd $mode "$dst"; } || exit 1
+  else
+
+    # Make a couple of temp file names in the proper directory.
+    dsttmp=$dstdir/_inst.$$_
+    rmtmp=$dstdir/_rm.$$_
+
+    # Trap to clean up those temp files at exit.
+    trap 'ret=$?; rm -f "$dsttmp" "$rmtmp" && exit $ret' 0
+
+    # Copy the file name to the temp name.
+    (umask $cp_umask && $doit_exec $cpprog "$src" "$dsttmp") &&
+
+    # and set any options; do chmod last to preserve setuid bits.
+    #
+    # If any of these fail, we abort the whole thing.  If we want to
+    # ignore errors from any of these, just make sure not to ignore
+    # errors from the above "$doit $cpprog $src $dsttmp" command.
+    #
+    { test -z "$chowncmd" || $doit $chowncmd "$dsttmp"; } &&
+    { test -z "$chgrpcmd" || $doit $chgrpcmd "$dsttmp"; } &&
+    { test -z "$stripcmd" || $doit $stripcmd "$dsttmp"; } &&
+    { test -z "$chmodcmd" || $doit $chmodcmd $mode "$dsttmp"; } &&
+
+    # If -C, don't bother to copy if it wouldn't change the file.
+    if $copy_on_change &&
+       old=`LC_ALL=C ls -dlL "$dst"	2>/dev/null` &&
+       new=`LC_ALL=C ls -dlL "$dsttmp"	2>/dev/null` &&
+
+       eval "$initialize_posix_glob" &&
+       $posix_glob set -f &&
+       set X $old && old=:$2:$4:$5:$6 &&
+       set X $new && new=:$2:$4:$5:$6 &&
+       $posix_glob set +f &&
+
+       test "$old" = "$new" &&
+       $cmpprog "$dst" "$dsttmp" >/dev/null 2>&1
+    then
+      rm -f "$dsttmp"
+    else
+      # Rename the file to the real destination.
+      $doit $mvcmd -f "$dsttmp" "$dst" 2>/dev/null ||
+
+      # The rename failed, perhaps because mv can't rename something else
+      # to itself, or perhaps because mv is so ancient that it does not
+      # support -f.
+      {
+	# Now remove or move aside any old file at destination location.
+	# We try this two ways since rm can't unlink itself on some
+	# systems and the destination file might be busy for other
+	# reasons.  In this case, the final cleanup might fail but the new
+	# file should still install successfully.
+	{
+	  test ! -f "$dst" ||
+	  $doit $rmcmd -f "$dst" 2>/dev/null ||
+	  { $doit $mvcmd -f "$dst" "$rmtmp" 2>/dev/null &&
+	    { $doit $rmcmd -f "$rmtmp" 2>/dev/null; :; }
+	  } ||
+	  { echo "$0: cannot unlink or rename $dst" >&2
+	    (exit 1); exit 1
+	  }
+	} &&
+
+	# Now rename the file to the real destination.
+	$doit $mvcmd "$dsttmp" "$dst"
+      }
+    fi || exit 1
+
+    trap '' 0
+  fi
+done
+
+# Local variables:
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "scriptversion="
+# time-stamp-format: "%:y-%02m-%02d.%02H"
+# time-stamp-time-zone: "UTC"
+# time-stamp-end: "; # UTC"
+# End:
diff --git a/auto/ltmain.sh b/auto/ltmain.sh
new file mode 100644
index 0000000..bffda54
--- /dev/null
+++ b/auto/ltmain.sh
@@ -0,0 +1,9661 @@
+
+# libtool (GNU libtool) 2.4.2
+# Written by Gordon Matzigkeit <gord@gnu.ai.mit.edu>, 1996
+
+# Copyright (C) 1996, 1997, 1998, 1999, 2000, 2001, 2003, 2004, 2005, 2006,
+# 2007, 2008, 2009, 2010, 2011 Free Software Foundation, Inc.
+# This is free software; see the source for copying conditions.  There is NO
+# warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+
+# GNU Libtool is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2 of the License, or
+# (at your option) any later version.
+#
+# As a special exception to the GNU General Public License,
+# if you distribute this file as part of a program or library that
+# is built using GNU Libtool, you may include this file under the
+# same distribution terms that you use for the rest of that program.
+#
+# GNU Libtool is distributed in the hope that it will be useful, but
+# WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
+# General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with GNU Libtool; see the file COPYING.  If not, a copy
+# can be downloaded from http://www.gnu.org/licenses/gpl.html,
+# or obtained by writing to the Free Software Foundation, Inc.,
+# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
+
+# Usage: $progname [OPTION]... [MODE-ARG]...
+#
+# Provide generalized library-building support services.
+#
+#       --config             show all configuration variables
+#       --debug              enable verbose shell tracing
+#   -n, --dry-run            display commands without modifying any files
+#       --features           display basic configuration information and exit
+#       --mode=MODE          use operation mode MODE
+#       --preserve-dup-deps  don't remove duplicate dependency libraries
+#       --quiet, --silent    don't print informational messages
+#       --no-quiet, --no-silent
+#                            print informational messages (default)
+#       --no-warn            don't display warning messages
+#       --tag=TAG            use configuration variables from tag TAG
+#   -v, --verbose            print more informational messages than default
+#       --no-verbose         don't print the extra informational messages
+#       --version            print version information
+#   -h, --help, --help-all   print short, long, or detailed help message
+#
+# MODE must be one of the following:
+#
+#         clean              remove files from the build directory
+#         compile            compile a source file into a libtool object
+#         execute            automatically set library path, then run a program
+#         finish             complete the installation of libtool libraries
+#         install            install libraries or executables
+#         link               create a library or an executable
+#         uninstall          remove libraries from an installed directory
+#
+# MODE-ARGS vary depending on the MODE.  When passed as first option,
+# `--mode=MODE' may be abbreviated as `MODE' or a unique abbreviation of that.
+# Try `$progname --help --mode=MODE' for a more detailed description of MODE.
+#
+# When reporting a bug, please describe a test case to reproduce it and
+# include the following information:
+#
+#         host-triplet:	$host
+#         shell:		$SHELL
+#         compiler:		$LTCC
+#         compiler flags:		$LTCFLAGS
+#         linker:		$LD (gnu? $with_gnu_ld)
+#         $progname:	(GNU libtool) 2.4.2 Debian-2.4.2-1.11
+#         automake:	$automake_version
+#         autoconf:	$autoconf_version
+#
+# Report bugs to <bug-libtool@gnu.org>.
+# GNU libtool home page: <http://www.gnu.org/software/libtool/>.
+# General help using GNU software: <http://www.gnu.org/gethelp/>.
+
+PROGRAM=libtool
+PACKAGE=libtool
+VERSION="2.4.2 Debian-2.4.2-1.11"
+TIMESTAMP=""
+package_revision=1.3337
+
+# Be Bourne compatible
+if test -n "${ZSH_VERSION+set}" && (emulate sh) >/dev/null 2>&1; then
+  emulate sh
+  NULLCMD=:
+  # Zsh 3.x and 4.x performs word splitting on ${1+"$@"}, which
+  # is contrary to our usage.  Disable this feature.
+  alias -g '${1+"$@"}'='"$@"'
+  setopt NO_GLOB_SUBST
+else
+  case `(set -o) 2>/dev/null` in *posix*) set -o posix;; esac
+fi
+BIN_SH=xpg4; export BIN_SH # for Tru64
+DUALCASE=1; export DUALCASE # for MKS sh
+
+# A function that is used when there is no print builtin or printf.
+func_fallback_echo ()
+{
+  eval 'cat <<_LTECHO_EOF
+$1
+_LTECHO_EOF'
+}
+
+# NLS nuisances: We save the old values to restore during execute mode.
+lt_user_locale=
+lt_safe_locale=
+for lt_var in LANG LANGUAGE LC_ALL LC_CTYPE LC_COLLATE LC_MESSAGES
+do
+  eval "if test \"\${$lt_var+set}\" = set; then
+          save_$lt_var=\$$lt_var
+          $lt_var=C
+	  export $lt_var
+	  lt_user_locale=\"$lt_var=\\\$save_\$lt_var; \$lt_user_locale\"
+	  lt_safe_locale=\"$lt_var=C; \$lt_safe_locale\"
+	fi"
+done
+LC_ALL=C
+LANGUAGE=C
+export LANGUAGE LC_ALL
+
+$lt_unset CDPATH
+
+
+# Work around backward compatibility issue on IRIX 6.5. On IRIX 6.4+, sh
+# is ksh but when the shell is invoked as "sh" and the current value of
+# the _XPG environment variable is not equal to 1 (one), the special
+# positional parameter $0, within a function call, is the name of the
+# function.
+progpath="$0"
+
+
+
+: ${CP="cp -f"}
+test "${ECHO+set}" = set || ECHO=${as_echo-'printf %s\n'}
+: ${MAKE="make"}
+: ${MKDIR="mkdir"}
+: ${MV="mv -f"}
+: ${RM="rm -f"}
+: ${SHELL="${CONFIG_SHELL-/bin/sh}"}
+: ${Xsed="$SED -e 1s/^X//"}
+
+# Global variables:
+EXIT_SUCCESS=0
+EXIT_FAILURE=1
+EXIT_MISMATCH=63  # $? = 63 is used to indicate version mismatch to missing.
+EXIT_SKIP=77	  # $? = 77 is used to indicate a skipped test to automake.
+
+exit_status=$EXIT_SUCCESS
+
+# Make sure IFS has a sensible default
+lt_nl='
+'
+IFS=" 	$lt_nl"
+
+dirname="s,/[^/]*$,,"
+basename="s,^.*/,,"
+
+# func_dirname file append nondir_replacement
+# Compute the dirname of FILE.  If nonempty, add APPEND to the result,
+# otherwise set result to NONDIR_REPLACEMENT.
+func_dirname ()
+{
+    func_dirname_result=`$ECHO "${1}" | $SED "$dirname"`
+    if test "X$func_dirname_result" = "X${1}"; then
+      func_dirname_result="${3}"
+    else
+      func_dirname_result="$func_dirname_result${2}"
+    fi
+} # func_dirname may be replaced by extended shell implementation
+
+
+# func_basename file
+func_basename ()
+{
+    func_basename_result=`$ECHO "${1}" | $SED "$basename"`
+} # func_basename may be replaced by extended shell implementation
+
+
+# func_dirname_and_basename file append nondir_replacement
+# perform func_basename and func_dirname in a single function
+# call:
+#   dirname:  Compute the dirname of FILE.  If nonempty,
+#             add APPEND to the result, otherwise set result
+#             to NONDIR_REPLACEMENT.
+#             value returned in "$func_dirname_result"
+#   basename: Compute filename of FILE.
+#             value retuned in "$func_basename_result"
+# Implementation must be kept synchronized with func_dirname
+# and func_basename. For efficiency, we do not delegate to
+# those functions but instead duplicate the functionality here.
+func_dirname_and_basename ()
+{
+    # Extract subdirectory from the argument.
+    func_dirname_result=`$ECHO "${1}" | $SED -e "$dirname"`
+    if test "X$func_dirname_result" = "X${1}"; then
+      func_dirname_result="${3}"
+    else
+      func_dirname_result="$func_dirname_result${2}"
+    fi
+    func_basename_result=`$ECHO "${1}" | $SED -e "$basename"`
+} # func_dirname_and_basename may be replaced by extended shell implementation
+
+
+# func_stripname prefix suffix name
+# strip PREFIX and SUFFIX off of NAME.
+# PREFIX and SUFFIX must not contain globbing or regex special
+# characters, hashes, percent signs, but SUFFIX may contain a leading
+# dot (in which case that matches only a dot).
+# func_strip_suffix prefix name
+func_stripname ()
+{
+    case ${2} in
+      .*) func_stripname_result=`$ECHO "${3}" | $SED "s%^${1}%%; s%\\\\${2}\$%%"`;;
+      *)  func_stripname_result=`$ECHO "${3}" | $SED "s%^${1}%%; s%${2}\$%%"`;;
+    esac
+} # func_stripname may be replaced by extended shell implementation
+
+
+# These SED scripts presuppose an absolute path with a trailing slash.
+pathcar='s,^/\([^/]*\).*$,\1,'
+pathcdr='s,^/[^/]*,,'
+removedotparts=':dotsl
+		s@/\./@/@g
+		t dotsl
+		s,/\.$,/,'
+collapseslashes='s@/\{1,\}@/@g'
+finalslash='s,/*$,/,'
+
+# func_normal_abspath PATH
+# Remove doubled-up and trailing slashes, "." path components,
+# and cancel out any ".." path components in PATH after making
+# it an absolute path.
+#             value returned in "$func_normal_abspath_result"
+func_normal_abspath ()
+{
+  # Start from root dir and reassemble the path.
+  func_normal_abspath_result=
+  func_normal_abspath_tpath=$1
+  func_normal_abspath_altnamespace=
+  case $func_normal_abspath_tpath in
+    "")
+      # Empty path, that just means $cwd.
+      func_stripname '' '/' "`pwd`"
+      func_normal_abspath_result=$func_stripname_result
+      return
+    ;;
+    # The next three entries are used to spot a run of precisely
+    # two leading slashes without using negated character classes;
+    # we take advantage of case's first-match behaviour.
+    ///*)
+      # Unusual form of absolute path, do nothing.
+    ;;
+    //*)
+      # Not necessarily an ordinary path; POSIX reserves leading '//'
+      # and for example Cygwin uses it to access remote file shares
+      # over CIFS/SMB, so we conserve a leading double slash if found.
+      func_normal_abspath_altnamespace=/
+    ;;
+    /*)
+      # Absolute path, do nothing.
+    ;;
+    *)
+      # Relative path, prepend $cwd.
+      func_normal_abspath_tpath=`pwd`/$func_normal_abspath_tpath
+    ;;
+  esac
+  # Cancel out all the simple stuff to save iterations.  We also want
+  # the path to end with a slash for ease of parsing, so make sure
+  # there is one (and only one) here.
+  func_normal_abspath_tpath=`$ECHO "$func_normal_abspath_tpath" | $SED \
+        -e "$removedotparts" -e "$collapseslashes" -e "$finalslash"`
+  while :; do
+    # Processed it all yet?
+    if test "$func_normal_abspath_tpath" = / ; then
+      # If we ascended to the root using ".." the result may be empty now.
+      if test -z "$func_normal_abspath_result" ; then
+        func_normal_abspath_result=/
+      fi
+      break
+    fi
+    func_normal_abspath_tcomponent=`$ECHO "$func_normal_abspath_tpath" | $SED \
+        -e "$pathcar"`
+    func_normal_abspath_tpath=`$ECHO "$func_normal_abspath_tpath" | $SED \
+        -e "$pathcdr"`
+    # Figure out what to do with it
+    case $func_normal_abspath_tcomponent in
+      "")
+        # Trailing empty path component, ignore it.
+      ;;
+      ..)
+        # Parent dir; strip last assembled component from result.
+        func_dirname "$func_normal_abspath_result"
+        func_normal_abspath_result=$func_dirname_result
+      ;;
+      *)
+        # Actual path component, append it.
+        func_normal_abspath_result=$func_normal_abspath_result/$func_normal_abspath_tcomponent
+      ;;
+    esac
+  done
+  # Restore leading double-slash if one was found on entry.
+  func_normal_abspath_result=$func_normal_abspath_altnamespace$func_normal_abspath_result
+}
+
+# func_relative_path SRCDIR DSTDIR
+# generates a relative path from SRCDIR to DSTDIR, with a trailing
+# slash if non-empty, suitable for immediately appending a filename
+# without needing to append a separator.
+#             value returned in "$func_relative_path_result"
+func_relative_path ()
+{
+  func_relative_path_result=
+  func_normal_abspath "$1"
+  func_relative_path_tlibdir=$func_normal_abspath_result
+  func_normal_abspath "$2"
+  func_relative_path_tbindir=$func_normal_abspath_result
+
+  # Ascend the tree starting from libdir
+  while :; do
+    # check if we have found a prefix of bindir
+    case $func_relative_path_tbindir in
+      $func_relative_path_tlibdir)
+        # found an exact match
+        func_relative_path_tcancelled=
+        break
+        ;;
+      $func_relative_path_tlibdir*)
+        # found a matching prefix
+        func_stripname "$func_relative_path_tlibdir" '' "$func_relative_path_tbindir"
+        func_relative_path_tcancelled=$func_stripname_result
+        if test -z "$func_relative_path_result"; then
+          func_relative_path_result=.
+        fi
+        break
+        ;;
+      *)
+        func_dirname $func_relative_path_tlibdir
+        func_relative_path_tlibdir=${func_dirname_result}
+        if test "x$func_relative_path_tlibdir" = x ; then
+          # Have to descend all the way to the root!
+          func_relative_path_result=../$func_relative_path_result
+          func_relative_path_tcancelled=$func_relative_path_tbindir
+          break
+        fi
+        func_relative_path_result=../$func_relative_path_result
+        ;;
+    esac
+  done
+
+  # Now calculate path; take care to avoid doubling-up slashes.
+  func_stripname '' '/' "$func_relative_path_result"
+  func_relative_path_result=$func_stripname_result
+  func_stripname '/' '/' "$func_relative_path_tcancelled"
+  if test "x$func_stripname_result" != x ; then
+    func_relative_path_result=${func_relative_path_result}/${func_stripname_result}
+  fi
+
+  # Normalisation. If bindir is libdir, return empty string,
+  # else relative path ending with a slash; either way, target
+  # file name can be directly appended.
+  if test ! -z "$func_relative_path_result"; then
+    func_stripname './' '' "$func_relative_path_result/"
+    func_relative_path_result=$func_stripname_result
+  fi
+}
+
+# The name of this program:
+func_dirname_and_basename "$progpath"
+progname=$func_basename_result
+
+# Make sure we have an absolute path for reexecution:
+case $progpath in
+  [\\/]*|[A-Za-z]:\\*) ;;
+  *[\\/]*)
+     progdir=$func_dirname_result
+     progdir=`cd "$progdir" && pwd`
+     progpath="$progdir/$progname"
+     ;;
+  *)
+     save_IFS="$IFS"
+     IFS=${PATH_SEPARATOR-:}
+     for progdir in $PATH; do
+       IFS="$save_IFS"
+       test -x "$progdir/$progname" && break
+     done
+     IFS="$save_IFS"
+     test -n "$progdir" || progdir=`pwd`
+     progpath="$progdir/$progname"
+     ;;
+esac
+
+# Sed substitution that helps us do robust quoting.  It backslashifies
+# metacharacters that are still active within double-quoted strings.
+Xsed="${SED}"' -e 1s/^X//'
+sed_quote_subst='s/\([`"$\\]\)/\\\1/g'
+
+# Same as above, but do not quote variable references.
+double_quote_subst='s/\(["`\\]\)/\\\1/g'
+
+# Sed substitution that turns a string into a regex matching for the
+# string literally.
+sed_make_literal_regex='s,[].[^$\\*\/],\\&,g'
+
+# Sed substitution that converts a w32 file name or path
+# which contains forward slashes, into one that contains
+# (escaped) backslashes.  A very naive implementation.
+lt_sed_naive_backslashify='s|\\\\*|\\|g;s|/|\\|g;s|\\|\\\\|g'
+
+# Re-`\' parameter expansions in output of double_quote_subst that were
+# `\'-ed in input to the same.  If an odd number of `\' preceded a '$'
+# in input to double_quote_subst, that '$' was protected from expansion.
+# Since each input `\' is now two `\'s, look for any number of runs of
+# four `\'s followed by two `\'s and then a '$'.  `\' that '$'.
+bs='\\'
+bs2='\\\\'
+bs4='\\\\\\\\'
+dollar='\$'
+sed_double_backslash="\
+  s/$bs4/&\\
+/g
+  s/^$bs2$dollar/$bs&/
+  s/\\([^$bs]\\)$bs2$dollar/\\1$bs2$bs$dollar/g
+  s/\n//g"
+
+# Standard options:
+opt_dry_run=false
+opt_help=false
+opt_quiet=false
+opt_verbose=false
+opt_warning=:
+
+# func_echo arg...
+# Echo program name prefixed message, along with the current mode
+# name if it has been set yet.
+func_echo ()
+{
+    $ECHO "$progname: ${opt_mode+$opt_mode: }$*"
+}
+
+# func_verbose arg...
+# Echo program name prefixed message in verbose mode only.
+func_verbose ()
+{
+    $opt_verbose && func_echo ${1+"$@"}
+
+    # A bug in bash halts the script if the last line of a function
+    # fails when set -e is in force, so we need another command to
+    # work around that:
+    :
+}
+
+# func_echo_all arg...
+# Invoke $ECHO with all args, space-separated.
+func_echo_all ()
+{
+    $ECHO "$*"
+}
+
+# func_error arg...
+# Echo program name prefixed message to standard error.
+func_error ()
+{
+    $ECHO "$progname: ${opt_mode+$opt_mode: }"${1+"$@"} 1>&2
+}
+
+# func_warning arg...
+# Echo program name prefixed warning message to standard error.
+func_warning ()
+{
+    $opt_warning && $ECHO "$progname: ${opt_mode+$opt_mode: }warning: "${1+"$@"} 1>&2
+
+    # bash bug again:
+    :
+}
+
+# func_fatal_error arg...
+# Echo program name prefixed message to standard error, and exit.
+func_fatal_error ()
+{
+    func_error ${1+"$@"}
+    exit $EXIT_FAILURE
+}
+
+# func_fatal_help arg...
+# Echo program name prefixed message to standard error, followed by
+# a help hint, and exit.
+func_fatal_help ()
+{
+    func_error ${1+"$@"}
+    func_fatal_error "$help"
+}
+help="Try \`$progname --help' for more information."  ## default
+
+
+# func_grep expression filename
+# Check whether EXPRESSION matches any line of FILENAME, without output.
+func_grep ()
+{
+    $GREP "$1" "$2" >/dev/null 2>&1
+}
+
+
+# func_mkdir_p directory-path
+# Make sure the entire path to DIRECTORY-PATH is available.
+func_mkdir_p ()
+{
+    my_directory_path="$1"
+    my_dir_list=
+
+    if test -n "$my_directory_path" && test "$opt_dry_run" != ":"; then
+
+      # Protect directory names starting with `-'
+      case $my_directory_path in
+        -*) my_directory_path="./$my_directory_path" ;;
+      esac
+
+      # While some portion of DIR does not yet exist...
+      while test ! -d "$my_directory_path"; do
+        # ...make a list in topmost first order.  Use a colon delimited
+	# list incase some portion of path contains whitespace.
+        my_dir_list="$my_directory_path:$my_dir_list"
+
+        # If the last portion added has no slash in it, the list is done
+        case $my_directory_path in */*) ;; *) break ;; esac
+
+        # ...otherwise throw away the child directory and loop
+        my_directory_path=`$ECHO "$my_directory_path" | $SED -e "$dirname"`
+      done
+      my_dir_list=`$ECHO "$my_dir_list" | $SED 's,:*$,,'`
+
+      save_mkdir_p_IFS="$IFS"; IFS=':'
+      for my_dir in $my_dir_list; do
+	IFS="$save_mkdir_p_IFS"
+        # mkdir can fail with a `File exist' error if two processes
+        # try to create one of the directories concurrently.  Don't
+        # stop in that case!
+        $MKDIR "$my_dir" 2>/dev/null || :
+      done
+      IFS="$save_mkdir_p_IFS"
+
+      # Bail out if we (or some other process) failed to create a directory.
+      test -d "$my_directory_path" || \
+        func_fatal_error "Failed to create \`$1'"
+    fi
+}
+
+
+# func_mktempdir [string]
+# Make a temporary directory that won't clash with other running
+# libtool processes, and avoids race conditions if possible.  If
+# given, STRING is the basename for that directory.
+func_mktempdir ()
+{
+    my_template="${TMPDIR-/tmp}/${1-$progname}"
+
+    if test "$opt_dry_run" = ":"; then
+      # Return a directory name, but don't create it in dry-run mode
+      my_tmpdir="${my_template}-$$"
+    else
+
+      # If mktemp works, use that first and foremost
+      my_tmpdir=`mktemp -d "${my_template}-XXXXXXXX" 2>/dev/null`
+
+      if test ! -d "$my_tmpdir"; then
+        # Failing that, at least try and use $RANDOM to avoid a race
+        my_tmpdir="${my_template}-${RANDOM-0}$$"
+
+        save_mktempdir_umask=`umask`
+        umask 0077
+        $MKDIR "$my_tmpdir"
+        umask $save_mktempdir_umask
+      fi
+
+      # If we're not in dry-run mode, bomb out on failure
+      test -d "$my_tmpdir" || \
+        func_fatal_error "cannot create temporary directory \`$my_tmpdir'"
+    fi
+
+    $ECHO "$my_tmpdir"
+}
+
+
+# func_quote_for_eval arg
+# Aesthetically quote ARG to be evaled later.
+# This function returns two values: FUNC_QUOTE_FOR_EVAL_RESULT
+# is double-quoted, suitable for a subsequent eval, whereas
+# FUNC_QUOTE_FOR_EVAL_UNQUOTED_RESULT has merely all characters
+# which are still active within double quotes backslashified.
+func_quote_for_eval ()
+{
+    case $1 in
+      *[\\\`\"\$]*)
+	func_quote_for_eval_unquoted_result=`$ECHO "$1" | $SED "$sed_quote_subst"` ;;
+      *)
+        func_quote_for_eval_unquoted_result="$1" ;;
+    esac
+
+    case $func_quote_for_eval_unquoted_result in
+      # Double-quote args containing shell metacharacters to delay
+      # word splitting, command substitution and and variable
+      # expansion for a subsequent eval.
+      # Many Bourne shells cannot handle close brackets correctly
+      # in scan sets, so we specify it separately.
+      *[\[\~\#\^\&\*\(\)\{\}\|\;\<\>\?\'\ \	]*|*]*|"")
+        func_quote_for_eval_result="\"$func_quote_for_eval_unquoted_result\""
+        ;;
+      *)
+        func_quote_for_eval_result="$func_quote_for_eval_unquoted_result"
+    esac
+}
+
+
+# func_quote_for_expand arg
+# Aesthetically quote ARG to be evaled later; same as above,
+# but do not quote variable references.
+func_quote_for_expand ()
+{
+    case $1 in
+      *[\\\`\"]*)
+	my_arg=`$ECHO "$1" | $SED \
+	    -e "$double_quote_subst" -e "$sed_double_backslash"` ;;
+      *)
+        my_arg="$1" ;;
+    esac
+
+    case $my_arg in
+      # Double-quote args containing shell metacharacters to delay
+      # word splitting and command substitution for a subsequent eval.
+      # Many Bourne shells cannot handle close brackets correctly
+      # in scan sets, so we specify it separately.
+      *[\[\~\#\^\&\*\(\)\{\}\|\;\<\>\?\'\ \	]*|*]*|"")
+        my_arg="\"$my_arg\""
+        ;;
+    esac
+
+    func_quote_for_expand_result="$my_arg"
+}
+
+
+# func_show_eval cmd [fail_exp]
+# Unless opt_silent is true, then output CMD.  Then, if opt_dryrun is
+# not true, evaluate CMD.  If the evaluation of CMD fails, and FAIL_EXP
+# is given, then evaluate it.
+func_show_eval ()
+{
+    my_cmd="$1"
+    my_fail_exp="${2-:}"
+
+    ${opt_silent-false} || {
+      func_quote_for_expand "$my_cmd"
+      eval "func_echo $func_quote_for_expand_result"
+    }
+
+    if ${opt_dry_run-false}; then :; else
+      eval "$my_cmd"
+      my_status=$?
+      if test "$my_status" -eq 0; then :; else
+	eval "(exit $my_status); $my_fail_exp"
+      fi
+    fi
+}
+
+
+# func_show_eval_locale cmd [fail_exp]
+# Unless opt_silent is true, then output CMD.  Then, if opt_dryrun is
+# not true, evaluate CMD.  If the evaluation of CMD fails, and FAIL_EXP
+# is given, then evaluate it.  Use the saved locale for evaluation.
+func_show_eval_locale ()
+{
+    my_cmd="$1"
+    my_fail_exp="${2-:}"
+
+    ${opt_silent-false} || {
+      func_quote_for_expand "$my_cmd"
+      eval "func_echo $func_quote_for_expand_result"
+    }
+
+    if ${opt_dry_run-false}; then :; else
+      eval "$lt_user_locale
+	    $my_cmd"
+      my_status=$?
+      eval "$lt_safe_locale"
+      if test "$my_status" -eq 0; then :; else
+	eval "(exit $my_status); $my_fail_exp"
+      fi
+    fi
+}
+
+# func_tr_sh
+# Turn $1 into a string suitable for a shell variable name.
+# Result is stored in $func_tr_sh_result.  All characters
+# not in the set a-zA-Z0-9_ are replaced with '_'. Further,
+# if $1 begins with a digit, a '_' is prepended as well.
+func_tr_sh ()
+{
+  case $1 in
+  [0-9]* | *[!a-zA-Z0-9_]*)
+    func_tr_sh_result=`$ECHO "$1" | $SED 's/^\([0-9]\)/_\1/; s/[^a-zA-Z0-9_]/_/g'`
+    ;;
+  * )
+    func_tr_sh_result=$1
+    ;;
+  esac
+}
+
+
+# func_version
+# Echo version message to standard output and exit.
+func_version ()
+{
+    $opt_debug
+
+    $SED -n '/(C)/!b go
+	:more
+	/\./!{
+	  N
+	  s/\n# / /
+	  b more
+	}
+	:go
+	/^# '$PROGRAM' (GNU /,/# warranty; / {
+        s/^# //
+	s/^# *$//
+        s/\((C)\)[ 0-9,-]*\( [1-9][0-9]*\)/\1\2/
+        p
+     }' < "$progpath"
+     exit $?
+}
+
+# func_usage
+# Echo short help message to standard output and exit.
+func_usage ()
+{
+    $opt_debug
+
+    $SED -n '/^# Usage:/,/^#  *.*--help/ {
+        s/^# //
+	s/^# *$//
+	s/\$progname/'$progname'/
+	p
+    }' < "$progpath"
+    echo
+    $ECHO "run \`$progname --help | more' for full usage"
+    exit $?
+}
+
+# func_help [NOEXIT]
+# Echo long help message to standard output and exit,
+# unless 'noexit' is passed as argument.
+func_help ()
+{
+    $opt_debug
+
+    $SED -n '/^# Usage:/,/# Report bugs to/ {
+	:print
+        s/^# //
+	s/^# *$//
+	s*\$progname*'$progname'*
+	s*\$host*'"$host"'*
+	s*\$SHELL*'"$SHELL"'*
+	s*\$LTCC*'"$LTCC"'*
+	s*\$LTCFLAGS*'"$LTCFLAGS"'*
+	s*\$LD*'"$LD"'*
+	s/\$with_gnu_ld/'"$with_gnu_ld"'/
+	s/\$automake_version/'"`(${AUTOMAKE-automake} --version) 2>/dev/null |$SED 1q`"'/
+	s/\$autoconf_version/'"`(${AUTOCONF-autoconf} --version) 2>/dev/null |$SED 1q`"'/
+	p
+	d
+     }
+     /^# .* home page:/b print
+     /^# General help using/b print
+     ' < "$progpath"
+    ret=$?
+    if test -z "$1"; then
+      exit $ret
+    fi
+}
+
+# func_missing_arg argname
+# Echo program name prefixed message to standard error and set global
+# exit_cmd.
+func_missing_arg ()
+{
+    $opt_debug
+
+    func_error "missing argument for $1."
+    exit_cmd=exit
+}
+
+
+# func_split_short_opt shortopt
+# Set func_split_short_opt_name and func_split_short_opt_arg shell
+# variables after splitting SHORTOPT after the 2nd character.
+func_split_short_opt ()
+{
+    my_sed_short_opt='1s/^\(..\).*$/\1/;q'
+    my_sed_short_rest='1s/^..\(.*\)$/\1/;q'
+
+    func_split_short_opt_name=`$ECHO "$1" | $SED "$my_sed_short_opt"`
+    func_split_short_opt_arg=`$ECHO "$1" | $SED "$my_sed_short_rest"`
+} # func_split_short_opt may be replaced by extended shell implementation
+
+
+# func_split_long_opt longopt
+# Set func_split_long_opt_name and func_split_long_opt_arg shell
+# variables after splitting LONGOPT at the `=' sign.
+func_split_long_opt ()
+{
+    my_sed_long_opt='1s/^\(--[^=]*\)=.*/\1/;q'
+    my_sed_long_arg='1s/^--[^=]*=//'
+
+    func_split_long_opt_name=`$ECHO "$1" | $SED "$my_sed_long_opt"`
+    func_split_long_opt_arg=`$ECHO "$1" | $SED "$my_sed_long_arg"`
+} # func_split_long_opt may be replaced by extended shell implementation
+
+exit_cmd=:
+
+
+
+
+
+magic="%%%MAGIC variable%%%"
+magic_exe="%%%MAGIC EXE variable%%%"
+
+# Global variables.
+nonopt=
+preserve_args=
+lo2o="s/\\.lo\$/.${objext}/"
+o2lo="s/\\.${objext}\$/.lo/"
+extracted_archives=
+extracted_serial=0
+
+# If this variable is set in any of the actions, the command in it
+# will be execed at the end.  This prevents here-documents from being
+# left over by shells.
+exec_cmd=
+
+# func_append var value
+# Append VALUE to the end of shell variable VAR.
+func_append ()
+{
+    eval "${1}=\$${1}\${2}"
+} # func_append may be replaced by extended shell implementation
+
+# func_append_quoted var value
+# Quote VALUE and append to the end of shell variable VAR, separated
+# by a space.
+func_append_quoted ()
+{
+    func_quote_for_eval "${2}"
+    eval "${1}=\$${1}\\ \$func_quote_for_eval_result"
+} # func_append_quoted may be replaced by extended shell implementation
+
+
+# func_arith arithmetic-term...
+func_arith ()
+{
+    func_arith_result=`expr "${@}"`
+} # func_arith may be replaced by extended shell implementation
+
+
+# func_len string
+# STRING may not start with a hyphen.
+func_len ()
+{
+    func_len_result=`expr "${1}" : ".*" 2>/dev/null || echo $max_cmd_len`
+} # func_len may be replaced by extended shell implementation
+
+
+# func_lo2o object
+func_lo2o ()
+{
+    func_lo2o_result=`$ECHO "${1}" | $SED "$lo2o"`
+} # func_lo2o may be replaced by extended shell implementation
+
+
+# func_xform libobj-or-source
+func_xform ()
+{
+    func_xform_result=`$ECHO "${1}" | $SED 's/\.[^.]*$/.lo/'`
+} # func_xform may be replaced by extended shell implementation
+
+
+# func_fatal_configuration arg...
+# Echo program name prefixed message to standard error, followed by
+# a configuration failure hint, and exit.
+func_fatal_configuration ()
+{
+    func_error ${1+"$@"}
+    func_error "See the $PACKAGE documentation for more information."
+    func_fatal_error "Fatal configuration error."
+}
+
+
+# func_config
+# Display the configuration for all the tags in this script.
+func_config ()
+{
+    re_begincf='^# ### BEGIN LIBTOOL'
+    re_endcf='^# ### END LIBTOOL'
+
+    # Default configuration.
+    $SED "1,/$re_begincf CONFIG/d;/$re_endcf CONFIG/,\$d" < "$progpath"
+
+    # Now print the configurations for the tags.
+    for tagname in $taglist; do
+      $SED -n "/$re_begincf TAG CONFIG: $tagname\$/,/$re_endcf TAG CONFIG: $tagname\$/p" < "$progpath"
+    done
+
+    exit $?
+}
+
+# func_features
+# Display the features supported by this script.
+func_features ()
+{
+    echo "host: $host"
+    if test "$build_libtool_libs" = yes; then
+      echo "enable shared libraries"
+    else
+      echo "disable shared libraries"
+    fi
+    if test "$build_old_libs" = yes; then
+      echo "enable static libraries"
+    else
+      echo "disable static libraries"
+    fi
+
+    exit $?
+}
+
+# func_enable_tag tagname
+# Verify that TAGNAME is valid, and either flag an error and exit, or
+# enable the TAGNAME tag.  We also add TAGNAME to the global $taglist
+# variable here.
+func_enable_tag ()
+{
+  # Global variable:
+  tagname="$1"
+
+  re_begincf="^# ### BEGIN LIBTOOL TAG CONFIG: $tagname\$"
+  re_endcf="^# ### END LIBTOOL TAG CONFIG: $tagname\$"
+  sed_extractcf="/$re_begincf/,/$re_endcf/p"
+
+  # Validate tagname.
+  case $tagname in
+    *[!-_A-Za-z0-9,/]*)
+      func_fatal_error "invalid tag name: $tagname"
+      ;;
+  esac
+
+  # Don't test for the "default" C tag, as we know it's
+  # there but not specially marked.
+  case $tagname in
+    CC) ;;
+    *)
+      if $GREP "$re_begincf" "$progpath" >/dev/null 2>&1; then
+	taglist="$taglist $tagname"
+
+	# Evaluate the configuration.  Be careful to quote the path
+	# and the sed script, to avoid splitting on whitespace, but
+	# also don't use non-portable quotes within backquotes within
+	# quotes we have to do it in 2 steps:
+	extractedcf=`$SED -n -e "$sed_extractcf" < "$progpath"`
+	eval "$extractedcf"
+      else
+	func_error "ignoring unknown tag $tagname"
+      fi
+      ;;
+  esac
+}
+
+# func_check_version_match
+# Ensure that we are using m4 macros, and libtool script from the same
+# release of libtool.
+func_check_version_match ()
+{
+  if test "$package_revision" != "$macro_revision"; then
+    if test "$VERSION" != "$macro_version"; then
+      if test -z "$macro_version"; then
+        cat >&2 <<_LT_EOF
+$progname: Version mismatch error.  This is $PACKAGE $VERSION, but the
+$progname: definition of this LT_INIT comes from an older release.
+$progname: You should recreate aclocal.m4 with macros from $PACKAGE $VERSION
+$progname: and run autoconf again.
+_LT_EOF
+      else
+        cat >&2 <<_LT_EOF
+$progname: Version mismatch error.  This is $PACKAGE $VERSION, but the
+$progname: definition of this LT_INIT comes from $PACKAGE $macro_version.
+$progname: You should recreate aclocal.m4 with macros from $PACKAGE $VERSION
+$progname: and run autoconf again.
+_LT_EOF
+      fi
+    else
+      cat >&2 <<_LT_EOF
+$progname: Version mismatch error.  This is $PACKAGE $VERSION, revision $package_revision,
+$progname: but the definition of this LT_INIT comes from revision $macro_revision.
+$progname: You should recreate aclocal.m4 with macros from revision $package_revision
+$progname: of $PACKAGE $VERSION and run autoconf again.
+_LT_EOF
+    fi
+
+    exit $EXIT_MISMATCH
+  fi
+}
+
+
+# Shorthand for --mode=foo, only valid as the first argument
+case $1 in
+clean|clea|cle|cl)
+  shift; set dummy --mode clean ${1+"$@"}; shift
+  ;;
+compile|compil|compi|comp|com|co|c)
+  shift; set dummy --mode compile ${1+"$@"}; shift
+  ;;
+execute|execut|execu|exec|exe|ex|e)
+  shift; set dummy --mode execute ${1+"$@"}; shift
+  ;;
+finish|finis|fini|fin|fi|f)
+  shift; set dummy --mode finish ${1+"$@"}; shift
+  ;;
+install|instal|insta|inst|ins|in|i)
+  shift; set dummy --mode install ${1+"$@"}; shift
+  ;;
+link|lin|li|l)
+  shift; set dummy --mode link ${1+"$@"}; shift
+  ;;
+uninstall|uninstal|uninsta|uninst|unins|unin|uni|un|u)
+  shift; set dummy --mode uninstall ${1+"$@"}; shift
+  ;;
+esac
+
+
+
+# Option defaults:
+opt_debug=:
+opt_dry_run=false
+opt_config=false
+opt_preserve_dup_deps=false
+opt_features=false
+opt_finish=false
+opt_help=false
+opt_help_all=false
+opt_silent=:
+opt_warning=:
+opt_verbose=:
+opt_silent=false
+opt_verbose=false
+
+
+# Parse options once, thoroughly.  This comes as soon as possible in the
+# script to make things like `--version' happen as quickly as we can.
+{
+  # this just eases exit handling
+  while test $# -gt 0; do
+    opt="$1"
+    shift
+    case $opt in
+      --debug|-x)	opt_debug='set -x'
+			func_echo "enabling shell trace mode"
+			$opt_debug
+			;;
+      --dry-run|--dryrun|-n)
+			opt_dry_run=:
+			;;
+      --config)
+			opt_config=:
+func_config
+			;;
+      --dlopen|-dlopen)
+			optarg="$1"
+			opt_dlopen="${opt_dlopen+$opt_dlopen
+}$optarg"
+			shift
+			;;
+      --preserve-dup-deps)
+			opt_preserve_dup_deps=:
+			;;
+      --features)
+			opt_features=:
+func_features
+			;;
+      --finish)
+			opt_finish=:
+set dummy --mode finish ${1+"$@"}; shift
+			;;
+      --help)
+			opt_help=:
+			;;
+      --help-all)
+			opt_help_all=:
+opt_help=': help-all'
+			;;
+      --mode)
+			test $# = 0 && func_missing_arg $opt && break
+			optarg="$1"
+			opt_mode="$optarg"
+case $optarg in
+  # Valid mode arguments:
+  clean|compile|execute|finish|install|link|relink|uninstall) ;;
+
+  # Catch anything else as an error
+  *) func_error "invalid argument for $opt"
+     exit_cmd=exit
+     break
+     ;;
+esac
+			shift
+			;;
+      --no-silent|--no-quiet)
+			opt_silent=false
+func_append preserve_args " $opt"
+			;;
+      --no-warning|--no-warn)
+			opt_warning=false
+func_append preserve_args " $opt"
+			;;
+      --no-verbose)
+			opt_verbose=false
+func_append preserve_args " $opt"
+			;;
+      --silent|--quiet)
+			opt_silent=:
+func_append preserve_args " $opt"
+        opt_verbose=false
+			;;
+      --verbose|-v)
+			opt_verbose=:
+func_append preserve_args " $opt"
+opt_silent=false
+			;;
+      --tag)
+			test $# = 0 && func_missing_arg $opt && break
+			optarg="$1"
+			opt_tag="$optarg"
+func_append preserve_args " $opt $optarg"
+func_enable_tag "$optarg"
+			shift
+			;;
+
+      -\?|-h)		func_usage				;;
+      --help)		func_help				;;
+      --version)	func_version				;;
+
+      # Separate optargs to long options:
+      --*=*)
+			func_split_long_opt "$opt"
+			set dummy "$func_split_long_opt_name" "$func_split_long_opt_arg" ${1+"$@"}
+			shift
+			;;
+
+      # Separate non-argument short options:
+      -\?*|-h*|-n*|-v*)
+			func_split_short_opt "$opt"
+			set dummy "$func_split_short_opt_name" "-$func_split_short_opt_arg" ${1+"$@"}
+			shift
+			;;
+
+      --)		break					;;
+      -*)		func_fatal_help "unrecognized option \`$opt'" ;;
+      *)		set dummy "$opt" ${1+"$@"};	shift; break  ;;
+    esac
+  done
+
+  # Validate options:
+
+  # save first non-option argument
+  if test "$#" -gt 0; then
+    nonopt="$opt"
+    shift
+  fi
+
+  # preserve --debug
+  test "$opt_debug" = : || func_append preserve_args " --debug"
+
+  case $host in
+    *cygwin* | *mingw* | *pw32* | *cegcc*)
+      # don't eliminate duplications in $postdeps and $predeps
+      opt_duplicate_compiler_generated_deps=:
+      ;;
+    *)
+      opt_duplicate_compiler_generated_deps=$opt_preserve_dup_deps
+      ;;
+  esac
+
+  $opt_help || {
+    # Sanity checks first:
+    func_check_version_match
+
+    if test "$build_libtool_libs" != yes && test "$build_old_libs" != yes; then
+      func_fatal_configuration "not configured to build any kind of library"
+    fi
+
+    # Darwin sucks
+    eval std_shrext=\"$shrext_cmds\"
+
+    # Only execute mode is allowed to have -dlopen flags.
+    if test -n "$opt_dlopen" && test "$opt_mode" != execute; then
+      func_error "unrecognized option \`-dlopen'"
+      $ECHO "$help" 1>&2
+      exit $EXIT_FAILURE
+    fi
+
+    # Change the help message to a mode-specific one.
+    generic_help="$help"
+    help="Try \`$progname --help --mode=$opt_mode' for more information."
+  }
+
+
+  # Bail if the options were screwed
+  $exit_cmd $EXIT_FAILURE
+}
+
+
+
+
+## ----------- ##
+##    Main.    ##
+## ----------- ##
+
+# func_lalib_p file
+# True iff FILE is a libtool `.la' library or `.lo' object file.
+# This function is only a basic sanity check; it will hardly flush out
+# determined imposters.
+func_lalib_p ()
+{
+    test -f "$1" &&
+      $SED -e 4q "$1" 2>/dev/null \
+        | $GREP "^# Generated by .*$PACKAGE" > /dev/null 2>&1
+}
+
+# func_lalib_unsafe_p file
+# True iff FILE is a libtool `.la' library or `.lo' object file.
+# This function implements the same check as func_lalib_p without
+# resorting to external programs.  To this end, it redirects stdin and
+# closes it afterwards, without saving the original file descriptor.
+# As a safety measure, use it only where a negative result would be
+# fatal anyway.  Works if `file' does not exist.
+func_lalib_unsafe_p ()
+{
+    lalib_p=no
+    if test -f "$1" && test -r "$1" && exec 5<&0 <"$1"; then
+	for lalib_p_l in 1 2 3 4
+	do
+	    read lalib_p_line
+	    case "$lalib_p_line" in
+		\#\ Generated\ by\ *$PACKAGE* ) lalib_p=yes; break;;
+	    esac
+	done
+	exec 0<&5 5<&-
+    fi
+    test "$lalib_p" = yes
+}
+
+# func_ltwrapper_script_p file
+# True iff FILE is a libtool wrapper script
+# This function is only a basic sanity check; it will hardly flush out
+# determined imposters.
+func_ltwrapper_script_p ()
+{
+    func_lalib_p "$1"
+}
+
+# func_ltwrapper_executable_p file
+# True iff FILE is a libtool wrapper executable
+# This function is only a basic sanity check; it will hardly flush out
+# determined imposters.
+func_ltwrapper_executable_p ()
+{
+    func_ltwrapper_exec_suffix=
+    case $1 in
+    *.exe) ;;
+    *) func_ltwrapper_exec_suffix=.exe ;;
+    esac
+    $GREP "$magic_exe" "$1$func_ltwrapper_exec_suffix" >/dev/null 2>&1
+}
+
+# func_ltwrapper_scriptname file
+# Assumes file is an ltwrapper_executable
+# uses $file to determine the appropriate filename for a
+# temporary ltwrapper_script.
+func_ltwrapper_scriptname ()
+{
+    func_dirname_and_basename "$1" "" "."
+    func_stripname '' '.exe' "$func_basename_result"
+    func_ltwrapper_scriptname_result="$func_dirname_result/$objdir/${func_stripname_result}_ltshwrapper"
+}
+
+# func_ltwrapper_p file
+# True iff FILE is a libtool wrapper script or wrapper executable
+# This function is only a basic sanity check; it will hardly flush out
+# determined imposters.
+func_ltwrapper_p ()
+{
+    func_ltwrapper_script_p "$1" || func_ltwrapper_executable_p "$1"
+}
+
+
+# func_execute_cmds commands fail_cmd
+# Execute tilde-delimited COMMANDS.
+# If FAIL_CMD is given, eval that upon failure.
+# FAIL_CMD may read-access the current command in variable CMD!
+func_execute_cmds ()
+{
+    $opt_debug
+    save_ifs=$IFS; IFS='~'
+    for cmd in $1; do
+      IFS=$save_ifs
+      eval cmd=\"$cmd\"
+      func_show_eval "$cmd" "${2-:}"
+    done
+    IFS=$save_ifs
+}
+
+
+# func_source file
+# Source FILE, adding directory component if necessary.
+# Note that it is not necessary on cygwin/mingw to append a dot to
+# FILE even if both FILE and FILE.exe exist: automatic-append-.exe
+# behavior happens only for exec(3), not for open(2)!  Also, sourcing
+# `FILE.' does not work on cygwin managed mounts.
+func_source ()
+{
+    $opt_debug
+    case $1 in
+    */* | *\\*)	. "$1" ;;
+    *)		. "./$1" ;;
+    esac
+}
+
+
+# func_resolve_sysroot PATH
+# Replace a leading = in PATH with a sysroot.  Store the result into
+# func_resolve_sysroot_result
+func_resolve_sysroot ()
+{
+  func_resolve_sysroot_result=$1
+  case $func_resolve_sysroot_result in
+  =*)
+    func_stripname '=' '' "$func_resolve_sysroot_result"
+    func_resolve_sysroot_result=$lt_sysroot$func_stripname_result
+    ;;
+  esac
+}
+
+# func_replace_sysroot PATH
+# If PATH begins with the sysroot, replace it with = and
+# store the result into func_replace_sysroot_result.
+func_replace_sysroot ()
+{
+  case "$lt_sysroot:$1" in
+  ?*:"$lt_sysroot"*)
+    func_stripname "$lt_sysroot" '' "$1"
+    func_replace_sysroot_result="=$func_stripname_result"
+    ;;
+  *)
+    # Including no sysroot.
+    func_replace_sysroot_result=$1
+    ;;
+  esac
+}
+
+# func_infer_tag arg
+# Infer tagged configuration to use if any are available and
+# if one wasn't chosen via the "--tag" command line option.
+# Only attempt this if the compiler in the base compile
+# command doesn't match the default compiler.
+# arg is usually of the form 'gcc ...'
+func_infer_tag ()
+{
+    $opt_debug
+    if test -n "$available_tags" && test -z "$tagname"; then
+      CC_quoted=
+      for arg in $CC; do
+	func_append_quoted CC_quoted "$arg"
+      done
+      CC_expanded=`func_echo_all $CC`
+      CC_quoted_expanded=`func_echo_all $CC_quoted`
+      case $@ in
+      # Blanks in the command may have been stripped by the calling shell,
+      # but not from the CC environment variable when configure was run.
+      " $CC "* | "$CC "* | " $CC_expanded "* | "$CC_expanded "* | \
+      " $CC_quoted"* | "$CC_quoted "* | " $CC_quoted_expanded "* | "$CC_quoted_expanded "*) ;;
+      # Blanks at the start of $base_compile will cause this to fail
+      # if we don't check for them as well.
+      *)
+	for z in $available_tags; do
+	  if $GREP "^# ### BEGIN LIBTOOL TAG CONFIG: $z$" < "$progpath" > /dev/null; then
+	    # Evaluate the configuration.
+	    eval "`${SED} -n -e '/^# ### BEGIN LIBTOOL TAG CONFIG: '$z'$/,/^# ### END LIBTOOL TAG CONFIG: '$z'$/p' < $progpath`"
+	    CC_quoted=
+	    for arg in $CC; do
+	      # Double-quote args containing other shell metacharacters.
+	      func_append_quoted CC_quoted "$arg"
+	    done
+	    CC_expanded=`func_echo_all $CC`
+	    CC_quoted_expanded=`func_echo_all $CC_quoted`
+	    case "$@ " in
+	    " $CC "* | "$CC "* | " $CC_expanded "* | "$CC_expanded "* | \
+	    " $CC_quoted"* | "$CC_quoted "* | " $CC_quoted_expanded "* | "$CC_quoted_expanded "*)
+	      # The compiler in the base compile command matches
+	      # the one in the tagged configuration.
+	      # Assume this is the tagged configuration we want.
+	      tagname=$z
+	      break
+	      ;;
+	    esac
+	  fi
+	done
+	# If $tagname still isn't set, then no tagged configuration
+	# was found and let the user know that the "--tag" command
+	# line option must be used.
+	if test -z "$tagname"; then
+	  func_echo "unable to infer tagged configuration"
+	  func_fatal_error "specify a tag with \`--tag'"
+#	else
+#	  func_verbose "using $tagname tagged configuration"
+	fi
+	;;
+      esac
+    fi
+}
+
+
+
+# func_write_libtool_object output_name pic_name nonpic_name
+# Create a libtool object file (analogous to a ".la" file),
+# but don't create it if we're doing a dry run.
+func_write_libtool_object ()
+{
+    write_libobj=${1}
+    if test "$build_libtool_libs" = yes; then
+      write_lobj=\'${2}\'
+    else
+      write_lobj=none
+    fi
+
+    if test "$build_old_libs" = yes; then
+      write_oldobj=\'${3}\'
+    else
+      write_oldobj=none
+    fi
+
+    $opt_dry_run || {
+      cat >${write_libobj}T <<EOF
+# $write_libobj - a libtool object file
+# Generated by $PROGRAM (GNU $PACKAGE$TIMESTAMP) $VERSION
+#
+# Please DO NOT delete this file!
+# It is necessary for linking the library.
+
+# Name of the PIC object.
+pic_object=$write_lobj
+
+# Name of the non-PIC object
+non_pic_object=$write_oldobj
+
+EOF
+      $MV "${write_libobj}T" "${write_libobj}"
+    }
+}
+
+
+##################################################
+# FILE NAME AND PATH CONVERSION HELPER FUNCTIONS #
+##################################################
+
+# func_convert_core_file_wine_to_w32 ARG
+# Helper function used by file name conversion functions when $build is *nix,
+# and $host is mingw, cygwin, or some other w32 environment. Relies on a
+# correctly configured wine environment available, with the winepath program
+# in $build's $PATH.
+#
+# ARG is the $build file name to be converted to w32 format.
+# Result is available in $func_convert_core_file_wine_to_w32_result, and will
+# be empty on error (or when ARG is empty)
+func_convert_core_file_wine_to_w32 ()
+{
+  $opt_debug
+  func_convert_core_file_wine_to_w32_result="$1"
+  if test -n "$1"; then
+    # Unfortunately, winepath does not exit with a non-zero error code, so we
+    # are forced to check the contents of stdout. On the other hand, if the
+    # command is not found, the shell will set an exit code of 127 and print
+    # *an error message* to stdout. So we must check for both error code of
+    # zero AND non-empty stdout, which explains the odd construction:
+    func_convert_core_file_wine_to_w32_tmp=`winepath -w "$1" 2>/dev/null`
+    if test "$?" -eq 0 && test -n "${func_convert_core_file_wine_to_w32_tmp}"; then
+      func_convert_core_file_wine_to_w32_result=`$ECHO "$func_convert_core_file_wine_to_w32_tmp" |
+        $SED -e "$lt_sed_naive_backslashify"`
+    else
+      func_convert_core_file_wine_to_w32_result=
+    fi
+  fi
+}
+# end: func_convert_core_file_wine_to_w32
+
+
+# func_convert_core_path_wine_to_w32 ARG
+# Helper function used by path conversion functions when $build is *nix, and
+# $host is mingw, cygwin, or some other w32 environment. Relies on a correctly
+# configured wine environment available, with the winepath program in $build's
+# $PATH. Assumes ARG has no leading or trailing path separator characters.
+#
+# ARG is path to be converted from $build format to win32.
+# Result is available in $func_convert_core_path_wine_to_w32_result.
+# Unconvertible file (directory) names in ARG are skipped; if no directory names
+# are convertible, then the result may be empty.
+func_convert_core_path_wine_to_w32 ()
+{
+  $opt_debug
+  # unfortunately, winepath doesn't convert paths, only file names
+  func_convert_core_path_wine_to_w32_result=""
+  if test -n "$1"; then
+    oldIFS=$IFS
+    IFS=:
+    for func_convert_core_path_wine_to_w32_f in $1; do
+      IFS=$oldIFS
+      func_convert_core_file_wine_to_w32 "$func_convert_core_path_wine_to_w32_f"
+      if test -n "$func_convert_core_file_wine_to_w32_result" ; then
+        if test -z "$func_convert_core_path_wine_to_w32_result"; then
+          func_convert_core_path_wine_to_w32_result="$func_convert_core_file_wine_to_w32_result"
+        else
+          func_append func_convert_core_path_wine_to_w32_result ";$func_convert_core_file_wine_to_w32_result"
+        fi
+      fi
+    done
+    IFS=$oldIFS
+  fi
+}
+# end: func_convert_core_path_wine_to_w32
+
+
+# func_cygpath ARGS...
+# Wrapper around calling the cygpath program via LT_CYGPATH. This is used when
+# when (1) $build is *nix and Cygwin is hosted via a wine environment; or (2)
+# $build is MSYS and $host is Cygwin, or (3) $build is Cygwin. In case (1) or
+# (2), returns the Cygwin file name or path in func_cygpath_result (input
+# file name or path is assumed to be in w32 format, as previously converted
+# from $build's *nix or MSYS format). In case (3), returns the w32 file name
+# or path in func_cygpath_result (input file name or path is assumed to be in
+# Cygwin format). Returns an empty string on error.
+#
+# ARGS are passed to cygpath, with the last one being the file name or path to
+# be converted.
+#
+# Specify the absolute *nix (or w32) name to cygpath in the LT_CYGPATH
+# environment variable; do not put it in $PATH.
+func_cygpath ()
+{
+  $opt_debug
+  if test -n "$LT_CYGPATH" && test -f "$LT_CYGPATH"; then
+    func_cygpath_result=`$LT_CYGPATH "$@" 2>/dev/null`
+    if test "$?" -ne 0; then
+      # on failure, ensure result is empty
+      func_cygpath_result=
+    fi
+  else
+    func_cygpath_result=
+    func_error "LT_CYGPATH is empty or specifies non-existent file: \`$LT_CYGPATH'"
+  fi
+}
+#end: func_cygpath
+
+
+# func_convert_core_msys_to_w32 ARG
+# Convert file name or path ARG from MSYS format to w32 format.  Return
+# result in func_convert_core_msys_to_w32_result.
+func_convert_core_msys_to_w32 ()
+{
+  $opt_debug
+  # awkward: cmd appends spaces to result
+  func_convert_core_msys_to_w32_result=`( cmd //c echo "$1" ) 2>/dev/null |
+    $SED -e 's/[ ]*$//' -e "$lt_sed_naive_backslashify"`
+}
+#end: func_convert_core_msys_to_w32
+
+
+# func_convert_file_check ARG1 ARG2
+# Verify that ARG1 (a file name in $build format) was converted to $host
+# format in ARG2. Otherwise, emit an error message, but continue (resetting
+# func_to_host_file_result to ARG1).
+func_convert_file_check ()
+{
+  $opt_debug
+  if test -z "$2" && test -n "$1" ; then
+    func_error "Could not determine host file name corresponding to"
+    func_error "  \`$1'"
+    func_error "Continuing, but uninstalled executables may not work."
+    # Fallback:
+    func_to_host_file_result="$1"
+  fi
+}
+# end func_convert_file_check
+
+
+# func_convert_path_check FROM_PATHSEP TO_PATHSEP FROM_PATH TO_PATH
+# Verify that FROM_PATH (a path in $build format) was converted to $host
+# format in TO_PATH. Otherwise, emit an error message, but continue, resetting
+# func_to_host_file_result to a simplistic fallback value (see below).
+func_convert_path_check ()
+{
+  $opt_debug
+  if test -z "$4" && test -n "$3"; then
+    func_error "Could not determine the host path corresponding to"
+    func_error "  \`$3'"
+    func_error "Continuing, but uninstalled executables may not work."
+    # Fallback.  This is a deliberately simplistic "conversion" and
+    # should not be "improved".  See libtool.info.
+    if test "x$1" != "x$2"; then
+      lt_replace_pathsep_chars="s|$1|$2|g"
+      func_to_host_path_result=`echo "$3" |
+        $SED -e "$lt_replace_pathsep_chars"`
+    else
+      func_to_host_path_result="$3"
+    fi
+  fi
+}
+# end func_convert_path_check
+
+
+# func_convert_path_front_back_pathsep FRONTPAT BACKPAT REPL ORIG
+# Modifies func_to_host_path_result by prepending REPL if ORIG matches FRONTPAT
+# and appending REPL if ORIG matches BACKPAT.
+func_convert_path_front_back_pathsep ()
+{
+  $opt_debug
+  case $4 in
+  $1 ) func_to_host_path_result="$3$func_to_host_path_result"
+    ;;
+  esac
+  case $4 in
+  $2 ) func_append func_to_host_path_result "$3"
+    ;;
+  esac
+}
+# end func_convert_path_front_back_pathsep
+
+
+##################################################
+# $build to $host FILE NAME CONVERSION FUNCTIONS #
+##################################################
+# invoked via `$to_host_file_cmd ARG'
+#
+# In each case, ARG is the path to be converted from $build to $host format.
+# Result will be available in $func_to_host_file_result.
+
+
+# func_to_host_file ARG
+# Converts the file name ARG from $build format to $host format. Return result
+# in func_to_host_file_result.
+func_to_host_file ()
+{
+  $opt_debug
+  $to_host_file_cmd "$1"
+}
+# end func_to_host_file
+
+
+# func_to_tool_file ARG LAZY
+# converts the file name ARG from $build format to toolchain format. Return
+# result in func_to_tool_file_result.  If the conversion in use is listed
+# in (the comma separated) LAZY, no conversion takes place.
+func_to_tool_file ()
+{
+  $opt_debug
+  case ,$2, in
+    *,"$to_tool_file_cmd",*)
+      func_to_tool_file_result=$1
+      ;;
+    *)
+      $to_tool_file_cmd "$1"
+      func_to_tool_file_result=$func_to_host_file_result
+      ;;
+  esac
+}
+# end func_to_tool_file
+
+
+# func_convert_file_noop ARG
+# Copy ARG to func_to_host_file_result.
+func_convert_file_noop ()
+{
+  func_to_host_file_result="$1"
+}
+# end func_convert_file_noop
+
+
+# func_convert_file_msys_to_w32 ARG
+# Convert file name ARG from (mingw) MSYS to (mingw) w32 format; automatic
+# conversion to w32 is not available inside the cwrapper.  Returns result in
+# func_to_host_file_result.
+func_convert_file_msys_to_w32 ()
+{
+  $opt_debug
+  func_to_host_file_result="$1"
+  if test -n "$1"; then
+    func_convert_core_msys_to_w32 "$1"
+    func_to_host_file_result="$func_convert_core_msys_to_w32_result"
+  fi
+  func_convert_file_check "$1" "$func_to_host_file_result"
+}
+# end func_convert_file_msys_to_w32
+
+
+# func_convert_file_cygwin_to_w32 ARG
+# Convert file name ARG from Cygwin to w32 format.  Returns result in
+# func_to_host_file_result.
+func_convert_file_cygwin_to_w32 ()
+{
+  $opt_debug
+  func_to_host_file_result="$1"
+  if test -n "$1"; then
+    # because $build is cygwin, we call "the" cygpath in $PATH; no need to use
+    # LT_CYGPATH in this case.
+    func_to_host_file_result=`cygpath -m "$1"`
+  fi
+  func_convert_file_check "$1" "$func_to_host_file_result"
+}
+# end func_convert_file_cygwin_to_w32
+
+
+# func_convert_file_nix_to_w32 ARG
+# Convert file name ARG from *nix to w32 format.  Requires a wine environment
+# and a working winepath. Returns result in func_to_host_file_result.
+func_convert_file_nix_to_w32 ()
+{
+  $opt_debug
+  func_to_host_file_result="$1"
+  if test -n "$1"; then
+    func_convert_core_file_wine_to_w32 "$1"
+    func_to_host_file_result="$func_convert_core_file_wine_to_w32_result"
+  fi
+  func_convert_file_check "$1" "$func_to_host_file_result"
+}
+# end func_convert_file_nix_to_w32
+
+
+# func_convert_file_msys_to_cygwin ARG
+# Convert file name ARG from MSYS to Cygwin format.  Requires LT_CYGPATH set.
+# Returns result in func_to_host_file_result.
+func_convert_file_msys_to_cygwin ()
+{
+  $opt_debug
+  func_to_host_file_result="$1"
+  if test -n "$1"; then
+    func_convert_core_msys_to_w32 "$1"
+    func_cygpath -u "$func_convert_core_msys_to_w32_result"
+    func_to_host_file_result="$func_cygpath_result"
+  fi
+  func_convert_file_check "$1" "$func_to_host_file_result"
+}
+# end func_convert_file_msys_to_cygwin
+
+
+# func_convert_file_nix_to_cygwin ARG
+# Convert file name ARG from *nix to Cygwin format.  Requires Cygwin installed
+# in a wine environment, working winepath, and LT_CYGPATH set.  Returns result
+# in func_to_host_file_result.
+func_convert_file_nix_to_cygwin ()
+{
+  $opt_debug
+  func_to_host_file_result="$1"
+  if test -n "$1"; then
+    # convert from *nix to w32, then use cygpath to convert from w32 to cygwin.
+    func_convert_core_file_wine_to_w32 "$1"
+    func_cygpath -u "$func_convert_core_file_wine_to_w32_result"
+    func_to_host_file_result="$func_cygpath_result"
+  fi
+  func_convert_file_check "$1" "$func_to_host_file_result"
+}
+# end func_convert_file_nix_to_cygwin
+
+
+#############################################
+# $build to $host PATH CONVERSION FUNCTIONS #
+#############################################
+# invoked via `$to_host_path_cmd ARG'
+#
+# In each case, ARG is the path to be converted from $build to $host format.
+# The result will be available in $func_to_host_path_result.
+#
+# Path separators are also converted from $build format to $host format.  If
+# ARG begins or ends with a path separator character, it is preserved (but
+# converted to $host format) on output.
+#
+# All path conversion functions are named using the following convention:
+#   file name conversion function    : func_convert_file_X_to_Y ()
+#   path conversion function         : func_convert_path_X_to_Y ()
+# where, for any given $build/$host combination the 'X_to_Y' value is the
+# same.  If conversion functions are added for new $build/$host combinations,
+# the two new functions must follow this pattern, or func_init_to_host_path_cmd
+# will break.
+
+
+# func_init_to_host_path_cmd
+# Ensures that function "pointer" variable $to_host_path_cmd is set to the
+# appropriate value, based on the value of $to_host_file_cmd.
+to_host_path_cmd=
+func_init_to_host_path_cmd ()
+{
+  $opt_debug
+  if test -z "$to_host_path_cmd"; then
+    func_stripname 'func_convert_file_' '' "$to_host_file_cmd"
+    to_host_path_cmd="func_convert_path_${func_stripname_result}"
+  fi
+}
+
+
+# func_to_host_path ARG
+# Converts the path ARG from $build format to $host format. Return result
+# in func_to_host_path_result.
+func_to_host_path ()
+{
+  $opt_debug
+  func_init_to_host_path_cmd
+  $to_host_path_cmd "$1"
+}
+# end func_to_host_path
+
+
+# func_convert_path_noop ARG
+# Copy ARG to func_to_host_path_result.
+func_convert_path_noop ()
+{
+  func_to_host_path_result="$1"
+}
+# end func_convert_path_noop
+
+
+# func_convert_path_msys_to_w32 ARG
+# Convert path ARG from (mingw) MSYS to (mingw) w32 format; automatic
+# conversion to w32 is not available inside the cwrapper.  Returns result in
+# func_to_host_path_result.
+func_convert_path_msys_to_w32 ()
+{
+  $opt_debug
+  func_to_host_path_result="$1"
+  if test -n "$1"; then
+    # Remove leading and trailing path separator characters from ARG.  MSYS
+    # behavior is inconsistent here; cygpath turns them into '.;' and ';.';
+    # and winepath ignores them completely.
+    func_stripname : : "$1"
+    func_to_host_path_tmp1=$func_stripname_result
+    func_convert_core_msys_to_w32 "$func_to_host_path_tmp1"
+    func_to_host_path_result="$func_convert_core_msys_to_w32_result"
+    func_convert_path_check : ";" \
+      "$func_to_host_path_tmp1" "$func_to_host_path_result"
+    func_convert_path_front_back_pathsep ":*" "*:" ";" "$1"
+  fi
+}
+# end func_convert_path_msys_to_w32
+
+
+# func_convert_path_cygwin_to_w32 ARG
+# Convert path ARG from Cygwin to w32 format.  Returns result in
+# func_to_host_file_result.
+func_convert_path_cygwin_to_w32 ()
+{
+  $opt_debug
+  func_to_host_path_result="$1"
+  if test -n "$1"; then
+    # See func_convert_path_msys_to_w32:
+    func_stripname : : "$1"
+    func_to_host_path_tmp1=$func_stripname_result
+    func_to_host_path_result=`cygpath -m -p "$func_to_host_path_tmp1"`
+    func_convert_path_check : ";" \
+      "$func_to_host_path_tmp1" "$func_to_host_path_result"
+    func_convert_path_front_back_pathsep ":*" "*:" ";" "$1"
+  fi
+}
+# end func_convert_path_cygwin_to_w32
+
+
+# func_convert_path_nix_to_w32 ARG
+# Convert path ARG from *nix to w32 format.  Requires a wine environment and
+# a working winepath.  Returns result in func_to_host_file_result.
+func_convert_path_nix_to_w32 ()
+{
+  $opt_debug
+  func_to_host_path_result="$1"
+  if test -n "$1"; then
+    # See func_convert_path_msys_to_w32:
+    func_stripname : : "$1"
+    func_to_host_path_tmp1=$func_stripname_result
+    func_convert_core_path_wine_to_w32 "$func_to_host_path_tmp1"
+    func_to_host_path_result="$func_convert_core_path_wine_to_w32_result"
+    func_convert_path_check : ";" \
+      "$func_to_host_path_tmp1" "$func_to_host_path_result"
+    func_convert_path_front_back_pathsep ":*" "*:" ";" "$1"
+  fi
+}
+# end func_convert_path_nix_to_w32
+
+
+# func_convert_path_msys_to_cygwin ARG
+# Convert path ARG from MSYS to Cygwin format.  Requires LT_CYGPATH set.
+# Returns result in func_to_host_file_result.
+func_convert_path_msys_to_cygwin ()
+{
+  $opt_debug
+  func_to_host_path_result="$1"
+  if test -n "$1"; then
+    # See func_convert_path_msys_to_w32:
+    func_stripname : : "$1"
+    func_to_host_path_tmp1=$func_stripname_result
+    func_convert_core_msys_to_w32 "$func_to_host_path_tmp1"
+    func_cygpath -u -p "$func_convert_core_msys_to_w32_result"
+    func_to_host_path_result="$func_cygpath_result"
+    func_convert_path_check : : \
+      "$func_to_host_path_tmp1" "$func_to_host_path_result"
+    func_convert_path_front_back_pathsep ":*" "*:" : "$1"
+  fi
+}
+# end func_convert_path_msys_to_cygwin
+
+
+# func_convert_path_nix_to_cygwin ARG
+# Convert path ARG from *nix to Cygwin format.  Requires Cygwin installed in a
+# a wine environment, working winepath, and LT_CYGPATH set.  Returns result in
+# func_to_host_file_result.
+func_convert_path_nix_to_cygwin ()
+{
+  $opt_debug
+  func_to_host_path_result="$1"
+  if test -n "$1"; then
+    # Remove leading and trailing path separator characters from
+    # ARG. msys behavior is inconsistent here, cygpath turns them
+    # into '.;' and ';.', and winepath ignores them completely.
+    func_stripname : : "$1"
+    func_to_host_path_tmp1=$func_stripname_result
+    func_convert_core_path_wine_to_w32 "$func_to_host_path_tmp1"
+    func_cygpath -u -p "$func_convert_core_path_wine_to_w32_result"
+    func_to_host_path_result="$func_cygpath_result"
+    func_convert_path_check : : \
+      "$func_to_host_path_tmp1" "$func_to_host_path_result"
+    func_convert_path_front_back_pathsep ":*" "*:" : "$1"
+  fi
+}
+# end func_convert_path_nix_to_cygwin
+
+
+# func_mode_compile arg...
+func_mode_compile ()
+{
+    $opt_debug
+    # Get the compilation command and the source file.
+    base_compile=
+    srcfile="$nonopt"  #  always keep a non-empty value in "srcfile"
+    suppress_opt=yes
+    suppress_output=
+    arg_mode=normal
+    libobj=
+    later=
+    pie_flag=
+
+    for arg
+    do
+      case $arg_mode in
+      arg  )
+	# do not "continue".  Instead, add this to base_compile
+	lastarg="$arg"
+	arg_mode=normal
+	;;
+
+      target )
+	libobj="$arg"
+	arg_mode=normal
+	continue
+	;;
+
+      normal )
+	# Accept any command-line options.
+	case $arg in
+	-o)
+	  test -n "$libobj" && \
+	    func_fatal_error "you cannot specify \`-o' more than once"
+	  arg_mode=target
+	  continue
+	  ;;
+
+	-pie | -fpie | -fPIE)
+          func_append pie_flag " $arg"
+	  continue
+	  ;;
+
+	-shared | -static | -prefer-pic | -prefer-non-pic)
+	  func_append later " $arg"
+	  continue
+	  ;;
+
+	-no-suppress)
+	  suppress_opt=no
+	  continue
+	  ;;
+
+	-Xcompiler)
+	  arg_mode=arg  #  the next one goes into the "base_compile" arg list
+	  continue      #  The current "srcfile" will either be retained or
+	  ;;            #  replaced later.  I would guess that would be a bug.
+
+	-Wc,*)
+	  func_stripname '-Wc,' '' "$arg"
+	  args=$func_stripname_result
+	  lastarg=
+	  save_ifs="$IFS"; IFS=','
+	  for arg in $args; do
+	    IFS="$save_ifs"
+	    func_append_quoted lastarg "$arg"
+	  done
+	  IFS="$save_ifs"
+	  func_stripname ' ' '' "$lastarg"
+	  lastarg=$func_stripname_result
+
+	  # Add the arguments to base_compile.
+	  func_append base_compile " $lastarg"
+	  continue
+	  ;;
+
+	*)
+	  # Accept the current argument as the source file.
+	  # The previous "srcfile" becomes the current argument.
+	  #
+	  lastarg="$srcfile"
+	  srcfile="$arg"
+	  ;;
+	esac  #  case $arg
+	;;
+      esac    #  case $arg_mode
+
+      # Aesthetically quote the previous argument.
+      func_append_quoted base_compile "$lastarg"
+    done # for arg
+
+    case $arg_mode in
+    arg)
+      func_fatal_error "you must specify an argument for -Xcompile"
+      ;;
+    target)
+      func_fatal_error "you must specify a target with \`-o'"
+      ;;
+    *)
+      # Get the name of the library object.
+      test -z "$libobj" && {
+	func_basename "$srcfile"
+	libobj="$func_basename_result"
+      }
+      ;;
+    esac
+
+    # Recognize several different file suffixes.
+    # If the user specifies -o file.o, it is replaced with file.lo
+    case $libobj in
+    *.[cCFSifmso] | \
+    *.ada | *.adb | *.ads | *.asm | \
+    *.c++ | *.cc | *.ii | *.class | *.cpp | *.cxx | \
+    *.[fF][09]? | *.for | *.java | *.go | *.obj | *.sx | *.cu | *.cup)
+      func_xform "$libobj"
+      libobj=$func_xform_result
+      ;;
+    esac
+
+    case $libobj in
+    *.lo) func_lo2o "$libobj"; obj=$func_lo2o_result ;;
+    *)
+      func_fatal_error "cannot determine name of library object from \`$libobj'"
+      ;;
+    esac
+
+    func_infer_tag $base_compile
+
+    for arg in $later; do
+      case $arg in
+      -shared)
+	test "$build_libtool_libs" != yes && \
+	  func_fatal_configuration "can not build a shared library"
+	build_old_libs=no
+	continue
+	;;
+
+      -static)
+	build_libtool_libs=no
+	build_old_libs=yes
+	continue
+	;;
+
+      -prefer-pic)
+	pic_mode=yes
+	continue
+	;;
+
+      -prefer-non-pic)
+	pic_mode=no
+	continue
+	;;
+      esac
+    done
+
+    func_quote_for_eval "$libobj"
+    test "X$libobj" != "X$func_quote_for_eval_result" \
+      && $ECHO "X$libobj" | $GREP '[]~#^*{};<>?"'"'"'	 &()|`$[]' \
+      && func_warning "libobj name \`$libobj' may not contain shell special characters."
+    func_dirname_and_basename "$obj" "/" ""
+    objname="$func_basename_result"
+    xdir="$func_dirname_result"
+    lobj=${xdir}$objdir/$objname
+
+    test -z "$base_compile" && \
+      func_fatal_help "you must specify a compilation command"
+
+    # Delete any leftover library objects.
+    if test "$build_old_libs" = yes; then
+      removelist="$obj $lobj $libobj ${libobj}T"
+    else
+      removelist="$lobj $libobj ${libobj}T"
+    fi
+
+    # On Cygwin there's no "real" PIC flag so we must build both object types
+    case $host_os in
+    cygwin* | mingw* | pw32* | os2* | cegcc*)
+      pic_mode=default
+      ;;
+    esac
+    if test "$pic_mode" = no && test "$deplibs_check_method" != pass_all; then
+      # non-PIC code in shared libraries is not supported
+      pic_mode=default
+    fi
+
+    # Calculate the filename of the output object if compiler does
+    # not support -o with -c
+    if test "$compiler_c_o" = no; then
+      output_obj=`$ECHO "$srcfile" | $SED 's%^.*/%%; s%\.[^.]*$%%'`.${objext}
+      lockfile="$output_obj.lock"
+    else
+      output_obj=
+      need_locks=no
+      lockfile=
+    fi
+
+    # Lock this critical section if it is needed
+    # We use this script file to make the link, it avoids creating a new file
+    if test "$need_locks" = yes; then
+      until $opt_dry_run || ln "$progpath" "$lockfile" 2>/dev/null; do
+	func_echo "Waiting for $lockfile to be removed"
+	sleep 2
+      done
+    elif test "$need_locks" = warn; then
+      if test -f "$lockfile"; then
+	$ECHO "\
+*** ERROR, $lockfile exists and contains:
+`cat $lockfile 2>/dev/null`
+
+This indicates that another process is trying to use the same
+temporary object file, and libtool could not work around it because
+your compiler does not support \`-c' and \`-o' together.  If you
+repeat this compilation, it may succeed, by chance, but you had better
+avoid parallel builds (make -j) in this platform, or get a better
+compiler."
+
+	$opt_dry_run || $RM $removelist
+	exit $EXIT_FAILURE
+      fi
+      func_append removelist " $output_obj"
+      $ECHO "$srcfile" > "$lockfile"
+    fi
+
+    $opt_dry_run || $RM $removelist
+    func_append removelist " $lockfile"
+    trap '$opt_dry_run || $RM $removelist; exit $EXIT_FAILURE' 1 2 15
+
+    func_to_tool_file "$srcfile" func_convert_file_msys_to_w32
+    srcfile=$func_to_tool_file_result
+    func_quote_for_eval "$srcfile"
+    qsrcfile=$func_quote_for_eval_result
+
+    # Only build a PIC object if we are building libtool libraries.
+    if test "$build_libtool_libs" = yes; then
+      # Without this assignment, base_compile gets emptied.
+      fbsd_hideous_sh_bug=$base_compile
+
+      if test "$pic_mode" != no; then
+	command="$base_compile $qsrcfile $pic_flag"
+      else
+	# Don't build PIC code
+	command="$base_compile $qsrcfile"
+      fi
+
+      func_mkdir_p "$xdir$objdir"
+
+      if test -z "$output_obj"; then
+	# Place PIC objects in $objdir
+	func_append command " -o $lobj"
+      fi
+
+      func_show_eval_locale "$command"	\
+          'test -n "$output_obj" && $RM $removelist; exit $EXIT_FAILURE'
+
+      if test "$need_locks" = warn &&
+	 test "X`cat $lockfile 2>/dev/null`" != "X$srcfile"; then
+	$ECHO "\
+*** ERROR, $lockfile contains:
+`cat $lockfile 2>/dev/null`
+
+but it should contain:
+$srcfile
+
+This indicates that another process is trying to use the same
+temporary object file, and libtool could not work around it because
+your compiler does not support \`-c' and \`-o' together.  If you
+repeat this compilation, it may succeed, by chance, but you had better
+avoid parallel builds (make -j) in this platform, or get a better
+compiler."
+
+	$opt_dry_run || $RM $removelist
+	exit $EXIT_FAILURE
+      fi
+
+      # Just move the object if needed, then go on to compile the next one
+      if test -n "$output_obj" && test "X$output_obj" != "X$lobj"; then
+	func_show_eval '$MV "$output_obj" "$lobj"' \
+	  'error=$?; $opt_dry_run || $RM $removelist; exit $error'
+      fi
+
+      # Allow error messages only from the first compilation.
+      if test "$suppress_opt" = yes; then
+	suppress_output=' >/dev/null 2>&1'
+      fi
+    fi
+
+    # Only build a position-dependent object if we build old libraries.
+    if test "$build_old_libs" = yes; then
+      if test "$pic_mode" != yes; then
+	# Don't build PIC code
+	command="$base_compile $qsrcfile$pie_flag"
+      else
+	command="$base_compile $qsrcfile $pic_flag"
+      fi
+      if test "$compiler_c_o" = yes; then
+	func_append command " -o $obj"
+      fi
+
+      # Suppress compiler output if we already did a PIC compilation.
+      func_append command "$suppress_output"
+      func_show_eval_locale "$command" \
+        '$opt_dry_run || $RM $removelist; exit $EXIT_FAILURE'
+
+      if test "$need_locks" = warn &&
+	 test "X`cat $lockfile 2>/dev/null`" != "X$srcfile"; then
+	$ECHO "\
+*** ERROR, $lockfile contains:
+`cat $lockfile 2>/dev/null`
+
+but it should contain:
+$srcfile
+
+This indicates that another process is trying to use the same
+temporary object file, and libtool could not work around it because
+your compiler does not support \`-c' and \`-o' together.  If you
+repeat this compilation, it may succeed, by chance, but you had better
+avoid parallel builds (make -j) in this platform, or get a better
+compiler."
+
+	$opt_dry_run || $RM $removelist
+	exit $EXIT_FAILURE
+      fi
+
+      # Just move the object if needed
+      if test -n "$output_obj" && test "X$output_obj" != "X$obj"; then
+	func_show_eval '$MV "$output_obj" "$obj"' \
+	  'error=$?; $opt_dry_run || $RM $removelist; exit $error'
+      fi
+    fi
+
+    $opt_dry_run || {
+      func_write_libtool_object "$libobj" "$objdir/$objname" "$objname"
+
+      # Unlock the critical section if it was locked
+      if test "$need_locks" != no; then
+	removelist=$lockfile
+        $RM "$lockfile"
+      fi
+    }
+
+    exit $EXIT_SUCCESS
+}
+
+$opt_help || {
+  test "$opt_mode" = compile && func_mode_compile ${1+"$@"}
+}
+
+func_mode_help ()
+{
+    # We need to display help for each of the modes.
+    case $opt_mode in
+      "")
+        # Generic help is extracted from the usage comments
+        # at the start of this file.
+        func_help
+        ;;
+
+      clean)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=clean RM [RM-OPTION]... FILE...
+
+Remove files from the build directory.
+
+RM is the name of the program to use to delete files associated with each FILE
+(typically \`/bin/rm').  RM-OPTIONS are options (such as \`-f') to be passed
+to RM.
+
+If FILE is a libtool library, object or program, all the files associated
+with it are deleted. Otherwise, only FILE itself is deleted using RM."
+        ;;
+
+      compile)
+      $ECHO \
+"Usage: $progname [OPTION]... --mode=compile COMPILE-COMMAND... SOURCEFILE
+
+Compile a source file into a libtool library object.
+
+This mode accepts the following additional options:
+
+  -o OUTPUT-FILE    set the output file name to OUTPUT-FILE
+  -no-suppress      do not suppress compiler output for multiple passes
+  -prefer-pic       try to build PIC objects only
+  -prefer-non-pic   try to build non-PIC objects only
+  -shared           do not build a \`.o' file suitable for static linking
+  -static           only build a \`.o' file suitable for static linking
+  -Wc,FLAG          pass FLAG directly to the compiler
+
+COMPILE-COMMAND is a command to be used in creating a \`standard' object file
+from the given SOURCEFILE.
+
+The output file name is determined by removing the directory component from
+SOURCEFILE, then substituting the C source code suffix \`.c' with the
+library object suffix, \`.lo'."
+        ;;
+
+      execute)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=execute COMMAND [ARGS]...
+
+Automatically set library path, then run a program.
+
+This mode accepts the following additional options:
+
+  -dlopen FILE      add the directory containing FILE to the library path
+
+This mode sets the library path environment variable according to \`-dlopen'
+flags.
+
+If any of the ARGS are libtool executable wrappers, then they are translated
+into their corresponding uninstalled binary, and any of their required library
+directories are added to the library path.
+
+Then, COMMAND is executed, with ARGS as arguments."
+        ;;
+
+      finish)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=finish [LIBDIR]...
+
+Complete the installation of libtool libraries.
+
+Each LIBDIR is a directory that contains libtool libraries.
+
+The commands that this mode executes may require superuser privileges.  Use
+the \`--dry-run' option if you just want to see what would be executed."
+        ;;
+
+      install)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=install INSTALL-COMMAND...
+
+Install executables or libraries.
+
+INSTALL-COMMAND is the installation command.  The first component should be
+either the \`install' or \`cp' program.
+
+The following components of INSTALL-COMMAND are treated specially:
+
+  -inst-prefix-dir PREFIX-DIR  Use PREFIX-DIR as a staging area for installation
+
+The rest of the components are interpreted as arguments to that command (only
+BSD-compatible install options are recognized)."
+        ;;
+
+      link)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=link LINK-COMMAND...
+
+Link object files or libraries together to form another library, or to
+create an executable program.
+
+LINK-COMMAND is a command using the C compiler that you would use to create
+a program from several object files.
+
+The following components of LINK-COMMAND are treated specially:
+
+  -all-static       do not do any dynamic linking at all
+  -avoid-version    do not add a version suffix if possible
+  -bindir BINDIR    specify path to binaries directory (for systems where
+                    libraries must be found in the PATH setting at runtime)
+  -dlopen FILE      \`-dlpreopen' FILE if it cannot be dlopened at runtime
+  -dlpreopen FILE   link in FILE and add its symbols to lt_preloaded_symbols
+  -export-dynamic   allow symbols from OUTPUT-FILE to be resolved with dlsym(3)
+  -export-symbols SYMFILE
+                    try to export only the symbols listed in SYMFILE
+  -export-symbols-regex REGEX
+                    try to export only the symbols matching REGEX
+  -LLIBDIR          search LIBDIR for required installed libraries
+  -lNAME            OUTPUT-FILE requires the installed library libNAME
+  -module           build a library that can dlopened
+  -no-fast-install  disable the fast-install mode
+  -no-install       link a not-installable executable
+  -no-undefined     declare that a library does not refer to external symbols
+  -o OUTPUT-FILE    create OUTPUT-FILE from the specified objects
+  -objectlist FILE  Use a list of object files found in FILE to specify objects
+  -precious-files-regex REGEX
+                    don't remove output files matching REGEX
+  -release RELEASE  specify package release information
+  -rpath LIBDIR     the created library will eventually be installed in LIBDIR
+  -R[ ]LIBDIR       add LIBDIR to the runtime path of programs and libraries
+  -shared           only do dynamic linking of libtool libraries
+  -shrext SUFFIX    override the standard shared library file extension
+  -static           do not do any dynamic linking of uninstalled libtool libraries
+  -static-libtool-libs
+                    do not do any dynamic linking of libtool libraries
+  -version-info CURRENT[:REVISION[:AGE]]
+                    specify library version info [each variable defaults to 0]
+  -weak LIBNAME     declare that the target provides the LIBNAME interface
+  -Wc,FLAG
+  -Xcompiler FLAG   pass linker-specific FLAG directly to the compiler
+  -Wl,FLAG
+  -Xlinker FLAG     pass linker-specific FLAG directly to the linker
+  -XCClinker FLAG   pass link-specific FLAG to the compiler driver (CC)
+
+All other options (arguments beginning with \`-') are ignored.
+
+Every other argument is treated as a filename.  Files ending in \`.la' are
+treated as uninstalled libtool libraries, other files are standard or library
+object files.
+
+If the OUTPUT-FILE ends in \`.la', then a libtool library is created,
+only library objects (\`.lo' files) may be specified, and \`-rpath' is
+required, except when creating a convenience library.
+
+If OUTPUT-FILE ends in \`.a' or \`.lib', then a standard library is created
+using \`ar' and \`ranlib', or on Windows using \`lib'.
+
+If OUTPUT-FILE ends in \`.lo' or \`.${objext}', then a reloadable object file
+is created, otherwise an executable program is created."
+        ;;
+
+      uninstall)
+        $ECHO \
+"Usage: $progname [OPTION]... --mode=uninstall RM [RM-OPTION]... FILE...
+
+Remove libraries from an installation directory.
+
+RM is the name of the program to use to delete files associated with each FILE
+(typically \`/bin/rm').  RM-OPTIONS are options (such as \`-f') to be passed
+to RM.
+
+If FILE is a libtool library, all the files associated with it are deleted.
+Otherwise, only FILE itself is deleted using RM."
+        ;;
+
+      *)
+        func_fatal_help "invalid operation mode \`$opt_mode'"
+        ;;
+    esac
+
+    echo
+    $ECHO "Try \`$progname --help' for more information about other modes."
+}
+
+# Now that we've collected a possible --mode arg, show help if necessary
+if $opt_help; then
+  if test "$opt_help" = :; then
+    func_mode_help
+  else
+    {
+      func_help noexit
+      for opt_mode in compile link execute install finish uninstall clean; do
+	func_mode_help
+      done
+    } | sed -n '1p; 2,$s/^Usage:/  or: /p'
+    {
+      func_help noexit
+      for opt_mode in compile link execute install finish uninstall clean; do
+	echo
+	func_mode_help
+      done
+    } |
+    sed '1d
+      /^When reporting/,/^Report/{
+	H
+	d
+      }
+      $x
+      /information about other modes/d
+      /more detailed .*MODE/d
+      s/^Usage:.*--mode=\([^ ]*\) .*/Description of \1 mode:/'
+  fi
+  exit $?
+fi
+
+
+# func_mode_execute arg...
+func_mode_execute ()
+{
+    $opt_debug
+    # The first argument is the command name.
+    cmd="$nonopt"
+    test -z "$cmd" && \
+      func_fatal_help "you must specify a COMMAND"
+
+    # Handle -dlopen flags immediately.
+    for file in $opt_dlopen; do
+      test -f "$file" \
+	|| func_fatal_help "\`$file' is not a file"
+
+      dir=
+      case $file in
+      *.la)
+	func_resolve_sysroot "$file"
+	file=$func_resolve_sysroot_result
+
+	# Check to see that this really is a libtool archive.
+	func_lalib_unsafe_p "$file" \
+	  || func_fatal_help "\`$lib' is not a valid libtool archive"
+
+	# Read the libtool library.
+	dlname=
+	library_names=
+	func_source "$file"
+
+	# Skip this library if it cannot be dlopened.
+	if test -z "$dlname"; then
+	  # Warn if it was a shared library.
+	  test -n "$library_names" && \
+	    func_warning "\`$file' was not linked with \`-export-dynamic'"
+	  continue
+	fi
+
+	func_dirname "$file" "" "."
+	dir="$func_dirname_result"
+
+	if test -f "$dir/$objdir/$dlname"; then
+	  func_append dir "/$objdir"
+	else
+	  if test ! -f "$dir/$dlname"; then
+	    func_fatal_error "cannot find \`$dlname' in \`$dir' or \`$dir/$objdir'"
+	  fi
+	fi
+	;;
+
+      *.lo)
+	# Just add the directory containing the .lo file.
+	func_dirname "$file" "" "."
+	dir="$func_dirname_result"
+	;;
+
+      *)
+	func_warning "\`-dlopen' is ignored for non-libtool libraries and objects"
+	continue
+	;;
+      esac
+
+      # Get the absolute pathname.
+      absdir=`cd "$dir" && pwd`
+      test -n "$absdir" && dir="$absdir"
+
+      # Now add the directory to shlibpath_var.
+      if eval "test -z \"\$$shlibpath_var\""; then
+	eval "$shlibpath_var=\"\$dir\""
+      else
+	eval "$shlibpath_var=\"\$dir:\$$shlibpath_var\""
+      fi
+    done
+
+    # This variable tells wrapper scripts just to set shlibpath_var
+    # rather than running their programs.
+    libtool_execute_magic="$magic"
+
+    # Check if any of the arguments is a wrapper script.
+    args=
+    for file
+    do
+      case $file in
+      -* | *.la | *.lo ) ;;
+      *)
+	# Do a test to see if this is really a libtool program.
+	if func_ltwrapper_script_p "$file"; then
+	  func_source "$file"
+	  # Transform arg to wrapped name.
+	  file="$progdir/$program"
+	elif func_ltwrapper_executable_p "$file"; then
+	  func_ltwrapper_scriptname "$file"
+	  func_source "$func_ltwrapper_scriptname_result"
+	  # Transform arg to wrapped name.
+	  file="$progdir/$program"
+	fi
+	;;
+      esac
+      # Quote arguments (to preserve shell metacharacters).
+      func_append_quoted args "$file"
+    done
+
+    if test "X$opt_dry_run" = Xfalse; then
+      if test -n "$shlibpath_var"; then
+	# Export the shlibpath_var.
+	eval "export $shlibpath_var"
+      fi
+
+      # Restore saved environment variables
+      for lt_var in LANG LANGUAGE LC_ALL LC_CTYPE LC_COLLATE LC_MESSAGES
+      do
+	eval "if test \"\${save_$lt_var+set}\" = set; then
+                $lt_var=\$save_$lt_var; export $lt_var
+	      else
+		$lt_unset $lt_var
+	      fi"
+      done
+
+      # Now prepare to actually exec the command.
+      exec_cmd="\$cmd$args"
+    else
+      # Display what would be done.
+      if test -n "$shlibpath_var"; then
+	eval "\$ECHO \"\$shlibpath_var=\$$shlibpath_var\""
+	echo "export $shlibpath_var"
+      fi
+      $ECHO "$cmd$args"
+      exit $EXIT_SUCCESS
+    fi
+}
+
+test "$opt_mode" = execute && func_mode_execute ${1+"$@"}
+
+
+# func_mode_finish arg...
+func_mode_finish ()
+{
+    $opt_debug
+    libs=
+    libdirs=
+    admincmds=
+
+    for opt in "$nonopt" ${1+"$@"}
+    do
+      if test -d "$opt"; then
+	func_append libdirs " $opt"
+
+      elif test -f "$opt"; then
+	if func_lalib_unsafe_p "$opt"; then
+	  func_append libs " $opt"
+	else
+	  func_warning "\`$opt' is not a valid libtool archive"
+	fi
+
+      else
+	func_fatal_error "invalid argument \`$opt'"
+      fi
+    done
+
+    if test -n "$libs"; then
+      if test -n "$lt_sysroot"; then
+        sysroot_regex=`$ECHO "$lt_sysroot" | $SED "$sed_make_literal_regex"`
+        sysroot_cmd="s/\([ ']\)$sysroot_regex/\1/g;"
+      else
+        sysroot_cmd=
+      fi
+
+      # Remove sysroot references
+      if $opt_dry_run; then
+        for lib in $libs; do
+          echo "removing references to $lt_sysroot and \`=' prefixes from $lib"
+        done
+      else
+        tmpdir=`func_mktempdir`
+        for lib in $libs; do
+	  sed -e "${sysroot_cmd} s/\([ ']-[LR]\)=/\1/g; s/\([ ']\)=/\1/g" $lib \
+	    > $tmpdir/tmp-la
+	  mv -f $tmpdir/tmp-la $lib
+	done
+        ${RM}r "$tmpdir"
+      fi
+    fi
+
+    if test -n "$finish_cmds$finish_eval" && test -n "$libdirs"; then
+      for libdir in $libdirs; do
+	if test -n "$finish_cmds"; then
+	  # Do each command in the finish commands.
+	  func_execute_cmds "$finish_cmds" 'admincmds="$admincmds
+'"$cmd"'"'
+	fi
+	if test -n "$finish_eval"; then
+	  # Do the single finish_eval.
+	  eval cmds=\"$finish_eval\"
+	  $opt_dry_run || eval "$cmds" || func_append admincmds "
+       $cmds"
+	fi
+      done
+    fi
+
+    # Exit here if they wanted silent mode.
+    $opt_silent && exit $EXIT_SUCCESS
+
+    if test -n "$finish_cmds$finish_eval" && test -n "$libdirs"; then
+      echo "----------------------------------------------------------------------"
+      echo "Libraries have been installed in:"
+      for libdir in $libdirs; do
+	$ECHO "   $libdir"
+      done
+      echo
+      echo "If you ever happen to want to link against installed libraries"
+      echo "in a given directory, LIBDIR, you must either use libtool, and"
+      echo "specify the full pathname of the library, or use the \`-LLIBDIR'"
+      echo "flag during linking and do at least one of the following:"
+      if test -n "$shlibpath_var"; then
+	echo "   - add LIBDIR to the \`$shlibpath_var' environment variable"
+	echo "     during execution"
+      fi
+      if test -n "$runpath_var"; then
+	echo "   - add LIBDIR to the \`$runpath_var' environment variable"
+	echo "     during linking"
+      fi
+      if test -n "$hardcode_libdir_flag_spec"; then
+	libdir=LIBDIR
+	eval flag=\"$hardcode_libdir_flag_spec\"
+
+	$ECHO "   - use the \`$flag' linker flag"
+      fi
+      if test -n "$admincmds"; then
+	$ECHO "   - have your system administrator run these commands:$admincmds"
+      fi
+      if test -f /etc/ld.so.conf; then
+	echo "   - have your system administrator add LIBDIR to \`/etc/ld.so.conf'"
+      fi
+      echo
+
+      echo "See any operating system documentation about shared libraries for"
+      case $host in
+	solaris2.[6789]|solaris2.1[0-9])
+	  echo "more information, such as the ld(1), crle(1) and ld.so(8) manual"
+	  echo "pages."
+	  ;;
+	*)
+	  echo "more information, such as the ld(1) and ld.so(8) manual pages."
+	  ;;
+      esac
+      echo "----------------------------------------------------------------------"
+    fi
+    exit $EXIT_SUCCESS
+}
+
+test "$opt_mode" = finish && func_mode_finish ${1+"$@"}
+
+
+# func_mode_install arg...
+func_mode_install ()
+{
+    $opt_debug
+    # There may be an optional sh(1) argument at the beginning of
+    # install_prog (especially on Windows NT).
+    if test "$nonopt" = "$SHELL" || test "$nonopt" = /bin/sh ||
+       # Allow the use of GNU shtool's install command.
+       case $nonopt in *shtool*) :;; *) false;; esac; then
+      # Aesthetically quote it.
+      func_quote_for_eval "$nonopt"
+      install_prog="$func_quote_for_eval_result "
+      arg=$1
+      shift
+    else
+      install_prog=
+      arg=$nonopt
+    fi
+
+    # The real first argument should be the name of the installation program.
+    # Aesthetically quote it.
+    func_quote_for_eval "$arg"
+    func_append install_prog "$func_quote_for_eval_result"
+    install_shared_prog=$install_prog
+    case " $install_prog " in
+      *[\\\ /]cp\ *) install_cp=: ;;
+      *) install_cp=false ;;
+    esac
+
+    # We need to accept at least all the BSD install flags.
+    dest=
+    files=
+    opts=
+    prev=
+    install_type=
+    isdir=no
+    stripme=
+    no_mode=:
+    for arg
+    do
+      arg2=
+      if test -n "$dest"; then
+	func_append files " $dest"
+	dest=$arg
+	continue
+      fi
+
+      case $arg in
+      -d) isdir=yes ;;
+      -f)
+	if $install_cp; then :; else
+	  prev=$arg
+	fi
+	;;
+      -g | -m | -o)
+	prev=$arg
+	;;
+      -s)
+	stripme=" -s"
+	continue
+	;;
+      -*)
+	;;
+      *)
+	# If the previous option needed an argument, then skip it.
+	if test -n "$prev"; then
+	  if test "x$prev" = x-m && test -n "$install_override_mode"; then
+	    arg2=$install_override_mode
+	    no_mode=false
+	  fi
+	  prev=
+	else
+	  dest=$arg
+	  continue
+	fi
+	;;
+      esac
+
+      # Aesthetically quote the argument.
+      func_quote_for_eval "$arg"
+      func_append install_prog " $func_quote_for_eval_result"
+      if test -n "$arg2"; then
+	func_quote_for_eval "$arg2"
+      fi
+      func_append install_shared_prog " $func_quote_for_eval_result"
+    done
+
+    test -z "$install_prog" && \
+      func_fatal_help "you must specify an install program"
+
+    test -n "$prev" && \
+      func_fatal_help "the \`$prev' option requires an argument"
+
+    if test -n "$install_override_mode" && $no_mode; then
+      if $install_cp; then :; else
+	func_quote_for_eval "$install_override_mode"
+	func_append install_shared_prog " -m $func_quote_for_eval_result"
+      fi
+    fi
+
+    if test -z "$files"; then
+      if test -z "$dest"; then
+	func_fatal_help "no file or destination specified"
+      else
+	func_fatal_help "you must specify a destination"
+      fi
+    fi
+
+    # Strip any trailing slash from the destination.
+    func_stripname '' '/' "$dest"
+    dest=$func_stripname_result
+
+    # Check to see that the destination is a directory.
+    test -d "$dest" && isdir=yes
+    if test "$isdir" = yes; then
+      destdir="$dest"
+      destname=
+    else
+      func_dirname_and_basename "$dest" "" "."
+      destdir="$func_dirname_result"
+      destname="$func_basename_result"
+
+      # Not a directory, so check to see that there is only one file specified.
+      set dummy $files; shift
+      test "$#" -gt 1 && \
+	func_fatal_help "\`$dest' is not a directory"
+    fi
+    case $destdir in
+    [\\/]* | [A-Za-z]:[\\/]*) ;;
+    *)
+      for file in $files; do
+	case $file in
+	*.lo) ;;
+	*)
+	  func_fatal_help "\`$destdir' must be an absolute directory name"
+	  ;;
+	esac
+      done
+      ;;
+    esac
+
+    # This variable tells wrapper scripts just to set variables rather
+    # than running their programs.
+    libtool_install_magic="$magic"
+
+    staticlibs=
+    future_libdirs=
+    current_libdirs=
+    for file in $files; do
+
+      # Do each installation.
+      case $file in
+      *.$libext)
+	# Do the static libraries later.
+	func_append staticlibs " $file"
+	;;
+
+      *.la)
+	func_resolve_sysroot "$file"
+	file=$func_resolve_sysroot_result
+
+	# Check to see that this really is a libtool archive.
+	func_lalib_unsafe_p "$file" \
+	  || func_fatal_help "\`$file' is not a valid libtool archive"
+
+	library_names=
+	old_library=
+	relink_command=
+	func_source "$file"
+
+	# Add the libdir to current_libdirs if it is the destination.
+	if test "X$destdir" = "X$libdir"; then
+	  case "$current_libdirs " in
+	  *" $libdir "*) ;;
+	  *) func_append current_libdirs " $libdir" ;;
+	  esac
+	else
+	  # Note the libdir as a future libdir.
+	  case "$future_libdirs " in
+	  *" $libdir "*) ;;
+	  *) func_append future_libdirs " $libdir" ;;
+	  esac
+	fi
+
+	func_dirname "$file" "/" ""
+	dir="$func_dirname_result"
+	func_append dir "$objdir"
+
+	if test -n "$relink_command"; then
+	  # Determine the prefix the user has applied to our future dir.
+	  inst_prefix_dir=`$ECHO "$destdir" | $SED -e "s%$libdir\$%%"`
+
+	  # Don't allow the user to place us outside of our expected
+	  # location b/c this prevents finding dependent libraries that
+	  # are installed to the same prefix.
+	  # At present, this check doesn't affect windows .dll's that
+	  # are installed into $libdir/../bin (currently, that works fine)
+	  # but it's something to keep an eye on.
+	  test "$inst_prefix_dir" = "$destdir" && \
+	    func_fatal_error "error: cannot install \`$file' to a directory not ending in $libdir"
+
+	  if test -n "$inst_prefix_dir"; then
+	    # Stick the inst_prefix_dir data into the link command.
+	    relink_command=`$ECHO "$relink_command" | $SED "s%@inst_prefix_dir@%-inst-prefix-dir $inst_prefix_dir%"`
+	  else
+	    relink_command=`$ECHO "$relink_command" | $SED "s%@inst_prefix_dir@%%"`
+	  fi
+
+	  func_warning "relinking \`$file'"
+	  func_show_eval "$relink_command" \
+	    'func_fatal_error "error: relink \`$file'\'' with the above command before installing it"'
+	fi
+
+	# See the names of the shared library.
+	set dummy $library_names; shift
+	if test -n "$1"; then
+	  realname="$1"
+	  shift
+
+	  srcname="$realname"
+	  test -n "$relink_command" && srcname="$realname"T
+
+	  # Install the shared library and build the symlinks.
+	  func_show_eval "$install_shared_prog $dir/$srcname $destdir/$realname" \
+	      'exit $?'
+	  tstripme="$stripme"
+	  case $host_os in
+	  cygwin* | mingw* | pw32* | cegcc*)
+	    case $realname in
+	    *.dll.a)
+	      tstripme=""
+	      ;;
+	    esac
+	    ;;
+	  esac
+	  if test -n "$tstripme" && test -n "$striplib"; then
+	    func_show_eval "$striplib $destdir/$realname" 'exit $?'
+	  fi
+
+	  if test "$#" -gt 0; then
+	    # Delete the old symlinks, and create new ones.
+	    # Try `ln -sf' first, because the `ln' binary might depend on
+	    # the symlink we replace!  Solaris /bin/ln does not understand -f,
+	    # so we also need to try rm && ln -s.
+	    for linkname
+	    do
+	      test "$linkname" != "$realname" \
+		&& func_show_eval "(cd $destdir && { $LN_S -f $realname $linkname || { $RM $linkname && $LN_S $realname $linkname; }; })"
+	    done
+	  fi
+
+	  # Do each command in the postinstall commands.
+	  lib="$destdir/$realname"
+	  func_execute_cmds "$postinstall_cmds" 'exit $?'
+	fi
+
+	# Install the pseudo-library for information purposes.
+	func_basename "$file"
+	name="$func_basename_result"
+	instname="$dir/$name"i
+	func_show_eval "$install_prog $instname $destdir/$name" 'exit $?'
+
+	# Maybe install the static library, too.
+	test -n "$old_library" && func_append staticlibs " $dir/$old_library"
+	;;
+
+      *.lo)
+	# Install (i.e. copy) a libtool object.
+
+	# Figure out destination file name, if it wasn't already specified.
+	if test -n "$destname"; then
+	  destfile="$destdir/$destname"
+	else
+	  func_basename "$file"
+	  destfile="$func_basename_result"
+	  destfile="$destdir/$destfile"
+	fi
+
+	# Deduce the name of the destination old-style object file.
+	case $destfile in
+	*.lo)
+	  func_lo2o "$destfile"
+	  staticdest=$func_lo2o_result
+	  ;;
+	*.$objext)
+	  staticdest="$destfile"
+	  destfile=
+	  ;;
+	*)
+	  func_fatal_help "cannot copy a libtool object to \`$destfile'"
+	  ;;
+	esac
+
+	# Install the libtool object if requested.
+	test -n "$destfile" && \
+	  func_show_eval "$install_prog $file $destfile" 'exit $?'
+
+	# Install the old object if enabled.
+	if test "$build_old_libs" = yes; then
+	  # Deduce the name of the old-style object file.
+	  func_lo2o "$file"
+	  staticobj=$func_lo2o_result
+	  func_show_eval "$install_prog \$staticobj \$staticdest" 'exit $?'
+	fi
+	exit $EXIT_SUCCESS
+	;;
+
+      *)
+	# Figure out destination file name, if it wasn't already specified.
+	if test -n "$destname"; then
+	  destfile="$destdir/$destname"
+	else
+	  func_basename "$file"
+	  destfile="$func_basename_result"
+	  destfile="$destdir/$destfile"
+	fi
+
+	# If the file is missing, and there is a .exe on the end, strip it
+	# because it is most likely a libtool script we actually want to
+	# install
+	stripped_ext=""
+	case $file in
+	  *.exe)
+	    if test ! -f "$file"; then
+	      func_stripname '' '.exe' "$file"
+	      file=$func_stripname_result
+	      stripped_ext=".exe"
+	    fi
+	    ;;
+	esac
+
+	# Do a test to see if this is really a libtool program.
+	case $host in
+	*cygwin* | *mingw*)
+	    if func_ltwrapper_executable_p "$file"; then
+	      func_ltwrapper_scriptname "$file"
+	      wrapper=$func_ltwrapper_scriptname_result
+	    else
+	      func_stripname '' '.exe' "$file"
+	      wrapper=$func_stripname_result
+	    fi
+	    ;;
+	*)
+	    wrapper=$file
+	    ;;
+	esac
+	if func_ltwrapper_script_p "$wrapper"; then
+	  notinst_deplibs=
+	  relink_command=
+
+	  func_source "$wrapper"
+
+	  # Check the variables that should have been set.
+	  test -z "$generated_by_libtool_version" && \
+	    func_fatal_error "invalid libtool wrapper script \`$wrapper'"
+
+	  finalize=yes
+	  for lib in $notinst_deplibs; do
+	    # Check to see that each library is installed.
+	    libdir=
+	    if test -f "$lib"; then
+	      func_source "$lib"
+	    fi
+	    libfile="$libdir/"`$ECHO "$lib" | $SED 's%^.*/%%g'` ### testsuite: skip nested quoting test
+	    if test -n "$libdir" && test ! -f "$libfile"; then
+	      func_warning "\`$lib' has not been installed in \`$libdir'"
+	      finalize=no
+	    fi
+	  done
+
+	  relink_command=
+	  func_source "$wrapper"
+
+	  outputname=
+	  if test "$fast_install" = no && test -n "$relink_command"; then
+	    $opt_dry_run || {
+	      if test "$finalize" = yes; then
+	        tmpdir=`func_mktempdir`
+		func_basename "$file$stripped_ext"
+		file="$func_basename_result"
+	        outputname="$tmpdir/$file"
+	        # Replace the output file specification.
+	        relink_command=`$ECHO "$relink_command" | $SED 's%@OUTPUT@%'"$outputname"'%g'`
+
+	        $opt_silent || {
+	          func_quote_for_expand "$relink_command"
+		  eval "func_echo $func_quote_for_expand_result"
+	        }
+	        if eval "$relink_command"; then :
+	          else
+		  func_error "error: relink \`$file' with the above command before installing it"
+		  $opt_dry_run || ${RM}r "$tmpdir"
+		  continue
+	        fi
+	        file="$outputname"
+	      else
+	        func_warning "cannot relink \`$file'"
+	      fi
+	    }
+	  else
+	    # Install the binary that we compiled earlier.
+	    file=`$ECHO "$file$stripped_ext" | $SED "s%\([^/]*\)$%$objdir/\1%"`
+	  fi
+	fi
+
+	# remove .exe since cygwin /usr/bin/install will append another
+	# one anyway
+	case $install_prog,$host in
+	*/usr/bin/install*,*cygwin*)
+	  case $file:$destfile in
+	  *.exe:*.exe)
+	    # this is ok
+	    ;;
+	  *.exe:*)
+	    destfile=$destfile.exe
+	    ;;
+	  *:*.exe)
+	    func_stripname '' '.exe' "$destfile"
+	    destfile=$func_stripname_result
+	    ;;
+	  esac
+	  ;;
+	esac
+	func_show_eval "$install_prog\$stripme \$file \$destfile" 'exit $?'
+	$opt_dry_run || if test -n "$outputname"; then
+	  ${RM}r "$tmpdir"
+	fi
+	;;
+      esac
+    done
+
+    for file in $staticlibs; do
+      func_basename "$file"
+      name="$func_basename_result"
+
+      # Set up the ranlib parameters.
+      oldlib="$destdir/$name"
+      func_to_tool_file "$oldlib" func_convert_file_msys_to_w32
+      tool_oldlib=$func_to_tool_file_result
+
+      func_show_eval "$install_prog \$file \$oldlib" 'exit $?'
+
+      if test -n "$stripme" && test -n "$old_striplib"; then
+	func_show_eval "$old_striplib $tool_oldlib" 'exit $?'
+      fi
+
+      # Do each command in the postinstall commands.
+      func_execute_cmds "$old_postinstall_cmds" 'exit $?'
+    done
+
+    test -n "$future_libdirs" && \
+      func_warning "remember to run \`$progname --finish$future_libdirs'"
+
+    if test -n "$current_libdirs"; then
+      # Maybe just do a dry run.
+      $opt_dry_run && current_libdirs=" -n$current_libdirs"
+      exec_cmd='$SHELL $progpath $preserve_args --finish$current_libdirs'
+    else
+      exit $EXIT_SUCCESS
+    fi
+}
+
+test "$opt_mode" = install && func_mode_install ${1+"$@"}
+
+
+# func_generate_dlsyms outputname originator pic_p
+# Extract symbols from dlprefiles and create ${outputname}S.o with
+# a dlpreopen symbol table.
+func_generate_dlsyms ()
+{
+    $opt_debug
+    my_outputname="$1"
+    my_originator="$2"
+    my_pic_p="${3-no}"
+    my_prefix=`$ECHO "$my_originator" | sed 's%[^a-zA-Z0-9]%_%g'`
+    my_dlsyms=
+
+    if test -n "$dlfiles$dlprefiles" || test "$dlself" != no; then
+      if test -n "$NM" && test -n "$global_symbol_pipe"; then
+	my_dlsyms="${my_outputname}S.c"
+      else
+	func_error "not configured to extract global symbols from dlpreopened files"
+      fi
+    fi
+
+    if test -n "$my_dlsyms"; then
+      case $my_dlsyms in
+      "") ;;
+      *.c)
+	# Discover the nlist of each of the dlfiles.
+	nlist="$output_objdir/${my_outputname}.nm"
+
+	func_show_eval "$RM $nlist ${nlist}S ${nlist}T"
+
+	# Parse the name list into a source file.
+	func_verbose "creating $output_objdir/$my_dlsyms"
+
+	$opt_dry_run || $ECHO > "$output_objdir/$my_dlsyms" "\
+/* $my_dlsyms - symbol resolution table for \`$my_outputname' dlsym emulation. */
+/* Generated by $PROGRAM (GNU $PACKAGE$TIMESTAMP) $VERSION */
+
+#ifdef __cplusplus
+extern \"C\" {
+#endif
+
+#if defined(__GNUC__) && (((__GNUC__ == 4) && (__GNUC_MINOR__ >= 4)) || (__GNUC__ > 4))
+#pragma GCC diagnostic ignored \"-Wstrict-prototypes\"
+#endif
+
+/* Keep this code in sync between libtool.m4, ltmain, lt_system.h, and tests.  */
+#if defined(_WIN32) || defined(__CYGWIN__) || defined(_WIN32_WCE)
+/* DATA imports from DLLs on WIN32 con't be const, because runtime
+   relocations are performed -- see ld's documentation on pseudo-relocs.  */
+# define LT_DLSYM_CONST
+#elif defined(__osf__)
+/* This system does not cope well with relocations in const data.  */
+# define LT_DLSYM_CONST
+#else
+# define LT_DLSYM_CONST const
+#endif
+
+/* External symbol declarations for the compiler. */\
+"
+
+	if test "$dlself" = yes; then
+	  func_verbose "generating symbol list for \`$output'"
+
+	  $opt_dry_run || echo ': @PROGRAM@ ' > "$nlist"
+
+	  # Add our own program objects to the symbol list.
+	  progfiles=`$ECHO "$objs$old_deplibs" | $SP2NL | $SED "$lo2o" | $NL2SP`
+	  for progfile in $progfiles; do
+	    func_to_tool_file "$progfile" func_convert_file_msys_to_w32
+	    func_verbose "extracting global C symbols from \`$func_to_tool_file_result'"
+	    $opt_dry_run || eval "$NM $func_to_tool_file_result | $global_symbol_pipe >> '$nlist'"
+	  done
+
+	  if test -n "$exclude_expsyms"; then
+	    $opt_dry_run || {
+	      eval '$EGREP -v " ($exclude_expsyms)$" "$nlist" > "$nlist"T'
+	      eval '$MV "$nlist"T "$nlist"'
+	    }
+	  fi
+
+	  if test -n "$export_symbols_regex"; then
+	    $opt_dry_run || {
+	      eval '$EGREP -e "$export_symbols_regex" "$nlist" > "$nlist"T'
+	      eval '$MV "$nlist"T "$nlist"'
+	    }
+	  fi
+
+	  # Prepare the list of exported symbols
+	  if test -z "$export_symbols"; then
+	    export_symbols="$output_objdir/$outputname.exp"
+	    $opt_dry_run || {
+	      $RM $export_symbols
+	      eval "${SED} -n -e '/^: @PROGRAM@ $/d' -e 's/^.* \(.*\)$/\1/p' "'< "$nlist" > "$export_symbols"'
+	      case $host in
+	      *cygwin* | *mingw* | *cegcc* )
+                eval "echo EXPORTS "'> "$output_objdir/$outputname.def"'
+                eval 'cat "$export_symbols" >> "$output_objdir/$outputname.def"'
+	        ;;
+	      esac
+	    }
+	  else
+	    $opt_dry_run || {
+	      eval "${SED} -e 's/\([].[*^$]\)/\\\\\1/g' -e 's/^/ /' -e 's/$/$/'"' < "$export_symbols" > "$output_objdir/$outputname.exp"'
+	      eval '$GREP -f "$output_objdir/$outputname.exp" < "$nlist" > "$nlist"T'
+	      eval '$MV "$nlist"T "$nlist"'
+	      case $host in
+	        *cygwin* | *mingw* | *cegcc* )
+	          eval "echo EXPORTS "'> "$output_objdir/$outputname.def"'
+	          eval 'cat "$nlist" >> "$output_objdir/$outputname.def"'
+	          ;;
+	      esac
+	    }
+	  fi
+	fi
+
+	for dlprefile in $dlprefiles; do
+	  func_verbose "extracting global C symbols from \`$dlprefile'"
+	  func_basename "$dlprefile"
+	  name="$func_basename_result"
+          case $host in
+	    *cygwin* | *mingw* | *cegcc* )
+	      # if an import library, we need to obtain dlname
+	      if func_win32_import_lib_p "$dlprefile"; then
+	        func_tr_sh "$dlprefile"
+	        eval "curr_lafile=\$libfile_$func_tr_sh_result"
+	        dlprefile_dlbasename=""
+	        if test -n "$curr_lafile" && func_lalib_p "$curr_lafile"; then
+	          # Use subshell, to avoid clobbering current variable values
+	          dlprefile_dlname=`source "$curr_lafile" && echo "$dlname"`
+	          if test -n "$dlprefile_dlname" ; then
+	            func_basename "$dlprefile_dlname"
+	            dlprefile_dlbasename="$func_basename_result"
+	          else
+	            # no lafile. user explicitly requested -dlpreopen <import library>.
+	            $sharedlib_from_linklib_cmd "$dlprefile"
+	            dlprefile_dlbasename=$sharedlib_from_linklib_result
+	          fi
+	        fi
+	        $opt_dry_run || {
+	          if test -n "$dlprefile_dlbasename" ; then
+	            eval '$ECHO ": $dlprefile_dlbasename" >> "$nlist"'
+	          else
+	            func_warning "Could not compute DLL name from $name"
+	            eval '$ECHO ": $name " >> "$nlist"'
+	          fi
+	          func_to_tool_file "$dlprefile" func_convert_file_msys_to_w32
+	          eval "$NM \"$func_to_tool_file_result\" 2>/dev/null | $global_symbol_pipe |
+	            $SED -e '/I __imp/d' -e 's/I __nm_/D /;s/_nm__//' >> '$nlist'"
+	        }
+	      else # not an import lib
+	        $opt_dry_run || {
+	          eval '$ECHO ": $name " >> "$nlist"'
+	          func_to_tool_file "$dlprefile" func_convert_file_msys_to_w32
+	          eval "$NM \"$func_to_tool_file_result\" 2>/dev/null | $global_symbol_pipe >> '$nlist'"
+	        }
+	      fi
+	    ;;
+	    *)
+	      $opt_dry_run || {
+	        eval '$ECHO ": $name " >> "$nlist"'
+	        func_to_tool_file "$dlprefile" func_convert_file_msys_to_w32
+	        eval "$NM \"$func_to_tool_file_result\" 2>/dev/null | $global_symbol_pipe >> '$nlist'"
+	      }
+	    ;;
+          esac
+	done
+
+	$opt_dry_run || {
+	  # Make sure we have at least an empty file.
+	  test -f "$nlist" || : > "$nlist"
+
+	  if test -n "$exclude_expsyms"; then
+	    $EGREP -v " ($exclude_expsyms)$" "$nlist" > "$nlist"T
+	    $MV "$nlist"T "$nlist"
+	  fi
+
+	  # Try sorting and uniquifying the output.
+	  if $GREP -v "^: " < "$nlist" |
+	      if sort -k 3 </dev/null >/dev/null 2>&1; then
+		sort -k 3
+	      else
+		sort +2
+	      fi |
+	      uniq > "$nlist"S; then
+	    :
+	  else
+	    $GREP -v "^: " < "$nlist" > "$nlist"S
+	  fi
+
+	  if test -f "$nlist"S; then
+	    eval "$global_symbol_to_cdecl"' < "$nlist"S >> "$output_objdir/$my_dlsyms"'
+	  else
+	    echo '/* NONE */' >> "$output_objdir/$my_dlsyms"
+	  fi
+
+	  echo >> "$output_objdir/$my_dlsyms" "\
+
+/* The mapping between symbol names and symbols.  */
+typedef struct {
+  const char *name;
+  void *address;
+} lt_dlsymlist;
+extern LT_DLSYM_CONST lt_dlsymlist
+lt_${my_prefix}_LTX_preloaded_symbols[];
+LT_DLSYM_CONST lt_dlsymlist
+lt_${my_prefix}_LTX_preloaded_symbols[] =
+{\
+  { \"$my_originator\", (void *) 0 },"
+
+	  case $need_lib_prefix in
+	  no)
+	    eval "$global_symbol_to_c_name_address" < "$nlist" >> "$output_objdir/$my_dlsyms"
+	    ;;
+	  *)
+	    eval "$global_symbol_to_c_name_address_lib_prefix" < "$nlist" >> "$output_objdir/$my_dlsyms"
+	    ;;
+	  esac
+	  echo >> "$output_objdir/$my_dlsyms" "\
+  {0, (void *) 0}
+};
+
+/* This works around a problem in FreeBSD linker */
+#ifdef FREEBSD_WORKAROUND
+static const void *lt_preloaded_setup() {
+  return lt_${my_prefix}_LTX_preloaded_symbols;
+}
+#endif
+
+#ifdef __cplusplus
+}
+#endif\
+"
+	} # !$opt_dry_run
+
+	pic_flag_for_symtable=
+	case "$compile_command " in
+	*" -static "*) ;;
+	*)
+	  case $host in
+	  # compiling the symbol table file with pic_flag works around
+	  # a FreeBSD bug that causes programs to crash when -lm is
+	  # linked before any other PIC object.  But we must not use
+	  # pic_flag when linking with -static.  The problem exists in
+	  # FreeBSD 2.2.6 and is fixed in FreeBSD 3.1.
+	  *-*-freebsd2.*|*-*-freebsd3.0*|*-*-freebsdelf3.0*)
+	    pic_flag_for_symtable=" $pic_flag -DFREEBSD_WORKAROUND" ;;
+	  *-*-hpux*)
+	    pic_flag_for_symtable=" $pic_flag"  ;;
+	  *)
+	    if test "X$my_pic_p" != Xno; then
+	      pic_flag_for_symtable=" $pic_flag"
+	    fi
+	    ;;
+	  esac
+	  ;;
+	esac
+	symtab_cflags=
+	for arg in $LTCFLAGS; do
+	  case $arg in
+	  -pie | -fpie | -fPIE) ;;
+	  *) func_append symtab_cflags " $arg" ;;
+	  esac
+	done
+
+	# Now compile the dynamic symbol file.
+	func_show_eval '(cd $output_objdir && $LTCC$symtab_cflags -c$no_builtin_flag$pic_flag_for_symtable "$my_dlsyms")' 'exit $?'
+
+	# Clean up the generated files.
+	func_show_eval '$RM "$output_objdir/$my_dlsyms" "$nlist" "${nlist}S" "${nlist}T"'
+
+	# Transform the symbol file into the correct name.
+	symfileobj="$output_objdir/${my_outputname}S.$objext"
+	case $host in
+	*cygwin* | *mingw* | *cegcc* )
+	  if test -f "$output_objdir/$my_outputname.def"; then
+	    compile_command=`$ECHO "$compile_command" | $SED "s%@SYMFILE@%$output_objdir/$my_outputname.def $symfileobj%"`
+	    finalize_command=`$ECHO "$finalize_command" | $SED "s%@SYMFILE@%$output_objdir/$my_outputname.def $symfileobj%"`
+	  else
+	    compile_command=`$ECHO "$compile_command" | $SED "s%@SYMFILE@%$symfileobj%"`
+	    finalize_command=`$ECHO "$finalize_command" | $SED "s%@SYMFILE@%$symfileobj%"`
+	  fi
+	  ;;
+	*)
+	  compile_command=`$ECHO "$compile_command" | $SED "s%@SYMFILE@%$symfileobj%"`
+	  finalize_command=`$ECHO "$finalize_command" | $SED "s%@SYMFILE@%$symfileobj%"`
+	  ;;
+	esac
+	;;
+      *)
+	func_fatal_error "unknown suffix for \`$my_dlsyms'"
+	;;
+      esac
+    else
+      # We keep going just in case the user didn't refer to
+      # lt_preloaded_symbols.  The linker will fail if global_symbol_pipe
+      # really was required.
+
+      # Nullify the symbol file.
+      compile_command=`$ECHO "$compile_command" | $SED "s% @SYMFILE@%%"`
+      finalize_command=`$ECHO "$finalize_command" | $SED "s% @SYMFILE@%%"`
+    fi
+}
+
+# func_win32_libid arg
+# return the library type of file 'arg'
+#
+# Need a lot of goo to handle *both* DLLs and import libs
+# Has to be a shell function in order to 'eat' the argument
+# that is supplied when $file_magic_command is called.
+# Despite the name, also deal with 64 bit binaries.
+func_win32_libid ()
+{
+  $opt_debug
+  win32_libid_type="unknown"
+  win32_fileres=`file -L $1 2>/dev/null`
+  case $win32_fileres in
+  *ar\ archive\ import\ library*) # definitely import
+    win32_libid_type="x86 archive import"
+    ;;
+  *ar\ archive*) # could be an import, or static
+    # Keep the egrep pattern in sync with the one in _LT_CHECK_MAGIC_METHOD.
+    if eval $OBJDUMP -f $1 | $SED -e '10q' 2>/dev/null |
+       $EGREP 'file format (pei*-i386(.*architecture: i386)?|pe-arm-wince|pe-x86-64)' >/dev/null; then
+      func_to_tool_file "$1" func_convert_file_msys_to_w32
+      win32_nmres=`eval $NM -f posix -A \"$func_to_tool_file_result\" |
+	$SED -n -e '
+	    1,100{
+		/ I /{
+		    s,.*,import,
+		    p
+		    q
+		}
+	    }'`
+      case $win32_nmres in
+      import*)  win32_libid_type="x86 archive import";;
+      *)        win32_libid_type="x86 archive static";;
+      esac
+    fi
+    ;;
+  *DLL*)
+    win32_libid_type="x86 DLL"
+    ;;
+  *executable*) # but shell scripts are "executable" too...
+    case $win32_fileres in
+    *MS\ Windows\ PE\ Intel*)
+      win32_libid_type="x86 DLL"
+      ;;
+    esac
+    ;;
+  esac
+  $ECHO "$win32_libid_type"
+}
+
+# func_cygming_dll_for_implib ARG
+#
+# Platform-specific function to extract the
+# name of the DLL associated with the specified
+# import library ARG.
+# Invoked by eval'ing the libtool variable
+#    $sharedlib_from_linklib_cmd
+# Result is available in the variable
+#    $sharedlib_from_linklib_result
+func_cygming_dll_for_implib ()
+{
+  $opt_debug
+  sharedlib_from_linklib_result=`$DLLTOOL --identify-strict --identify "$1"`
+}
+
+# func_cygming_dll_for_implib_fallback_core SECTION_NAME LIBNAMEs
+#
+# The is the core of a fallback implementation of a
+# platform-specific function to extract the name of the
+# DLL associated with the specified import library LIBNAME.
+#
+# SECTION_NAME is either .idata$6 or .idata$7, depending
+# on the platform and compiler that created the implib.
+#
+# Echos the name of the DLL associated with the
+# specified import library.
+func_cygming_dll_for_implib_fallback_core ()
+{
+  $opt_debug
+  match_literal=`$ECHO "$1" | $SED "$sed_make_literal_regex"`
+  $OBJDUMP -s --section "$1" "$2" 2>/dev/null |
+    $SED '/^Contents of section '"$match_literal"':/{
+      # Place marker at beginning of archive member dllname section
+      s/.*/====MARK====/
+      p
+      d
+    }
+    # These lines can sometimes be longer than 43 characters, but
+    # are always uninteresting
+    /:[	 ]*file format pe[i]\{,1\}-/d
+    /^In archive [^:]*:/d
+    # Ensure marker is printed
+    /^====MARK====/p
+    # Remove all lines with less than 43 characters
+    /^.\{43\}/!d
+    # From remaining lines, remove first 43 characters
+    s/^.\{43\}//' |
+    $SED -n '
+      # Join marker and all lines until next marker into a single line
+      /^====MARK====/ b para
+      H
+      $ b para
+      b
+      :para
+      x
+      s/\n//g
+      # Remove the marker
+      s/^====MARK====//
+      # Remove trailing dots and whitespace
+      s/[\. \t]*$//
+      # Print
+      /./p' |
+    # we now have a list, one entry per line, of the stringified
+    # contents of the appropriate section of all members of the
+    # archive which possess that section. Heuristic: eliminate
+    # all those which have a first or second character that is
+    # a '.' (that is, objdump's representation of an unprintable
+    # character.) This should work for all archives with less than
+    # 0x302f exports -- but will fail for DLLs whose name actually
+    # begins with a literal '.' or a single character followed by
+    # a '.'.
+    #
+    # Of those that remain, print the first one.
+    $SED -e '/^\./d;/^.\./d;q'
+}
+
+# func_cygming_gnu_implib_p ARG
+# This predicate returns with zero status (TRUE) if
+# ARG is a GNU/binutils-style import library. Returns
+# with nonzero status (FALSE) otherwise.
+func_cygming_gnu_implib_p ()
+{
+  $opt_debug
+  func_to_tool_file "$1" func_convert_file_msys_to_w32
+  func_cygming_gnu_implib_tmp=`$NM "$func_to_tool_file_result" | eval "$global_symbol_pipe" | $EGREP ' (_head_[A-Za-z0-9_]+_[ad]l*|[A-Za-z0-9_]+_[ad]l*_iname)$'`
+  test -n "$func_cygming_gnu_implib_tmp"
+}
+
+# func_cygming_ms_implib_p ARG
+# This predicate returns with zero status (TRUE) if
+# ARG is an MS-style import library. Returns
+# with nonzero status (FALSE) otherwise.
+func_cygming_ms_implib_p ()
+{
+  $opt_debug
+  func_to_tool_file "$1" func_convert_file_msys_to_w32
+  func_cygming_ms_implib_tmp=`$NM "$func_to_tool_file_result" | eval "$global_symbol_pipe" | $GREP '_NULL_IMPORT_DESCRIPTOR'`
+  test -n "$func_cygming_ms_implib_tmp"
+}
+
+# func_cygming_dll_for_implib_fallback ARG
+# Platform-specific function to extract the
+# name of the DLL associated with the specified
+# import library ARG.
+#
+# This fallback implementation is for use when $DLLTOOL
+# does not support the --identify-strict option.
+# Invoked by eval'ing the libtool variable
+#    $sharedlib_from_linklib_cmd
+# Result is available in the variable
+#    $sharedlib_from_linklib_result
+func_cygming_dll_for_implib_fallback ()
+{
+  $opt_debug
+  if func_cygming_gnu_implib_p "$1" ; then
+    # binutils import library
+    sharedlib_from_linklib_result=`func_cygming_dll_for_implib_fallback_core '.idata$7' "$1"`
+  elif func_cygming_ms_implib_p "$1" ; then
+    # ms-generated import library
+    sharedlib_from_linklib_result=`func_cygming_dll_for_implib_fallback_core '.idata$6' "$1"`
+  else
+    # unknown
+    sharedlib_from_linklib_result=""
+  fi
+}
+
+
+# func_extract_an_archive dir oldlib
+func_extract_an_archive ()
+{
+    $opt_debug
+    f_ex_an_ar_dir="$1"; shift
+    f_ex_an_ar_oldlib="$1"
+    if test "$lock_old_archive_extraction" = yes; then
+      lockfile=$f_ex_an_ar_oldlib.lock
+      until $opt_dry_run || ln "$progpath" "$lockfile" 2>/dev/null; do
+	func_echo "Waiting for $lockfile to be removed"
+	sleep 2
+      done
+    fi
+    func_show_eval "(cd \$f_ex_an_ar_dir && $AR x \"\$f_ex_an_ar_oldlib\")" \
+		   'stat=$?; rm -f "$lockfile"; exit $stat'
+    if test "$lock_old_archive_extraction" = yes; then
+      $opt_dry_run || rm -f "$lockfile"
+    fi
+    if ($AR t "$f_ex_an_ar_oldlib" | sort | sort -uc >/dev/null 2>&1); then
+     :
+    else
+      func_fatal_error "object name conflicts in archive: $f_ex_an_ar_dir/$f_ex_an_ar_oldlib"
+    fi
+}
+
+
+# func_extract_archives gentop oldlib ...
+func_extract_archives ()
+{
+    $opt_debug
+    my_gentop="$1"; shift
+    my_oldlibs=${1+"$@"}
+    my_oldobjs=""
+    my_xlib=""
+    my_xabs=""
+    my_xdir=""
+
+    for my_xlib in $my_oldlibs; do
+      # Extract the objects.
+      case $my_xlib in
+	[\\/]* | [A-Za-z]:[\\/]*) my_xabs="$my_xlib" ;;
+	*) my_xabs=`pwd`"/$my_xlib" ;;
+      esac
+      func_basename "$my_xlib"
+      my_xlib="$func_basename_result"
+      my_xlib_u=$my_xlib
+      while :; do
+        case " $extracted_archives " in
+	*" $my_xlib_u "*)
+	  func_arith $extracted_serial + 1
+	  extracted_serial=$func_arith_result
+	  my_xlib_u=lt$extracted_serial-$my_xlib ;;
+	*) break ;;
+	esac
+      done
+      extracted_archives="$extracted_archives $my_xlib_u"
+      my_xdir="$my_gentop/$my_xlib_u"
+
+      func_mkdir_p "$my_xdir"
+
+      case $host in
+      *-darwin*)
+	func_verbose "Extracting $my_xabs"
+	# Do not bother doing anything if just a dry run
+	$opt_dry_run || {
+	  darwin_orig_dir=`pwd`
+	  cd $my_xdir || exit $?
+	  darwin_archive=$my_xabs
+	  darwin_curdir=`pwd`
+	  darwin_base_archive=`basename "$darwin_archive"`
+	  darwin_arches=`$LIPO -info "$darwin_archive" 2>/dev/null | $GREP Architectures 2>/dev/null || true`
+	  if test -n "$darwin_arches"; then
+	    darwin_arches=`$ECHO "$darwin_arches" | $SED -e 's/.*are://'`
+	    darwin_arch=
+	    func_verbose "$darwin_base_archive has multiple architectures $darwin_arches"
+	    for darwin_arch in  $darwin_arches ; do
+	      func_mkdir_p "unfat-$$/${darwin_base_archive}-${darwin_arch}"
+	      $LIPO -thin $darwin_arch -output "unfat-$$/${darwin_base_archive}-${darwin_arch}/${darwin_base_archive}" "${darwin_archive}"
+	      cd "unfat-$$/${darwin_base_archive}-${darwin_arch}"
+	      func_extract_an_archive "`pwd`" "${darwin_base_archive}"
+	      cd "$darwin_curdir"
+	      $RM "unfat-$$/${darwin_base_archive}-${darwin_arch}/${darwin_base_archive}"
+	    done # $darwin_arches
+            ## Okay now we've a bunch of thin objects, gotta fatten them up :)
+	    darwin_filelist=`find unfat-$$ -type f -name \*.o -print -o -name \*.lo -print | $SED -e "$basename" | sort -u`
+	    darwin_file=
+	    darwin_files=
+	    for darwin_file in $darwin_filelist; do
+	      darwin_files=`find unfat-$$ -name $darwin_file -print | sort | $NL2SP`
+	      $LIPO -create -output "$darwin_file" $darwin_files
+	    done # $darwin_filelist
+	    $RM -rf unfat-$$
+	    cd "$darwin_orig_dir"
+	  else
+	    cd $darwin_orig_dir
+	    func_extract_an_archive "$my_xdir" "$my_xabs"
+	  fi # $darwin_arches
+	} # !$opt_dry_run
+	;;
+      *)
+        func_extract_an_archive "$my_xdir" "$my_xabs"
+	;;
+      esac
+      my_oldobjs="$my_oldobjs "`find $my_xdir -name \*.$objext -print -o -name \*.lo -print | sort | $NL2SP`
+    done
+
+    func_extract_archives_result="$my_oldobjs"
+}
+
+
+# func_emit_wrapper [arg=no]
+#
+# Emit a libtool wrapper script on stdout.
+# Don't directly open a file because we may want to
+# incorporate the script contents within a cygwin/mingw
+# wrapper executable.  Must ONLY be called from within
+# func_mode_link because it depends on a number of variables
+# set therein.
+#
+# ARG is the value that the WRAPPER_SCRIPT_BELONGS_IN_OBJDIR
+# variable will take.  If 'yes', then the emitted script
+# will assume that the directory in which it is stored is
+# the $objdir directory.  This is a cygwin/mingw-specific
+# behavior.
+func_emit_wrapper ()
+{
+	func_emit_wrapper_arg1=${1-no}
+
+	$ECHO "\
+#! $SHELL
+
+# $output - temporary wrapper script for $objdir/$outputname
+# Generated by $PROGRAM (GNU $PACKAGE$TIMESTAMP) $VERSION
+#
+# The $output program cannot be directly executed until all the libtool
+# libraries that it depends on are installed.
+#
+# This wrapper script should never be moved out of the build directory.
+# If it is, it will not operate correctly.
+
+# Sed substitution that helps us do robust quoting.  It backslashifies
+# metacharacters that are still active within double-quoted strings.
+sed_quote_subst='$sed_quote_subst'
+
+# Be Bourne compatible
+if test -n \"\${ZSH_VERSION+set}\" && (emulate sh) >/dev/null 2>&1; then
+  emulate sh
+  NULLCMD=:
+  # Zsh 3.x and 4.x performs word splitting on \${1+\"\$@\"}, which
+  # is contrary to our usage.  Disable this feature.
+  alias -g '\${1+\"\$@\"}'='\"\$@\"'
+  setopt NO_GLOB_SUBST
+else
+  case \`(set -o) 2>/dev/null\` in *posix*) set -o posix;; esac
+fi
+BIN_SH=xpg4; export BIN_SH # for Tru64
+DUALCASE=1; export DUALCASE # for MKS sh
+
+# The HP-UX ksh and POSIX shell print the target directory to stdout
+# if CDPATH is set.
+(unset CDPATH) >/dev/null 2>&1 && unset CDPATH
+
+relink_command=\"$relink_command\"
+
+# This environment variable determines our operation mode.
+if test \"\$libtool_install_magic\" = \"$magic\"; then
+  # install mode needs the following variables:
+  generated_by_libtool_version='$macro_version'
+  notinst_deplibs='$notinst_deplibs'
+else
+  # When we are sourced in execute mode, \$file and \$ECHO are already set.
+  if test \"\$libtool_execute_magic\" != \"$magic\"; then
+    file=\"\$0\""
+
+    qECHO=`$ECHO "$ECHO" | $SED "$sed_quote_subst"`
+    $ECHO "\
+
+# A function that is used when there is no print builtin or printf.
+func_fallback_echo ()
+{
+  eval 'cat <<_LTECHO_EOF
+\$1
+_LTECHO_EOF'
+}
+    ECHO=\"$qECHO\"
+  fi
+
+# Very basic option parsing. These options are (a) specific to
+# the libtool wrapper, (b) are identical between the wrapper
+# /script/ and the wrapper /executable/ which is used only on
+# windows platforms, and (c) all begin with the string "--lt-"
+# (application programs are unlikely to have options which match
+# this pattern).
+#
+# There are only two supported options: --lt-debug and
+# --lt-dump-script. There is, deliberately, no --lt-help.
+#
+# The first argument to this parsing function should be the
+# script's $0 value, followed by "$@".
+lt_option_debug=
+func_parse_lt_options ()
+{
+  lt_script_arg0=\$0
+  shift
+  for lt_opt
+  do
+    case \"\$lt_opt\" in
+    --lt-debug) lt_option_debug=1 ;;
+    --lt-dump-script)
+        lt_dump_D=\`\$ECHO \"X\$lt_script_arg0\" | $SED -e 's/^X//' -e 's%/[^/]*$%%'\`
+        test \"X\$lt_dump_D\" = \"X\$lt_script_arg0\" && lt_dump_D=.
+        lt_dump_F=\`\$ECHO \"X\$lt_script_arg0\" | $SED -e 's/^X//' -e 's%^.*/%%'\`
+        cat \"\$lt_dump_D/\$lt_dump_F\"
+        exit 0
+      ;;
+    --lt-*)
+        \$ECHO \"Unrecognized --lt- option: '\$lt_opt'\" 1>&2
+        exit 1
+      ;;
+    esac
+  done
+
+  # Print the debug banner immediately:
+  if test -n \"\$lt_option_debug\"; then
+    echo \"${outputname}:${output}:\${LINENO}: libtool wrapper (GNU $PACKAGE$TIMESTAMP) $VERSION\" 1>&2
+  fi
+}
+
+# Used when --lt-debug. Prints its arguments to stdout
+# (redirection is the responsibility of the caller)
+func_lt_dump_args ()
+{
+  lt_dump_args_N=1;
+  for lt_arg
+  do
+    \$ECHO \"${outputname}:${output}:\${LINENO}: newargv[\$lt_dump_args_N]: \$lt_arg\"
+    lt_dump_args_N=\`expr \$lt_dump_args_N + 1\`
+  done
+}
+
+# Core function for launching the target application
+func_exec_program_core ()
+{
+"
+  case $host in
+  # Backslashes separate directories on plain windows
+  *-*-mingw | *-*-os2* | *-cegcc*)
+    $ECHO "\
+      if test -n \"\$lt_option_debug\"; then
+        \$ECHO \"${outputname}:${output}:\${LINENO}: newargv[0]: \$progdir\\\\\$program\" 1>&2
+        func_lt_dump_args \${1+\"\$@\"} 1>&2
+      fi
+      exec \"\$progdir\\\\\$program\" \${1+\"\$@\"}
+"
+    ;;
+
+  *)
+    $ECHO "\
+      if test -n \"\$lt_option_debug\"; then
+        \$ECHO \"${outputname}:${output}:\${LINENO}: newargv[0]: \$progdir/\$program\" 1>&2
+        func_lt_dump_args \${1+\"\$@\"} 1>&2
+      fi
+      exec \"\$progdir/\$program\" \${1+\"\$@\"}
+"
+    ;;
+  esac
+  $ECHO "\
+      \$ECHO \"\$0: cannot exec \$program \$*\" 1>&2
+      exit 1
+}
+
+# A function to encapsulate launching the target application
+# Strips options in the --lt-* namespace from \$@ and
+# launches target application with the remaining arguments.
+func_exec_program ()
+{
+  case \" \$* \" in
+  *\\ --lt-*)
+    for lt_wr_arg
+    do
+      case \$lt_wr_arg in
+      --lt-*) ;;
+      *) set x \"\$@\" \"\$lt_wr_arg\"; shift;;
+      esac
+      shift
+    done ;;
+  esac
+  func_exec_program_core \${1+\"\$@\"}
+}
+
+  # Parse options
+  func_parse_lt_options \"\$0\" \${1+\"\$@\"}
+
+  # Find the directory that this script lives in.
+  thisdir=\`\$ECHO \"\$file\" | $SED 's%/[^/]*$%%'\`
+  test \"x\$thisdir\" = \"x\$file\" && thisdir=.
+
+  # Follow symbolic links until we get to the real thisdir.
+  file=\`ls -ld \"\$file\" | $SED -n 's/.*-> //p'\`
+  while test -n \"\$file\"; do
+    destdir=\`\$ECHO \"\$file\" | $SED 's%/[^/]*\$%%'\`
+
+    # If there was a directory component, then change thisdir.
+    if test \"x\$destdir\" != \"x\$file\"; then
+      case \"\$destdir\" in
+      [\\\\/]* | [A-Za-z]:[\\\\/]*) thisdir=\"\$destdir\" ;;
+      *) thisdir=\"\$thisdir/\$destdir\" ;;
+      esac
+    fi
+
+    file=\`\$ECHO \"\$file\" | $SED 's%^.*/%%'\`
+    file=\`ls -ld \"\$thisdir/\$file\" | $SED -n 's/.*-> //p'\`
+  done
+
+  # Usually 'no', except on cygwin/mingw when embedded into
+  # the cwrapper.
+  WRAPPER_SCRIPT_BELONGS_IN_OBJDIR=$func_emit_wrapper_arg1
+  if test \"\$WRAPPER_SCRIPT_BELONGS_IN_OBJDIR\" = \"yes\"; then
+    # special case for '.'
+    if test \"\$thisdir\" = \".\"; then
+      thisdir=\`pwd\`
+    fi
+    # remove .libs from thisdir
+    case \"\$thisdir\" in
+    *[\\\\/]$objdir ) thisdir=\`\$ECHO \"\$thisdir\" | $SED 's%[\\\\/][^\\\\/]*$%%'\` ;;
+    $objdir )   thisdir=. ;;
+    esac
+  fi
+
+  # Try to get the absolute directory name.
+  absdir=\`cd \"\$thisdir\" && pwd\`
+  test -n \"\$absdir\" && thisdir=\"\$absdir\"
+"
+
+	if test "$fast_install" = yes; then
+	  $ECHO "\
+  program=lt-'$outputname'$exeext
+  progdir=\"\$thisdir/$objdir\"
+
+  if test ! -f \"\$progdir/\$program\" ||
+     { file=\`ls -1dt \"\$progdir/\$program\" \"\$progdir/../\$program\" 2>/dev/null | ${SED} 1q\`; \\
+       test \"X\$file\" != \"X\$progdir/\$program\"; }; then
+
+    file=\"\$\$-\$program\"
+
+    if test ! -d \"\$progdir\"; then
+      $MKDIR \"\$progdir\"
+    else
+      $RM \"\$progdir/\$file\"
+    fi"
+
+	  $ECHO "\
+
+    # relink executable if necessary
+    if test -n \"\$relink_command\"; then
+      if relink_command_output=\`eval \$relink_command 2>&1\`; then :
+      else
+	$ECHO \"\$relink_command_output\" >&2
+	$RM \"\$progdir/\$file\"
+	exit 1
+      fi
+    fi
+
+    $MV \"\$progdir/\$file\" \"\$progdir/\$program\" 2>/dev/null ||
+    { $RM \"\$progdir/\$program\";
+      $MV \"\$progdir/\$file\" \"\$progdir/\$program\"; }
+    $RM \"\$progdir/\$file\"
+  fi"
+	else
+	  $ECHO "\
+  program='$outputname'
+  progdir=\"\$thisdir/$objdir\"
+"
+	fi
+
+	$ECHO "\
+
+  if test -f \"\$progdir/\$program\"; then"
+
+	# fixup the dll searchpath if we need to.
+	#
+	# Fix the DLL searchpath if we need to.  Do this before prepending
+	# to shlibpath, because on Windows, both are PATH and uninstalled
+	# libraries must come first.
+	if test -n "$dllsearchpath"; then
+	  $ECHO "\
+    # Add the dll search path components to the executable PATH
+    PATH=$dllsearchpath:\$PATH
+"
+	fi
+
+	# Export our shlibpath_var if we have one.
+	if test "$shlibpath_overrides_runpath" = yes && test -n "$shlibpath_var" && test -n "$temp_rpath"; then
+	  $ECHO "\
+    # Add our own library path to $shlibpath_var
+    $shlibpath_var=\"$temp_rpath\$$shlibpath_var\"
+
+    # Some systems cannot cope with colon-terminated $shlibpath_var
+    # The second colon is a workaround for a bug in BeOS R4 sed
+    $shlibpath_var=\`\$ECHO \"\$$shlibpath_var\" | $SED 's/::*\$//'\`
+
+    export $shlibpath_var
+"
+	fi
+
+	$ECHO "\
+    if test \"\$libtool_execute_magic\" != \"$magic\"; then
+      # Run the actual program with our arguments.
+      func_exec_program \${1+\"\$@\"}
+    fi
+  else
+    # The program doesn't exist.
+    \$ECHO \"\$0: error: \\\`\$progdir/\$program' does not exist\" 1>&2
+    \$ECHO \"This script is just a wrapper for \$program.\" 1>&2
+    \$ECHO \"See the $PACKAGE documentation for more information.\" 1>&2
+    exit 1
+  fi
+fi\
+"
+}
+
+
+# func_emit_cwrapperexe_src
+# emit the source code for a wrapper executable on stdout
+# Must ONLY be called from within func_mode_link because
+# it depends on a number of variable set therein.
+func_emit_cwrapperexe_src ()
+{
+	cat <<EOF
+
+/* $cwrappersource - temporary wrapper executable for $objdir/$outputname
+   Generated by $PROGRAM (GNU $PACKAGE$TIMESTAMP) $VERSION
+
+   The $output program cannot be directly executed until all the libtool
+   libraries that it depends on are installed.
+
+   This wrapper executable should never be moved out of the build directory.
+   If it is, it will not operate correctly.
+*/
+EOF
+	    cat <<"EOF"
+#ifdef _MSC_VER
+# define _CRT_SECURE_NO_DEPRECATE 1
+#endif
+#include <stdio.h>
+#include <stdlib.h>
+#ifdef _MSC_VER
+# include <direct.h>
+# include <process.h>
+# include <io.h>
+#else
+# include <unistd.h>
+# include <stdint.h>
+# ifdef __CYGWIN__
+#  include <io.h>
+# endif
+#endif
+#include <malloc.h>
+#include <stdarg.h>
+#include <assert.h>
+#include <string.h>
+#include <ctype.h>
+#include <errno.h>
+#include <fcntl.h>
+#include <sys/stat.h>
+
+/* declarations of non-ANSI functions */
+#if defined(__MINGW32__)
+# ifdef __STRICT_ANSI__
+int _putenv (const char *);
+# endif
+#elif defined(__CYGWIN__)
+# ifdef __STRICT_ANSI__
+char *realpath (const char *, char *);
+int putenv (char *);
+int setenv (const char *, const char *, int);
+# endif
+/* #elif defined (other platforms) ... */
+#endif
+
+/* portability defines, excluding path handling macros */
+#if defined(_MSC_VER)
+# define setmode _setmode
+# define stat    _stat
+# define chmod   _chmod
+# define getcwd  _getcwd
+# define putenv  _putenv
+# define S_IXUSR _S_IEXEC
+# ifndef _INTPTR_T_DEFINED
+#  define _INTPTR_T_DEFINED
+#  define intptr_t int
+# endif
+#elif defined(__MINGW32__)
+# define setmode _setmode
+# define stat    _stat
+# define chmod   _chmod
+# define getcwd  _getcwd
+# define putenv  _putenv
+#elif defined(__CYGWIN__)
+# define HAVE_SETENV
+# define FOPEN_WB "wb"
+/* #elif defined (other platforms) ... */
+#endif
+
+#if defined(PATH_MAX)
+# define LT_PATHMAX PATH_MAX
+#elif defined(MAXPATHLEN)
+# define LT_PATHMAX MAXPATHLEN
+#else
+# define LT_PATHMAX 1024
+#endif
+
+#ifndef S_IXOTH
+# define S_IXOTH 0
+#endif
+#ifndef S_IXGRP
+# define S_IXGRP 0
+#endif
+
+/* path handling portability macros */
+#ifndef DIR_SEPARATOR
+# define DIR_SEPARATOR '/'
+# define PATH_SEPARATOR ':'
+#endif
+
+#if defined (_WIN32) || defined (__MSDOS__) || defined (__DJGPP__) || \
+  defined (__OS2__)
+# define HAVE_DOS_BASED_FILE_SYSTEM
+# define FOPEN_WB "wb"
+# ifndef DIR_SEPARATOR_2
+#  define DIR_SEPARATOR_2 '\\'
+# endif
+# ifndef PATH_SEPARATOR_2
+#  define PATH_SEPARATOR_2 ';'
+# endif
+#endif
+
+#ifndef DIR_SEPARATOR_2
+# define IS_DIR_SEPARATOR(ch) ((ch) == DIR_SEPARATOR)
+#else /* DIR_SEPARATOR_2 */
+# define IS_DIR_SEPARATOR(ch) \
+	(((ch) == DIR_SEPARATOR) || ((ch) == DIR_SEPARATOR_2))
+#endif /* DIR_SEPARATOR_2 */
+
+#ifndef PATH_SEPARATOR_2
+# define IS_PATH_SEPARATOR(ch) ((ch) == PATH_SEPARATOR)
+#else /* PATH_SEPARATOR_2 */
+# define IS_PATH_SEPARATOR(ch) ((ch) == PATH_SEPARATOR_2)
+#endif /* PATH_SEPARATOR_2 */
+
+#ifndef FOPEN_WB
+# define FOPEN_WB "w"
+#endif
+#ifndef _O_BINARY
+# define _O_BINARY 0
+#endif
+
+#define XMALLOC(type, num)      ((type *) xmalloc ((num) * sizeof(type)))
+#define XFREE(stale) do { \
+  if (stale) { free ((void *) stale); stale = 0; } \
+} while (0)
+
+#if defined(LT_DEBUGWRAPPER)
+static int lt_debug = 1;
+#else
+static int lt_debug = 0;
+#endif
+
+const char *program_name = "libtool-wrapper"; /* in case xstrdup fails */
+
+void *xmalloc (size_t num);
+char *xstrdup (const char *string);
+const char *base_name (const char *name);
+char *find_executable (const char *wrapper);
+char *chase_symlinks (const char *pathspec);
+int make_executable (const char *path);
+int check_executable (const char *path);
+char *strendzap (char *str, const char *pat);
+void lt_debugprintf (const char *file, int line, const char *fmt, ...);
+void lt_fatal (const char *file, int line, const char *message, ...);
+static const char *nonnull (const char *s);
+static const char *nonempty (const char *s);
+void lt_setenv (const char *name, const char *value);
+char *lt_extend_str (const char *orig_value, const char *add, int to_end);
+void lt_update_exe_path (const char *name, const char *value);
+void lt_update_lib_path (const char *name, const char *value);
+char **prepare_spawn (char **argv);
+void lt_dump_script (FILE *f);
+EOF
+
+	    cat <<EOF
+volatile const char * MAGIC_EXE = "$magic_exe";
+const char * LIB_PATH_VARNAME = "$shlibpath_var";
+EOF
+
+	    if test "$shlibpath_overrides_runpath" = yes && test -n "$shlibpath_var" && test -n "$temp_rpath"; then
+              func_to_host_path "$temp_rpath"
+	      cat <<EOF
+const char * LIB_PATH_VALUE   = "$func_to_host_path_result";
+EOF
+	    else
+	      cat <<"EOF"
+const char * LIB_PATH_VALUE   = "";
+EOF
+	    fi
+
+	    if test -n "$dllsearchpath"; then
+              func_to_host_path "$dllsearchpath:"
+	      cat <<EOF
+const char * EXE_PATH_VARNAME = "PATH";
+const char * EXE_PATH_VALUE   = "$func_to_host_path_result";
+EOF
+	    else
+	      cat <<"EOF"
+const char * EXE_PATH_VARNAME = "";
+const char * EXE_PATH_VALUE   = "";
+EOF
+	    fi
+
+	    if test "$fast_install" = yes; then
+	      cat <<EOF
+const char * TARGET_PROGRAM_NAME = "lt-$outputname"; /* hopefully, no .exe */
+EOF
+	    else
+	      cat <<EOF
+const char * TARGET_PROGRAM_NAME = "$outputname"; /* hopefully, no .exe */
+EOF
+	    fi
+
+
+	    cat <<"EOF"
+
+#define LTWRAPPER_OPTION_PREFIX         "--lt-"
+
+static const char *ltwrapper_option_prefix = LTWRAPPER_OPTION_PREFIX;
+static const char *dumpscript_opt       = LTWRAPPER_OPTION_PREFIX "dump-script";
+static const char *debug_opt            = LTWRAPPER_OPTION_PREFIX "debug";
+
+int
+main (int argc, char *argv[])
+{
+  char **newargz;
+  int  newargc;
+  char *tmp_pathspec;
+  char *actual_cwrapper_path;
+  char *actual_cwrapper_name;
+  char *target_name;
+  char *lt_argv_zero;
+  intptr_t rval = 127;
+
+  int i;
+
+  program_name = (char *) xstrdup (base_name (argv[0]));
+  newargz = XMALLOC (char *, argc + 1);
+
+  /* very simple arg parsing; don't want to rely on getopt
+   * also, copy all non cwrapper options to newargz, except
+   * argz[0], which is handled differently
+   */
+  newargc=0;
+  for (i = 1; i < argc; i++)
+    {
+      if (strcmp (argv[i], dumpscript_opt) == 0)
+	{
+EOF
+	    case "$host" in
+	      *mingw* | *cygwin* )
+		# make stdout use "unix" line endings
+		echo "          setmode(1,_O_BINARY);"
+		;;
+	      esac
+
+	    cat <<"EOF"
+	  lt_dump_script (stdout);
+	  return 0;
+	}
+      if (strcmp (argv[i], debug_opt) == 0)
+	{
+          lt_debug = 1;
+          continue;
+	}
+      if (strcmp (argv[i], ltwrapper_option_prefix) == 0)
+        {
+          /* however, if there is an option in the LTWRAPPER_OPTION_PREFIX
+             namespace, but it is not one of the ones we know about and
+             have already dealt with, above (inluding dump-script), then
+             report an error. Otherwise, targets might begin to believe
+             they are allowed to use options in the LTWRAPPER_OPTION_PREFIX
+             namespace. The first time any user complains about this, we'll
+             need to make LTWRAPPER_OPTION_PREFIX a configure-time option
+             or a configure.ac-settable value.
+           */
+          lt_fatal (__FILE__, __LINE__,
+		    "unrecognized %s option: '%s'",
+                    ltwrapper_option_prefix, argv[i]);
+        }
+      /* otherwise ... */
+      newargz[++newargc] = xstrdup (argv[i]);
+    }
+  newargz[++newargc] = NULL;
+
+EOF
+	    cat <<EOF
+  /* The GNU banner must be the first non-error debug message */
+  lt_debugprintf (__FILE__, __LINE__, "libtool wrapper (GNU $PACKAGE$TIMESTAMP) $VERSION\n");
+EOF
+	    cat <<"EOF"
+  lt_debugprintf (__FILE__, __LINE__, "(main) argv[0]: %s\n", argv[0]);
+  lt_debugprintf (__FILE__, __LINE__, "(main) program_name: %s\n", program_name);
+
+  tmp_pathspec = find_executable (argv[0]);
+  if (tmp_pathspec == NULL)
+    lt_fatal (__FILE__, __LINE__, "couldn't find %s", argv[0]);
+  lt_debugprintf (__FILE__, __LINE__,
+                  "(main) found exe (before symlink chase) at: %s\n",
+		  tmp_pathspec);
+
+  actual_cwrapper_path = chase_symlinks (tmp_pathspec);
+  lt_debugprintf (__FILE__, __LINE__,
+                  "(main) found exe (after symlink chase) at: %s\n",
+		  actual_cwrapper_path);
+  XFREE (tmp_pathspec);
+
+  actual_cwrapper_name = xstrdup (base_name (actual_cwrapper_path));
+  strendzap (actual_cwrapper_path, actual_cwrapper_name);
+
+  /* wrapper name transforms */
+  strendzap (actual_cwrapper_name, ".exe");
+  tmp_pathspec = lt_extend_str (actual_cwrapper_name, ".exe", 1);
+  XFREE (actual_cwrapper_name);
+  actual_cwrapper_name = tmp_pathspec;
+  tmp_pathspec = 0;
+
+  /* target_name transforms -- use actual target program name; might have lt- prefix */
+  target_name = xstrdup (base_name (TARGET_PROGRAM_NAME));
+  strendzap (target_name, ".exe");
+  tmp_pathspec = lt_extend_str (target_name, ".exe", 1);
+  XFREE (target_name);
+  target_name = tmp_pathspec;
+  tmp_pathspec = 0;
+
+  lt_debugprintf (__FILE__, __LINE__,
+		  "(main) libtool target name: %s\n",
+		  target_name);
+EOF
+
+	    cat <<EOF
+  newargz[0] =
+    XMALLOC (char, (strlen (actual_cwrapper_path) +
+		    strlen ("$objdir") + 1 + strlen (actual_cwrapper_name) + 1));
+  strcpy (newargz[0], actual_cwrapper_path);
+  strcat (newargz[0], "$objdir");
+  strcat (newargz[0], "/");
+EOF
+
+	    cat <<"EOF"
+  /* stop here, and copy so we don't have to do this twice */
+  tmp_pathspec = xstrdup (newargz[0]);
+
+  /* do NOT want the lt- prefix here, so use actual_cwrapper_name */
+  strcat (newargz[0], actual_cwrapper_name);
+
+  /* DO want the lt- prefix here if it exists, so use target_name */
+  lt_argv_zero = lt_extend_str (tmp_pathspec, target_name, 1);
+  XFREE (tmp_pathspec);
+  tmp_pathspec = NULL;
+EOF
+
+	    case $host_os in
+	      mingw*)
+	    cat <<"EOF"
+  {
+    char* p;
+    while ((p = strchr (newargz[0], '\\')) != NULL)
+      {
+	*p = '/';
+      }
+    while ((p = strchr (lt_argv_zero, '\\')) != NULL)
+      {
+	*p = '/';
+      }
+  }
+EOF
+	    ;;
+	    esac
+
+	    cat <<"EOF"
+  XFREE (target_name);
+  XFREE (actual_cwrapper_path);
+  XFREE (actual_cwrapper_name);
+
+  lt_setenv ("BIN_SH", "xpg4"); /* for Tru64 */
+  lt_setenv ("DUALCASE", "1");  /* for MSK sh */
+  /* Update the DLL searchpath.  EXE_PATH_VALUE ($dllsearchpath) must
+     be prepended before (that is, appear after) LIB_PATH_VALUE ($temp_rpath)
+     because on Windows, both *_VARNAMEs are PATH but uninstalled
+     libraries must come first. */
+  lt_update_exe_path (EXE_PATH_VARNAME, EXE_PATH_VALUE);
+  lt_update_lib_path (LIB_PATH_VARNAME, LIB_PATH_VALUE);
+
+  lt_debugprintf (__FILE__, __LINE__, "(main) lt_argv_zero: %s\n",
+		  nonnull (lt_argv_zero));
+  for (i = 0; i < newargc; i++)
+    {
+      lt_debugprintf (__FILE__, __LINE__, "(main) newargz[%d]: %s\n",
+		      i, nonnull (newargz[i]));
+    }
+
+EOF
+
+	    case $host_os in
+	      mingw*)
+		cat <<"EOF"
+  /* execv doesn't actually work on mingw as expected on unix */
+  newargz = prepare_spawn (newargz);
+  rval = _spawnv (_P_WAIT, lt_argv_zero, (const char * const *) newargz);
+  if (rval == -1)
+    {
+      /* failed to start process */
+      lt_debugprintf (__FILE__, __LINE__,
+		      "(main) failed to launch target \"%s\": %s\n",
+		      lt_argv_zero, nonnull (strerror (errno)));
+      return 127;
+    }
+  return rval;
+EOF
+		;;
+	      *)
+		cat <<"EOF"
+  execv (lt_argv_zero, newargz);
+  return rval; /* =127, but avoids unused variable warning */
+EOF
+		;;
+	    esac
+
+	    cat <<"EOF"
+}
+
+void *
+xmalloc (size_t num)
+{
+  void *p = (void *) malloc (num);
+  if (!p)
+    lt_fatal (__FILE__, __LINE__, "memory exhausted");
+
+  return p;
+}
+
+char *
+xstrdup (const char *string)
+{
+  return string ? strcpy ((char *) xmalloc (strlen (string) + 1),
+			  string) : NULL;
+}
+
+const char *
+base_name (const char *name)
+{
+  const char *base;
+
+#if defined (HAVE_DOS_BASED_FILE_SYSTEM)
+  /* Skip over the disk name in MSDOS pathnames. */
+  if (isalpha ((unsigned char) name[0]) && name[1] == ':')
+    name += 2;
+#endif
+
+  for (base = name; *name; name++)
+    if (IS_DIR_SEPARATOR (*name))
+      base = name + 1;
+  return base;
+}
+
+int
+check_executable (const char *path)
+{
+  struct stat st;
+
+  lt_debugprintf (__FILE__, __LINE__, "(check_executable): %s\n",
+                  nonempty (path));
+  if ((!path) || (!*path))
+    return 0;
+
+  if ((stat (path, &st) >= 0)
+      && (st.st_mode & (S_IXUSR | S_IXGRP | S_IXOTH)))
+    return 1;
+  else
+    return 0;
+}
+
+int
+make_executable (const char *path)
+{
+  int rval = 0;
+  struct stat st;
+
+  lt_debugprintf (__FILE__, __LINE__, "(make_executable): %s\n",
+                  nonempty (path));
+  if ((!path) || (!*path))
+    return 0;
+
+  if (stat (path, &st) >= 0)
+    {
+      rval = chmod (path, st.st_mode | S_IXOTH | S_IXGRP | S_IXUSR);
+    }
+  return rval;
+}
+
+/* Searches for the full path of the wrapper.  Returns
+   newly allocated full path name if found, NULL otherwise
+   Does not chase symlinks, even on platforms that support them.
+*/
+char *
+find_executable (const char *wrapper)
+{
+  int has_slash = 0;
+  const char *p;
+  const char *p_next;
+  /* static buffer for getcwd */
+  char tmp[LT_PATHMAX + 1];
+  int tmp_len;
+  char *concat_name;
+
+  lt_debugprintf (__FILE__, __LINE__, "(find_executable): %s\n",
+                  nonempty (wrapper));
+
+  if ((wrapper == NULL) || (*wrapper == '\0'))
+    return NULL;
+
+  /* Absolute path? */
+#if defined (HAVE_DOS_BASED_FILE_SYSTEM)
+  if (isalpha ((unsigned char) wrapper[0]) && wrapper[1] == ':')
+    {
+      concat_name = xstrdup (wrapper);
+      if (check_executable (concat_name))
+	return concat_name;
+      XFREE (concat_name);
+    }
+  else
+    {
+#endif
+      if (IS_DIR_SEPARATOR (wrapper[0]))
+	{
+	  concat_name = xstrdup (wrapper);
+	  if (check_executable (concat_name))
+	    return concat_name;
+	  XFREE (concat_name);
+	}
+#if defined (HAVE_DOS_BASED_FILE_SYSTEM)
+    }
+#endif
+
+  for (p = wrapper; *p; p++)
+    if (*p == '/')
+      {
+	has_slash = 1;
+	break;
+      }
+  if (!has_slash)
+    {
+      /* no slashes; search PATH */
+      const char *path = getenv ("PATH");
+      if (path != NULL)
+	{
+	  for (p = path; *p; p = p_next)
+	    {
+	      const char *q;
+	      size_t p_len;
+	      for (q = p; *q; q++)
+		if (IS_PATH_SEPARATOR (*q))
+		  break;
+	      p_len = q - p;
+	      p_next = (*q == '\0' ? q : q + 1);
+	      if (p_len == 0)
+		{
+		  /* empty path: current directory */
+		  if (getcwd (tmp, LT_PATHMAX) == NULL)
+		    lt_fatal (__FILE__, __LINE__, "getcwd failed: %s",
+                              nonnull (strerror (errno)));
+		  tmp_len = strlen (tmp);
+		  concat_name =
+		    XMALLOC (char, tmp_len + 1 + strlen (wrapper) + 1);
+		  memcpy (concat_name, tmp, tmp_len);
+		  concat_name[tmp_len] = '/';
+		  strcpy (concat_name + tmp_len + 1, wrapper);
+		}
+	      else
+		{
+		  concat_name =
+		    XMALLOC (char, p_len + 1 + strlen (wrapper) + 1);
+		  memcpy (concat_name, p, p_len);
+		  concat_name[p_len] = '/';
+		  strcpy (concat_name + p_len + 1, wrapper);
+		}
+	      if (check_executable (concat_name))
+		return concat_name;
+	      XFREE (concat_name);
+	    }
+	}
+      /* not found in PATH; assume curdir */
+    }
+  /* Relative path | not found in path: prepend cwd */
+  if (getcwd (tmp, LT_PATHMAX) == NULL)
+    lt_fatal (__FILE__, __LINE__, "getcwd failed: %s",
+              nonnull (strerror (errno)));
+  tmp_len = strlen (tmp);
+  concat_name = XMALLOC (char, tmp_len + 1 + strlen (wrapper) + 1);
+  memcpy (concat_name, tmp, tmp_len);
+  concat_name[tmp_len] = '/';
+  strcpy (concat_name + tmp_len + 1, wrapper);
+
+  if (check_executable (concat_name))
+    return concat_name;
+  XFREE (concat_name);
+  return NULL;
+}
+
+char *
+chase_symlinks (const char *pathspec)
+{
+#ifndef S_ISLNK
+  return xstrdup (pathspec);
+#else
+  char buf[LT_PATHMAX];
+  struct stat s;
+  char *tmp_pathspec = xstrdup (pathspec);
+  char *p;
+  int has_symlinks = 0;
+  while (strlen (tmp_pathspec) && !has_symlinks)
+    {
+      lt_debugprintf (__FILE__, __LINE__,
+		      "checking path component for symlinks: %s\n",
+		      tmp_pathspec);
+      if (lstat (tmp_pathspec, &s) == 0)
+	{
+	  if (S_ISLNK (s.st_mode) != 0)
+	    {
+	      has_symlinks = 1;
+	      break;
+	    }
+
+	  /* search backwards for last DIR_SEPARATOR */
+	  p = tmp_pathspec + strlen (tmp_pathspec) - 1;
+	  while ((p > tmp_pathspec) && (!IS_DIR_SEPARATOR (*p)))
+	    p--;
+	  if ((p == tmp_pathspec) && (!IS_DIR_SEPARATOR (*p)))
+	    {
+	      /* no more DIR_SEPARATORS left */
+	      break;
+	    }
+	  *p = '\0';
+	}
+      else
+	{
+	  lt_fatal (__FILE__, __LINE__,
+		    "error accessing file \"%s\": %s",
+		    tmp_pathspec, nonnull (strerror (errno)));
+	}
+    }
+  XFREE (tmp_pathspec);
+
+  if (!has_symlinks)
+    {
+      return xstrdup (pathspec);
+    }
+
+  tmp_pathspec = realpath (pathspec, buf);
+  if (tmp_pathspec == 0)
+    {
+      lt_fatal (__FILE__, __LINE__,
+		"could not follow symlinks for %s", pathspec);
+    }
+  return xstrdup (tmp_pathspec);
+#endif
+}
+
+char *
+strendzap (char *str, const char *pat)
+{
+  size_t len, patlen;
+
+  assert (str != NULL);
+  assert (pat != NULL);
+
+  len = strlen (str);
+  patlen = strlen (pat);
+
+  if (patlen <= len)
+    {
+      str += len - patlen;
+      if (strcmp (str, pat) == 0)
+	*str = '\0';
+    }
+  return str;
+}
+
+void
+lt_debugprintf (const char *file, int line, const char *fmt, ...)
+{
+  va_list args;
+  if (lt_debug)
+    {
+      (void) fprintf (stderr, "%s:%s:%d: ", program_name, file, line);
+      va_start (args, fmt);
+      (void) vfprintf (stderr, fmt, args);
+      va_end (args);
+    }
+}
+
+static void
+lt_error_core (int exit_status, const char *file,
+	       int line, const char *mode,
+	       const char *message, va_list ap)
+{
+  fprintf (stderr, "%s:%s:%d: %s: ", program_name, file, line, mode);
+  vfprintf (stderr, message, ap);
+  fprintf (stderr, ".\n");
+
+  if (exit_status >= 0)
+    exit (exit_status);
+}
+
+void
+lt_fatal (const char *file, int line, const char *message, ...)
+{
+  va_list ap;
+  va_start (ap, message);
+  lt_error_core (EXIT_FAILURE, file, line, "FATAL", message, ap);
+  va_end (ap);
+}
+
+static const char *
+nonnull (const char *s)
+{
+  return s ? s : "(null)";
+}
+
+static const char *
+nonempty (const char *s)
+{
+  return (s && !*s) ? "(empty)" : nonnull (s);
+}
+
+void
+lt_setenv (const char *name, const char *value)
+{
+  lt_debugprintf (__FILE__, __LINE__,
+		  "(lt_setenv) setting '%s' to '%s'\n",
+                  nonnull (name), nonnull (value));
+  {
+#ifdef HAVE_SETENV
+    /* always make a copy, for consistency with !HAVE_SETENV */
+    char *str = xstrdup (value);
+    setenv (name, str, 1);
+#else
+    int len = strlen (name) + 1 + strlen (value) + 1;
+    char *str = XMALLOC (char, len);
+    sprintf (str, "%s=%s", name, value);
+    if (putenv (str) != EXIT_SUCCESS)
+      {
+        XFREE (str);
+      }
+#endif
+  }
+}
+
+char *
+lt_extend_str (const char *orig_value, const char *add, int to_end)
+{
+  char *new_value;
+  if (orig_value && *orig_value)
+    {
+      int orig_value_len = strlen (orig_value);
+      int add_len = strlen (add);
+      new_value = XMALLOC (char, add_len + orig_value_len + 1);
+      if (to_end)
+        {
+          strcpy (new_value, orig_value);
+          strcpy (new_value + orig_value_len, add);
+        }
+      else
+        {
+          strcpy (new_value, add);
+          strcpy (new_value + add_len, orig_value);
+        }
+    }
+  else
+    {
+      new_value = xstrdup (add);
+    }
+  return new_value;
+}
+
+void
+lt_update_exe_path (const char *name, const char *value)
+{
+  lt_debugprintf (__FILE__, __LINE__,
+		  "(lt_update_exe_path) modifying '%s' by prepending '%s'\n",
+                  nonnull (name), nonnull (value));
+
+  if (name && *name && value && *value)
+    {
+      char *new_value = lt_extend_str (getenv (name), value, 0);
+      /* some systems can't cope with a ':'-terminated path #' */
+      int len = strlen (new_value);
+      while (((len = strlen (new_value)) > 0) && IS_PATH_SEPARATOR (new_value[len-1]))
+        {
+          new_value[len-1] = '\0';
+        }
+      lt_setenv (name, new_value);
+      XFREE (new_value);
+    }
+}
+
+void
+lt_update_lib_path (const char *name, const char *value)
+{
+  lt_debugprintf (__FILE__, __LINE__,
+		  "(lt_update_lib_path) modifying '%s' by prepending '%s'\n",
+                  nonnull (name), nonnull (value));
+
+  if (name && *name && value && *value)
+    {
+      char *new_value = lt_extend_str (getenv (name), value, 0);
+      lt_setenv (name, new_value);
+      XFREE (new_value);
+    }
+}
+
+EOF
+	    case $host_os in
+	      mingw*)
+		cat <<"EOF"
+
+/* Prepares an argument vector before calling spawn().
+   Note that spawn() does not by itself call the command interpreter
+     (getenv ("COMSPEC") != NULL ? getenv ("COMSPEC") :
+      ({ OSVERSIONINFO v; v.dwOSVersionInfoSize = sizeof(OSVERSIONINFO);
+         GetVersionEx(&v);
+         v.dwPlatformId == VER_PLATFORM_WIN32_NT;
+      }) ? "cmd.exe" : "command.com").
+   Instead it simply concatenates the arguments, separated by ' ', and calls
+   CreateProcess().  We must quote the arguments since Win32 CreateProcess()
+   interprets characters like ' ', '\t', '\\', '"' (but not '<' and '>') in a
+   special way:
+   - Space and tab are interpreted as delimiters. They are not treated as
+     delimiters if they are surrounded by double quotes: "...".
+   - Unescaped double quotes are removed from the input. Their only effect is
+     that within double quotes, space and tab are treated like normal
+     characters.
+   - Backslashes not followed by double quotes are not special.
+   - But 2*n+1 backslashes followed by a double quote become
+     n backslashes followed by a double quote (n >= 0):
+       \" -> "
+       \\\" -> \"
+       \\\\\" -> \\"
+ */
+#define SHELL_SPECIAL_CHARS "\"\\ \001\002\003\004\005\006\007\010\011\012\013\014\015\016\017\020\021\022\023\024\025\026\027\030\031\032\033\034\035\036\037"
+#define SHELL_SPACE_CHARS " \001\002\003\004\005\006\007\010\011\012\013\014\015\016\017\020\021\022\023\024\025\026\027\030\031\032\033\034\035\036\037"
+char **
+prepare_spawn (char **argv)
+{
+  size_t argc;
+  char **new_argv;
+  size_t i;
+
+  /* Count number of arguments.  */
+  for (argc = 0; argv[argc] != NULL; argc++)
+    ;
+
+  /* Allocate new argument vector.  */
+  new_argv = XMALLOC (char *, argc + 1);
+
+  /* Put quoted arguments into the new argument vector.  */
+  for (i = 0; i < argc; i++)
+    {
+      const char *string = argv[i];
+
+      if (string[0] == '\0')
+	new_argv[i] = xstrdup ("\"\"");
+      else if (strpbrk (string, SHELL_SPECIAL_CHARS) != NULL)
+	{
+	  int quote_around = (strpbrk (string, SHELL_SPACE_CHARS) != NULL);
+	  size_t length;
+	  unsigned int backslashes;
+	  const char *s;
+	  char *quoted_string;
+	  char *p;
+
+	  length = 0;
+	  backslashes = 0;
+	  if (quote_around)
+	    length++;
+	  for (s = string; *s != '\0'; s++)
+	    {
+	      char c = *s;
+	      if (c == '"')
+		length += backslashes + 1;
+	      length++;
+	      if (c == '\\')
+		backslashes++;
+	      else
+		backslashes = 0;
+	    }
+	  if (quote_around)
+	    length += backslashes + 1;
+
+	  quoted_string = XMALLOC (char, length + 1);
+
+	  p = quoted_string;
+	  backslashes = 0;
+	  if (quote_around)
+	    *p++ = '"';
+	  for (s = string; *s != '\0'; s++)
+	    {
+	      char c = *s;
+	      if (c == '"')
+		{
+		  unsigned int j;
+		  for (j = backslashes + 1; j > 0; j--)
+		    *p++ = '\\';
+		}
+	      *p++ = c;
+	      if (c == '\\')
+		backslashes++;
+	      else
+		backslashes = 0;
+	    }
+	  if (quote_around)
+	    {
+	      unsigned int j;
+	      for (j = backslashes; j > 0; j--)
+		*p++ = '\\';
+	      *p++ = '"';
+	    }
+	  *p = '\0';
+
+	  new_argv[i] = quoted_string;
+	}
+      else
+	new_argv[i] = (char *) string;
+    }
+  new_argv[argc] = NULL;
+
+  return new_argv;
+}
+EOF
+		;;
+	    esac
+
+            cat <<"EOF"
+void lt_dump_script (FILE* f)
+{
+EOF
+	    func_emit_wrapper yes |
+	      $SED -n -e '
+s/^\(.\{79\}\)\(..*\)/\1\
+\2/
+h
+s/\([\\"]\)/\\\1/g
+s/$/\\n/
+s/\([^\n]*\).*/  fputs ("\1", f);/p
+g
+D'
+            cat <<"EOF"
+}
+EOF
+}
+# end: func_emit_cwrapperexe_src
+
+# func_win32_import_lib_p ARG
+# True if ARG is an import lib, as indicated by $file_magic_cmd
+func_win32_import_lib_p ()
+{
+    $opt_debug
+    case `eval $file_magic_cmd \"\$1\" 2>/dev/null | $SED -e 10q` in
+    *import*) : ;;
+    *) false ;;
+    esac
+}
+
+# func_mode_link arg...
+func_mode_link ()
+{
+    $opt_debug
+    case $host in
+    *-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-os2* | *-cegcc*)
+      # It is impossible to link a dll without this setting, and
+      # we shouldn't force the makefile maintainer to figure out
+      # which system we are compiling for in order to pass an extra
+      # flag for every libtool invocation.
+      # allow_undefined=no
+
+      # FIXME: Unfortunately, there are problems with the above when trying
+      # to make a dll which has undefined symbols, in which case not
+      # even a static library is built.  For now, we need to specify
+      # -no-undefined on the libtool link line when we can be certain
+      # that all symbols are satisfied, otherwise we get a static library.
+      allow_undefined=yes
+      ;;
+    *)
+      allow_undefined=yes
+      ;;
+    esac
+    libtool_args=$nonopt
+    base_compile="$nonopt $@"
+    compile_command=$nonopt
+    finalize_command=$nonopt
+
+    compile_rpath=
+    finalize_rpath=
+    compile_shlibpath=
+    finalize_shlibpath=
+    convenience=
+    old_convenience=
+    deplibs=
+    old_deplibs=
+    compiler_flags=
+    linker_flags=
+    dllsearchpath=
+    lib_search_path=`pwd`
+    inst_prefix_dir=
+    new_inherited_linker_flags=
+
+    avoid_version=no
+    bindir=
+    dlfiles=
+    dlprefiles=
+    dlself=no
+    export_dynamic=no
+    export_symbols=
+    export_symbols_regex=
+    generated=
+    libobjs=
+    ltlibs=
+    module=no
+    no_install=no
+    objs=
+    non_pic_objects=
+    precious_files_regex=
+    prefer_static_libs=no
+    preload=no
+    prev=
+    prevarg=
+    release=
+    rpath=
+    xrpath=
+    perm_rpath=
+    temp_rpath=
+    thread_safe=no
+    vinfo=
+    vinfo_number=no
+    weak_libs=
+    single_module="${wl}-single_module"
+    func_infer_tag $base_compile
+
+    # We need to know -static, to get the right output filenames.
+    for arg
+    do
+      case $arg in
+      -shared)
+	test "$build_libtool_libs" != yes && \
+	  func_fatal_configuration "can not build a shared library"
+	build_old_libs=no
+	break
+	;;
+      -all-static | -static | -static-libtool-libs)
+	case $arg in
+	-all-static)
+	  if test "$build_libtool_libs" = yes && test -z "$link_static_flag"; then
+	    func_warning "complete static linking is impossible in this configuration"
+	  fi
+	  if test -n "$link_static_flag"; then
+	    dlopen_self=$dlopen_self_static
+	  fi
+	  prefer_static_libs=yes
+	  ;;
+	-static)
+	  if test -z "$pic_flag" && test -n "$link_static_flag"; then
+	    dlopen_self=$dlopen_self_static
+	  fi
+	  prefer_static_libs=built
+	  ;;
+	-static-libtool-libs)
+	  if test -z "$pic_flag" && test -n "$link_static_flag"; then
+	    dlopen_self=$dlopen_self_static
+	  fi
+	  prefer_static_libs=yes
+	  ;;
+	esac
+	build_libtool_libs=no
+	build_old_libs=yes
+	break
+	;;
+      esac
+    done
+
+    # See if our shared archives depend on static archives.
+    test -n "$old_archive_from_new_cmds" && build_old_libs=yes
+
+    # Go through the arguments, transforming them on the way.
+    while test "$#" -gt 0; do
+      arg="$1"
+      shift
+      func_quote_for_eval "$arg"
+      qarg=$func_quote_for_eval_unquoted_result
+      func_append libtool_args " $func_quote_for_eval_result"
+
+      # If the previous option needs an argument, assign it.
+      if test -n "$prev"; then
+	case $prev in
+	output)
+	  func_append compile_command " @OUTPUT@"
+	  func_append finalize_command " @OUTPUT@"
+	  ;;
+	esac
+
+	case $prev in
+	bindir)
+	  bindir="$arg"
+	  prev=
+	  continue
+	  ;;
+	dlfiles|dlprefiles)
+	  if test "$preload" = no; then
+	    # Add the symbol object into the linking commands.
+	    func_append compile_command " @SYMFILE@"
+	    func_append finalize_command " @SYMFILE@"
+	    preload=yes
+	  fi
+	  case $arg in
+	  *.la | *.lo) ;;  # We handle these cases below.
+	  force)
+	    if test "$dlself" = no; then
+	      dlself=needless
+	      export_dynamic=yes
+	    fi
+	    prev=
+	    continue
+	    ;;
+	  self)
+	    if test "$prev" = dlprefiles; then
+	      dlself=yes
+	    elif test "$prev" = dlfiles && test "$dlopen_self" != yes; then
+	      dlself=yes
+	    else
+	      dlself=needless
+	      export_dynamic=yes
+	    fi
+	    prev=
+	    continue
+	    ;;
+	  *)
+	    if test "$prev" = dlfiles; then
+	      func_append dlfiles " $arg"
+	    else
+	      func_append dlprefiles " $arg"
+	    fi
+	    prev=
+	    continue
+	    ;;
+	  esac
+	  ;;
+	expsyms)
+	  export_symbols="$arg"
+	  test -f "$arg" \
+	    || func_fatal_error "symbol file \`$arg' does not exist"
+	  prev=
+	  continue
+	  ;;
+	expsyms_regex)
+	  export_symbols_regex="$arg"
+	  prev=
+	  continue
+	  ;;
+	framework)
+	  case $host in
+	    *-*-darwin*)
+	      case "$deplibs " in
+		*" $qarg.ltframework "*) ;;
+		*) func_append deplibs " $qarg.ltframework" # this is fixed later
+		   ;;
+	      esac
+	      ;;
+	  esac
+	  prev=
+	  continue
+	  ;;
+	inst_prefix)
+	  inst_prefix_dir="$arg"
+	  prev=
+	  continue
+	  ;;
+	objectlist)
+	  if test -f "$arg"; then
+	    save_arg=$arg
+	    moreargs=
+	    for fil in `cat "$save_arg"`
+	    do
+#	      func_append moreargs " $fil"
+	      arg=$fil
+	      # A libtool-controlled object.
+
+	      # Check to see that this really is a libtool object.
+	      if func_lalib_unsafe_p "$arg"; then
+		pic_object=
+		non_pic_object=
+
+		# Read the .lo file
+		func_source "$arg"
+
+		if test -z "$pic_object" ||
+		   test -z "$non_pic_object" ||
+		   test "$pic_object" = none &&
+		   test "$non_pic_object" = none; then
+		  func_fatal_error "cannot find name of object for \`$arg'"
+		fi
+
+		# Extract subdirectory from the argument.
+		func_dirname "$arg" "/" ""
+		xdir="$func_dirname_result"
+
+		if test "$pic_object" != none; then
+		  # Prepend the subdirectory the object is found in.
+		  pic_object="$xdir$pic_object"
+
+		  if test "$prev" = dlfiles; then
+		    if test "$build_libtool_libs" = yes && test "$dlopen_support" = yes; then
+		      func_append dlfiles " $pic_object"
+		      prev=
+		      continue
+		    else
+		      # If libtool objects are unsupported, then we need to preload.
+		      prev=dlprefiles
+		    fi
+		  fi
+
+		  # CHECK ME:  I think I busted this.  -Ossama
+		  if test "$prev" = dlprefiles; then
+		    # Preload the old-style object.
+		    func_append dlprefiles " $pic_object"
+		    prev=
+		  fi
+
+		  # A PIC object.
+		  func_append libobjs " $pic_object"
+		  arg="$pic_object"
+		fi
+
+		# Non-PIC object.
+		if test "$non_pic_object" != none; then
+		  # Prepend the subdirectory the object is found in.
+		  non_pic_object="$xdir$non_pic_object"
+
+		  # A standard non-PIC object
+		  func_append non_pic_objects " $non_pic_object"
+		  if test -z "$pic_object" || test "$pic_object" = none ; then
+		    arg="$non_pic_object"
+		  fi
+		else
+		  # If the PIC object exists, use it instead.
+		  # $xdir was prepended to $pic_object above.
+		  non_pic_object="$pic_object"
+		  func_append non_pic_objects " $non_pic_object"
+		fi
+	      else
+		# Only an error if not doing a dry-run.
+		if $opt_dry_run; then
+		  # Extract subdirectory from the argument.
+		  func_dirname "$arg" "/" ""
+		  xdir="$func_dirname_result"
+
+		  func_lo2o "$arg"
+		  pic_object=$xdir$objdir/$func_lo2o_result
+		  non_pic_object=$xdir$func_lo2o_result
+		  func_append libobjs " $pic_object"
+		  func_append non_pic_objects " $non_pic_object"
+	        else
+		  func_fatal_error "\`$arg' is not a valid libtool object"
+		fi
+	      fi
+	    done
+	  else
+	    func_fatal_error "link input file \`$arg' does not exist"
+	  fi
+	  arg=$save_arg
+	  prev=
+	  continue
+	  ;;
+	precious_regex)
+	  precious_files_regex="$arg"
+	  prev=
+	  continue
+	  ;;
+	release)
+	  release="-$arg"
+	  prev=
+	  continue
+	  ;;
+	rpath | xrpath)
+	  # We need an absolute path.
+	  case $arg in
+	  [\\/]* | [A-Za-z]:[\\/]*) ;;
+	  *)
+	    func_fatal_error "only absolute run-paths are allowed"
+	    ;;
+	  esac
+	  if test "$prev" = rpath; then
+	    case "$rpath " in
+	    *" $arg "*) ;;
+	    *) func_append rpath " $arg" ;;
+	    esac
+	  else
+	    case "$xrpath " in
+	    *" $arg "*) ;;
+	    *) func_append xrpath " $arg" ;;
+	    esac
+	  fi
+	  prev=
+	  continue
+	  ;;
+	shrext)
+	  shrext_cmds="$arg"
+	  prev=
+	  continue
+	  ;;
+	weak)
+	  func_append weak_libs " $arg"
+	  prev=
+	  continue
+	  ;;
+	xcclinker)
+	  func_append linker_flags " $qarg"
+	  func_append compiler_flags " $qarg"
+	  prev=
+	  func_append compile_command " $qarg"
+	  func_append finalize_command " $qarg"
+	  continue
+	  ;;
+	xcompiler)
+	  func_append compiler_flags " $qarg"
+	  prev=
+	  func_append compile_command " $qarg"
+	  func_append finalize_command " $qarg"
+	  continue
+	  ;;
+	xlinker)
+	  func_append linker_flags " $qarg"
+	  func_append compiler_flags " $wl$qarg"
+	  prev=
+	  func_append compile_command " $wl$qarg"
+	  func_append finalize_command " $wl$qarg"
+	  continue
+	  ;;
+	*)
+	  eval "$prev=\"\$arg\""
+	  prev=
+	  continue
+	  ;;
+	esac
+      fi # test -n "$prev"
+
+      prevarg="$arg"
+
+      case $arg in
+      -all-static)
+	if test -n "$link_static_flag"; then
+	  # See comment for -static flag below, for more details.
+	  func_append compile_command " $link_static_flag"
+	  func_append finalize_command " $link_static_flag"
+	fi
+	continue
+	;;
+
+      -allow-undefined)
+	# FIXME: remove this flag sometime in the future.
+	func_fatal_error "\`-allow-undefined' must not be used because it is the default"
+	;;
+
+      -avoid-version)
+	avoid_version=yes
+	continue
+	;;
+
+      -bindir)
+	prev=bindir
+	continue
+	;;
+
+      -dlopen)
+	prev=dlfiles
+	continue
+	;;
+
+      -dlpreopen)
+	prev=dlprefiles
+	continue
+	;;
+
+      -export-dynamic)
+	export_dynamic=yes
+	continue
+	;;
+
+      -export-symbols | -export-symbols-regex)
+	if test -n "$export_symbols" || test -n "$export_symbols_regex"; then
+	  func_fatal_error "more than one -exported-symbols argument is not allowed"
+	fi
+	if test "X$arg" = "X-export-symbols"; then
+	  prev=expsyms
+	else
+	  prev=expsyms_regex
+	fi
+	continue
+	;;
+
+      -framework)
+	prev=framework
+	continue
+	;;
+
+      -inst-prefix-dir)
+	prev=inst_prefix
+	continue
+	;;
+
+      # The native IRIX linker understands -LANG:*, -LIST:* and -LNO:*
+      # so, if we see these flags be careful not to treat them like -L
+      -L[A-Z][A-Z]*:*)
+	case $with_gcc/$host in
+	no/*-*-irix* | /*-*-irix*)
+	  func_append compile_command " $arg"
+	  func_append finalize_command " $arg"
+	  ;;
+	esac
+	continue
+	;;
+
+      -L*)
+	func_stripname "-L" '' "$arg"
+	if test -z "$func_stripname_result"; then
+	  if test "$#" -gt 0; then
+	    func_fatal_error "require no space between \`-L' and \`$1'"
+	  else
+	    func_fatal_error "need path for \`-L' option"
+	  fi
+	fi
+	func_resolve_sysroot "$func_stripname_result"
+	dir=$func_resolve_sysroot_result
+	# We need an absolute path.
+	case $dir in
+	[\\/]* | [A-Za-z]:[\\/]*) ;;
+	*)
+	  absdir=`cd "$dir" && pwd`
+	  test -z "$absdir" && \
+	    func_fatal_error "cannot determine absolute directory name of \`$dir'"
+	  dir="$absdir"
+	  ;;
+	esac
+	case "$deplibs " in
+	*" -L$dir "* | *" $arg "*)
+	  # Will only happen for absolute or sysroot arguments
+	  ;;
+	*)
+	  # Preserve sysroot, but never include relative directories
+	  case $dir in
+	    [\\/]* | [A-Za-z]:[\\/]* | =*) func_append deplibs " $arg" ;;
+	    *) func_append deplibs " -L$dir" ;;
+	  esac
+	  func_append lib_search_path " $dir"
+	  ;;
+	esac
+	case $host in
+	*-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-os2* | *-cegcc*)
+	  testbindir=`$ECHO "$dir" | $SED 's*/lib$*/bin*'`
+	  case :$dllsearchpath: in
+	  *":$dir:"*) ;;
+	  ::) dllsearchpath=$dir;;
+	  *) func_append dllsearchpath ":$dir";;
+	  esac
+	  case :$dllsearchpath: in
+	  *":$testbindir:"*) ;;
+	  ::) dllsearchpath=$testbindir;;
+	  *) func_append dllsearchpath ":$testbindir";;
+	  esac
+	  ;;
+	esac
+	continue
+	;;
+
+      -l*)
+	if test "X$arg" = "X-lc" || test "X$arg" = "X-lm"; then
+	  case $host in
+	  *-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-beos* | *-cegcc* | *-*-haiku*)
+	    # These systems don't actually have a C or math library (as such)
+	    continue
+	    ;;
+	  *-*-os2*)
+	    # These systems don't actually have a C library (as such)
+	    test "X$arg" = "X-lc" && continue
+	    ;;
+	  *-*-openbsd* | *-*-freebsd* | *-*-dragonfly*)
+	    # Do not include libc due to us having libc/libc_r.
+	    test "X$arg" = "X-lc" && continue
+	    ;;
+	  *-*-rhapsody* | *-*-darwin1.[012])
+	    # Rhapsody C and math libraries are in the System framework
+	    func_append deplibs " System.ltframework"
+	    continue
+	    ;;
+	  *-*-sco3.2v5* | *-*-sco5v6*)
+	    # Causes problems with __ctype
+	    test "X$arg" = "X-lc" && continue
+	    ;;
+	  *-*-sysv4.2uw2* | *-*-sysv5* | *-*-unixware* | *-*-OpenUNIX*)
+	    # Compiler inserts libc in the correct place for threads to work
+	    test "X$arg" = "X-lc" && continue
+	    ;;
+	  esac
+	elif test "X$arg" = "X-lc_r"; then
+	 case $host in
+	 *-*-openbsd* | *-*-freebsd* | *-*-dragonfly*)
+	   # Do not include libc_r directly, use -pthread flag.
+	   continue
+	   ;;
+	 esac
+	fi
+	func_append deplibs " $arg"
+	continue
+	;;
+
+      -module)
+	module=yes
+	continue
+	;;
+
+      # Tru64 UNIX uses -model [arg] to determine the layout of C++
+      # classes, name mangling, and exception handling.
+      # Darwin uses the -arch flag to determine output architecture.
+      -model|-arch|-isysroot|--sysroot)
+	func_append compiler_flags " $arg"
+	func_append compile_command " $arg"
+	func_append finalize_command " $arg"
+	prev=xcompiler
+	continue
+	;;
+
+      -mt|-mthreads|-kthread|-Kthread|-pthread|-pthreads|--thread-safe \
+      |-threads|-fopenmp|-openmp|-mp|-xopenmp|-omp|-qsmp=*)
+	func_append compiler_flags " $arg"
+	func_append compile_command " $arg"
+	func_append finalize_command " $arg"
+	case "$new_inherited_linker_flags " in
+	    *" $arg "*) ;;
+	    * ) func_append new_inherited_linker_flags " $arg" ;;
+	esac
+	continue
+	;;
+
+      -multi_module)
+	single_module="${wl}-multi_module"
+	continue
+	;;
+
+      -no-fast-install)
+	fast_install=no
+	continue
+	;;
+
+      -no-install)
+	case $host in
+	*-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-os2* | *-*-darwin* | *-cegcc*)
+	  # The PATH hackery in wrapper scripts is required on Windows
+	  # and Darwin in order for the loader to find any dlls it needs.
+	  func_warning "\`-no-install' is ignored for $host"
+	  func_warning "assuming \`-no-fast-install' instead"
+	  fast_install=no
+	  ;;
+	*) no_install=yes ;;
+	esac
+	continue
+	;;
+
+      -no-undefined)
+	allow_undefined=no
+	continue
+	;;
+
+      -objectlist)
+	prev=objectlist
+	continue
+	;;
+
+      -o) prev=output ;;
+
+      -precious-files-regex)
+	prev=precious_regex
+	continue
+	;;
+
+      -release)
+	prev=release
+	continue
+	;;
+
+      -rpath)
+	prev=rpath
+	continue
+	;;
+
+      -R)
+	prev=xrpath
+	continue
+	;;
+
+      -R*)
+	func_stripname '-R' '' "$arg"
+	dir=$func_stripname_result
+	# We need an absolute path.
+	case $dir in
+	[\\/]* | [A-Za-z]:[\\/]*) ;;
+	=*)
+	  func_stripname '=' '' "$dir"
+	  dir=$lt_sysroot$func_stripname_result
+	  ;;
+	*)
+	  func_fatal_error "only absolute run-paths are allowed"
+	  ;;
+	esac
+	case "$xrpath " in
+	*" $dir "*) ;;
+	*) func_append xrpath " $dir" ;;
+	esac
+	continue
+	;;
+
+      -shared)
+	# The effects of -shared are defined in a previous loop.
+	continue
+	;;
+
+      -shrext)
+	prev=shrext
+	continue
+	;;
+
+      -static | -static-libtool-libs)
+	# The effects of -static are defined in a previous loop.
+	# We used to do the same as -all-static on platforms that
+	# didn't have a PIC flag, but the assumption that the effects
+	# would be equivalent was wrong.  It would break on at least
+	# Digital Unix and AIX.
+	continue
+	;;
+
+      -thread-safe)
+	thread_safe=yes
+	continue
+	;;
+
+      -version-info)
+	prev=vinfo
+	continue
+	;;
+
+      -version-number)
+	prev=vinfo
+	vinfo_number=yes
+	continue
+	;;
+
+      -weak)
+        prev=weak
+	continue
+	;;
+
+      -Wc,*)
+	func_stripname '-Wc,' '' "$arg"
+	args=$func_stripname_result
+	arg=
+	save_ifs="$IFS"; IFS=','
+	for flag in $args; do
+	  IFS="$save_ifs"
+          func_quote_for_eval "$flag"
+	  func_append arg " $func_quote_for_eval_result"
+	  func_append compiler_flags " $func_quote_for_eval_result"
+	done
+	IFS="$save_ifs"
+	func_stripname ' ' '' "$arg"
+	arg=$func_stripname_result
+	;;
+
+      -Wl,*)
+	func_stripname '-Wl,' '' "$arg"
+	args=$func_stripname_result
+	arg=
+	save_ifs="$IFS"; IFS=','
+	for flag in $args; do
+	  IFS="$save_ifs"
+          func_quote_for_eval "$flag"
+	  func_append arg " $wl$func_quote_for_eval_result"
+	  func_append compiler_flags " $wl$func_quote_for_eval_result"
+	  func_append linker_flags " $func_quote_for_eval_result"
+	done
+	IFS="$save_ifs"
+	func_stripname ' ' '' "$arg"
+	arg=$func_stripname_result
+	;;
+
+      -Xcompiler)
+	prev=xcompiler
+	continue
+	;;
+
+      -Xlinker)
+	prev=xlinker
+	continue
+	;;
+
+      -XCClinker)
+	prev=xcclinker
+	continue
+	;;
+
+      # -msg_* for osf cc
+      -msg_*)
+	func_quote_for_eval "$arg"
+	arg="$func_quote_for_eval_result"
+	;;
+
+      # Flags to be passed through unchanged, with rationale:
+      # -64, -mips[0-9]      enable 64-bit mode for the SGI compiler
+      # -r[0-9][0-9]*        specify processor for the SGI compiler
+      # -xarch=*, -xtarget=* enable 64-bit mode for the Sun compiler
+      # +DA*, +DD*           enable 64-bit mode for the HP compiler
+      # -q*                  compiler args for the IBM compiler
+      # -m*, -t[45]*, -txscale* architecture-specific flags for GCC
+      # -F/path              path to uninstalled frameworks, gcc on darwin
+      # -p, -pg, --coverage, -fprofile-*  profiling flags for GCC
+      # @file                GCC response files
+      # -tp=*                Portland pgcc target processor selection
+      # --sysroot=*          for sysroot support
+      # -O*, -flto*, -fwhopr*, -fuse-linker-plugin GCC link-time optimization
+      -64|-mips[0-9]|-r[0-9][0-9]*|-xarch=*|-xtarget=*|+DA*|+DD*|-q*|-m*| \
+      -t[45]*|-txscale*|-p|-pg|--coverage|-fprofile-*|-F*|@*|-tp=*|--sysroot=*| \
+      -O*|-flto*|-fwhopr*|-fuse-linker-plugin)
+        func_quote_for_eval "$arg"
+	arg="$func_quote_for_eval_result"
+        func_append compile_command " $arg"
+        func_append finalize_command " $arg"
+        func_append compiler_flags " $arg"
+        continue
+        ;;
+
+      # Some other compiler flag.
+      -* | +*)
+        func_quote_for_eval "$arg"
+	arg="$func_quote_for_eval_result"
+	;;
+
+      *.$objext)
+	# A standard object.
+	func_append objs " $arg"
+	;;
+
+      *.lo)
+	# A libtool-controlled object.
+
+	# Check to see that this really is a libtool object.
+	if func_lalib_unsafe_p "$arg"; then
+	  pic_object=
+	  non_pic_object=
+
+	  # Read the .lo file
+	  func_source "$arg"
+
+	  if test -z "$pic_object" ||
+	     test -z "$non_pic_object" ||
+	     test "$pic_object" = none &&
+	     test "$non_pic_object" = none; then
+	    func_fatal_error "cannot find name of object for \`$arg'"
+	  fi
+
+	  # Extract subdirectory from the argument.
+	  func_dirname "$arg" "/" ""
+	  xdir="$func_dirname_result"
+
+	  if test "$pic_object" != none; then
+	    # Prepend the subdirectory the object is found in.
+	    pic_object="$xdir$pic_object"
+
+	    if test "$prev" = dlfiles; then
+	      if test "$build_libtool_libs" = yes && test "$dlopen_support" = yes; then
+		func_append dlfiles " $pic_object"
+		prev=
+		continue
+	      else
+		# If libtool objects are unsupported, then we need to preload.
+		prev=dlprefiles
+	      fi
+	    fi
+
+	    # CHECK ME:  I think I busted this.  -Ossama
+	    if test "$prev" = dlprefiles; then
+	      # Preload the old-style object.
+	      func_append dlprefiles " $pic_object"
+	      prev=
+	    fi
+
+	    # A PIC object.
+	    func_append libobjs " $pic_object"
+	    arg="$pic_object"
+	  fi
+
+	  # Non-PIC object.
+	  if test "$non_pic_object" != none; then
+	    # Prepend the subdirectory the object is found in.
+	    non_pic_object="$xdir$non_pic_object"
+
+	    # A standard non-PIC object
+	    func_append non_pic_objects " $non_pic_object"
+	    if test -z "$pic_object" || test "$pic_object" = none ; then
+	      arg="$non_pic_object"
+	    fi
+	  else
+	    # If the PIC object exists, use it instead.
+	    # $xdir was prepended to $pic_object above.
+	    non_pic_object="$pic_object"
+	    func_append non_pic_objects " $non_pic_object"
+	  fi
+	else
+	  # Only an error if not doing a dry-run.
+	  if $opt_dry_run; then
+	    # Extract subdirectory from the argument.
+	    func_dirname "$arg" "/" ""
+	    xdir="$func_dirname_result"
+
+	    func_lo2o "$arg"
+	    pic_object=$xdir$objdir/$func_lo2o_result
+	    non_pic_object=$xdir$func_lo2o_result
+	    func_append libobjs " $pic_object"
+	    func_append non_pic_objects " $non_pic_object"
+	  else
+	    func_fatal_error "\`$arg' is not a valid libtool object"
+	  fi
+	fi
+	;;
+
+      *.$libext)
+	# An archive.
+	func_append deplibs " $arg"
+	func_append old_deplibs " $arg"
+	continue
+	;;
+
+      *.la)
+	# A libtool-controlled library.
+
+	func_resolve_sysroot "$arg"
+	if test "$prev" = dlfiles; then
+	  # This library was specified with -dlopen.
+	  func_append dlfiles " $func_resolve_sysroot_result"
+	  prev=
+	elif test "$prev" = dlprefiles; then
+	  # The library was specified with -dlpreopen.
+	  func_append dlprefiles " $func_resolve_sysroot_result"
+	  prev=
+	else
+	  func_append deplibs " $func_resolve_sysroot_result"
+	fi
+	continue
+	;;
+
+      # Some other compiler argument.
+      *)
+	# Unknown arguments in both finalize_command and compile_command need
+	# to be aesthetically quoted because they are evaled later.
+	func_quote_for_eval "$arg"
+	arg="$func_quote_for_eval_result"
+	;;
+      esac # arg
+
+      # Now actually substitute the argument into the commands.
+      if test -n "$arg"; then
+	func_append compile_command " $arg"
+	func_append finalize_command " $arg"
+      fi
+    done # argument parsing loop
+
+    test -n "$prev" && \
+      func_fatal_help "the \`$prevarg' option requires an argument"
+
+    if test "$export_dynamic" = yes && test -n "$export_dynamic_flag_spec"; then
+      eval arg=\"$export_dynamic_flag_spec\"
+      func_append compile_command " $arg"
+      func_append finalize_command " $arg"
+    fi
+
+    oldlibs=
+    # calculate the name of the file, without its directory
+    func_basename "$output"
+    outputname="$func_basename_result"
+    libobjs_save="$libobjs"
+
+    if test -n "$shlibpath_var"; then
+      # get the directories listed in $shlibpath_var
+      eval shlib_search_path=\`\$ECHO \"\${$shlibpath_var}\" \| \$SED \'s/:/ /g\'\`
+    else
+      shlib_search_path=
+    fi
+    eval sys_lib_search_path=\"$sys_lib_search_path_spec\"
+    eval sys_lib_dlsearch_path=\"$sys_lib_dlsearch_path_spec\"
+
+    func_dirname "$output" "/" ""
+    output_objdir="$func_dirname_result$objdir"
+    func_to_tool_file "$output_objdir/"
+    tool_output_objdir=$func_to_tool_file_result
+    # Create the object directory.
+    func_mkdir_p "$output_objdir"
+
+    # Determine the type of output
+    case $output in
+    "")
+      func_fatal_help "you must specify an output file"
+      ;;
+    *.$libext) linkmode=oldlib ;;
+    *.lo | *.$objext) linkmode=obj ;;
+    *.la) linkmode=lib ;;
+    *) linkmode=prog ;; # Anything else should be a program.
+    esac
+
+    specialdeplibs=
+
+    libs=
+    # Find all interdependent deplibs by searching for libraries
+    # that are linked more than once (e.g. -la -lb -la)
+    for deplib in $deplibs; do
+      if $opt_preserve_dup_deps ; then
+	case "$libs " in
+	*" $deplib "*) func_append specialdeplibs " $deplib" ;;
+	esac
+      fi
+      func_append libs " $deplib"
+    done
+
+    if test "$linkmode" = lib; then
+      libs="$predeps $libs $compiler_lib_search_path $postdeps"
+
+      # Compute libraries that are listed more than once in $predeps
+      # $postdeps and mark them as special (i.e., whose duplicates are
+      # not to be eliminated).
+      pre_post_deps=
+      if $opt_duplicate_compiler_generated_deps; then
+	for pre_post_dep in $predeps $postdeps; do
+	  case "$pre_post_deps " in
+	  *" $pre_post_dep "*) func_append specialdeplibs " $pre_post_deps" ;;
+	  esac
+	  func_append pre_post_deps " $pre_post_dep"
+	done
+      fi
+      pre_post_deps=
+    fi
+
+    deplibs=
+    newdependency_libs=
+    newlib_search_path=
+    need_relink=no # whether we're linking any uninstalled libtool libraries
+    notinst_deplibs= # not-installed libtool libraries
+    notinst_path= # paths that contain not-installed libtool libraries
+
+    case $linkmode in
+    lib)
+	passes="conv dlpreopen link"
+	for file in $dlfiles $dlprefiles; do
+	  case $file in
+	  *.la) ;;
+	  *)
+	    func_fatal_help "libraries can \`-dlopen' only libtool libraries: $file"
+	    ;;
+	  esac
+	done
+	;;
+    prog)
+	compile_deplibs=
+	finalize_deplibs=
+	alldeplibs=no
+	newdlfiles=
+	newdlprefiles=
+	passes="conv scan dlopen dlpreopen link"
+	;;
+    *)  passes="conv"
+	;;
+    esac
+
+    for pass in $passes; do
+      # The preopen pass in lib mode reverses $deplibs; put it back here
+      # so that -L comes before libs that need it for instance...
+      if test "$linkmode,$pass" = "lib,link"; then
+	## FIXME: Find the place where the list is rebuilt in the wrong
+	##        order, and fix it there properly
+        tmp_deplibs=
+	for deplib in $deplibs; do
+	  tmp_deplibs="$deplib $tmp_deplibs"
+	done
+	deplibs="$tmp_deplibs"
+      fi
+
+      if test "$linkmode,$pass" = "lib,link" ||
+	 test "$linkmode,$pass" = "prog,scan"; then
+	libs="$deplibs"
+	deplibs=
+      fi
+      if test "$linkmode" = prog; then
+	case $pass in
+	dlopen) libs="$dlfiles" ;;
+	dlpreopen) libs="$dlprefiles" ;;
+	link)
+	  libs="$deplibs %DEPLIBS%"
+	  test "X$link_all_deplibs" != Xno && libs="$libs $dependency_libs"
+	  ;;
+	esac
+      fi
+      if test "$linkmode,$pass" = "lib,dlpreopen"; then
+	# Collect and forward deplibs of preopened libtool libs
+	for lib in $dlprefiles; do
+	  # Ignore non-libtool-libs
+	  dependency_libs=
+	  func_resolve_sysroot "$lib"
+	  case $lib in
+	  *.la)	func_source "$func_resolve_sysroot_result" ;;
+	  esac
+
+	  # Collect preopened libtool deplibs, except any this library
+	  # has declared as weak libs
+	  for deplib in $dependency_libs; do
+	    func_basename "$deplib"
+            deplib_base=$func_basename_result
+	    case " $weak_libs " in
+	    *" $deplib_base "*) ;;
+	    *) func_append deplibs " $deplib" ;;
+	    esac
+	  done
+	done
+	libs="$dlprefiles"
+      fi
+      if test "$pass" = dlopen; then
+	# Collect dlpreopened libraries
+	save_deplibs="$deplibs"
+	deplibs=
+      fi
+
+      for deplib in $libs; do
+	lib=
+	found=no
+	case $deplib in
+	-mt|-mthreads|-kthread|-Kthread|-pthread|-pthreads|--thread-safe \
+        |-threads|-fopenmp|-openmp|-mp|-xopenmp|-omp|-qsmp=*)
+	  if test "$linkmode,$pass" = "prog,link"; then
+	    compile_deplibs="$deplib $compile_deplibs"
+	    finalize_deplibs="$deplib $finalize_deplibs"
+	  else
+	    func_append compiler_flags " $deplib"
+	    if test "$linkmode" = lib ; then
+		case "$new_inherited_linker_flags " in
+		    *" $deplib "*) ;;
+		    * ) func_append new_inherited_linker_flags " $deplib" ;;
+		esac
+	    fi
+	  fi
+	  continue
+	  ;;
+	-l*)
+	  if test "$linkmode" != lib && test "$linkmode" != prog; then
+	    func_warning "\`-l' is ignored for archives/objects"
+	    continue
+	  fi
+	  func_stripname '-l' '' "$deplib"
+	  name=$func_stripname_result
+	  if test "$linkmode" = lib; then
+	    searchdirs="$newlib_search_path $lib_search_path $compiler_lib_search_dirs $sys_lib_search_path $shlib_search_path"
+	  else
+	    searchdirs="$newlib_search_path $lib_search_path $sys_lib_search_path $shlib_search_path"
+	  fi
+	  for searchdir in $searchdirs; do
+	    for search_ext in .la $std_shrext .so .a; do
+	      # Search the libtool library
+	      lib="$searchdir/lib${name}${search_ext}"
+	      if test -f "$lib"; then
+		if test "$search_ext" = ".la"; then
+		  found=yes
+		else
+		  found=no
+		fi
+		break 2
+	      fi
+	    done
+	  done
+	  if test "$found" != yes; then
+	    # deplib doesn't seem to be a libtool library
+	    if test "$linkmode,$pass" = "prog,link"; then
+	      compile_deplibs="$deplib $compile_deplibs"
+	      finalize_deplibs="$deplib $finalize_deplibs"
+	    else
+	      deplibs="$deplib $deplibs"
+	      test "$linkmode" = lib && newdependency_libs="$deplib $newdependency_libs"
+	    fi
+	    continue
+	  else # deplib is a libtool library
+	    # If $allow_libtool_libs_with_static_runtimes && $deplib is a stdlib,
+	    # We need to do some special things here, and not later.
+	    if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+	      case " $predeps $postdeps " in
+	      *" $deplib "*)
+		if func_lalib_p "$lib"; then
+		  library_names=
+		  old_library=
+		  func_source "$lib"
+		  for l in $old_library $library_names; do
+		    ll="$l"
+		  done
+		  if test "X$ll" = "X$old_library" ; then # only static version available
+		    found=no
+		    func_dirname "$lib" "" "."
+		    ladir="$func_dirname_result"
+		    lib=$ladir/$old_library
+		    if test "$linkmode,$pass" = "prog,link"; then
+		      compile_deplibs="$deplib $compile_deplibs"
+		      finalize_deplibs="$deplib $finalize_deplibs"
+		    else
+		      deplibs="$deplib $deplibs"
+		      test "$linkmode" = lib && newdependency_libs="$deplib $newdependency_libs"
+		    fi
+		    continue
+		  fi
+		fi
+		;;
+	      *) ;;
+	      esac
+	    fi
+	  fi
+	  ;; # -l
+	*.ltframework)
+	  if test "$linkmode,$pass" = "prog,link"; then
+	    compile_deplibs="$deplib $compile_deplibs"
+	    finalize_deplibs="$deplib $finalize_deplibs"
+	  else
+	    deplibs="$deplib $deplibs"
+	    if test "$linkmode" = lib ; then
+		case "$new_inherited_linker_flags " in
+		    *" $deplib "*) ;;
+		    * ) func_append new_inherited_linker_flags " $deplib" ;;
+		esac
+	    fi
+	  fi
+	  continue
+	  ;;
+	-L*)
+	  case $linkmode in
+	  lib)
+	    deplibs="$deplib $deplibs"
+	    test "$pass" = conv && continue
+	    newdependency_libs="$deplib $newdependency_libs"
+	    func_stripname '-L' '' "$deplib"
+	    func_resolve_sysroot "$func_stripname_result"
+	    func_append newlib_search_path " $func_resolve_sysroot_result"
+	    ;;
+	  prog)
+	    if test "$pass" = conv; then
+	      deplibs="$deplib $deplibs"
+	      continue
+	    fi
+	    if test "$pass" = scan; then
+	      deplibs="$deplib $deplibs"
+	    else
+	      compile_deplibs="$deplib $compile_deplibs"
+	      finalize_deplibs="$deplib $finalize_deplibs"
+	    fi
+	    func_stripname '-L' '' "$deplib"
+	    func_resolve_sysroot "$func_stripname_result"
+	    func_append newlib_search_path " $func_resolve_sysroot_result"
+	    ;;
+	  *)
+	    func_warning "\`-L' is ignored for archives/objects"
+	    ;;
+	  esac # linkmode
+	  continue
+	  ;; # -L
+	-R*)
+	  if test "$pass" = link; then
+	    func_stripname '-R' '' "$deplib"
+	    func_resolve_sysroot "$func_stripname_result"
+	    dir=$func_resolve_sysroot_result
+	    # Make sure the xrpath contains only unique directories.
+	    case "$xrpath " in
+	    *" $dir "*) ;;
+	    *) func_append xrpath " $dir" ;;
+	    esac
+	  fi
+	  deplibs="$deplib $deplibs"
+	  continue
+	  ;;
+	*.la)
+	  func_resolve_sysroot "$deplib"
+	  lib=$func_resolve_sysroot_result
+	  ;;
+	*.$libext)
+	  if test "$pass" = conv; then
+	    deplibs="$deplib $deplibs"
+	    continue
+	  fi
+	  case $linkmode in
+	  lib)
+	    # Linking convenience modules into shared libraries is allowed,
+	    # but linking other static libraries is non-portable.
+	    case " $dlpreconveniencelibs " in
+	    *" $deplib "*) ;;
+	    *)
+	      valid_a_lib=no
+	      case $deplibs_check_method in
+		match_pattern*)
+		  set dummy $deplibs_check_method; shift
+		  match_pattern_regex=`expr "$deplibs_check_method" : "$1 \(.*\)"`
+		  if eval "\$ECHO \"$deplib\"" 2>/dev/null | $SED 10q \
+		    | $EGREP "$match_pattern_regex" > /dev/null; then
+		    valid_a_lib=yes
+		  fi
+		;;
+		pass_all)
+		  valid_a_lib=yes
+		;;
+	      esac
+	      if test "$valid_a_lib" != yes; then
+		echo
+		$ECHO "*** Warning: Trying to link with static lib archive $deplib."
+		echo "*** I have the capability to make that library automatically link in when"
+		echo "*** you link to this library.  But I can only do this if you have a"
+		echo "*** shared version of the library, which you do not appear to have"
+		echo "*** because the file extensions .$libext of this argument makes me believe"
+		echo "*** that it is just a static archive that I should not use here."
+	      else
+		echo
+		$ECHO "*** Warning: Linking the shared library $output against the"
+		$ECHO "*** static library $deplib is not portable!"
+		deplibs="$deplib $deplibs"
+	      fi
+	      ;;
+	    esac
+	    continue
+	    ;;
+	  prog)
+	    if test "$pass" != link; then
+	      deplibs="$deplib $deplibs"
+	    else
+	      compile_deplibs="$deplib $compile_deplibs"
+	      finalize_deplibs="$deplib $finalize_deplibs"
+	    fi
+	    continue
+	    ;;
+	  esac # linkmode
+	  ;; # *.$libext
+	*.lo | *.$objext)
+	  if test "$pass" = conv; then
+	    deplibs="$deplib $deplibs"
+	  elif test "$linkmode" = prog; then
+	    if test "$pass" = dlpreopen || test "$dlopen_support" != yes || test "$build_libtool_libs" = no; then
+	      # If there is no dlopen support or we're linking statically,
+	      # we need to preload.
+	      func_append newdlprefiles " $deplib"
+	      compile_deplibs="$deplib $compile_deplibs"
+	      finalize_deplibs="$deplib $finalize_deplibs"
+	    else
+	      func_append newdlfiles " $deplib"
+	    fi
+	  fi
+	  continue
+	  ;;
+	%DEPLIBS%)
+	  alldeplibs=yes
+	  continue
+	  ;;
+	esac # case $deplib
+
+	if test "$found" = yes || test -f "$lib"; then :
+	else
+	  func_fatal_error "cannot find the library \`$lib' or unhandled argument \`$deplib'"
+	fi
+
+	# Check to see that this really is a libtool archive.
+	func_lalib_unsafe_p "$lib" \
+	  || func_fatal_error "\`$lib' is not a valid libtool archive"
+
+	func_dirname "$lib" "" "."
+	ladir="$func_dirname_result"
+
+	dlname=
+	dlopen=
+	dlpreopen=
+	libdir=
+	library_names=
+	old_library=
+	inherited_linker_flags=
+	# If the library was installed with an old release of libtool,
+	# it will not redefine variables installed, or shouldnotlink
+	installed=yes
+	shouldnotlink=no
+	avoidtemprpath=
+
+
+	# Read the .la file
+	func_source "$lib"
+
+	# Convert "-framework foo" to "foo.ltframework"
+	if test -n "$inherited_linker_flags"; then
+	  tmp_inherited_linker_flags=`$ECHO "$inherited_linker_flags" | $SED 's/-framework \([^ $]*\)/\1.ltframework/g'`
+	  for tmp_inherited_linker_flag in $tmp_inherited_linker_flags; do
+	    case " $new_inherited_linker_flags " in
+	      *" $tmp_inherited_linker_flag "*) ;;
+	      *) func_append new_inherited_linker_flags " $tmp_inherited_linker_flag";;
+	    esac
+	  done
+	fi
+	dependency_libs=`$ECHO " $dependency_libs" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	if test "$linkmode,$pass" = "lib,link" ||
+	   test "$linkmode,$pass" = "prog,scan" ||
+	   { test "$linkmode" != prog && test "$linkmode" != lib; }; then
+	  test -n "$dlopen" && func_append dlfiles " $dlopen"
+	  test -n "$dlpreopen" && func_append dlprefiles " $dlpreopen"
+	fi
+
+	if test "$pass" = conv; then
+	  # Only check for convenience libraries
+	  deplibs="$lib $deplibs"
+	  if test -z "$libdir"; then
+	    if test -z "$old_library"; then
+	      func_fatal_error "cannot find name of link library for \`$lib'"
+	    fi
+	    # It is a libtool convenience library, so add in its objects.
+	    func_append convenience " $ladir/$objdir/$old_library"
+	    func_append old_convenience " $ladir/$objdir/$old_library"
+	    tmp_libs=
+	    for deplib in $dependency_libs; do
+	      deplibs="$deplib $deplibs"
+	      if $opt_preserve_dup_deps ; then
+		case "$tmp_libs " in
+		*" $deplib "*) func_append specialdeplibs " $deplib" ;;
+		esac
+	      fi
+	      func_append tmp_libs " $deplib"
+	    done
+	  elif test "$linkmode" != prog && test "$linkmode" != lib; then
+	    func_fatal_error "\`$lib' is not a convenience library"
+	  fi
+	  continue
+	fi # $pass = conv
+
+
+	# Get the name of the library we link against.
+	linklib=
+	if test -n "$old_library" &&
+	   { test "$prefer_static_libs" = yes ||
+	     test "$prefer_static_libs,$installed" = "built,no"; }; then
+	  linklib=$old_library
+	else
+	  for l in $old_library $library_names; do
+	    linklib="$l"
+	  done
+	fi
+	if test -z "$linklib"; then
+	  func_fatal_error "cannot find name of link library for \`$lib'"
+	fi
+
+	# This library was specified with -dlopen.
+	if test "$pass" = dlopen; then
+	  if test -z "$libdir"; then
+	    func_fatal_error "cannot -dlopen a convenience library: \`$lib'"
+	  fi
+	  if test -z "$dlname" ||
+	     test "$dlopen_support" != yes ||
+	     test "$build_libtool_libs" = no; then
+	    # If there is no dlname, no dlopen support or we're linking
+	    # statically, we need to preload.  We also need to preload any
+	    # dependent libraries so libltdl's deplib preloader doesn't
+	    # bomb out in the load deplibs phase.
+	    func_append dlprefiles " $lib $dependency_libs"
+	  else
+	    func_append newdlfiles " $lib"
+	  fi
+	  continue
+	fi # $pass = dlopen
+
+	# We need an absolute path.
+	case $ladir in
+	[\\/]* | [A-Za-z]:[\\/]*) abs_ladir="$ladir" ;;
+	*)
+	  abs_ladir=`cd "$ladir" && pwd`
+	  if test -z "$abs_ladir"; then
+	    func_warning "cannot determine absolute directory name of \`$ladir'"
+	    func_warning "passing it literally to the linker, although it might fail"
+	    abs_ladir="$ladir"
+	  fi
+	  ;;
+	esac
+	func_basename "$lib"
+	laname="$func_basename_result"
+
+	# Find the relevant object directory and library name.
+	if test "X$installed" = Xyes; then
+	  if test ! -f "$lt_sysroot$libdir/$linklib" && test -f "$abs_ladir/$linklib"; then
+	    func_warning "library \`$lib' was moved."
+	    dir="$ladir"
+	    absdir="$abs_ladir"
+	    libdir="$abs_ladir"
+	  else
+	    dir="$lt_sysroot$libdir"
+	    absdir="$lt_sysroot$libdir"
+	  fi
+	  test "X$hardcode_automatic" = Xyes && avoidtemprpath=yes
+	else
+	  if test ! -f "$ladir/$objdir/$linklib" && test -f "$abs_ladir/$linklib"; then
+	    dir="$ladir"
+	    absdir="$abs_ladir"
+	    # Remove this search path later
+	    func_append notinst_path " $abs_ladir"
+	  else
+	    dir="$ladir/$objdir"
+	    absdir="$abs_ladir/$objdir"
+	    # Remove this search path later
+	    func_append notinst_path " $abs_ladir"
+	  fi
+	fi # $installed = yes
+	func_stripname 'lib' '.la' "$laname"
+	name=$func_stripname_result
+
+	# This library was specified with -dlpreopen.
+	if test "$pass" = dlpreopen; then
+	  if test -z "$libdir" && test "$linkmode" = prog; then
+	    func_fatal_error "only libraries may -dlpreopen a convenience library: \`$lib'"
+	  fi
+	  case "$host" in
+	    # special handling for platforms with PE-DLLs.
+	    *cygwin* | *mingw* | *cegcc* )
+	      # Linker will automatically link against shared library if both
+	      # static and shared are present.  Therefore, ensure we extract
+	      # symbols from the import library if a shared library is present
+	      # (otherwise, the dlopen module name will be incorrect).  We do
+	      # this by putting the import library name into $newdlprefiles.
+	      # We recover the dlopen module name by 'saving' the la file
+	      # name in a special purpose variable, and (later) extracting the
+	      # dlname from the la file.
+	      if test -n "$dlname"; then
+	        func_tr_sh "$dir/$linklib"
+	        eval "libfile_$func_tr_sh_result=\$abs_ladir/\$laname"
+	        func_append newdlprefiles " $dir/$linklib"
+	      else
+	        func_append newdlprefiles " $dir/$old_library"
+	        # Keep a list of preopened convenience libraries to check
+	        # that they are being used correctly in the link pass.
+	        test -z "$libdir" && \
+	          func_append dlpreconveniencelibs " $dir/$old_library"
+	      fi
+	    ;;
+	    * )
+	      # Prefer using a static library (so that no silly _DYNAMIC symbols
+	      # are required to link).
+	      if test -n "$old_library"; then
+	        func_append newdlprefiles " $dir/$old_library"
+	        # Keep a list of preopened convenience libraries to check
+	        # that they are being used correctly in the link pass.
+	        test -z "$libdir" && \
+	          func_append dlpreconveniencelibs " $dir/$old_library"
+	      # Otherwise, use the dlname, so that lt_dlopen finds it.
+	      elif test -n "$dlname"; then
+	        func_append newdlprefiles " $dir/$dlname"
+	      else
+	        func_append newdlprefiles " $dir/$linklib"
+	      fi
+	    ;;
+	  esac
+	fi # $pass = dlpreopen
+
+	if test -z "$libdir"; then
+	  # Link the convenience library
+	  if test "$linkmode" = lib; then
+	    deplibs="$dir/$old_library $deplibs"
+	  elif test "$linkmode,$pass" = "prog,link"; then
+	    compile_deplibs="$dir/$old_library $compile_deplibs"
+	    finalize_deplibs="$dir/$old_library $finalize_deplibs"
+	  else
+	    deplibs="$lib $deplibs" # used for prog,scan pass
+	  fi
+	  continue
+	fi
+
+
+	if test "$linkmode" = prog && test "$pass" != link; then
+	  func_append newlib_search_path " $ladir"
+	  deplibs="$lib $deplibs"
+
+	  linkalldeplibs=no
+	  if test "$link_all_deplibs" != no || test -z "$library_names" ||
+	     test "$build_libtool_libs" = no; then
+	    linkalldeplibs=yes
+	  fi
+
+	  tmp_libs=
+	  for deplib in $dependency_libs; do
+	    case $deplib in
+	    -L*) func_stripname '-L' '' "$deplib"
+	         func_resolve_sysroot "$func_stripname_result"
+	         func_append newlib_search_path " $func_resolve_sysroot_result"
+		 ;;
+	    esac
+	    # Need to link against all dependency_libs?
+	    if test "$linkalldeplibs" = yes; then
+	      deplibs="$deplib $deplibs"
+	    else
+	      # Need to hardcode shared library paths
+	      # or/and link against static libraries
+	      newdependency_libs="$deplib $newdependency_libs"
+	    fi
+	    if $opt_preserve_dup_deps ; then
+	      case "$tmp_libs " in
+	      *" $deplib "*) func_append specialdeplibs " $deplib" ;;
+	      esac
+	    fi
+	    func_append tmp_libs " $deplib"
+	  done # for deplib
+	  continue
+	fi # $linkmode = prog...
+
+	if test "$linkmode,$pass" = "prog,link"; then
+	  if test -n "$library_names" &&
+	     { { test "$prefer_static_libs" = no ||
+	         test "$prefer_static_libs,$installed" = "built,yes"; } ||
+	       test -z "$old_library"; }; then
+	    # We need to hardcode the library path
+	    if test -n "$shlibpath_var" && test -z "$avoidtemprpath" ; then
+	      # Make sure the rpath contains only unique directories.
+	      case "$temp_rpath:" in
+	      *"$absdir:"*) ;;
+	      *) func_append temp_rpath "$absdir:" ;;
+	      esac
+	    fi
+
+	    # Hardcode the library path.
+	    # Skip directories that are in the system default run-time
+	    # search path.
+	    case " $sys_lib_dlsearch_path " in
+	    *" $absdir "*) ;;
+	    *)
+	      case "$compile_rpath " in
+	      *" $absdir "*) ;;
+	      *) func_append compile_rpath " $absdir" ;;
+	      esac
+	      ;;
+	    esac
+	    case " $sys_lib_dlsearch_path " in
+	    *" $libdir "*) ;;
+	    *)
+	      case "$finalize_rpath " in
+	      *" $libdir "*) ;;
+	      *) func_append finalize_rpath " $libdir" ;;
+	      esac
+	      ;;
+	    esac
+	  fi # $linkmode,$pass = prog,link...
+
+	  if test "$alldeplibs" = yes &&
+	     { test "$deplibs_check_method" = pass_all ||
+	       { test "$build_libtool_libs" = yes &&
+		 test -n "$library_names"; }; }; then
+	    # We only need to search for static libraries
+	    continue
+	  fi
+	fi
+
+	link_static=no # Whether the deplib will be linked statically
+	use_static_libs=$prefer_static_libs
+	if test "$use_static_libs" = built && test "$installed" = yes; then
+	  use_static_libs=no
+	fi
+	if test -n "$library_names" &&
+	   { test "$use_static_libs" = no || test -z "$old_library"; }; then
+	  case $host in
+	  *cygwin* | *mingw* | *cegcc*)
+	      # No point in relinking DLLs because paths are not encoded
+	      func_append notinst_deplibs " $lib"
+	      need_relink=no
+	    ;;
+	  *)
+	    if test "$installed" = no; then
+	      func_append notinst_deplibs " $lib"
+	      need_relink=yes
+	    fi
+	    ;;
+	  esac
+	  # This is a shared library
+
+	  # Warn about portability, can't link against -module's on some
+	  # systems (darwin).  Don't bleat about dlopened modules though!
+	  dlopenmodule=""
+	  for dlpremoduletest in $dlprefiles; do
+	    if test "X$dlpremoduletest" = "X$lib"; then
+	      dlopenmodule="$dlpremoduletest"
+	      break
+	    fi
+	  done
+	  if test -z "$dlopenmodule" && test "$shouldnotlink" = yes && test "$pass" = link; then
+	    echo
+	    if test "$linkmode" = prog; then
+	      $ECHO "*** Warning: Linking the executable $output against the loadable module"
+	    else
+	      $ECHO "*** Warning: Linking the shared library $output against the loadable module"
+	    fi
+	    $ECHO "*** $linklib is not portable!"
+	  fi
+	  if test "$linkmode" = lib &&
+	     test "$hardcode_into_libs" = yes; then
+	    # Hardcode the library path.
+	    # Skip directories that are in the system default run-time
+	    # search path.
+	    case " $sys_lib_dlsearch_path " in
+	    *" $absdir "*) ;;
+	    *)
+	      case "$compile_rpath " in
+	      *" $absdir "*) ;;
+	      *) func_append compile_rpath " $absdir" ;;
+	      esac
+	      ;;
+	    esac
+	    case " $sys_lib_dlsearch_path " in
+	    *" $libdir "*) ;;
+	    *)
+	      case "$finalize_rpath " in
+	      *" $libdir "*) ;;
+	      *) func_append finalize_rpath " $libdir" ;;
+	      esac
+	      ;;
+	    esac
+	  fi
+
+	  if test -n "$old_archive_from_expsyms_cmds"; then
+	    # figure out the soname
+	    set dummy $library_names
+	    shift
+	    realname="$1"
+	    shift
+	    libname=`eval "\\$ECHO \"$libname_spec\""`
+	    # use dlname if we got it. it's perfectly good, no?
+	    if test -n "$dlname"; then
+	      soname="$dlname"
+	    elif test -n "$soname_spec"; then
+	      # bleh windows
+	      case $host in
+	      *cygwin* | mingw* | *cegcc*)
+	        func_arith $current - $age
+		major=$func_arith_result
+		versuffix="-$major"
+		;;
+	      esac
+	      eval soname=\"$soname_spec\"
+	    else
+	      soname="$realname"
+	    fi
+
+	    # Make a new name for the extract_expsyms_cmds to use
+	    soroot="$soname"
+	    func_basename "$soroot"
+	    soname="$func_basename_result"
+	    func_stripname 'lib' '.dll' "$soname"
+	    newlib=libimp-$func_stripname_result.a
+
+	    # If the library has no export list, then create one now
+	    if test -f "$output_objdir/$soname-def"; then :
+	    else
+	      func_verbose "extracting exported symbol list from \`$soname'"
+	      func_execute_cmds "$extract_expsyms_cmds" 'exit $?'
+	    fi
+
+	    # Create $newlib
+	    if test -f "$output_objdir/$newlib"; then :; else
+	      func_verbose "generating import library for \`$soname'"
+	      func_execute_cmds "$old_archive_from_expsyms_cmds" 'exit $?'
+	    fi
+	    # make sure the library variables are pointing to the new library
+	    dir=$output_objdir
+	    linklib=$newlib
+	  fi # test -n "$old_archive_from_expsyms_cmds"
+
+	  if test "$linkmode" = prog || test "$opt_mode" != relink; then
+	    add_shlibpath=
+	    add_dir=
+	    add=
+	    lib_linked=yes
+	    case $hardcode_action in
+	    immediate | unsupported)
+	      if test "$hardcode_direct" = no; then
+		add="$dir/$linklib"
+		case $host in
+		  *-*-sco3.2v5.0.[024]*) add_dir="-L$dir" ;;
+		  *-*-sysv4*uw2*) add_dir="-L$dir" ;;
+		  *-*-sysv5OpenUNIX* | *-*-sysv5UnixWare7.[01].[10]* | \
+		    *-*-unixware7*) add_dir="-L$dir" ;;
+		  *-*-darwin* )
+		    # if the lib is a (non-dlopened) module then we can not
+		    # link against it, someone is ignoring the earlier warnings
+		    if /usr/bin/file -L $add 2> /dev/null |
+			 $GREP ": [^:]* bundle" >/dev/null ; then
+		      if test "X$dlopenmodule" != "X$lib"; then
+			$ECHO "*** Warning: lib $linklib is a module, not a shared library"
+			if test -z "$old_library" ; then
+			  echo
+			  echo "*** And there doesn't seem to be a static archive available"
+			  echo "*** The link will probably fail, sorry"
+			else
+			  add="$dir/$old_library"
+			fi
+		      elif test -n "$old_library"; then
+			add="$dir/$old_library"
+		      fi
+		    fi
+		esac
+	      elif test "$hardcode_minus_L" = no; then
+		case $host in
+		*-*-sunos*) add_shlibpath="$dir" ;;
+		esac
+		add_dir="-L$dir"
+		add="-l$name"
+	      elif test "$hardcode_shlibpath_var" = no; then
+		add_shlibpath="$dir"
+		add="-l$name"
+	      else
+		lib_linked=no
+	      fi
+	      ;;
+	    relink)
+	      if test "$hardcode_direct" = yes &&
+	         test "$hardcode_direct_absolute" = no; then
+		add="$dir/$linklib"
+	      elif test "$hardcode_minus_L" = yes; then
+		add_dir="-L$absdir"
+		# Try looking first in the location we're being installed to.
+		if test -n "$inst_prefix_dir"; then
+		  case $libdir in
+		    [\\/]*)
+		      func_append add_dir " -L$inst_prefix_dir$libdir"
+		      ;;
+		  esac
+		fi
+		add="-l$name"
+	      elif test "$hardcode_shlibpath_var" = yes; then
+		add_shlibpath="$dir"
+		add="-l$name"
+	      else
+		lib_linked=no
+	      fi
+	      ;;
+	    *) lib_linked=no ;;
+	    esac
+
+	    if test "$lib_linked" != yes; then
+	      func_fatal_configuration "unsupported hardcode properties"
+	    fi
+
+	    if test -n "$add_shlibpath"; then
+	      case :$compile_shlibpath: in
+	      *":$add_shlibpath:"*) ;;
+	      *) func_append compile_shlibpath "$add_shlibpath:" ;;
+	      esac
+	    fi
+	    if test "$linkmode" = prog; then
+	      test -n "$add_dir" && compile_deplibs="$add_dir $compile_deplibs"
+	      test -n "$add" && compile_deplibs="$add $compile_deplibs"
+	    else
+	      test -n "$add_dir" && deplibs="$add_dir $deplibs"
+	      test -n "$add" && deplibs="$add $deplibs"
+	      if test "$hardcode_direct" != yes &&
+		 test "$hardcode_minus_L" != yes &&
+		 test "$hardcode_shlibpath_var" = yes; then
+		case :$finalize_shlibpath: in
+		*":$libdir:"*) ;;
+		*) func_append finalize_shlibpath "$libdir:" ;;
+		esac
+	      fi
+	    fi
+	  fi
+
+	  if test "$linkmode" = prog || test "$opt_mode" = relink; then
+	    add_shlibpath=
+	    add_dir=
+	    add=
+	    # Finalize command for both is simple: just hardcode it.
+	    if test "$hardcode_direct" = yes &&
+	       test "$hardcode_direct_absolute" = no; then
+	      add="$libdir/$linklib"
+	    elif test "$hardcode_minus_L" = yes; then
+	      add_dir="-L$libdir"
+	      add="-l$name"
+	    elif test "$hardcode_shlibpath_var" = yes; then
+	      case :$finalize_shlibpath: in
+	      *":$libdir:"*) ;;
+	      *) func_append finalize_shlibpath "$libdir:" ;;
+	      esac
+	      add="-l$name"
+	    elif test "$hardcode_automatic" = yes; then
+	      if test -n "$inst_prefix_dir" &&
+		 test -f "$inst_prefix_dir$libdir/$linklib" ; then
+		add="$inst_prefix_dir$libdir/$linklib"
+	      else
+		add="$libdir/$linklib"
+	      fi
+	    else
+	      # We cannot seem to hardcode it, guess we'll fake it.
+	      add_dir="-L$libdir"
+	      # Try looking first in the location we're being installed to.
+	      if test -n "$inst_prefix_dir"; then
+		case $libdir in
+		  [\\/]*)
+		    func_append add_dir " -L$inst_prefix_dir$libdir"
+		    ;;
+		esac
+	      fi
+	      add="-l$name"
+	    fi
+
+	    if test "$linkmode" = prog; then
+	      test -n "$add_dir" && finalize_deplibs="$add_dir $finalize_deplibs"
+	      test -n "$add" && finalize_deplibs="$add $finalize_deplibs"
+	    else
+	      test -n "$add_dir" && deplibs="$add_dir $deplibs"
+	      test -n "$add" && deplibs="$add $deplibs"
+	    fi
+	  fi
+	elif test "$linkmode" = prog; then
+	  # Here we assume that one of hardcode_direct or hardcode_minus_L
+	  # is not unsupported.  This is valid on all known static and
+	  # shared platforms.
+	  if test "$hardcode_direct" != unsupported; then
+	    test -n "$old_library" && linklib="$old_library"
+	    compile_deplibs="$dir/$linklib $compile_deplibs"
+	    finalize_deplibs="$dir/$linklib $finalize_deplibs"
+	  else
+	    compile_deplibs="-l$name -L$dir $compile_deplibs"
+	    finalize_deplibs="-l$name -L$dir $finalize_deplibs"
+	  fi
+	elif test "$build_libtool_libs" = yes; then
+	  # Not a shared library
+	  if test "$deplibs_check_method" != pass_all; then
+	    # We're trying link a shared library against a static one
+	    # but the system doesn't support it.
+
+	    # Just print a warning and add the library to dependency_libs so
+	    # that the program can be linked against the static library.
+	    echo
+	    $ECHO "*** Warning: This system can not link to static lib archive $lib."
+	    echo "*** I have the capability to make that library automatically link in when"
+	    echo "*** you link to this library.  But I can only do this if you have a"
+	    echo "*** shared version of the library, which you do not appear to have."
+	    if test "$module" = yes; then
+	      echo "*** But as you try to build a module library, libtool will still create "
+	      echo "*** a static module, that should work as long as the dlopening application"
+	      echo "*** is linked with the -dlopen flag to resolve symbols at runtime."
+	      if test -z "$global_symbol_pipe"; then
+		echo
+		echo "*** However, this would only work if libtool was able to extract symbol"
+		echo "*** lists from a program, using \`nm' or equivalent, but libtool could"
+		echo "*** not find such a program.  So, this module is probably useless."
+		echo "*** \`nm' from GNU binutils and a full rebuild may help."
+	      fi
+	      if test "$build_old_libs" = no; then
+		build_libtool_libs=module
+		build_old_libs=yes
+	      else
+		build_libtool_libs=no
+	      fi
+	    fi
+	  else
+	    deplibs="$dir/$old_library $deplibs"
+	    link_static=yes
+	  fi
+	fi # link shared/static library?
+
+	if test "$linkmode" = lib; then
+	  if test -n "$dependency_libs" &&
+	     { test "$hardcode_into_libs" != yes ||
+	       test "$build_old_libs" = yes ||
+	       test "$link_static" = yes; }; then
+	    # Extract -R from dependency_libs
+	    temp_deplibs=
+	    for libdir in $dependency_libs; do
+	      case $libdir in
+	      -R*) func_stripname '-R' '' "$libdir"
+	           temp_xrpath=$func_stripname_result
+		   case " $xrpath " in
+		   *" $temp_xrpath "*) ;;
+		   *) func_append xrpath " $temp_xrpath";;
+		   esac;;
+	      *) func_append temp_deplibs " $libdir";;
+	      esac
+	    done
+	    dependency_libs="$temp_deplibs"
+	  fi
+
+	  func_append newlib_search_path " $absdir"
+	  # Link against this library
+	  test "$link_static" = no && newdependency_libs="$abs_ladir/$laname $newdependency_libs"
+	  # ... and its dependency_libs
+	  tmp_libs=
+	  for deplib in $dependency_libs; do
+	    newdependency_libs="$deplib $newdependency_libs"
+	    case $deplib in
+              -L*) func_stripname '-L' '' "$deplib"
+                   func_resolve_sysroot "$func_stripname_result";;
+              *) func_resolve_sysroot "$deplib" ;;
+            esac
+	    if $opt_preserve_dup_deps ; then
+	      case "$tmp_libs " in
+	      *" $func_resolve_sysroot_result "*)
+                func_append specialdeplibs " $func_resolve_sysroot_result" ;;
+	      esac
+	    fi
+	    func_append tmp_libs " $func_resolve_sysroot_result"
+	  done
+
+	  if test "$link_all_deplibs" != no; then
+	    # Add the search paths of all dependency libraries
+	    for deplib in $dependency_libs; do
+	      path=
+	      case $deplib in
+	      -L*) path="$deplib" ;;
+	      *.la)
+	        func_resolve_sysroot "$deplib"
+	        deplib=$func_resolve_sysroot_result
+	        func_dirname "$deplib" "" "."
+		dir=$func_dirname_result
+		# We need an absolute path.
+		case $dir in
+		[\\/]* | [A-Za-z]:[\\/]*) absdir="$dir" ;;
+		*)
+		  absdir=`cd "$dir" && pwd`
+		  if test -z "$absdir"; then
+		    func_warning "cannot determine absolute directory name of \`$dir'"
+		    absdir="$dir"
+		  fi
+		  ;;
+		esac
+		if $GREP "^installed=no" $deplib > /dev/null; then
+		case $host in
+		*-*-darwin*)
+		  depdepl=
+		  eval deplibrary_names=`${SED} -n -e 's/^library_names=\(.*\)$/\1/p' $deplib`
+		  if test -n "$deplibrary_names" ; then
+		    for tmp in $deplibrary_names ; do
+		      depdepl=$tmp
+		    done
+		    if test -f "$absdir/$objdir/$depdepl" ; then
+		      depdepl="$absdir/$objdir/$depdepl"
+		      darwin_install_name=`${OTOOL} -L $depdepl | awk '{if (NR == 2) {print $1;exit}}'`
+                      if test -z "$darwin_install_name"; then
+                          darwin_install_name=`${OTOOL64} -L $depdepl  | awk '{if (NR == 2) {print $1;exit}}'`
+                      fi
+		      func_append compiler_flags " ${wl}-dylib_file ${wl}${darwin_install_name}:${depdepl}"
+		      func_append linker_flags " -dylib_file ${darwin_install_name}:${depdepl}"
+		      path=
+		    fi
+		  fi
+		  ;;
+		*)
+		  path="-L$absdir/$objdir"
+		  ;;
+		esac
+		else
+		  eval libdir=`${SED} -n -e 's/^libdir=\(.*\)$/\1/p' $deplib`
+		  test -z "$libdir" && \
+		    func_fatal_error "\`$deplib' is not a valid libtool archive"
+		  test "$absdir" != "$libdir" && \
+		    func_warning "\`$deplib' seems to be moved"
+
+		  path="-L$absdir"
+		fi
+		;;
+	      esac
+	      case " $deplibs " in
+	      *" $path "*) ;;
+	      *) deplibs="$path $deplibs" ;;
+	      esac
+	    done
+	  fi # link_all_deplibs != no
+	fi # linkmode = lib
+      done # for deplib in $libs
+      if test "$pass" = link; then
+	if test "$linkmode" = "prog"; then
+	  compile_deplibs="$new_inherited_linker_flags $compile_deplibs"
+	  finalize_deplibs="$new_inherited_linker_flags $finalize_deplibs"
+	else
+	  compiler_flags="$compiler_flags "`$ECHO " $new_inherited_linker_flags" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	fi
+      fi
+      dependency_libs="$newdependency_libs"
+      if test "$pass" = dlpreopen; then
+	# Link the dlpreopened libraries before other libraries
+	for deplib in $save_deplibs; do
+	  deplibs="$deplib $deplibs"
+	done
+      fi
+      if test "$pass" != dlopen; then
+	if test "$pass" != conv; then
+	  # Make sure lib_search_path contains only unique directories.
+	  lib_search_path=
+	  for dir in $newlib_search_path; do
+	    case "$lib_search_path " in
+	    *" $dir "*) ;;
+	    *) func_append lib_search_path " $dir" ;;
+	    esac
+	  done
+	  newlib_search_path=
+	fi
+
+	if test "$linkmode,$pass" != "prog,link"; then
+	  vars="deplibs"
+	else
+	  vars="compile_deplibs finalize_deplibs"
+	fi
+	for var in $vars dependency_libs; do
+	  # Add libraries to $var in reverse order
+	  eval tmp_libs=\"\$$var\"
+	  new_libs=
+	  for deplib in $tmp_libs; do
+	    # FIXME: Pedantically, this is the right thing to do, so
+	    #        that some nasty dependency loop isn't accidentally
+	    #        broken:
+	    #new_libs="$deplib $new_libs"
+	    # Pragmatically, this seems to cause very few problems in
+	    # practice:
+	    case $deplib in
+	    -L*) new_libs="$deplib $new_libs" ;;
+	    -R*) ;;
+	    *)
+	      # And here is the reason: when a library appears more
+	      # than once as an explicit dependence of a library, or
+	      # is implicitly linked in more than once by the
+	      # compiler, it is considered special, and multiple
+	      # occurrences thereof are not removed.  Compare this
+	      # with having the same library being listed as a
+	      # dependency of multiple other libraries: in this case,
+	      # we know (pedantically, we assume) the library does not
+	      # need to be listed more than once, so we keep only the
+	      # last copy.  This is not always right, but it is rare
+	      # enough that we require users that really mean to play
+	      # such unportable linking tricks to link the library
+	      # using -Wl,-lname, so that libtool does not consider it
+	      # for duplicate removal.
+	      case " $specialdeplibs " in
+	      *" $deplib "*) new_libs="$deplib $new_libs" ;;
+	      *)
+		case " $new_libs " in
+		*" $deplib "*) ;;
+		*) new_libs="$deplib $new_libs" ;;
+		esac
+		;;
+	      esac
+	      ;;
+	    esac
+	  done
+	  tmp_libs=
+	  for deplib in $new_libs; do
+	    case $deplib in
+	    -L*)
+	      case " $tmp_libs " in
+	      *" $deplib "*) ;;
+	      *) func_append tmp_libs " $deplib" ;;
+	      esac
+	      ;;
+	    *) func_append tmp_libs " $deplib" ;;
+	    esac
+	  done
+	  eval $var=\"$tmp_libs\"
+	done # for var
+      fi
+      # Last step: remove runtime libs from dependency_libs
+      # (they stay in deplibs)
+      tmp_libs=
+      for i in $dependency_libs ; do
+	case " $predeps $postdeps $compiler_lib_search_path " in
+	*" $i "*)
+	  i=""
+	  ;;
+	esac
+	if test -n "$i" ; then
+	  func_append tmp_libs " $i"
+	fi
+      done
+      dependency_libs=$tmp_libs
+    done # for pass
+    if test "$linkmode" = prog; then
+      dlfiles="$newdlfiles"
+    fi
+    if test "$linkmode" = prog || test "$linkmode" = lib; then
+      dlprefiles="$newdlprefiles"
+    fi
+
+    case $linkmode in
+    oldlib)
+      if test -n "$dlfiles$dlprefiles" || test "$dlself" != no; then
+	func_warning "\`-dlopen' is ignored for archives"
+      fi
+
+      case " $deplibs" in
+      *\ -l* | *\ -L*)
+	func_warning "\`-l' and \`-L' are ignored for archives" ;;
+      esac
+
+      test -n "$rpath" && \
+	func_warning "\`-rpath' is ignored for archives"
+
+      test -n "$xrpath" && \
+	func_warning "\`-R' is ignored for archives"
+
+      test -n "$vinfo" && \
+	func_warning "\`-version-info/-version-number' is ignored for archives"
+
+      test -n "$release" && \
+	func_warning "\`-release' is ignored for archives"
+
+      test -n "$export_symbols$export_symbols_regex" && \
+	func_warning "\`-export-symbols' is ignored for archives"
+
+      # Now set the variables for building old libraries.
+      build_libtool_libs=no
+      oldlibs="$output"
+      func_append objs "$old_deplibs"
+      ;;
+
+    lib)
+      # Make sure we only generate libraries of the form `libNAME.la'.
+      case $outputname in
+      lib*)
+	func_stripname 'lib' '.la' "$outputname"
+	name=$func_stripname_result
+	eval shared_ext=\"$shrext_cmds\"
+	eval libname=\"$libname_spec\"
+	;;
+      *)
+	test "$module" = no && \
+	  func_fatal_help "libtool library \`$output' must begin with \`lib'"
+
+	if test "$need_lib_prefix" != no; then
+	  # Add the "lib" prefix for modules if required
+	  func_stripname '' '.la' "$outputname"
+	  name=$func_stripname_result
+	  eval shared_ext=\"$shrext_cmds\"
+	  eval libname=\"$libname_spec\"
+	else
+	  func_stripname '' '.la' "$outputname"
+	  libname=$func_stripname_result
+	fi
+	;;
+      esac
+
+      if test -n "$objs"; then
+	if test "$deplibs_check_method" != pass_all; then
+	  func_fatal_error "cannot build libtool library \`$output' from non-libtool objects on this host:$objs"
+	else
+	  echo
+	  $ECHO "*** Warning: Linking the shared library $output against the non-libtool"
+	  $ECHO "*** objects $objs is not portable!"
+	  func_append libobjs " $objs"
+	fi
+      fi
+
+      test "$dlself" != no && \
+	func_warning "\`-dlopen self' is ignored for libtool libraries"
+
+      set dummy $rpath
+      shift
+      test "$#" -gt 1 && \
+	func_warning "ignoring multiple \`-rpath's for a libtool library"
+
+      install_libdir="$1"
+
+      oldlibs=
+      if test -z "$rpath"; then
+	if test "$build_libtool_libs" = yes; then
+	  # Building a libtool convenience library.
+	  # Some compilers have problems with a `.al' extension so
+	  # convenience libraries should have the same extension an
+	  # archive normally would.
+	  oldlibs="$output_objdir/$libname.$libext $oldlibs"
+	  build_libtool_libs=convenience
+	  build_old_libs=yes
+	fi
+
+	test -n "$vinfo" && \
+	  func_warning "\`-version-info/-version-number' is ignored for convenience libraries"
+
+	test -n "$release" && \
+	  func_warning "\`-release' is ignored for convenience libraries"
+      else
+
+	# Parse the version information argument.
+	save_ifs="$IFS"; IFS=':'
+	set dummy $vinfo 0 0 0
+	shift
+	IFS="$save_ifs"
+
+	test -n "$7" && \
+	  func_fatal_help "too many parameters to \`-version-info'"
+
+	# convert absolute version numbers to libtool ages
+	# this retains compatibility with .la files and attempts
+	# to make the code below a bit more comprehensible
+
+	case $vinfo_number in
+	yes)
+	  number_major="$1"
+	  number_minor="$2"
+	  number_revision="$3"
+	  #
+	  # There are really only two kinds -- those that
+	  # use the current revision as the major version
+	  # and those that subtract age and use age as
+	  # a minor version.  But, then there is irix
+	  # which has an extra 1 added just for fun
+	  #
+	  case $version_type in
+	  # correct linux to gnu/linux during the next big refactor
+	  darwin|linux|osf|windows|none)
+	    func_arith $number_major + $number_minor
+	    current=$func_arith_result
+	    age="$number_minor"
+	    revision="$number_revision"
+	    ;;
+	  freebsd-aout|freebsd-elf|qnx|sunos)
+	    current="$number_major"
+	    revision="$number_minor"
+	    age="0"
+	    ;;
+	  irix|nonstopux)
+	    func_arith $number_major + $number_minor
+	    current=$func_arith_result
+	    age="$number_minor"
+	    revision="$number_minor"
+	    lt_irix_increment=no
+	    ;;
+	  *)
+	    func_fatal_configuration "$modename: unknown library version type \`$version_type'"
+	    ;;
+	  esac
+	  ;;
+	no)
+	  current="$1"
+	  revision="$2"
+	  age="$3"
+	  ;;
+	esac
+
+	# Check that each of the things are valid numbers.
+	case $current in
+	0|[1-9]|[1-9][0-9]|[1-9][0-9][0-9]|[1-9][0-9][0-9][0-9]|[1-9][0-9][0-9][0-9][0-9]) ;;
+	*)
+	  func_error "CURRENT \`$current' must be a nonnegative integer"
+	  func_fatal_error "\`$vinfo' is not valid version information"
+	  ;;
+	esac
+
+	case $revision in
+	0|[1-9]|[1-9][0-9]|[1-9][0-9][0-9]|[1-9][0-9][0-9][0-9]|[1-9][0-9][0-9][0-9][0-9]) ;;
+	*)
+	  func_error "REVISION \`$revision' must be a nonnegative integer"
+	  func_fatal_error "\`$vinfo' is not valid version information"
+	  ;;
+	esac
+
+	case $age in
+	0|[1-9]|[1-9][0-9]|[1-9][0-9][0-9]|[1-9][0-9][0-9][0-9]|[1-9][0-9][0-9][0-9][0-9]) ;;
+	*)
+	  func_error "AGE \`$age' must be a nonnegative integer"
+	  func_fatal_error "\`$vinfo' is not valid version information"
+	  ;;
+	esac
+
+	if test "$age" -gt "$current"; then
+	  func_error "AGE \`$age' is greater than the current interface number \`$current'"
+	  func_fatal_error "\`$vinfo' is not valid version information"
+	fi
+
+	# Calculate the version variables.
+	major=
+	versuffix=
+	verstring=
+	case $version_type in
+	none) ;;
+
+	darwin)
+	  # Like Linux, but with the current version available in
+	  # verstring for coding it into the library header
+	  func_arith $current - $age
+	  major=.$func_arith_result
+	  versuffix="$major.$age.$revision"
+	  # Darwin ld doesn't like 0 for these options...
+	  func_arith $current + 1
+	  minor_current=$func_arith_result
+	  xlcverstring="${wl}-compatibility_version ${wl}$minor_current ${wl}-current_version ${wl}$minor_current.$revision"
+	  verstring="-compatibility_version $minor_current -current_version $minor_current.$revision"
+	  ;;
+
+	freebsd-aout)
+	  major=".$current"
+	  versuffix=".$current.$revision";
+	  ;;
+
+	freebsd-elf)
+	  major=".$current"
+	  versuffix=".$current"
+	  ;;
+
+	irix | nonstopux)
+	  if test "X$lt_irix_increment" = "Xno"; then
+	    func_arith $current - $age
+	  else
+	    func_arith $current - $age + 1
+	  fi
+	  major=$func_arith_result
+
+	  case $version_type in
+	    nonstopux) verstring_prefix=nonstopux ;;
+	    *)         verstring_prefix=sgi ;;
+	  esac
+	  verstring="$verstring_prefix$major.$revision"
+
+	  # Add in all the interfaces that we are compatible with.
+	  loop=$revision
+	  while test "$loop" -ne 0; do
+	    func_arith $revision - $loop
+	    iface=$func_arith_result
+	    func_arith $loop - 1
+	    loop=$func_arith_result
+	    verstring="$verstring_prefix$major.$iface:$verstring"
+	  done
+
+	  # Before this point, $major must not contain `.'.
+	  major=.$major
+	  versuffix="$major.$revision"
+	  ;;
+
+	linux) # correct to gnu/linux during the next big refactor
+	  func_arith $current - $age
+	  major=.$func_arith_result
+	  versuffix="$major.$age.$revision"
+	  ;;
+
+	osf)
+	  func_arith $current - $age
+	  major=.$func_arith_result
+	  versuffix=".$current.$age.$revision"
+	  verstring="$current.$age.$revision"
+
+	  # Add in all the interfaces that we are compatible with.
+	  loop=$age
+	  while test "$loop" -ne 0; do
+	    func_arith $current - $loop
+	    iface=$func_arith_result
+	    func_arith $loop - 1
+	    loop=$func_arith_result
+	    verstring="$verstring:${iface}.0"
+	  done
+
+	  # Make executables depend on our current version.
+	  func_append verstring ":${current}.0"
+	  ;;
+
+	qnx)
+	  major=".$current"
+	  versuffix=".$current"
+	  ;;
+
+	sunos)
+	  major=".$current"
+	  versuffix=".$current.$revision"
+	  ;;
+
+	windows)
+	  # Use '-' rather than '.', since we only want one
+	  # extension on DOS 8.3 filesystems.
+	  func_arith $current - $age
+	  major=$func_arith_result
+	  versuffix="-$major"
+	  ;;
+
+	*)
+	  func_fatal_configuration "unknown library version type \`$version_type'"
+	  ;;
+	esac
+
+	# Clear the version info if we defaulted, and they specified a release.
+	if test -z "$vinfo" && test -n "$release"; then
+	  major=
+	  case $version_type in
+	  darwin)
+	    # we can't check for "0.0" in archive_cmds due to quoting
+	    # problems, so we reset it completely
+	    verstring=
+	    ;;
+	  *)
+	    verstring="0.0"
+	    ;;
+	  esac
+	  if test "$need_version" = no; then
+	    versuffix=
+	  else
+	    versuffix=".0.0"
+	  fi
+	fi
+
+	# Remove version info from name if versioning should be avoided
+	if test "$avoid_version" = yes && test "$need_version" = no; then
+	  major=
+	  versuffix=
+	  verstring=""
+	fi
+
+	# Check to see if the archive will have undefined symbols.
+	if test "$allow_undefined" = yes; then
+	  if test "$allow_undefined_flag" = unsupported; then
+	    func_warning "undefined symbols not allowed in $host shared libraries"
+	    build_libtool_libs=no
+	    build_old_libs=yes
+	  fi
+	else
+	  # Don't allow undefined symbols.
+	  allow_undefined_flag="$no_undefined_flag"
+	fi
+
+      fi
+
+      func_generate_dlsyms "$libname" "$libname" "yes"
+      func_append libobjs " $symfileobj"
+      test "X$libobjs" = "X " && libobjs=
+
+      if test "$opt_mode" != relink; then
+	# Remove our outputs, but don't remove object files since they
+	# may have been created when compiling PIC objects.
+	removelist=
+	tempremovelist=`$ECHO "$output_objdir/*"`
+	for p in $tempremovelist; do
+	  case $p in
+	    *.$objext | *.gcno)
+	       ;;
+	    $output_objdir/$outputname | $output_objdir/$libname.* | $output_objdir/${libname}${release}.*)
+	       if test "X$precious_files_regex" != "X"; then
+		 if $ECHO "$p" | $EGREP -e "$precious_files_regex" >/dev/null 2>&1
+		 then
+		   continue
+		 fi
+	       fi
+	       func_append removelist " $p"
+	       ;;
+	    *) ;;
+	  esac
+	done
+	test -n "$removelist" && \
+	  func_show_eval "${RM}r \$removelist"
+      fi
+
+      # Now set the variables for building old libraries.
+      if test "$build_old_libs" = yes && test "$build_libtool_libs" != convenience ; then
+	func_append oldlibs " $output_objdir/$libname.$libext"
+
+	# Transform .lo files to .o files.
+	oldobjs="$objs "`$ECHO "$libobjs" | $SP2NL | $SED "/\.${libext}$/d; $lo2o" | $NL2SP`
+      fi
+
+      # Eliminate all temporary directories.
+      #for path in $notinst_path; do
+      #	lib_search_path=`$ECHO "$lib_search_path " | $SED "s% $path % %g"`
+      #	deplibs=`$ECHO "$deplibs " | $SED "s% -L$path % %g"`
+      #	dependency_libs=`$ECHO "$dependency_libs " | $SED "s% -L$path % %g"`
+      #done
+
+      if test -n "$xrpath"; then
+	# If the user specified any rpath flags, then add them.
+	temp_xrpath=
+	for libdir in $xrpath; do
+	  func_replace_sysroot "$libdir"
+	  func_append temp_xrpath " -R$func_replace_sysroot_result"
+	  case "$finalize_rpath " in
+	  *" $libdir "*) ;;
+	  *) func_append finalize_rpath " $libdir" ;;
+	  esac
+	done
+	if test "$hardcode_into_libs" != yes || test "$build_old_libs" = yes; then
+	  dependency_libs="$temp_xrpath $dependency_libs"
+	fi
+      fi
+
+      # Make sure dlfiles contains only unique files that won't be dlpreopened
+      old_dlfiles="$dlfiles"
+      dlfiles=
+      for lib in $old_dlfiles; do
+	case " $dlprefiles $dlfiles " in
+	*" $lib "*) ;;
+	*) func_append dlfiles " $lib" ;;
+	esac
+      done
+
+      # Make sure dlprefiles contains only unique files
+      old_dlprefiles="$dlprefiles"
+      dlprefiles=
+      for lib in $old_dlprefiles; do
+	case "$dlprefiles " in
+	*" $lib "*) ;;
+	*) func_append dlprefiles " $lib" ;;
+	esac
+      done
+
+      if test "$build_libtool_libs" = yes; then
+	if test -n "$rpath"; then
+	  case $host in
+	  *-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-os2* | *-*-beos* | *-cegcc* | *-*-haiku*)
+	    # these systems don't actually have a c library (as such)!
+	    ;;
+	  *-*-rhapsody* | *-*-darwin1.[012])
+	    # Rhapsody C library is in the System framework
+	    func_append deplibs " System.ltframework"
+	    ;;
+	  *-*-netbsd*)
+	    # Don't link with libc until the a.out ld.so is fixed.
+	    ;;
+	  *-*-openbsd* | *-*-freebsd* | *-*-dragonfly*)
+	    # Do not include libc due to us having libc/libc_r.
+	    ;;
+	  *-*-sco3.2v5* | *-*-sco5v6*)
+	    # Causes problems with __ctype
+	    ;;
+	  *-*-sysv4.2uw2* | *-*-sysv5* | *-*-unixware* | *-*-OpenUNIX*)
+	    # Compiler inserts libc in the correct place for threads to work
+	    ;;
+	  *)
+	    # Add libc to deplibs on all other systems if necessary.
+	    if test "$build_libtool_need_lc" = "yes"; then
+	      func_append deplibs " -lc"
+	    fi
+	    ;;
+	  esac
+	fi
+
+	# Transform deplibs into only deplibs that can be linked in shared.
+	name_save=$name
+	libname_save=$libname
+	release_save=$release
+	versuffix_save=$versuffix
+	major_save=$major
+	# I'm not sure if I'm treating the release correctly.  I think
+	# release should show up in the -l (ie -lgmp5) so we don't want to
+	# add it in twice.  Is that correct?
+	release=""
+	versuffix=""
+	major=""
+	newdeplibs=
+	droppeddeps=no
+	case $deplibs_check_method in
+	pass_all)
+	  # Don't check for shared/static.  Everything works.
+	  # This might be a little naive.  We might want to check
+	  # whether the library exists or not.  But this is on
+	  # osf3 & osf4 and I'm not really sure... Just
+	  # implementing what was already the behavior.
+	  newdeplibs=$deplibs
+	  ;;
+	test_compile)
+	  # This code stresses the "libraries are programs" paradigm to its
+	  # limits. Maybe even breaks it.  We compile a program, linking it
+	  # against the deplibs as a proxy for the library.  Then we can check
+	  # whether they linked in statically or dynamically with ldd.
+	  $opt_dry_run || $RM conftest.c
+	  cat > conftest.c <<EOF
+	  int main() { return 0; }
+EOF
+	  $opt_dry_run || $RM conftest
+	  if $LTCC $LTCFLAGS -o conftest conftest.c $deplibs; then
+	    ldd_output=`ldd conftest`
+	    for i in $deplibs; do
+	      case $i in
+	      -l*)
+		func_stripname -l '' "$i"
+		name=$func_stripname_result
+		if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+		  case " $predeps $postdeps " in
+		  *" $i "*)
+		    func_append newdeplibs " $i"
+		    i=""
+		    ;;
+		  esac
+		fi
+		if test -n "$i" ; then
+		  libname=`eval "\\$ECHO \"$libname_spec\""`
+		  deplib_matches=`eval "\\$ECHO \"$library_names_spec\""`
+		  set dummy $deplib_matches; shift
+		  deplib_match=$1
+		  if test `expr "$ldd_output" : ".*$deplib_match"` -ne 0 ; then
+		    func_append newdeplibs " $i"
+		  else
+		    droppeddeps=yes
+		    echo
+		    $ECHO "*** Warning: dynamic linker does not accept needed library $i."
+		    echo "*** I have the capability to make that library automatically link in when"
+		    echo "*** you link to this library.  But I can only do this if you have a"
+		    echo "*** shared version of the library, which I believe you do not have"
+		    echo "*** because a test_compile did reveal that the linker did not use it for"
+		    echo "*** its dynamic dependency list that programs get resolved with at runtime."
+		  fi
+		fi
+		;;
+	      *)
+		func_append newdeplibs " $i"
+		;;
+	      esac
+	    done
+	  else
+	    # Error occurred in the first compile.  Let's try to salvage
+	    # the situation: Compile a separate program for each library.
+	    for i in $deplibs; do
+	      case $i in
+	      -l*)
+		func_stripname -l '' "$i"
+		name=$func_stripname_result
+		$opt_dry_run || $RM conftest
+		if $LTCC $LTCFLAGS -o conftest conftest.c $i; then
+		  ldd_output=`ldd conftest`
+		  if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+		    case " $predeps $postdeps " in
+		    *" $i "*)
+		      func_append newdeplibs " $i"
+		      i=""
+		      ;;
+		    esac
+		  fi
+		  if test -n "$i" ; then
+		    libname=`eval "\\$ECHO \"$libname_spec\""`
+		    deplib_matches=`eval "\\$ECHO \"$library_names_spec\""`
+		    set dummy $deplib_matches; shift
+		    deplib_match=$1
+		    if test `expr "$ldd_output" : ".*$deplib_match"` -ne 0 ; then
+		      func_append newdeplibs " $i"
+		    else
+		      droppeddeps=yes
+		      echo
+		      $ECHO "*** Warning: dynamic linker does not accept needed library $i."
+		      echo "*** I have the capability to make that library automatically link in when"
+		      echo "*** you link to this library.  But I can only do this if you have a"
+		      echo "*** shared version of the library, which you do not appear to have"
+		      echo "*** because a test_compile did reveal that the linker did not use this one"
+		      echo "*** as a dynamic dependency that programs can get resolved with at runtime."
+		    fi
+		  fi
+		else
+		  droppeddeps=yes
+		  echo
+		  $ECHO "*** Warning!  Library $i is needed by this library but I was not able to"
+		  echo "*** make it link in!  You will probably need to install it or some"
+		  echo "*** library that it depends on before this library will be fully"
+		  echo "*** functional.  Installing it before continuing would be even better."
+		fi
+		;;
+	      *)
+		func_append newdeplibs " $i"
+		;;
+	      esac
+	    done
+	  fi
+	  ;;
+	file_magic*)
+	  set dummy $deplibs_check_method; shift
+	  file_magic_regex=`expr "$deplibs_check_method" : "$1 \(.*\)"`
+	  for a_deplib in $deplibs; do
+	    case $a_deplib in
+	    -l*)
+	      func_stripname -l '' "$a_deplib"
+	      name=$func_stripname_result
+	      if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+		case " $predeps $postdeps " in
+		*" $a_deplib "*)
+		  func_append newdeplibs " $a_deplib"
+		  a_deplib=""
+		  ;;
+		esac
+	      fi
+	      if test -n "$a_deplib" ; then
+		libname=`eval "\\$ECHO \"$libname_spec\""`
+		if test -n "$file_magic_glob"; then
+		  libnameglob=`func_echo_all "$libname" | $SED -e $file_magic_glob`
+		else
+		  libnameglob=$libname
+		fi
+		test "$want_nocaseglob" = yes && nocaseglob=`shopt -p nocaseglob`
+		for i in $lib_search_path $sys_lib_search_path $shlib_search_path; do
+		  if test "$want_nocaseglob" = yes; then
+		    shopt -s nocaseglob
+		    potential_libs=`ls $i/$libnameglob[.-]* 2>/dev/null`
+		    $nocaseglob
+		  else
+		    potential_libs=`ls $i/$libnameglob[.-]* 2>/dev/null`
+		  fi
+		  for potent_lib in $potential_libs; do
+		      # Follow soft links.
+		      if ls -lLd "$potent_lib" 2>/dev/null |
+			 $GREP " -> " >/dev/null; then
+			continue
+		      fi
+		      # The statement above tries to avoid entering an
+		      # endless loop below, in case of cyclic links.
+		      # We might still enter an endless loop, since a link
+		      # loop can be closed while we follow links,
+		      # but so what?
+		      potlib="$potent_lib"
+		      while test -h "$potlib" 2>/dev/null; do
+			potliblink=`ls -ld $potlib | ${SED} 's/.* -> //'`
+			case $potliblink in
+			[\\/]* | [A-Za-z]:[\\/]*) potlib="$potliblink";;
+			*) potlib=`$ECHO "$potlib" | $SED 's,[^/]*$,,'`"$potliblink";;
+			esac
+		      done
+		      if eval $file_magic_cmd \"\$potlib\" 2>/dev/null |
+			 $SED -e 10q |
+			 $EGREP "$file_magic_regex" > /dev/null; then
+			func_append newdeplibs " $a_deplib"
+			a_deplib=""
+			break 2
+		      fi
+		  done
+		done
+	      fi
+	      if test -n "$a_deplib" ; then
+		droppeddeps=yes
+		echo
+		$ECHO "*** Warning: linker path does not have real file for library $a_deplib."
+		echo "*** I have the capability to make that library automatically link in when"
+		echo "*** you link to this library.  But I can only do this if you have a"
+		echo "*** shared version of the library, which you do not appear to have"
+		echo "*** because I did check the linker path looking for a file starting"
+		if test -z "$potlib" ; then
+		  $ECHO "*** with $libname but no candidates were found. (...for file magic test)"
+		else
+		  $ECHO "*** with $libname and none of the candidates passed a file format test"
+		  $ECHO "*** using a file magic. Last file checked: $potlib"
+		fi
+	      fi
+	      ;;
+	    *)
+	      # Add a -L argument.
+	      func_append newdeplibs " $a_deplib"
+	      ;;
+	    esac
+	  done # Gone through all deplibs.
+	  ;;
+	match_pattern*)
+	  set dummy $deplibs_check_method; shift
+	  match_pattern_regex=`expr "$deplibs_check_method" : "$1 \(.*\)"`
+	  for a_deplib in $deplibs; do
+	    case $a_deplib in
+	    -l*)
+	      func_stripname -l '' "$a_deplib"
+	      name=$func_stripname_result
+	      if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+		case " $predeps $postdeps " in
+		*" $a_deplib "*)
+		  func_append newdeplibs " $a_deplib"
+		  a_deplib=""
+		  ;;
+		esac
+	      fi
+	      if test -n "$a_deplib" ; then
+		libname=`eval "\\$ECHO \"$libname_spec\""`
+		for i in $lib_search_path $sys_lib_search_path $shlib_search_path; do
+		  potential_libs=`ls $i/$libname[.-]* 2>/dev/null`
+		  for potent_lib in $potential_libs; do
+		    potlib="$potent_lib" # see symlink-check above in file_magic test
+		    if eval "\$ECHO \"$potent_lib\"" 2>/dev/null | $SED 10q | \
+		       $EGREP "$match_pattern_regex" > /dev/null; then
+		      func_append newdeplibs " $a_deplib"
+		      a_deplib=""
+		      break 2
+		    fi
+		  done
+		done
+	      fi
+	      if test -n "$a_deplib" ; then
+		droppeddeps=yes
+		echo
+		$ECHO "*** Warning: linker path does not have real file for library $a_deplib."
+		echo "*** I have the capability to make that library automatically link in when"
+		echo "*** you link to this library.  But I can only do this if you have a"
+		echo "*** shared version of the library, which you do not appear to have"
+		echo "*** because I did check the linker path looking for a file starting"
+		if test -z "$potlib" ; then
+		  $ECHO "*** with $libname but no candidates were found. (...for regex pattern test)"
+		else
+		  $ECHO "*** with $libname and none of the candidates passed a file format test"
+		  $ECHO "*** using a regex pattern. Last file checked: $potlib"
+		fi
+	      fi
+	      ;;
+	    *)
+	      # Add a -L argument.
+	      func_append newdeplibs " $a_deplib"
+	      ;;
+	    esac
+	  done # Gone through all deplibs.
+	  ;;
+	none | unknown | *)
+	  newdeplibs=""
+	  tmp_deplibs=`$ECHO " $deplibs" | $SED 's/ -lc$//; s/ -[LR][^ ]*//g'`
+	  if test "X$allow_libtool_libs_with_static_runtimes" = "Xyes" ; then
+	    for i in $predeps $postdeps ; do
+	      # can't use Xsed below, because $i might contain '/'
+	      tmp_deplibs=`$ECHO " $tmp_deplibs" | $SED "s,$i,,"`
+	    done
+	  fi
+	  case $tmp_deplibs in
+	  *[!\	\ ]*)
+	    echo
+	    if test "X$deplibs_check_method" = "Xnone"; then
+	      echo "*** Warning: inter-library dependencies are not supported in this platform."
+	    else
+	      echo "*** Warning: inter-library dependencies are not known to be supported."
+	    fi
+	    echo "*** All declared inter-library dependencies are being dropped."
+	    droppeddeps=yes
+	    ;;
+	  esac
+	  ;;
+	esac
+	versuffix=$versuffix_save
+	major=$major_save
+	release=$release_save
+	libname=$libname_save
+	name=$name_save
+
+	case $host in
+	*-*-rhapsody* | *-*-darwin1.[012])
+	  # On Rhapsody replace the C library with the System framework
+	  newdeplibs=`$ECHO " $newdeplibs" | $SED 's/ -lc / System.ltframework /'`
+	  ;;
+	esac
+
+	if test "$droppeddeps" = yes; then
+	  if test "$module" = yes; then
+	    echo
+	    echo "*** Warning: libtool could not satisfy all declared inter-library"
+	    $ECHO "*** dependencies of module $libname.  Therefore, libtool will create"
+	    echo "*** a static module, that should work as long as the dlopening"
+	    echo "*** application is linked with the -dlopen flag."
+	    if test -z "$global_symbol_pipe"; then
+	      echo
+	      echo "*** However, this would only work if libtool was able to extract symbol"
+	      echo "*** lists from a program, using \`nm' or equivalent, but libtool could"
+	      echo "*** not find such a program.  So, this module is probably useless."
+	      echo "*** \`nm' from GNU binutils and a full rebuild may help."
+	    fi
+	    if test "$build_old_libs" = no; then
+	      oldlibs="$output_objdir/$libname.$libext"
+	      build_libtool_libs=module
+	      build_old_libs=yes
+	    else
+	      build_libtool_libs=no
+	    fi
+	  else
+	    echo "*** The inter-library dependencies that have been dropped here will be"
+	    echo "*** automatically added whenever a program is linked with this library"
+	    echo "*** or is declared to -dlopen it."
+
+	    if test "$allow_undefined" = no; then
+	      echo
+	      echo "*** Since this library must not contain undefined symbols,"
+	      echo "*** because either the platform does not support them or"
+	      echo "*** it was explicitly requested with -no-undefined,"
+	      echo "*** libtool will only create a static version of it."
+	      if test "$build_old_libs" = no; then
+		oldlibs="$output_objdir/$libname.$libext"
+		build_libtool_libs=module
+		build_old_libs=yes
+	      else
+		build_libtool_libs=no
+	      fi
+	    fi
+	  fi
+	fi
+	# Done checking deplibs!
+	deplibs=$newdeplibs
+      fi
+      # Time to change all our "foo.ltframework" stuff back to "-framework foo"
+      case $host in
+	*-*-darwin*)
+	  newdeplibs=`$ECHO " $newdeplibs" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	  new_inherited_linker_flags=`$ECHO " $new_inherited_linker_flags" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	  deplibs=`$ECHO " $deplibs" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	  ;;
+      esac
+
+      # move library search paths that coincide with paths to not yet
+      # installed libraries to the beginning of the library search list
+      new_libs=
+      for path in $notinst_path; do
+	case " $new_libs " in
+	*" -L$path/$objdir "*) ;;
+	*)
+	  case " $deplibs " in
+	  *" -L$path/$objdir "*)
+	    func_append new_libs " -L$path/$objdir" ;;
+	  esac
+	  ;;
+	esac
+      done
+      for deplib in $deplibs; do
+	case $deplib in
+	-L*)
+	  case " $new_libs " in
+	  *" $deplib "*) ;;
+	  *) func_append new_libs " $deplib" ;;
+	  esac
+	  ;;
+	*) func_append new_libs " $deplib" ;;
+	esac
+      done
+      deplibs="$new_libs"
+
+      # All the library-specific variables (install_libdir is set above).
+      library_names=
+      old_library=
+      dlname=
+
+      # Test again, we may have decided not to build it any more
+      if test "$build_libtool_libs" = yes; then
+	# Remove ${wl} instances when linking with ld.
+	# FIXME: should test the right _cmds variable.
+	case $archive_cmds in
+	  *\$LD\ *) wl= ;;
+        esac
+	if test "$hardcode_into_libs" = yes; then
+	  # Hardcode the library paths
+	  hardcode_libdirs=
+	  dep_rpath=
+	  rpath="$finalize_rpath"
+	  test "$opt_mode" != relink && rpath="$compile_rpath$rpath"
+	  for libdir in $rpath; do
+	    if test -n "$hardcode_libdir_flag_spec"; then
+	      if test -n "$hardcode_libdir_separator"; then
+		func_replace_sysroot "$libdir"
+		libdir=$func_replace_sysroot_result
+		if test -z "$hardcode_libdirs"; then
+		  hardcode_libdirs="$libdir"
+		else
+		  # Just accumulate the unique libdirs.
+		  case $hardcode_libdir_separator$hardcode_libdirs$hardcode_libdir_separator in
+		  *"$hardcode_libdir_separator$libdir$hardcode_libdir_separator"*)
+		    ;;
+		  *)
+		    func_append hardcode_libdirs "$hardcode_libdir_separator$libdir"
+		    ;;
+		  esac
+		fi
+	      else
+		eval flag=\"$hardcode_libdir_flag_spec\"
+		func_append dep_rpath " $flag"
+	      fi
+	    elif test -n "$runpath_var"; then
+	      case "$perm_rpath " in
+	      *" $libdir "*) ;;
+	      *) func_append perm_rpath " $libdir" ;;
+	      esac
+	    fi
+	  done
+	  # Substitute the hardcoded libdirs into the rpath.
+	  if test -n "$hardcode_libdir_separator" &&
+	     test -n "$hardcode_libdirs"; then
+	    libdir="$hardcode_libdirs"
+	    eval "dep_rpath=\"$hardcode_libdir_flag_spec\""
+	  fi
+	  if test -n "$runpath_var" && test -n "$perm_rpath"; then
+	    # We should set the runpath_var.
+	    rpath=
+	    for dir in $perm_rpath; do
+	      func_append rpath "$dir:"
+	    done
+	    eval "$runpath_var='$rpath\$$runpath_var'; export $runpath_var"
+	  fi
+	  test -n "$dep_rpath" && deplibs="$dep_rpath $deplibs"
+	fi
+
+	shlibpath="$finalize_shlibpath"
+	test "$opt_mode" != relink && shlibpath="$compile_shlibpath$shlibpath"
+	if test -n "$shlibpath"; then
+	  eval "$shlibpath_var='$shlibpath\$$shlibpath_var'; export $shlibpath_var"
+	fi
+
+	# Get the real and link names of the library.
+	eval shared_ext=\"$shrext_cmds\"
+	eval library_names=\"$library_names_spec\"
+	set dummy $library_names
+	shift
+	realname="$1"
+	shift
+
+	if test -n "$soname_spec"; then
+	  eval soname=\"$soname_spec\"
+	else
+	  soname="$realname"
+	fi
+	if test -z "$dlname"; then
+	  dlname=$soname
+	fi
+
+	lib="$output_objdir/$realname"
+	linknames=
+	for link
+	do
+	  func_append linknames " $link"
+	done
+
+	# Use standard objects if they are pic
+	test -z "$pic_flag" && libobjs=`$ECHO "$libobjs" | $SP2NL | $SED "$lo2o" | $NL2SP`
+	test "X$libobjs" = "X " && libobjs=
+
+	delfiles=
+	if test -n "$export_symbols" && test -n "$include_expsyms"; then
+	  $opt_dry_run || cp "$export_symbols" "$output_objdir/$libname.uexp"
+	  export_symbols="$output_objdir/$libname.uexp"
+	  func_append delfiles " $export_symbols"
+	fi
+
+	orig_export_symbols=
+	case $host_os in
+	cygwin* | mingw* | cegcc*)
+	  if test -n "$export_symbols" && test -z "$export_symbols_regex"; then
+	    # exporting using user supplied symfile
+	    if test "x`$SED 1q $export_symbols`" != xEXPORTS; then
+	      # and it's NOT already a .def file. Must figure out
+	      # which of the given symbols are data symbols and tag
+	      # them as such. So, trigger use of export_symbols_cmds.
+	      # export_symbols gets reassigned inside the "prepare
+	      # the list of exported symbols" if statement, so the
+	      # include_expsyms logic still works.
+	      orig_export_symbols="$export_symbols"
+	      export_symbols=
+	      always_export_symbols=yes
+	    fi
+	  fi
+	  ;;
+	esac
+
+	# Prepare the list of exported symbols
+	if test -z "$export_symbols"; then
+	  if test "$always_export_symbols" = yes || test -n "$export_symbols_regex"; then
+	    func_verbose "generating symbol list for \`$libname.la'"
+	    export_symbols="$output_objdir/$libname.exp"
+	    $opt_dry_run || $RM $export_symbols
+	    cmds=$export_symbols_cmds
+	    save_ifs="$IFS"; IFS='~'
+	    for cmd1 in $cmds; do
+	      IFS="$save_ifs"
+	      # Take the normal branch if the nm_file_list_spec branch
+	      # doesn't work or if tool conversion is not needed.
+	      case $nm_file_list_spec~$to_tool_file_cmd in
+		*~func_convert_file_noop | *~func_convert_file_msys_to_w32 | ~*)
+		  try_normal_branch=yes
+		  eval cmd=\"$cmd1\"
+		  func_len " $cmd"
+		  len=$func_len_result
+		  ;;
+		*)
+		  try_normal_branch=no
+		  ;;
+	      esac
+	      if test "$try_normal_branch" = yes \
+		 && { test "$len" -lt "$max_cmd_len" \
+		      || test "$max_cmd_len" -le -1; }
+	      then
+		func_show_eval "$cmd" 'exit $?'
+		skipped_export=false
+	      elif test -n "$nm_file_list_spec"; then
+		func_basename "$output"
+		output_la=$func_basename_result
+		save_libobjs=$libobjs
+		save_output=$output
+		output=${output_objdir}/${output_la}.nm
+		func_to_tool_file "$output"
+		libobjs=$nm_file_list_spec$func_to_tool_file_result
+		func_append delfiles " $output"
+		func_verbose "creating $NM input file list: $output"
+		for obj in $save_libobjs; do
+		  func_to_tool_file "$obj"
+		  $ECHO "$func_to_tool_file_result"
+		done > "$output"
+		eval cmd=\"$cmd1\"
+		func_show_eval "$cmd" 'exit $?'
+		output=$save_output
+		libobjs=$save_libobjs
+		skipped_export=false
+	      else
+		# The command line is too long to execute in one step.
+		func_verbose "using reloadable object file for export list..."
+		skipped_export=:
+		# Break out early, otherwise skipped_export may be
+		# set to false by a later but shorter cmd.
+		break
+	      fi
+	    done
+	    IFS="$save_ifs"
+	    if test -n "$export_symbols_regex" && test "X$skipped_export" != "X:"; then
+	      func_show_eval '$EGREP -e "$export_symbols_regex" "$export_symbols" > "${export_symbols}T"'
+	      func_show_eval '$MV "${export_symbols}T" "$export_symbols"'
+	    fi
+	  fi
+	fi
+
+	if test -n "$export_symbols" && test -n "$include_expsyms"; then
+	  tmp_export_symbols="$export_symbols"
+	  test -n "$orig_export_symbols" && tmp_export_symbols="$orig_export_symbols"
+	  $opt_dry_run || eval '$ECHO "$include_expsyms" | $SP2NL >> "$tmp_export_symbols"'
+	fi
+
+	if test "X$skipped_export" != "X:" && test -n "$orig_export_symbols"; then
+	  # The given exports_symbols file has to be filtered, so filter it.
+	  func_verbose "filter symbol list for \`$libname.la' to tag DATA exports"
+	  # FIXME: $output_objdir/$libname.filter potentially contains lots of
+	  # 's' commands which not all seds can handle. GNU sed should be fine
+	  # though. Also, the filter scales superlinearly with the number of
+	  # global variables. join(1) would be nice here, but unfortunately
+	  # isn't a blessed tool.
+	  $opt_dry_run || $SED -e '/[ ,]DATA/!d;s,\(.*\)\([ \,].*\),s|^\1$|\1\2|,' < $export_symbols > $output_objdir/$libname.filter
+	  func_append delfiles " $export_symbols $output_objdir/$libname.filter"
+	  export_symbols=$output_objdir/$libname.def
+	  $opt_dry_run || $SED -f $output_objdir/$libname.filter < $orig_export_symbols > $export_symbols
+	fi
+
+	tmp_deplibs=
+	for test_deplib in $deplibs; do
+	  case " $convenience " in
+	  *" $test_deplib "*) ;;
+	  *)
+	    func_append tmp_deplibs " $test_deplib"
+	    ;;
+	  esac
+	done
+	deplibs="$tmp_deplibs"
+
+	if test -n "$convenience"; then
+	  if test -n "$whole_archive_flag_spec" &&
+	    test "$compiler_needs_object" = yes &&
+	    test -z "$libobjs"; then
+	    # extract the archives, so we have objects to list.
+	    # TODO: could optimize this to just extract one archive.
+	    whole_archive_flag_spec=
+	  fi
+	  if test -n "$whole_archive_flag_spec"; then
+	    save_libobjs=$libobjs
+	    eval libobjs=\"\$libobjs $whole_archive_flag_spec\"
+	    test "X$libobjs" = "X " && libobjs=
+	  else
+	    gentop="$output_objdir/${outputname}x"
+	    func_append generated " $gentop"
+
+	    func_extract_archives $gentop $convenience
+	    func_append libobjs " $func_extract_archives_result"
+	    test "X$libobjs" = "X " && libobjs=
+	  fi
+	fi
+
+	if test "$thread_safe" = yes && test -n "$thread_safe_flag_spec"; then
+	  eval flag=\"$thread_safe_flag_spec\"
+	  func_append linker_flags " $flag"
+	fi
+
+	# Make a backup of the uninstalled library when relinking
+	if test "$opt_mode" = relink; then
+	  $opt_dry_run || eval '(cd $output_objdir && $RM ${realname}U && $MV $realname ${realname}U)' || exit $?
+	fi
+
+	# Do each of the archive commands.
+	if test "$module" = yes && test -n "$module_cmds" ; then
+	  if test -n "$export_symbols" && test -n "$module_expsym_cmds"; then
+	    eval test_cmds=\"$module_expsym_cmds\"
+	    cmds=$module_expsym_cmds
+	  else
+	    eval test_cmds=\"$module_cmds\"
+	    cmds=$module_cmds
+	  fi
+	else
+	  if test -n "$export_symbols" && test -n "$archive_expsym_cmds"; then
+	    eval test_cmds=\"$archive_expsym_cmds\"
+	    cmds=$archive_expsym_cmds
+	  else
+	    eval test_cmds=\"$archive_cmds\"
+	    cmds=$archive_cmds
+	  fi
+	fi
+
+	if test "X$skipped_export" != "X:" &&
+	   func_len " $test_cmds" &&
+	   len=$func_len_result &&
+	   test "$len" -lt "$max_cmd_len" || test "$max_cmd_len" -le -1; then
+	  :
+	else
+	  # The command line is too long to link in one step, link piecewise
+	  # or, if using GNU ld and skipped_export is not :, use a linker
+	  # script.
+
+	  # Save the value of $output and $libobjs because we want to
+	  # use them later.  If we have whole_archive_flag_spec, we
+	  # want to use save_libobjs as it was before
+	  # whole_archive_flag_spec was expanded, because we can't
+	  # assume the linker understands whole_archive_flag_spec.
+	  # This may have to be revisited, in case too many
+	  # convenience libraries get linked in and end up exceeding
+	  # the spec.
+	  if test -z "$convenience" || test -z "$whole_archive_flag_spec"; then
+	    save_libobjs=$libobjs
+	  fi
+	  save_output=$output
+	  func_basename "$output"
+	  output_la=$func_basename_result
+
+	  # Clear the reloadable object creation command queue and
+	  # initialize k to one.
+	  test_cmds=
+	  concat_cmds=
+	  objlist=
+	  last_robj=
+	  k=1
+
+	  if test -n "$save_libobjs" && test "X$skipped_export" != "X:" && test "$with_gnu_ld" = yes; then
+	    output=${output_objdir}/${output_la}.lnkscript
+	    func_verbose "creating GNU ld script: $output"
+	    echo 'INPUT (' > $output
+	    for obj in $save_libobjs
+	    do
+	      func_to_tool_file "$obj"
+	      $ECHO "$func_to_tool_file_result" >> $output
+	    done
+	    echo ')' >> $output
+	    func_append delfiles " $output"
+	    func_to_tool_file "$output"
+	    output=$func_to_tool_file_result
+	  elif test -n "$save_libobjs" && test "X$skipped_export" != "X:" && test "X$file_list_spec" != X; then
+	    output=${output_objdir}/${output_la}.lnk
+	    func_verbose "creating linker input file list: $output"
+	    : > $output
+	    set x $save_libobjs
+	    shift
+	    firstobj=
+	    if test "$compiler_needs_object" = yes; then
+	      firstobj="$1 "
+	      shift
+	    fi
+	    for obj
+	    do
+	      func_to_tool_file "$obj"
+	      $ECHO "$func_to_tool_file_result" >> $output
+	    done
+	    func_append delfiles " $output"
+	    func_to_tool_file "$output"
+	    output=$firstobj\"$file_list_spec$func_to_tool_file_result\"
+	  else
+	    if test -n "$save_libobjs"; then
+	      func_verbose "creating reloadable object files..."
+	      output=$output_objdir/$output_la-${k}.$objext
+	      eval test_cmds=\"$reload_cmds\"
+	      func_len " $test_cmds"
+	      len0=$func_len_result
+	      len=$len0
+
+	      # Loop over the list of objects to be linked.
+	      for obj in $save_libobjs
+	      do
+		func_len " $obj"
+		func_arith $len + $func_len_result
+		len=$func_arith_result
+		if test "X$objlist" = X ||
+		   test "$len" -lt "$max_cmd_len"; then
+		  func_append objlist " $obj"
+		else
+		  # The command $test_cmds is almost too long, add a
+		  # command to the queue.
+		  if test "$k" -eq 1 ; then
+		    # The first file doesn't have a previous command to add.
+		    reload_objs=$objlist
+		    eval concat_cmds=\"$reload_cmds\"
+		  else
+		    # All subsequent reloadable object files will link in
+		    # the last one created.
+		    reload_objs="$objlist $last_robj"
+		    eval concat_cmds=\"\$concat_cmds~$reload_cmds~\$RM $last_robj\"
+		  fi
+		  last_robj=$output_objdir/$output_la-${k}.$objext
+		  func_arith $k + 1
+		  k=$func_arith_result
+		  output=$output_objdir/$output_la-${k}.$objext
+		  objlist=" $obj"
+		  func_len " $last_robj"
+		  func_arith $len0 + $func_len_result
+		  len=$func_arith_result
+		fi
+	      done
+	      # Handle the remaining objects by creating one last
+	      # reloadable object file.  All subsequent reloadable object
+	      # files will link in the last one created.
+	      test -z "$concat_cmds" || concat_cmds=$concat_cmds~
+	      reload_objs="$objlist $last_robj"
+	      eval concat_cmds=\"\${concat_cmds}$reload_cmds\"
+	      if test -n "$last_robj"; then
+	        eval concat_cmds=\"\${concat_cmds}~\$RM $last_robj\"
+	      fi
+	      func_append delfiles " $output"
+
+	    else
+	      output=
+	    fi
+
+	    if ${skipped_export-false}; then
+	      func_verbose "generating symbol list for \`$libname.la'"
+	      export_symbols="$output_objdir/$libname.exp"
+	      $opt_dry_run || $RM $export_symbols
+	      libobjs=$output
+	      # Append the command to create the export file.
+	      test -z "$concat_cmds" || concat_cmds=$concat_cmds~
+	      eval concat_cmds=\"\$concat_cmds$export_symbols_cmds\"
+	      if test -n "$last_robj"; then
+		eval concat_cmds=\"\$concat_cmds~\$RM $last_robj\"
+	      fi
+	    fi
+
+	    test -n "$save_libobjs" &&
+	      func_verbose "creating a temporary reloadable object file: $output"
+
+	    # Loop through the commands generated above and execute them.
+	    save_ifs="$IFS"; IFS='~'
+	    for cmd in $concat_cmds; do
+	      IFS="$save_ifs"
+	      $opt_silent || {
+		  func_quote_for_expand "$cmd"
+		  eval "func_echo $func_quote_for_expand_result"
+	      }
+	      $opt_dry_run || eval "$cmd" || {
+		lt_exit=$?
+
+		# Restore the uninstalled library and exit
+		if test "$opt_mode" = relink; then
+		  ( cd "$output_objdir" && \
+		    $RM "${realname}T" && \
+		    $MV "${realname}U" "$realname" )
+		fi
+
+		exit $lt_exit
+	      }
+	    done
+	    IFS="$save_ifs"
+
+	    if test -n "$export_symbols_regex" && ${skipped_export-false}; then
+	      func_show_eval '$EGREP -e "$export_symbols_regex" "$export_symbols" > "${export_symbols}T"'
+	      func_show_eval '$MV "${export_symbols}T" "$export_symbols"'
+	    fi
+	  fi
+
+          if ${skipped_export-false}; then
+	    if test -n "$export_symbols" && test -n "$include_expsyms"; then
+	      tmp_export_symbols="$export_symbols"
+	      test -n "$orig_export_symbols" && tmp_export_symbols="$orig_export_symbols"
+	      $opt_dry_run || eval '$ECHO "$include_expsyms" | $SP2NL >> "$tmp_export_symbols"'
+	    fi
+
+	    if test -n "$orig_export_symbols"; then
+	      # The given exports_symbols file has to be filtered, so filter it.
+	      func_verbose "filter symbol list for \`$libname.la' to tag DATA exports"
+	      # FIXME: $output_objdir/$libname.filter potentially contains lots of
+	      # 's' commands which not all seds can handle. GNU sed should be fine
+	      # though. Also, the filter scales superlinearly with the number of
+	      # global variables. join(1) would be nice here, but unfortunately
+	      # isn't a blessed tool.
+	      $opt_dry_run || $SED -e '/[ ,]DATA/!d;s,\(.*\)\([ \,].*\),s|^\1$|\1\2|,' < $export_symbols > $output_objdir/$libname.filter
+	      func_append delfiles " $export_symbols $output_objdir/$libname.filter"
+	      export_symbols=$output_objdir/$libname.def
+	      $opt_dry_run || $SED -f $output_objdir/$libname.filter < $orig_export_symbols > $export_symbols
+	    fi
+	  fi
+
+	  libobjs=$output
+	  # Restore the value of output.
+	  output=$save_output
+
+	  if test -n "$convenience" && test -n "$whole_archive_flag_spec"; then
+	    eval libobjs=\"\$libobjs $whole_archive_flag_spec\"
+	    test "X$libobjs" = "X " && libobjs=
+	  fi
+	  # Expand the library linking commands again to reset the
+	  # value of $libobjs for piecewise linking.
+
+	  # Do each of the archive commands.
+	  if test "$module" = yes && test -n "$module_cmds" ; then
+	    if test -n "$export_symbols" && test -n "$module_expsym_cmds"; then
+	      cmds=$module_expsym_cmds
+	    else
+	      cmds=$module_cmds
+	    fi
+	  else
+	    if test -n "$export_symbols" && test -n "$archive_expsym_cmds"; then
+	      cmds=$archive_expsym_cmds
+	    else
+	      cmds=$archive_cmds
+	    fi
+	  fi
+	fi
+
+	if test -n "$delfiles"; then
+	  # Append the command to remove temporary files to $cmds.
+	  eval cmds=\"\$cmds~\$RM $delfiles\"
+	fi
+
+	# Add any objects from preloaded convenience libraries
+	if test -n "$dlprefiles"; then
+	  gentop="$output_objdir/${outputname}x"
+	  func_append generated " $gentop"
+
+	  func_extract_archives $gentop $dlprefiles
+	  func_append libobjs " $func_extract_archives_result"
+	  test "X$libobjs" = "X " && libobjs=
+	fi
+
+	save_ifs="$IFS"; IFS='~'
+	for cmd in $cmds; do
+	  IFS="$save_ifs"
+	  eval cmd=\"$cmd\"
+	  $opt_silent || {
+	    func_quote_for_expand "$cmd"
+	    eval "func_echo $func_quote_for_expand_result"
+	  }
+	  $opt_dry_run || eval "$cmd" || {
+	    lt_exit=$?
+
+	    # Restore the uninstalled library and exit
+	    if test "$opt_mode" = relink; then
+	      ( cd "$output_objdir" && \
+	        $RM "${realname}T" && \
+		$MV "${realname}U" "$realname" )
+	    fi
+
+	    exit $lt_exit
+	  }
+	done
+	IFS="$save_ifs"
+
+	# Restore the uninstalled library and exit
+	if test "$opt_mode" = relink; then
+	  $opt_dry_run || eval '(cd $output_objdir && $RM ${realname}T && $MV $realname ${realname}T && $MV ${realname}U $realname)' || exit $?
+
+	  if test -n "$convenience"; then
+	    if test -z "$whole_archive_flag_spec"; then
+	      func_show_eval '${RM}r "$gentop"'
+	    fi
+	  fi
+
+	  exit $EXIT_SUCCESS
+	fi
+
+	# Create links to the real library.
+	for linkname in $linknames; do
+	  if test "$realname" != "$linkname"; then
+	    func_show_eval '(cd "$output_objdir" && $RM "$linkname" && $LN_S "$realname" "$linkname")' 'exit $?'
+	  fi
+	done
+
+	# If -module or -export-dynamic was specified, set the dlname.
+	if test "$module" = yes || test "$export_dynamic" = yes; then
+	  # On all known operating systems, these are identical.
+	  dlname="$soname"
+	fi
+      fi
+      ;;
+
+    obj)
+      if test -n "$dlfiles$dlprefiles" || test "$dlself" != no; then
+	func_warning "\`-dlopen' is ignored for objects"
+      fi
+
+      case " $deplibs" in
+      *\ -l* | *\ -L*)
+	func_warning "\`-l' and \`-L' are ignored for objects" ;;
+      esac
+
+      test -n "$rpath" && \
+	func_warning "\`-rpath' is ignored for objects"
+
+      test -n "$xrpath" && \
+	func_warning "\`-R' is ignored for objects"
+
+      test -n "$vinfo" && \
+	func_warning "\`-version-info' is ignored for objects"
+
+      test -n "$release" && \
+	func_warning "\`-release' is ignored for objects"
+
+      case $output in
+      *.lo)
+	test -n "$objs$old_deplibs" && \
+	  func_fatal_error "cannot build library object \`$output' from non-libtool objects"
+
+	libobj=$output
+	func_lo2o "$libobj"
+	obj=$func_lo2o_result
+	;;
+      *)
+	libobj=
+	obj="$output"
+	;;
+      esac
+
+      # Delete the old objects.
+      $opt_dry_run || $RM $obj $libobj
+
+      # Objects from convenience libraries.  This assumes
+      # single-version convenience libraries.  Whenever we create
+      # different ones for PIC/non-PIC, this we'll have to duplicate
+      # the extraction.
+      reload_conv_objs=
+      gentop=
+      # reload_cmds runs $LD directly, so let us get rid of
+      # -Wl from whole_archive_flag_spec and hope we can get by with
+      # turning comma into space..
+      wl=
+
+      if test -n "$convenience"; then
+	if test -n "$whole_archive_flag_spec"; then
+	  eval tmp_whole_archive_flags=\"$whole_archive_flag_spec\"
+	  reload_conv_objs=$reload_objs\ `$ECHO "$tmp_whole_archive_flags" | $SED 's|,| |g'`
+	else
+	  gentop="$output_objdir/${obj}x"
+	  func_append generated " $gentop"
+
+	  func_extract_archives $gentop $convenience
+	  reload_conv_objs="$reload_objs $func_extract_archives_result"
+	fi
+      fi
+
+      # If we're not building shared, we need to use non_pic_objs
+      test "$build_libtool_libs" != yes && libobjs="$non_pic_objects"
+
+      # Create the old-style object.
+      reload_objs="$objs$old_deplibs "`$ECHO "$libobjs" | $SP2NL | $SED "/\.${libext}$/d; /\.lib$/d; $lo2o" | $NL2SP`" $reload_conv_objs" ### testsuite: skip nested quoting test
+
+      output="$obj"
+      func_execute_cmds "$reload_cmds" 'exit $?'
+
+      # Exit if we aren't doing a library object file.
+      if test -z "$libobj"; then
+	if test -n "$gentop"; then
+	  func_show_eval '${RM}r "$gentop"'
+	fi
+
+	exit $EXIT_SUCCESS
+      fi
+
+      if test "$build_libtool_libs" != yes; then
+	if test -n "$gentop"; then
+	  func_show_eval '${RM}r "$gentop"'
+	fi
+
+	# Create an invalid libtool object if no PIC, so that we don't
+	# accidentally link it into a program.
+	# $show "echo timestamp > $libobj"
+	# $opt_dry_run || eval "echo timestamp > $libobj" || exit $?
+	exit $EXIT_SUCCESS
+      fi
+
+      if test -n "$pic_flag" || test "$pic_mode" != default; then
+	# Only do commands if we really have different PIC objects.
+	reload_objs="$libobjs $reload_conv_objs"
+	output="$libobj"
+	func_execute_cmds "$reload_cmds" 'exit $?'
+      fi
+
+      if test -n "$gentop"; then
+	func_show_eval '${RM}r "$gentop"'
+      fi
+
+      exit $EXIT_SUCCESS
+      ;;
+
+    prog)
+      case $host in
+	*cygwin*) func_stripname '' '.exe' "$output"
+	          output=$func_stripname_result.exe;;
+      esac
+      test -n "$vinfo" && \
+	func_warning "\`-version-info' is ignored for programs"
+
+      test -n "$release" && \
+	func_warning "\`-release' is ignored for programs"
+
+      test "$preload" = yes \
+        && test "$dlopen_support" = unknown \
+	&& test "$dlopen_self" = unknown \
+	&& test "$dlopen_self_static" = unknown && \
+	  func_warning "\`LT_INIT([dlopen])' not used. Assuming no dlopen support."
+
+      case $host in
+      *-*-rhapsody* | *-*-darwin1.[012])
+	# On Rhapsody replace the C library is the System framework
+	compile_deplibs=`$ECHO " $compile_deplibs" | $SED 's/ -lc / System.ltframework /'`
+	finalize_deplibs=`$ECHO " $finalize_deplibs" | $SED 's/ -lc / System.ltframework /'`
+	;;
+      esac
+
+      case $host in
+      *-*-darwin*)
+	# Don't allow lazy linking, it breaks C++ global constructors
+	# But is supposedly fixed on 10.4 or later (yay!).
+	if test "$tagname" = CXX ; then
+	  case ${MACOSX_DEPLOYMENT_TARGET-10.0} in
+	    10.[0123])
+	      func_append compile_command " ${wl}-bind_at_load"
+	      func_append finalize_command " ${wl}-bind_at_load"
+	    ;;
+	  esac
+	fi
+	# Time to change all our "foo.ltframework" stuff back to "-framework foo"
+	compile_deplibs=`$ECHO " $compile_deplibs" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	finalize_deplibs=`$ECHO " $finalize_deplibs" | $SED 's% \([^ $]*\).ltframework% -framework \1%g'`
+	;;
+      esac
+
+
+      # move library search paths that coincide with paths to not yet
+      # installed libraries to the beginning of the library search list
+      new_libs=
+      for path in $notinst_path; do
+	case " $new_libs " in
+	*" -L$path/$objdir "*) ;;
+	*)
+	  case " $compile_deplibs " in
+	  *" -L$path/$objdir "*)
+	    func_append new_libs " -L$path/$objdir" ;;
+	  esac
+	  ;;
+	esac
+      done
+      for deplib in $compile_deplibs; do
+	case $deplib in
+	-L*)
+	  case " $new_libs " in
+	  *" $deplib "*) ;;
+	  *) func_append new_libs " $deplib" ;;
+	  esac
+	  ;;
+	*) func_append new_libs " $deplib" ;;
+	esac
+      done
+      compile_deplibs="$new_libs"
+
+
+      func_append compile_command " $compile_deplibs"
+      func_append finalize_command " $finalize_deplibs"
+
+      if test -n "$rpath$xrpath"; then
+	# If the user specified any rpath flags, then add them.
+	for libdir in $rpath $xrpath; do
+	  # This is the magic to use -rpath.
+	  case "$finalize_rpath " in
+	  *" $libdir "*) ;;
+	  *) func_append finalize_rpath " $libdir" ;;
+	  esac
+	done
+      fi
+
+      # Now hardcode the library paths
+      rpath=
+      hardcode_libdirs=
+      for libdir in $compile_rpath $finalize_rpath; do
+	if test -n "$hardcode_libdir_flag_spec"; then
+	  if test -n "$hardcode_libdir_separator"; then
+	    if test -z "$hardcode_libdirs"; then
+	      hardcode_libdirs="$libdir"
+	    else
+	      # Just accumulate the unique libdirs.
+	      case $hardcode_libdir_separator$hardcode_libdirs$hardcode_libdir_separator in
+	      *"$hardcode_libdir_separator$libdir$hardcode_libdir_separator"*)
+		;;
+	      *)
+		func_append hardcode_libdirs "$hardcode_libdir_separator$libdir"
+		;;
+	      esac
+	    fi
+	  else
+	    eval flag=\"$hardcode_libdir_flag_spec\"
+	    func_append rpath " $flag"
+	  fi
+	elif test -n "$runpath_var"; then
+	  case "$perm_rpath " in
+	  *" $libdir "*) ;;
+	  *) func_append perm_rpath " $libdir" ;;
+	  esac
+	fi
+	case $host in
+	*-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-os2* | *-cegcc*)
+	  testbindir=`${ECHO} "$libdir" | ${SED} -e 's*/lib$*/bin*'`
+	  case :$dllsearchpath: in
+	  *":$libdir:"*) ;;
+	  ::) dllsearchpath=$libdir;;
+	  *) func_append dllsearchpath ":$libdir";;
+	  esac
+	  case :$dllsearchpath: in
+	  *":$testbindir:"*) ;;
+	  ::) dllsearchpath=$testbindir;;
+	  *) func_append dllsearchpath ":$testbindir";;
+	  esac
+	  ;;
+	esac
+      done
+      # Substitute the hardcoded libdirs into the rpath.
+      if test -n "$hardcode_libdir_separator" &&
+	 test -n "$hardcode_libdirs"; then
+	libdir="$hardcode_libdirs"
+	eval rpath=\" $hardcode_libdir_flag_spec\"
+      fi
+      compile_rpath="$rpath"
+
+      rpath=
+      hardcode_libdirs=
+      for libdir in $finalize_rpath; do
+	if test -n "$hardcode_libdir_flag_spec"; then
+	  if test -n "$hardcode_libdir_separator"; then
+	    if test -z "$hardcode_libdirs"; then
+	      hardcode_libdirs="$libdir"
+	    else
+	      # Just accumulate the unique libdirs.
+	      case $hardcode_libdir_separator$hardcode_libdirs$hardcode_libdir_separator in
+	      *"$hardcode_libdir_separator$libdir$hardcode_libdir_separator"*)
+		;;
+	      *)
+		func_append hardcode_libdirs "$hardcode_libdir_separator$libdir"
+		;;
+	      esac
+	    fi
+	  else
+	    eval flag=\"$hardcode_libdir_flag_spec\"
+	    func_append rpath " $flag"
+	  fi
+	elif test -n "$runpath_var"; then
+	  case "$finalize_perm_rpath " in
+	  *" $libdir "*) ;;
+	  *) func_append finalize_perm_rpath " $libdir" ;;
+	  esac
+	fi
+      done
+      # Substitute the hardcoded libdirs into the rpath.
+      if test -n "$hardcode_libdir_separator" &&
+	 test -n "$hardcode_libdirs"; then
+	libdir="$hardcode_libdirs"
+	eval rpath=\" $hardcode_libdir_flag_spec\"
+      fi
+      finalize_rpath="$rpath"
+
+      if test -n "$libobjs" && test "$build_old_libs" = yes; then
+	# Transform all the library objects into standard objects.
+	compile_command=`$ECHO "$compile_command" | $SP2NL | $SED "$lo2o" | $NL2SP`
+	finalize_command=`$ECHO "$finalize_command" | $SP2NL | $SED "$lo2o" | $NL2SP`
+      fi
+
+      func_generate_dlsyms "$outputname" "@PROGRAM@" "no"
+
+      # template prelinking step
+      if test -n "$prelink_cmds"; then
+	func_execute_cmds "$prelink_cmds" 'exit $?'
+      fi
+
+      wrappers_required=yes
+      case $host in
+      *cegcc* | *mingw32ce*)
+        # Disable wrappers for cegcc and mingw32ce hosts, we are cross compiling anyway.
+        wrappers_required=no
+        ;;
+      *cygwin* | *mingw* )
+        if test "$build_libtool_libs" != yes; then
+          wrappers_required=no
+        fi
+        ;;
+      *)
+        if test "$need_relink" = no || test "$build_libtool_libs" != yes; then
+          wrappers_required=no
+        fi
+        ;;
+      esac
+      if test "$wrappers_required" = no; then
+	# Replace the output file specification.
+	compile_command=`$ECHO "$compile_command" | $SED 's%@OUTPUT@%'"$output"'%g'`
+	link_command="$compile_command$compile_rpath"
+
+	# We have no uninstalled library dependencies, so finalize right now.
+	exit_status=0
+	func_show_eval "$link_command" 'exit_status=$?'
+
+	if test -n "$postlink_cmds"; then
+	  func_to_tool_file "$output"
+	  postlink_cmds=`func_echo_all "$postlink_cmds" | $SED -e 's%@OUTPUT@%'"$output"'%g' -e 's%@TOOL_OUTPUT@%'"$func_to_tool_file_result"'%g'`
+	  func_execute_cmds "$postlink_cmds" 'exit $?'
+	fi
+
+	# Delete the generated files.
+	if test -f "$output_objdir/${outputname}S.${objext}"; then
+	  func_show_eval '$RM "$output_objdir/${outputname}S.${objext}"'
+	fi
+
+	exit $exit_status
+      fi
+
+      if test -n "$compile_shlibpath$finalize_shlibpath"; then
+	compile_command="$shlibpath_var=\"$compile_shlibpath$finalize_shlibpath\$$shlibpath_var\" $compile_command"
+      fi
+      if test -n "$finalize_shlibpath"; then
+	finalize_command="$shlibpath_var=\"$finalize_shlibpath\$$shlibpath_var\" $finalize_command"
+      fi
+
+      compile_var=
+      finalize_var=
+      if test -n "$runpath_var"; then
+	if test -n "$perm_rpath"; then
+	  # We should set the runpath_var.
+	  rpath=
+	  for dir in $perm_rpath; do
+	    func_append rpath "$dir:"
+	  done
+	  compile_var="$runpath_var=\"$rpath\$$runpath_var\" "
+	fi
+	if test -n "$finalize_perm_rpath"; then
+	  # We should set the runpath_var.
+	  rpath=
+	  for dir in $finalize_perm_rpath; do
+	    func_append rpath "$dir:"
+	  done
+	  finalize_var="$runpath_var=\"$rpath\$$runpath_var\" "
+	fi
+      fi
+
+      if test "$no_install" = yes; then
+	# We don't need to create a wrapper script.
+	link_command="$compile_var$compile_command$compile_rpath"
+	# Replace the output file specification.
+	link_command=`$ECHO "$link_command" | $SED 's%@OUTPUT@%'"$output"'%g'`
+	# Delete the old output file.
+	$opt_dry_run || $RM $output
+	# Link the executable and exit
+	func_show_eval "$link_command" 'exit $?'
+
+	if test -n "$postlink_cmds"; then
+	  func_to_tool_file "$output"
+	  postlink_cmds=`func_echo_all "$postlink_cmds" | $SED -e 's%@OUTPUT@%'"$output"'%g' -e 's%@TOOL_OUTPUT@%'"$func_to_tool_file_result"'%g'`
+	  func_execute_cmds "$postlink_cmds" 'exit $?'
+	fi
+
+	exit $EXIT_SUCCESS
+      fi
+
+      if test "$hardcode_action" = relink; then
+	# Fast installation is not supported
+	link_command="$compile_var$compile_command$compile_rpath"
+	relink_command="$finalize_var$finalize_command$finalize_rpath"
+
+	func_warning "this platform does not like uninstalled shared libraries"
+	func_warning "\`$output' will be relinked during installation"
+      else
+	if test "$fast_install" != no; then
+	  link_command="$finalize_var$compile_command$finalize_rpath"
+	  if test "$fast_install" = yes; then
+	    relink_command=`$ECHO "$compile_var$compile_command$compile_rpath" | $SED 's%@OUTPUT@%\$progdir/\$file%g'`
+	  else
+	    # fast_install is set to needless
+	    relink_command=
+	  fi
+	else
+	  link_command="$compile_var$compile_command$compile_rpath"
+	  relink_command="$finalize_var$finalize_command$finalize_rpath"
+	fi
+      fi
+
+      # Replace the output file specification.
+      link_command=`$ECHO "$link_command" | $SED 's%@OUTPUT@%'"$output_objdir/$outputname"'%g'`
+
+      # Delete the old output files.
+      $opt_dry_run || $RM $output $output_objdir/$outputname $output_objdir/lt-$outputname
+
+      func_show_eval "$link_command" 'exit $?'
+
+      if test -n "$postlink_cmds"; then
+	func_to_tool_file "$output_objdir/$outputname"
+	postlink_cmds=`func_echo_all "$postlink_cmds" | $SED -e 's%@OUTPUT@%'"$output_objdir/$outputname"'%g' -e 's%@TOOL_OUTPUT@%'"$func_to_tool_file_result"'%g'`
+	func_execute_cmds "$postlink_cmds" 'exit $?'
+      fi
+
+      # Now create the wrapper script.
+      func_verbose "creating $output"
+
+      # Quote the relink command for shipping.
+      if test -n "$relink_command"; then
+	# Preserve any variables that may affect compiler behavior
+	for var in $variables_saved_for_relink; do
+	  if eval test -z \"\${$var+set}\"; then
+	    relink_command="{ test -z \"\${$var+set}\" || $lt_unset $var || { $var=; export $var; }; }; $relink_command"
+	  elif eval var_value=\$$var; test -z "$var_value"; then
+	    relink_command="$var=; export $var; $relink_command"
+	  else
+	    func_quote_for_eval "$var_value"
+	    relink_command="$var=$func_quote_for_eval_result; export $var; $relink_command"
+	  fi
+	done
+	relink_command="(cd `pwd`; $relink_command)"
+	relink_command=`$ECHO "$relink_command" | $SED "$sed_quote_subst"`
+      fi
+
+      # Only actually do things if not in dry run mode.
+      $opt_dry_run || {
+	# win32 will think the script is a binary if it has
+	# a .exe suffix, so we strip it off here.
+	case $output in
+	  *.exe) func_stripname '' '.exe' "$output"
+	         output=$func_stripname_result ;;
+	esac
+	# test for cygwin because mv fails w/o .exe extensions
+	case $host in
+	  *cygwin*)
+	    exeext=.exe
+	    func_stripname '' '.exe' "$outputname"
+	    outputname=$func_stripname_result ;;
+	  *) exeext= ;;
+	esac
+	case $host in
+	  *cygwin* | *mingw* )
+	    func_dirname_and_basename "$output" "" "."
+	    output_name=$func_basename_result
+	    output_path=$func_dirname_result
+	    cwrappersource="$output_path/$objdir/lt-$output_name.c"
+	    cwrapper="$output_path/$output_name.exe"
+	    $RM $cwrappersource $cwrapper
+	    trap "$RM $cwrappersource $cwrapper; exit $EXIT_FAILURE" 1 2 15
+
+	    func_emit_cwrapperexe_src > $cwrappersource
+
+	    # The wrapper executable is built using the $host compiler,
+	    # because it contains $host paths and files. If cross-
+	    # compiling, it, like the target executable, must be
+	    # executed on the $host or under an emulation environment.
+	    $opt_dry_run || {
+	      $LTCC $LTCFLAGS -o $cwrapper $cwrappersource
+	      $STRIP $cwrapper
+	    }
+
+	    # Now, create the wrapper script for func_source use:
+	    func_ltwrapper_scriptname $cwrapper
+	    $RM $func_ltwrapper_scriptname_result
+	    trap "$RM $func_ltwrapper_scriptname_result; exit $EXIT_FAILURE" 1 2 15
+	    $opt_dry_run || {
+	      # note: this script will not be executed, so do not chmod.
+	      if test "x$build" = "x$host" ; then
+		$cwrapper --lt-dump-script > $func_ltwrapper_scriptname_result
+	      else
+		func_emit_wrapper no > $func_ltwrapper_scriptname_result
+	      fi
+	    }
+	  ;;
+	  * )
+	    $RM $output
+	    trap "$RM $output; exit $EXIT_FAILURE" 1 2 15
+
+	    func_emit_wrapper no > $output
+	    chmod +x $output
+	  ;;
+	esac
+      }
+      exit $EXIT_SUCCESS
+      ;;
+    esac
+
+    # See if we need to build an old-fashioned archive.
+    for oldlib in $oldlibs; do
+
+      if test "$build_libtool_libs" = convenience; then
+	oldobjs="$libobjs_save $symfileobj"
+	addlibs="$convenience"
+	build_libtool_libs=no
+      else
+	if test "$build_libtool_libs" = module; then
+	  oldobjs="$libobjs_save"
+	  build_libtool_libs=no
+	else
+	  oldobjs="$old_deplibs $non_pic_objects"
+	  if test "$preload" = yes && test -f "$symfileobj"; then
+	    func_append oldobjs " $symfileobj"
+	  fi
+	fi
+	addlibs="$old_convenience"
+      fi
+
+      if test -n "$addlibs"; then
+	gentop="$output_objdir/${outputname}x"
+	func_append generated " $gentop"
+
+	func_extract_archives $gentop $addlibs
+	func_append oldobjs " $func_extract_archives_result"
+      fi
+
+      # Do each command in the archive commands.
+      if test -n "$old_archive_from_new_cmds" && test "$build_libtool_libs" = yes; then
+	cmds=$old_archive_from_new_cmds
+      else
+
+	# Add any objects from preloaded convenience libraries
+	if test -n "$dlprefiles"; then
+	  gentop="$output_objdir/${outputname}x"
+	  func_append generated " $gentop"
+
+	  func_extract_archives $gentop $dlprefiles
+	  func_append oldobjs " $func_extract_archives_result"
+	fi
+
+	# POSIX demands no paths to be encoded in archives.  We have
+	# to avoid creating archives with duplicate basenames if we
+	# might have to extract them afterwards, e.g., when creating a
+	# static archive out of a convenience library, or when linking
+	# the entirety of a libtool archive into another (currently
+	# not supported by libtool).
+	if (for obj in $oldobjs
+	    do
+	      func_basename "$obj"
+	      $ECHO "$func_basename_result"
+	    done | sort | sort -uc >/dev/null 2>&1); then
+	  :
+	else
+	  echo "copying selected object files to avoid basename conflicts..."
+	  gentop="$output_objdir/${outputname}x"
+	  func_append generated " $gentop"
+	  func_mkdir_p "$gentop"
+	  save_oldobjs=$oldobjs
+	  oldobjs=
+	  counter=1
+	  for obj in $save_oldobjs
+	  do
+	    func_basename "$obj"
+	    objbase="$func_basename_result"
+	    case " $oldobjs " in
+	    " ") oldobjs=$obj ;;
+	    *[\ /]"$objbase "*)
+	      while :; do
+		# Make sure we don't pick an alternate name that also
+		# overlaps.
+		newobj=lt$counter-$objbase
+		func_arith $counter + 1
+		counter=$func_arith_result
+		case " $oldobjs " in
+		*[\ /]"$newobj "*) ;;
+		*) if test ! -f "$gentop/$newobj"; then break; fi ;;
+		esac
+	      done
+	      func_show_eval "ln $obj $gentop/$newobj || cp $obj $gentop/$newobj"
+	      func_append oldobjs " $gentop/$newobj"
+	      ;;
+	    *) func_append oldobjs " $obj" ;;
+	    esac
+	  done
+	fi
+	func_to_tool_file "$oldlib" func_convert_file_msys_to_w32
+	tool_oldlib=$func_to_tool_file_result
+	eval cmds=\"$old_archive_cmds\"
+
+	func_len " $cmds"
+	len=$func_len_result
+	if test "$len" -lt "$max_cmd_len" || test "$max_cmd_len" -le -1; then
+	  cmds=$old_archive_cmds
+	elif test -n "$archiver_list_spec"; then
+	  func_verbose "using command file archive linking..."
+	  for obj in $oldobjs
+	  do
+	    func_to_tool_file "$obj"
+	    $ECHO "$func_to_tool_file_result"
+	  done > $output_objdir/$libname.libcmd
+	  func_to_tool_file "$output_objdir/$libname.libcmd"
+	  oldobjs=" $archiver_list_spec$func_to_tool_file_result"
+	  cmds=$old_archive_cmds
+	else
+	  # the command line is too long to link in one step, link in parts
+	  func_verbose "using piecewise archive linking..."
+	  save_RANLIB=$RANLIB
+	  RANLIB=:
+	  objlist=
+	  concat_cmds=
+	  save_oldobjs=$oldobjs
+	  oldobjs=
+	  # Is there a better way of finding the last object in the list?
+	  for obj in $save_oldobjs
+	  do
+	    last_oldobj=$obj
+	  done
+	  eval test_cmds=\"$old_archive_cmds\"
+	  func_len " $test_cmds"
+	  len0=$func_len_result
+	  len=$len0
+	  for obj in $save_oldobjs
+	  do
+	    func_len " $obj"
+	    func_arith $len + $func_len_result
+	    len=$func_arith_result
+	    func_append objlist " $obj"
+	    if test "$len" -lt "$max_cmd_len"; then
+	      :
+	    else
+	      # the above command should be used before it gets too long
+	      oldobjs=$objlist
+	      if test "$obj" = "$last_oldobj" ; then
+		RANLIB=$save_RANLIB
+	      fi
+	      test -z "$concat_cmds" || concat_cmds=$concat_cmds~
+	      eval concat_cmds=\"\${concat_cmds}$old_archive_cmds\"
+	      objlist=
+	      len=$len0
+	    fi
+	  done
+	  RANLIB=$save_RANLIB
+	  oldobjs=$objlist
+	  if test "X$oldobjs" = "X" ; then
+	    eval cmds=\"\$concat_cmds\"
+	  else
+	    eval cmds=\"\$concat_cmds~\$old_archive_cmds\"
+	  fi
+	fi
+      fi
+      func_execute_cmds "$cmds" 'exit $?'
+    done
+
+    test -n "$generated" && \
+      func_show_eval "${RM}r$generated"
+
+    # Now create the libtool archive.
+    case $output in
+    *.la)
+      old_library=
+      test "$build_old_libs" = yes && old_library="$libname.$libext"
+      func_verbose "creating $output"
+
+      # Preserve any variables that may affect compiler behavior
+      for var in $variables_saved_for_relink; do
+	if eval test -z \"\${$var+set}\"; then
+	  relink_command="{ test -z \"\${$var+set}\" || $lt_unset $var || { $var=; export $var; }; }; $relink_command"
+	elif eval var_value=\$$var; test -z "$var_value"; then
+	  relink_command="$var=; export $var; $relink_command"
+	else
+	  func_quote_for_eval "$var_value"
+	  relink_command="$var=$func_quote_for_eval_result; export $var; $relink_command"
+	fi
+      done
+      # Quote the link command for shipping.
+      relink_command="(cd `pwd`; $SHELL $progpath $preserve_args --mode=relink $libtool_args @inst_prefix_dir@)"
+      relink_command=`$ECHO "$relink_command" | $SED "$sed_quote_subst"`
+      if test "$hardcode_automatic" = yes ; then
+	relink_command=
+      fi
+
+      # Only create the output if not a dry run.
+      $opt_dry_run || {
+	for installed in no yes; do
+	  if test "$installed" = yes; then
+	    if test -z "$install_libdir"; then
+	      break
+	    fi
+	    output="$output_objdir/$outputname"i
+	    # Replace all uninstalled libtool libraries with the installed ones
+	    newdependency_libs=
+	    for deplib in $dependency_libs; do
+	      case $deplib in
+	      *.la)
+		func_basename "$deplib"
+		name="$func_basename_result"
+		func_resolve_sysroot "$deplib"
+		eval libdir=`${SED} -n -e 's/^libdir=\(.*\)$/\1/p' $func_resolve_sysroot_result`
+		test -z "$libdir" && \
+		  func_fatal_error "\`$deplib' is not a valid libtool archive"
+		func_append newdependency_libs " ${lt_sysroot:+=}$libdir/$name"
+		;;
+	      -L*)
+		func_stripname -L '' "$deplib"
+		func_replace_sysroot "$func_stripname_result"
+		func_append newdependency_libs " -L$func_replace_sysroot_result"
+		;;
+	      -R*)
+		func_stripname -R '' "$deplib"
+		func_replace_sysroot "$func_stripname_result"
+		func_append newdependency_libs " -R$func_replace_sysroot_result"
+		;;
+	      *) func_append newdependency_libs " $deplib" ;;
+	      esac
+	    done
+	    dependency_libs="$newdependency_libs"
+	    newdlfiles=
+
+	    for lib in $dlfiles; do
+	      case $lib in
+	      *.la)
+	        func_basename "$lib"
+		name="$func_basename_result"
+		eval libdir=`${SED} -n -e 's/^libdir=\(.*\)$/\1/p' $lib`
+		test -z "$libdir" && \
+		  func_fatal_error "\`$lib' is not a valid libtool archive"
+		func_append newdlfiles " ${lt_sysroot:+=}$libdir/$name"
+		;;
+	      *) func_append newdlfiles " $lib" ;;
+	      esac
+	    done
+	    dlfiles="$newdlfiles"
+	    newdlprefiles=
+	    for lib in $dlprefiles; do
+	      case $lib in
+	      *.la)
+		# Only pass preopened files to the pseudo-archive (for
+		# eventual linking with the app. that links it) if we
+		# didn't already link the preopened objects directly into
+		# the library:
+		func_basename "$lib"
+		name="$func_basename_result"
+		eval libdir=`${SED} -n -e 's/^libdir=\(.*\)$/\1/p' $lib`
+		test -z "$libdir" && \
+		  func_fatal_error "\`$lib' is not a valid libtool archive"
+		func_append newdlprefiles " ${lt_sysroot:+=}$libdir/$name"
+		;;
+	      esac
+	    done
+	    dlprefiles="$newdlprefiles"
+	  else
+	    newdlfiles=
+	    for lib in $dlfiles; do
+	      case $lib in
+		[\\/]* | [A-Za-z]:[\\/]*) abs="$lib" ;;
+		*) abs=`pwd`"/$lib" ;;
+	      esac
+	      func_append newdlfiles " $abs"
+	    done
+	    dlfiles="$newdlfiles"
+	    newdlprefiles=
+	    for lib in $dlprefiles; do
+	      case $lib in
+		[\\/]* | [A-Za-z]:[\\/]*) abs="$lib" ;;
+		*) abs=`pwd`"/$lib" ;;
+	      esac
+	      func_append newdlprefiles " $abs"
+	    done
+	    dlprefiles="$newdlprefiles"
+	  fi
+	  $RM $output
+	  # place dlname in correct position for cygwin
+	  # In fact, it would be nice if we could use this code for all target
+	  # systems that can't hard-code library paths into their executables
+	  # and that have no shared library path variable independent of PATH,
+	  # but it turns out we can't easily determine that from inspecting
+	  # libtool variables, so we have to hard-code the OSs to which it
+	  # applies here; at the moment, that means platforms that use the PE
+	  # object format with DLL files.  See the long comment at the top of
+	  # tests/bindir.at for full details.
+	  tdlname=$dlname
+	  case $host,$output,$installed,$module,$dlname in
+	    *cygwin*,*lai,yes,no,*.dll | *mingw*,*lai,yes,no,*.dll | *cegcc*,*lai,yes,no,*.dll)
+	      # If a -bindir argument was supplied, place the dll there.
+	      if test "x$bindir" != x ;
+	      then
+		func_relative_path "$install_libdir" "$bindir"
+		tdlname=$func_relative_path_result$dlname
+	      else
+		# Otherwise fall back on heuristic.
+		tdlname=../bin/$dlname
+	      fi
+	      ;;
+	  esac
+	  $ECHO > $output "\
+# $outputname - a libtool library file
+# Generated by $PROGRAM (GNU $PACKAGE$TIMESTAMP) $VERSION
+#
+# Please DO NOT delete this file!
+# It is necessary for linking the library.
+
+# The name that we can dlopen(3).
+dlname='$tdlname'
+
+# Names of this library.
+library_names='$library_names'
+
+# The name of the static archive.
+old_library='$old_library'
+
+# Linker flags that can not go in dependency_libs.
+inherited_linker_flags='$new_inherited_linker_flags'
+
+# Libraries that this one depends upon.
+dependency_libs='$dependency_libs'
+
+# Names of additional weak libraries provided by this library
+weak_library_names='$weak_libs'
+
+# Version information for $libname.
+current=$current
+age=$age
+revision=$revision
+
+# Is this an already installed library?
+installed=$installed
+
+# Should we warn about portability when linking against -modules?
+shouldnotlink=$module
+
+# Files to dlopen/dlpreopen
+dlopen='$dlfiles'
+dlpreopen='$dlprefiles'
+
+# Directory that this library needs to be installed in:
+libdir='$install_libdir'"
+	  if test "$installed" = no && test "$need_relink" = yes; then
+	    $ECHO >> $output "\
+relink_command=\"$relink_command\""
+	  fi
+	done
+      }
+
+      # Do a symbolic link so that the libtool archive can be found in
+      # LD_LIBRARY_PATH before the program is installed.
+      func_show_eval '( cd "$output_objdir" && $RM "$outputname" && $LN_S "../$outputname" "$outputname" )' 'exit $?'
+      ;;
+    esac
+    exit $EXIT_SUCCESS
+}
+
+{ test "$opt_mode" = link || test "$opt_mode" = relink; } &&
+    func_mode_link ${1+"$@"}
+
+
+# func_mode_uninstall arg...
+func_mode_uninstall ()
+{
+    $opt_debug
+    RM="$nonopt"
+    files=
+    rmforce=
+    exit_status=0
+
+    # This variable tells wrapper scripts just to set variables rather
+    # than running their programs.
+    libtool_install_magic="$magic"
+
+    for arg
+    do
+      case $arg in
+      -f) func_append RM " $arg"; rmforce=yes ;;
+      -*) func_append RM " $arg" ;;
+      *) func_append files " $arg" ;;
+      esac
+    done
+
+    test -z "$RM" && \
+      func_fatal_help "you must specify an RM program"
+
+    rmdirs=
+
+    for file in $files; do
+      func_dirname "$file" "" "."
+      dir="$func_dirname_result"
+      if test "X$dir" = X.; then
+	odir="$objdir"
+      else
+	odir="$dir/$objdir"
+      fi
+      func_basename "$file"
+      name="$func_basename_result"
+      test "$opt_mode" = uninstall && odir="$dir"
+
+      # Remember odir for removal later, being careful to avoid duplicates
+      if test "$opt_mode" = clean; then
+	case " $rmdirs " in
+	  *" $odir "*) ;;
+	  *) func_append rmdirs " $odir" ;;
+	esac
+      fi
+
+      # Don't error if the file doesn't exist and rm -f was used.
+      if { test -L "$file"; } >/dev/null 2>&1 ||
+	 { test -h "$file"; } >/dev/null 2>&1 ||
+	 test -f "$file"; then
+	:
+      elif test -d "$file"; then
+	exit_status=1
+	continue
+      elif test "$rmforce" = yes; then
+	continue
+      fi
+
+      rmfiles="$file"
+
+      case $name in
+      *.la)
+	# Possibly a libtool archive, so verify it.
+	if func_lalib_p "$file"; then
+	  func_source $dir/$name
+
+	  # Delete the libtool libraries and symlinks.
+	  for n in $library_names; do
+	    func_append rmfiles " $odir/$n"
+	  done
+	  test -n "$old_library" && func_append rmfiles " $odir/$old_library"
+
+	  case "$opt_mode" in
+	  clean)
+	    case " $library_names " in
+	    *" $dlname "*) ;;
+	    *) test -n "$dlname" && func_append rmfiles " $odir/$dlname" ;;
+	    esac
+	    test -n "$libdir" && func_append rmfiles " $odir/$name $odir/${name}i"
+	    ;;
+	  uninstall)
+	    if test -n "$library_names"; then
+	      # Do each command in the postuninstall commands.
+	      func_execute_cmds "$postuninstall_cmds" 'test "$rmforce" = yes || exit_status=1'
+	    fi
+
+	    if test -n "$old_library"; then
+	      # Do each command in the old_postuninstall commands.
+	      func_execute_cmds "$old_postuninstall_cmds" 'test "$rmforce" = yes || exit_status=1'
+	    fi
+	    # FIXME: should reinstall the best remaining shared library.
+	    ;;
+	  esac
+	fi
+	;;
+
+      *.lo)
+	# Possibly a libtool object, so verify it.
+	if func_lalib_p "$file"; then
+
+	  # Read the .lo file
+	  func_source $dir/$name
+
+	  # Add PIC object to the list of files to remove.
+	  if test -n "$pic_object" &&
+	     test "$pic_object" != none; then
+	    func_append rmfiles " $dir/$pic_object"
+	  fi
+
+	  # Add non-PIC object to the list of files to remove.
+	  if test -n "$non_pic_object" &&
+	     test "$non_pic_object" != none; then
+	    func_append rmfiles " $dir/$non_pic_object"
+	  fi
+	fi
+	;;
+
+      *)
+	if test "$opt_mode" = clean ; then
+	  noexename=$name
+	  case $file in
+	  *.exe)
+	    func_stripname '' '.exe' "$file"
+	    file=$func_stripname_result
+	    func_stripname '' '.exe' "$name"
+	    noexename=$func_stripname_result
+	    # $file with .exe has already been added to rmfiles,
+	    # add $file without .exe
+	    func_append rmfiles " $file"
+	    ;;
+	  esac
+	  # Do a test to see if this is a libtool program.
+	  if func_ltwrapper_p "$file"; then
+	    if func_ltwrapper_executable_p "$file"; then
+	      func_ltwrapper_scriptname "$file"
+	      relink_command=
+	      func_source $func_ltwrapper_scriptname_result
+	      func_append rmfiles " $func_ltwrapper_scriptname_result"
+	    else
+	      relink_command=
+	      func_source $dir/$noexename
+	    fi
+
+	    # note $name still contains .exe if it was in $file originally
+	    # as does the version of $file that was added into $rmfiles
+	    func_append rmfiles " $odir/$name $odir/${name}S.${objext}"
+	    if test "$fast_install" = yes && test -n "$relink_command"; then
+	      func_append rmfiles " $odir/lt-$name"
+	    fi
+	    if test "X$noexename" != "X$name" ; then
+	      func_append rmfiles " $odir/lt-${noexename}.c"
+	    fi
+	  fi
+	fi
+	;;
+      esac
+      func_show_eval "$RM $rmfiles" 'exit_status=1'
+    done
+
+    # Try to remove the ${objdir}s in the directories where we deleted files
+    for dir in $rmdirs; do
+      if test -d "$dir"; then
+	func_show_eval "rmdir $dir >/dev/null 2>&1"
+      fi
+    done
+
+    exit $exit_status
+}
+
+{ test "$opt_mode" = uninstall || test "$opt_mode" = clean; } &&
+    func_mode_uninstall ${1+"$@"}
+
+test -z "$opt_mode" && {
+  help="$generic_help"
+  func_fatal_help "you must specify a MODE"
+}
+
+test -z "$exec_cmd" && \
+  func_fatal_help "invalid operation mode \`$opt_mode'"
+
+if test -n "$exec_cmd"; then
+  eval exec "$exec_cmd"
+  exit $EXIT_FAILURE
+fi
+
+exit $exit_status
+
+
+# The TAGs below are defined such that we never get into a situation
+# in which we disable both kinds of libraries.  Given conflicting
+# choices, we go for a static library, that is the most portable,
+# since we can't tell whether shared libraries were disabled because
+# the user asked for that or because the platform doesn't support
+# them.  This is particularly important on AIX, because we don't
+# support having both static and shared libraries enabled at the same
+# time on that platform, so we default to a shared-only configuration.
+# If a disable-shared tag is given, we'll fallback to a static-only
+# configuration.  But we'll never go from static-only to shared-only.
+
+# ### BEGIN LIBTOOL TAG CONFIG: disable-shared
+build_libtool_libs=no
+build_old_libs=yes
+# ### END LIBTOOL TAG CONFIG: disable-shared
+
+# ### BEGIN LIBTOOL TAG CONFIG: disable-static
+build_old_libs=`case $build_libtool_libs in yes) echo no;; *) echo yes;; esac`
+# ### END LIBTOOL TAG CONFIG: disable-static
+
+# Local Variables:
+# mode:shell-script
+# sh-indentation:2
+# End:
+# vi:sw=2
+
diff --git a/auto/missing b/auto/missing
new file mode 100755
index 0000000..db98974
--- /dev/null
+++ b/auto/missing
@@ -0,0 +1,215 @@
+#! /bin/sh
+# Common wrapper for a few potentially missing GNU programs.
+
+scriptversion=2013-10-28.13; # UTC
+
+# Copyright (C) 1996-2013 Free Software Foundation, Inc.
+# Originally written by Fran,cois Pinard <pinard@iro.umontreal.ca>, 1996.
+
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 2, or (at your option)
+# any later version.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+
+# You should have received a copy of the GNU General Public License
+# along with this program.  If not, see <http://www.gnu.org/licenses/>.
+
+# As a special exception to the GNU General Public License, if you
+# distribute this file as part of a program that contains a
+# configuration script generated by Autoconf, you may include it under
+# the same distribution terms that you use for the rest of that program.
+
+if test $# -eq 0; then
+  echo 1>&2 "Try '$0 --help' for more information"
+  exit 1
+fi
+
+case $1 in
+
+  --is-lightweight)
+    # Used by our autoconf macros to check whether the available missing
+    # script is modern enough.
+    exit 0
+    ;;
+
+  --run)
+    # Back-compat with the calling convention used by older automake.
+    shift
+    ;;
+
+  -h|--h|--he|--hel|--help)
+    echo "\
+$0 [OPTION]... PROGRAM [ARGUMENT]...
+
+Run 'PROGRAM [ARGUMENT]...', returning a proper advice when this fails due
+to PROGRAM being missing or too old.
+
+Options:
+  -h, --help      display this help and exit
+  -v, --version   output version information and exit
+
+Supported PROGRAM values:
+  aclocal   autoconf  autoheader   autom4te  automake  makeinfo
+  bison     yacc      flex         lex       help2man
+
+Version suffixes to PROGRAM as well as the prefixes 'gnu-', 'gnu', and
+'g' are ignored when checking the name.
+
+Send bug reports to <bug-automake@gnu.org>."
+    exit $?
+    ;;
+
+  -v|--v|--ve|--ver|--vers|--versi|--versio|--version)
+    echo "missing $scriptversion (GNU Automake)"
+    exit $?
+    ;;
+
+  -*)
+    echo 1>&2 "$0: unknown '$1' option"
+    echo 1>&2 "Try '$0 --help' for more information"
+    exit 1
+    ;;
+
+esac
+
+# Run the given program, remember its exit status.
+"$@"; st=$?
+
+# If it succeeded, we are done.
+test $st -eq 0 && exit 0
+
+# Also exit now if we it failed (or wasn't found), and '--version' was
+# passed; such an option is passed most likely to detect whether the
+# program is present and works.
+case $2 in --version|--help) exit $st;; esac
+
+# Exit code 63 means version mismatch.  This often happens when the user
+# tries to use an ancient version of a tool on a file that requires a
+# minimum version.
+if test $st -eq 63; then
+  msg="probably too old"
+elif test $st -eq 127; then
+  # Program was missing.
+  msg="missing on your system"
+else
+  # Program was found and executed, but failed.  Give up.
+  exit $st
+fi
+
+perl_URL=http://www.perl.org/
+flex_URL=http://flex.sourceforge.net/
+gnu_software_URL=http://www.gnu.org/software
+
+program_details ()
+{
+  case $1 in
+    aclocal|automake)
+      echo "The '$1' program is part of the GNU Automake package:"
+      echo "<$gnu_software_URL/automake>"
+      echo "It also requires GNU Autoconf, GNU m4 and Perl in order to run:"
+      echo "<$gnu_software_URL/autoconf>"
+      echo "<$gnu_software_URL/m4/>"
+      echo "<$perl_URL>"
+      ;;
+    autoconf|autom4te|autoheader)
+      echo "The '$1' program is part of the GNU Autoconf package:"
+      echo "<$gnu_software_URL/autoconf/>"
+      echo "It also requires GNU m4 and Perl in order to run:"
+      echo "<$gnu_software_URL/m4/>"
+      echo "<$perl_URL>"
+      ;;
+  esac
+}
+
+give_advice ()
+{
+  # Normalize program name to check for.
+  normalized_program=`echo "$1" | sed '
+    s/^gnu-//; t
+    s/^gnu//; t
+    s/^g//; t'`
+
+  printf '%s\n' "'$1' is $msg."
+
+  configure_deps="'configure.ac' or m4 files included by 'configure.ac'"
+  case $normalized_program in
+    autoconf*)
+      echo "You should only need it if you modified 'configure.ac',"
+      echo "or m4 files included by it."
+      program_details 'autoconf'
+      ;;
+    autoheader*)
+      echo "You should only need it if you modified 'acconfig.h' or"
+      echo "$configure_deps."
+      program_details 'autoheader'
+      ;;
+    automake*)
+      echo "You should only need it if you modified 'Makefile.am' or"
+      echo "$configure_deps."
+      program_details 'automake'
+      ;;
+    aclocal*)
+      echo "You should only need it if you modified 'acinclude.m4' or"
+      echo "$configure_deps."
+      program_details 'aclocal'
+      ;;
+   autom4te*)
+      echo "You might have modified some maintainer files that require"
+      echo "the 'autom4te' program to be rebuilt."
+      program_details 'autom4te'
+      ;;
+    bison*|yacc*)
+      echo "You should only need it if you modified a '.y' file."
+      echo "You may want to install the GNU Bison package:"
+      echo "<$gnu_software_URL/bison/>"
+      ;;
+    lex*|flex*)
+      echo "You should only need it if you modified a '.l' file."
+      echo "You may want to install the Fast Lexical Analyzer package:"
+      echo "<$flex_URL>"
+      ;;
+    help2man*)
+      echo "You should only need it if you modified a dependency" \
+           "of a man page."
+      echo "You may want to install the GNU Help2man package:"
+      echo "<$gnu_software_URL/help2man/>"
+    ;;
+    makeinfo*)
+      echo "You should only need it if you modified a '.texi' file, or"
+      echo "any other file indirectly affecting the aspect of the manual."
+      echo "You might want to install the Texinfo package:"
+      echo "<$gnu_software_URL/texinfo/>"
+      echo "The spurious makeinfo call might also be the consequence of"
+      echo "using a buggy 'make' (AIX, DU, IRIX), in which case you might"
+      echo "want to install GNU make:"
+      echo "<$gnu_software_URL/make/>"
+      ;;
+    *)
+      echo "You might have modified some files without having the proper"
+      echo "tools for further handling them.  Check the 'README' file, it"
+      echo "often tells you about the needed prerequisites for installing"
+      echo "this package.  You may also peek at any GNU archive site, in"
+      echo "case some other package contains this missing '$1' program."
+      ;;
+  esac
+}
+
+give_advice "$1" | sed -e '1s/^/WARNING: /' \
+                       -e '2,$s/^/         /' >&2
+
+# Propagate the correct exit status (expected to be 127 for a program
+# not found, 63 for a program that failed due to version mismatch).
+exit $st
+
+# Local variables:
+# eval: (add-hook 'write-file-hooks 'time-stamp)
+# time-stamp-start: "scriptversion="
+# time-stamp-format: "%:y-%02m-%02d.%02H"
+# time-stamp-time-zone: "UTC"
+# time-stamp-end: "; # UTC"
+# End:
diff --git a/build-android.sh b/build-android.sh
new file mode 100755
index 0000000..40afd65
--- /dev/null
+++ b/build-android.sh
@@ -0,0 +1,33 @@
+#!/bin/sh
+set -ev
+VERSION=5.22
+DST=stunnel-$VERSION-android
+
+# to build Zlib:
+# export CHOST=arm-linux-androideabi
+# ./configure --static --prefix=/opt/androideabi/sysroot
+# make
+# make install
+
+# to build OpenSSL:
+# export CC=arm-linux-androideabi-gcc
+# ./Configure linux-armv4 threads no-shared zlib no-dso --openssldir=/opt/androideabi/sysroot
+# make
+# make install
+
+test -f Makefile && make distclean
+mkdir -p bin/android
+cd bin/android
+../../configure --with-sysroot --build=i686-pc-linux-gnu --host=arm-linux-androideabi --prefix=/data/local
+make clean
+make
+cd ../..
+mkdir $DST
+cp bin/android/src/stunnel $DST
+# arm-linux-androideabi-strip $DST/stunnel $DST/openssl
+# cp /opt/androideabi/sysroot/bin/openssl $DST
+# arm-linux-androideabi-strip $DST/openssl
+zip -r $DST.zip $DST
+rm -rf $DST
+# sha256sum $DST.zip
+# mv $DST.zip ../dist/
diff --git a/configure b/configure
new file mode 100755
index 0000000..3370f47
--- /dev/null
+++ b/configure
@@ -0,0 +1,17428 @@
+#! /bin/sh
+# Guess values for system-dependent variables and create Makefiles.
+# Generated by GNU Autoconf 2.69 for stunnel 5.22.
+#
+#
+# Copyright (C) 1992-1996, 1998-2012 Free Software Foundation, Inc.
+#
+#
+# This configure script is free software; the Free Software Foundation
+# gives unlimited permission to copy, distribute and modify it.
+## -------------------- ##
+## M4sh Initialization. ##
+## -------------------- ##
+
+# Be more Bourne compatible
+DUALCASE=1; export DUALCASE # for MKS sh
+if test -n "${ZSH_VERSION+set}" && (emulate sh) >/dev/null 2>&1; then :
+  emulate sh
+  NULLCMD=:
+  # Pre-4.2 versions of Zsh do word splitting on ${1+"$@"}, which
+  # is contrary to our usage.  Disable this feature.
+  alias -g '${1+"$@"}'='"$@"'
+  setopt NO_GLOB_SUBST
+else
+  case `(set -o) 2>/dev/null` in #(
+  *posix*) :
+    set -o posix ;; #(
+  *) :
+     ;;
+esac
+fi
+
+
+as_nl='
+'
+export as_nl
+# Printing a long string crashes Solaris 7 /usr/bin/printf.
+as_echo='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+as_echo=$as_echo$as_echo$as_echo$as_echo$as_echo
+as_echo=$as_echo$as_echo$as_echo$as_echo$as_echo$as_echo
+# Prefer a ksh shell builtin over an external printf program on Solaris,
+# but without wasting forks for bash or zsh.
+if test -z "$BASH_VERSION$ZSH_VERSION" \
+    && (test "X`print -r -- $as_echo`" = "X$as_echo") 2>/dev/null; then
+  as_echo='print -r --'
+  as_echo_n='print -rn --'
+elif (test "X`printf %s $as_echo`" = "X$as_echo") 2>/dev/null; then
+  as_echo='printf %s\n'
+  as_echo_n='printf %s'
+else
+  if test "X`(/usr/ucb/echo -n -n $as_echo) 2>/dev/null`" = "X-n $as_echo"; then
+    as_echo_body='eval /usr/ucb/echo -n "$1$as_nl"'
+    as_echo_n='/usr/ucb/echo -n'
+  else
+    as_echo_body='eval expr "X$1" : "X\\(.*\\)"'
+    as_echo_n_body='eval
+      arg=$1;
+      case $arg in #(
+      *"$as_nl"*)
+	expr "X$arg" : "X\\(.*\\)$as_nl";
+	arg=`expr "X$arg" : ".*$as_nl\\(.*\\)"`;;
+      esac;
+      expr "X$arg" : "X\\(.*\\)" | tr -d "$as_nl"
+    '
+    export as_echo_n_body
+    as_echo_n='sh -c $as_echo_n_body as_echo'
+  fi
+  export as_echo_body
+  as_echo='sh -c $as_echo_body as_echo'
+fi
+
+# The user is always right.
+if test "${PATH_SEPARATOR+set}" != set; then
+  PATH_SEPARATOR=:
+  (PATH='/bin;/bin'; FPATH=$PATH; sh -c :) >/dev/null 2>&1 && {
+    (PATH='/bin:/bin'; FPATH=$PATH; sh -c :) >/dev/null 2>&1 ||
+      PATH_SEPARATOR=';'
+  }
+fi
+
+
+# IFS
+# We need space, tab and new line, in precisely that order.  Quoting is
+# there to prevent editors from complaining about space-tab.
+# (If _AS_PATH_WALK were called with IFS unset, it would disable word
+# splitting by setting IFS to empty value.)
+IFS=" ""	$as_nl"
+
+# Find who we are.  Look in the path if we contain no directory separator.
+as_myself=
+case $0 in #((
+  *[\\/]* ) as_myself=$0 ;;
+  *) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    test -r "$as_dir/$0" && as_myself=$as_dir/$0 && break
+  done
+IFS=$as_save_IFS
+
+     ;;
+esac
+# We did not find ourselves, most probably we were run as `sh COMMAND'
+# in which case we are not to be found in the path.
+if test "x$as_myself" = x; then
+  as_myself=$0
+fi
+if test ! -f "$as_myself"; then
+  $as_echo "$as_myself: error: cannot find myself; rerun with an absolute file name" >&2
+  exit 1
+fi
+
+# Unset variables that we do not need and which cause bugs (e.g. in
+# pre-3.0 UWIN ksh).  But do not cause bugs in bash 2.01; the "|| exit 1"
+# suppresses any "Segmentation fault" message there.  '((' could
+# trigger a bug in pdksh 5.2.14.
+for as_var in BASH_ENV ENV MAIL MAILPATH
+do eval test x\${$as_var+set} = xset \
+  && ( (unset $as_var) || exit 1) >/dev/null 2>&1 && unset $as_var || :
+done
+PS1='$ '
+PS2='> '
+PS4='+ '
+
+# NLS nuisances.
+LC_ALL=C
+export LC_ALL
+LANGUAGE=C
+export LANGUAGE
+
+# CDPATH.
+(unset CDPATH) >/dev/null 2>&1 && unset CDPATH
+
+# Use a proper internal environment variable to ensure we don't fall
+  # into an infinite loop, continuously re-executing ourselves.
+  if test x"${_as_can_reexec}" != xno && test "x$CONFIG_SHELL" != x; then
+    _as_can_reexec=no; export _as_can_reexec;
+    # We cannot yet assume a decent shell, so we have to provide a
+# neutralization value for shells without unset; and this also
+# works around shells that cannot unset nonexistent variables.
+# Preserve -v and -x to the replacement shell.
+BASH_ENV=/dev/null
+ENV=/dev/null
+(unset BASH_ENV) >/dev/null 2>&1 && unset BASH_ENV ENV
+case $- in # ((((
+  *v*x* | *x*v* ) as_opts=-vx ;;
+  *v* ) as_opts=-v ;;
+  *x* ) as_opts=-x ;;
+  * ) as_opts= ;;
+esac
+exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"}
+# Admittedly, this is quite paranoid, since all the known shells bail
+# out after a failed `exec'.
+$as_echo "$0: could not re-execute with $CONFIG_SHELL" >&2
+as_fn_exit 255
+  fi
+  # We don't want this to propagate to other subprocesses.
+          { _as_can_reexec=; unset _as_can_reexec;}
+if test "x$CONFIG_SHELL" = x; then
+  as_bourne_compatible="if test -n \"\${ZSH_VERSION+set}\" && (emulate sh) >/dev/null 2>&1; then :
+  emulate sh
+  NULLCMD=:
+  # Pre-4.2 versions of Zsh do word splitting on \${1+\"\$@\"}, which
+  # is contrary to our usage.  Disable this feature.
+  alias -g '\${1+\"\$@\"}'='\"\$@\"'
+  setopt NO_GLOB_SUBST
+else
+  case \`(set -o) 2>/dev/null\` in #(
+  *posix*) :
+    set -o posix ;; #(
+  *) :
+     ;;
+esac
+fi
+"
+  as_required="as_fn_return () { (exit \$1); }
+as_fn_success () { as_fn_return 0; }
+as_fn_failure () { as_fn_return 1; }
+as_fn_ret_success () { return 0; }
+as_fn_ret_failure () { return 1; }
+
+exitcode=0
+as_fn_success || { exitcode=1; echo as_fn_success failed.; }
+as_fn_failure && { exitcode=1; echo as_fn_failure succeeded.; }
+as_fn_ret_success || { exitcode=1; echo as_fn_ret_success failed.; }
+as_fn_ret_failure && { exitcode=1; echo as_fn_ret_failure succeeded.; }
+if ( set x; as_fn_ret_success y && test x = \"\$1\" ); then :
+
+else
+  exitcode=1; echo positional parameters were not saved.
+fi
+test x\$exitcode = x0 || exit 1
+test -x / || exit 1"
+  as_suggested="  as_lineno_1=";as_suggested=$as_suggested$LINENO;as_suggested=$as_suggested" as_lineno_1a=\$LINENO
+  as_lineno_2=";as_suggested=$as_suggested$LINENO;as_suggested=$as_suggested" as_lineno_2a=\$LINENO
+  eval 'test \"x\$as_lineno_1'\$as_run'\" != \"x\$as_lineno_2'\$as_run'\" &&
+  test \"x\`expr \$as_lineno_1'\$as_run' + 1\`\" = \"x\$as_lineno_2'\$as_run'\"' || exit 1
+
+  test -n \"\${ZSH_VERSION+set}\${BASH_VERSION+set}\" || (
+    ECHO='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+    ECHO=\$ECHO\$ECHO\$ECHO\$ECHO\$ECHO
+    ECHO=\$ECHO\$ECHO\$ECHO\$ECHO\$ECHO\$ECHO
+    PATH=/empty FPATH=/empty; export PATH FPATH
+    test \"X\`printf %s \$ECHO\`\" = \"X\$ECHO\" \\
+      || test \"X\`print -r -- \$ECHO\`\" = \"X\$ECHO\" ) || exit 1
+test \$(( 1 + 1 )) = 2 || exit 1"
+  if (eval "$as_required") 2>/dev/null; then :
+  as_have_required=yes
+else
+  as_have_required=no
+fi
+  if test x$as_have_required = xyes && (eval "$as_suggested") 2>/dev/null; then :
+
+else
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+as_found=false
+for as_dir in /bin$PATH_SEPARATOR/usr/bin$PATH_SEPARATOR$PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+  as_found=:
+  case $as_dir in #(
+	 /*)
+	   for as_base in sh bash ksh sh5; do
+	     # Try only shells that exist, to save several forks.
+	     as_shell=$as_dir/$as_base
+	     if { test -f "$as_shell" || test -f "$as_shell.exe"; } &&
+		    { $as_echo "$as_bourne_compatible""$as_required" | as_run=a "$as_shell"; } 2>/dev/null; then :
+  CONFIG_SHELL=$as_shell as_have_required=yes
+		   if { $as_echo "$as_bourne_compatible""$as_suggested" | as_run=a "$as_shell"; } 2>/dev/null; then :
+  break 2
+fi
+fi
+	   done;;
+       esac
+  as_found=false
+done
+$as_found || { if { test -f "$SHELL" || test -f "$SHELL.exe"; } &&
+	      { $as_echo "$as_bourne_compatible""$as_required" | as_run=a "$SHELL"; } 2>/dev/null; then :
+  CONFIG_SHELL=$SHELL as_have_required=yes
+fi; }
+IFS=$as_save_IFS
+
+
+      if test "x$CONFIG_SHELL" != x; then :
+  export CONFIG_SHELL
+             # We cannot yet assume a decent shell, so we have to provide a
+# neutralization value for shells without unset; and this also
+# works around shells that cannot unset nonexistent variables.
+# Preserve -v and -x to the replacement shell.
+BASH_ENV=/dev/null
+ENV=/dev/null
+(unset BASH_ENV) >/dev/null 2>&1 && unset BASH_ENV ENV
+case $- in # ((((
+  *v*x* | *x*v* ) as_opts=-vx ;;
+  *v* ) as_opts=-v ;;
+  *x* ) as_opts=-x ;;
+  * ) as_opts= ;;
+esac
+exec $CONFIG_SHELL $as_opts "$as_myself" ${1+"$@"}
+# Admittedly, this is quite paranoid, since all the known shells bail
+# out after a failed `exec'.
+$as_echo "$0: could not re-execute with $CONFIG_SHELL" >&2
+exit 255
+fi
+
+    if test x$as_have_required = xno; then :
+  $as_echo "$0: This script requires a shell more modern than all"
+  $as_echo "$0: the shells that I found on your system."
+  if test x${ZSH_VERSION+set} = xset ; then
+    $as_echo "$0: In particular, zsh $ZSH_VERSION has bugs and should"
+    $as_echo "$0: be upgraded to zsh 4.3.4 or later."
+  else
+    $as_echo "$0: Please tell bug-autoconf@gnu.org about your system,
+$0: including any error possibly output before this
+$0: message. Then install a modern shell, or manually run
+$0: the script under such a shell if you do have one."
+  fi
+  exit 1
+fi
+fi
+fi
+SHELL=${CONFIG_SHELL-/bin/sh}
+export SHELL
+# Unset more variables known to interfere with behavior of common tools.
+CLICOLOR_FORCE= GREP_OPTIONS=
+unset CLICOLOR_FORCE GREP_OPTIONS
+
+## --------------------- ##
+## M4sh Shell Functions. ##
+## --------------------- ##
+# as_fn_unset VAR
+# ---------------
+# Portably unset VAR.
+as_fn_unset ()
+{
+  { eval $1=; unset $1;}
+}
+as_unset=as_fn_unset
+
+# as_fn_set_status STATUS
+# -----------------------
+# Set $? to STATUS, without forking.
+as_fn_set_status ()
+{
+  return $1
+} # as_fn_set_status
+
+# as_fn_exit STATUS
+# -----------------
+# Exit the shell with STATUS, even in a "trap 0" or "set -e" context.
+as_fn_exit ()
+{
+  set +e
+  as_fn_set_status $1
+  exit $1
+} # as_fn_exit
+
+# as_fn_mkdir_p
+# -------------
+# Create "$as_dir" as a directory, including parents if necessary.
+as_fn_mkdir_p ()
+{
+
+  case $as_dir in #(
+  -*) as_dir=./$as_dir;;
+  esac
+  test -d "$as_dir" || eval $as_mkdir_p || {
+    as_dirs=
+    while :; do
+      case $as_dir in #(
+      *\'*) as_qdir=`$as_echo "$as_dir" | sed "s/'/'\\\\\\\\''/g"`;; #'(
+      *) as_qdir=$as_dir;;
+      esac
+      as_dirs="'$as_qdir' $as_dirs"
+      as_dir=`$as_dirname -- "$as_dir" ||
+$as_expr X"$as_dir" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$as_dir" : 'X\(//\)[^/]' \| \
+	 X"$as_dir" : 'X\(//\)$' \| \
+	 X"$as_dir" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$as_dir" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+      test -d "$as_dir" && break
+    done
+    test -z "$as_dirs" || eval "mkdir $as_dirs"
+  } || test -d "$as_dir" || as_fn_error $? "cannot create directory $as_dir"
+
+
+} # as_fn_mkdir_p
+
+# as_fn_executable_p FILE
+# -----------------------
+# Test if FILE is an executable regular file.
+as_fn_executable_p ()
+{
+  test -f "$1" && test -x "$1"
+} # as_fn_executable_p
+# as_fn_append VAR VALUE
+# ----------------------
+# Append the text in VALUE to the end of the definition contained in VAR. Take
+# advantage of any shell optimizations that allow amortized linear growth over
+# repeated appends, instead of the typical quadratic growth present in naive
+# implementations.
+if (eval "as_var=1; as_var+=2; test x\$as_var = x12") 2>/dev/null; then :
+  eval 'as_fn_append ()
+  {
+    eval $1+=\$2
+  }'
+else
+  as_fn_append ()
+  {
+    eval $1=\$$1\$2
+  }
+fi # as_fn_append
+
+# as_fn_arith ARG...
+# ------------------
+# Perform arithmetic evaluation on the ARGs, and store the result in the
+# global $as_val. Take advantage of shells that can avoid forks. The arguments
+# must be portable across $(()) and expr.
+if (eval "test \$(( 1 + 1 )) = 2") 2>/dev/null; then :
+  eval 'as_fn_arith ()
+  {
+    as_val=$(( $* ))
+  }'
+else
+  as_fn_arith ()
+  {
+    as_val=`expr "$@" || test $? -eq 1`
+  }
+fi # as_fn_arith
+
+
+# as_fn_error STATUS ERROR [LINENO LOG_FD]
+# ----------------------------------------
+# Output "`basename $0`: error: ERROR" to stderr. If LINENO and LOG_FD are
+# provided, also output the error to LOG_FD, referencing LINENO. Then exit the
+# script with STATUS, using 1 if that was 0.
+as_fn_error ()
+{
+  as_status=$1; test $as_status -eq 0 && as_status=1
+  if test "$4"; then
+    as_lineno=${as_lineno-"$3"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+    $as_echo "$as_me:${as_lineno-$LINENO}: error: $2" >&$4
+  fi
+  $as_echo "$as_me: error: $2" >&2
+  as_fn_exit $as_status
+} # as_fn_error
+
+if expr a : '\(a\)' >/dev/null 2>&1 &&
+   test "X`expr 00001 : '.*\(...\)'`" = X001; then
+  as_expr=expr
+else
+  as_expr=false
+fi
+
+if (basename -- /) >/dev/null 2>&1 && test "X`basename -- / 2>&1`" = "X/"; then
+  as_basename=basename
+else
+  as_basename=false
+fi
+
+if (as_dir=`dirname -- /` && test "X$as_dir" = X/) >/dev/null 2>&1; then
+  as_dirname=dirname
+else
+  as_dirname=false
+fi
+
+as_me=`$as_basename -- "$0" ||
+$as_expr X/"$0" : '.*/\([^/][^/]*\)/*$' \| \
+	 X"$0" : 'X\(//\)$' \| \
+	 X"$0" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X/"$0" |
+    sed '/^.*\/\([^/][^/]*\)\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\/\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\/\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+
+# Avoid depending upon Character Ranges.
+as_cr_letters='abcdefghijklmnopqrstuvwxyz'
+as_cr_LETTERS='ABCDEFGHIJKLMNOPQRSTUVWXYZ'
+as_cr_Letters=$as_cr_letters$as_cr_LETTERS
+as_cr_digits='0123456789'
+as_cr_alnum=$as_cr_Letters$as_cr_digits
+
+
+  as_lineno_1=$LINENO as_lineno_1a=$LINENO
+  as_lineno_2=$LINENO as_lineno_2a=$LINENO
+  eval 'test "x$as_lineno_1'$as_run'" != "x$as_lineno_2'$as_run'" &&
+  test "x`expr $as_lineno_1'$as_run' + 1`" = "x$as_lineno_2'$as_run'"' || {
+  # Blame Lee E. McMahon (1931-1989) for sed's syntax.  :-)
+  sed -n '
+    p
+    /[$]LINENO/=
+  ' <$as_myself |
+    sed '
+      s/[$]LINENO.*/&-/
+      t lineno
+      b
+      :lineno
+      N
+      :loop
+      s/[$]LINENO\([^'$as_cr_alnum'_].*\n\)\(.*\)/\2\1\2/
+      t loop
+      s/-\n.*//
+    ' >$as_me.lineno &&
+  chmod +x "$as_me.lineno" ||
+    { $as_echo "$as_me: error: cannot create $as_me.lineno; rerun with a POSIX shell" >&2; as_fn_exit 1; }
+
+  # If we had to re-execute with $CONFIG_SHELL, we're ensured to have
+  # already done that, so ensure we don't try to do so again and fall
+  # in an infinite loop.  This has already happened in practice.
+  _as_can_reexec=no; export _as_can_reexec
+  # Don't try to exec as it changes $[0], causing all sort of problems
+  # (the dirname of $[0] is not the place where we might find the
+  # original and so on.  Autoconf is especially sensitive to this).
+  . "./$as_me.lineno"
+  # Exit status is that of the last command.
+  exit
+}
+
+ECHO_C= ECHO_N= ECHO_T=
+case `echo -n x` in #(((((
+-n*)
+  case `echo 'xy\c'` in
+  *c*) ECHO_T='	';;	# ECHO_T is single tab character.
+  xy)  ECHO_C='\c';;
+  *)   echo `echo ksh88 bug on AIX 6.1` > /dev/null
+       ECHO_T='	';;
+  esac;;
+*)
+  ECHO_N='-n';;
+esac
+
+rm -f conf$$ conf$$.exe conf$$.file
+if test -d conf$$.dir; then
+  rm -f conf$$.dir/conf$$.file
+else
+  rm -f conf$$.dir
+  mkdir conf$$.dir 2>/dev/null
+fi
+if (echo >conf$$.file) 2>/dev/null; then
+  if ln -s conf$$.file conf$$ 2>/dev/null; then
+    as_ln_s='ln -s'
+    # ... but there are two gotchas:
+    # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail.
+    # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable.
+    # In both cases, we have to default to `cp -pR'.
+    ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe ||
+      as_ln_s='cp -pR'
+  elif ln conf$$.file conf$$ 2>/dev/null; then
+    as_ln_s=ln
+  else
+    as_ln_s='cp -pR'
+  fi
+else
+  as_ln_s='cp -pR'
+fi
+rm -f conf$$ conf$$.exe conf$$.dir/conf$$.file conf$$.file
+rmdir conf$$.dir 2>/dev/null
+
+if mkdir -p . 2>/dev/null; then
+  as_mkdir_p='mkdir -p "$as_dir"'
+else
+  test -d ./-p && rmdir ./-p
+  as_mkdir_p=false
+fi
+
+as_test_x='test -x'
+as_executable_p=as_fn_executable_p
+
+# Sed expression to map a string onto a valid CPP name.
+as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'"
+
+# Sed expression to map a string onto a valid variable name.
+as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'"
+
+SHELL=${CONFIG_SHELL-/bin/sh}
+
+
+test -n "$DJDIR" || exec 7<&0 </dev/null
+exec 6>&1
+
+# Name of the host.
+# hostname on some systems (SVR3.2, old GNU/Linux) returns a bogus exit status,
+# so uname gets run too.
+ac_hostname=`(hostname || uname -n) 2>/dev/null | sed 1q`
+
+#
+# Initializations.
+#
+ac_default_prefix=/usr/local
+ac_clean_files=
+ac_config_libobj_dir=.
+LIBOBJS=
+cross_compiling=no
+subdirs=
+MFLAGS=
+MAKEFLAGS=
+
+# Identity of this package.
+PACKAGE_NAME='stunnel'
+PACKAGE_TARNAME='stunnel'
+PACKAGE_VERSION='5.22'
+PACKAGE_STRING='stunnel 5.22'
+PACKAGE_BUGREPORT=''
+PACKAGE_URL=''
+
+ac_unique_file="src/stunnel.c"
+# Factoring default headers for most tests.
+ac_includes_default="\
+#include <stdio.h>
+#ifdef HAVE_SYS_TYPES_H
+# include <sys/types.h>
+#endif
+#ifdef HAVE_SYS_STAT_H
+# include <sys/stat.h>
+#endif
+#ifdef STDC_HEADERS
+# include <stdlib.h>
+# include <stddef.h>
+#else
+# ifdef HAVE_STDLIB_H
+#  include <stdlib.h>
+# endif
+#endif
+#ifdef HAVE_STRING_H
+# if !defined STDC_HEADERS && defined HAVE_MEMORY_H
+#  include <memory.h>
+# endif
+# include <string.h>
+#endif
+#ifdef HAVE_STRINGS_H
+# include <strings.h>
+#endif
+#ifdef HAVE_INTTYPES_H
+# include <inttypes.h>
+#endif
+#ifdef HAVE_STDINT_H
+# include <stdint.h>
+#endif
+#ifdef HAVE_UNISTD_H
+# include <unistd.h>
+#endif"
+
+ac_subst_vars='am__EXEEXT_FALSE
+am__EXEEXT_TRUE
+LTLIBOBJS
+LIBOBJS
+SSLDIR
+DEFAULT_GROUP
+RANDOM_FILE
+LIBTOOL_DEPS
+CPP
+OTOOL64
+OTOOL
+LIPO
+NMEDIT
+DSYMUTIL
+MANIFEST_TOOL
+RANLIB
+ac_ct_AR
+AR
+DLLTOOL
+OBJDUMP
+LN_S
+NM
+ac_ct_DUMPBIN
+DUMPBIN
+LD
+FGREP
+EGREP
+GREP
+SED
+LIBTOOL
+PTHREAD_CFLAGS
+PTHREAD_LIBS
+PTHREAD_CC
+ax_pthread_config
+am__fastdepCC_FALSE
+am__fastdepCC_TRUE
+CCDEPMODE
+am__nodep
+AMDEPBACKSLASH
+AMDEP_FALSE
+AMDEP_TRUE
+am__quote
+am__include
+DEPDIR
+OBJEXT
+EXEEXT
+ac_ct_CC
+CPPFLAGS
+LDFLAGS
+CFLAGS
+CC
+host_os
+host_vendor
+host_cpu
+host
+build_os
+build_vendor
+build_cpu
+build
+AUTHOR_TESTS_FALSE
+AUTHOR_TESTS_TRUE
+AM_BACKSLASH
+AM_DEFAULT_VERBOSITY
+AM_DEFAULT_V
+AM_V
+am__untar
+am__tar
+AMTAR
+am__leading_dot
+SET_MAKE
+AWK
+mkdir_p
+MKDIR_P
+INSTALL_STRIP_PROGRAM
+STRIP
+install_sh
+MAKEINFO
+AUTOHEADER
+AUTOMAKE
+AUTOCONF
+ACLOCAL
+VERSION
+PACKAGE
+CYGPATH_W
+am__isrc
+INSTALL_DATA
+INSTALL_SCRIPT
+INSTALL_PROGRAM
+target_alias
+host_alias
+build_alias
+LIBS
+ECHO_T
+ECHO_N
+ECHO_C
+DEFS
+mandir
+localedir
+libdir
+psdir
+pdfdir
+dvidir
+htmldir
+infodir
+docdir
+oldincludedir
+includedir
+localstatedir
+sharedstatedir
+sysconfdir
+datadir
+datarootdir
+libexecdir
+sbindir
+bindir
+program_transform_name
+prefix
+exec_prefix
+PACKAGE_URL
+PACKAGE_BUGREPORT
+PACKAGE_STRING
+PACKAGE_VERSION
+PACKAGE_TARNAME
+PACKAGE_NAME
+PATH_SEPARATOR
+SHELL'
+ac_subst_files=''
+ac_user_opts='
+enable_option_checking
+enable_silent_rules
+enable_dependency_tracking
+with_threads
+enable_static
+enable_shared
+with_pic
+enable_fast_install
+with_gnu_ld
+with_sysroot
+enable_libtool_lock
+with_egd_socket
+with_random
+enable_ipv6
+enable_fips
+enable_systemd
+enable_libwrap
+with_ssl
+'
+      ac_precious_vars='build_alias
+host_alias
+target_alias
+CC
+CFLAGS
+LDFLAGS
+LIBS
+CPPFLAGS
+CPP'
+
+
+# Initialize some variables set by options.
+ac_init_help=
+ac_init_version=false
+ac_unrecognized_opts=
+ac_unrecognized_sep=
+# The variables have the same names as the options, with
+# dashes changed to underlines.
+cache_file=/dev/null
+exec_prefix=NONE
+no_create=
+no_recursion=
+prefix=NONE
+program_prefix=NONE
+program_suffix=NONE
+program_transform_name=s,x,x,
+silent=
+site=
+srcdir=
+verbose=
+x_includes=NONE
+x_libraries=NONE
+
+# Installation directory options.
+# These are left unexpanded so users can "make install exec_prefix=/foo"
+# and all the variables that are supposed to be based on exec_prefix
+# by default will actually change.
+# Use braces instead of parens because sh, perl, etc. also accept them.
+# (The list follows the same order as the GNU Coding Standards.)
+bindir='${exec_prefix}/bin'
+sbindir='${exec_prefix}/sbin'
+libexecdir='${exec_prefix}/libexec'
+datarootdir='${prefix}/share'
+datadir='${datarootdir}'
+sysconfdir='${prefix}/etc'
+sharedstatedir='${prefix}/com'
+localstatedir='${prefix}/var'
+includedir='${prefix}/include'
+oldincludedir='/usr/include'
+docdir='${datarootdir}/doc/${PACKAGE_TARNAME}'
+infodir='${datarootdir}/info'
+htmldir='${docdir}'
+dvidir='${docdir}'
+pdfdir='${docdir}'
+psdir='${docdir}'
+libdir='${exec_prefix}/lib'
+localedir='${datarootdir}/locale'
+mandir='${datarootdir}/man'
+
+ac_prev=
+ac_dashdash=
+for ac_option
+do
+  # If the previous option needs an argument, assign it.
+  if test -n "$ac_prev"; then
+    eval $ac_prev=\$ac_option
+    ac_prev=
+    continue
+  fi
+
+  case $ac_option in
+  *=?*) ac_optarg=`expr "X$ac_option" : '[^=]*=\(.*\)'` ;;
+  *=)   ac_optarg= ;;
+  *)    ac_optarg=yes ;;
+  esac
+
+  # Accept the important Cygnus configure options, so we can diagnose typos.
+
+  case $ac_dashdash$ac_option in
+  --)
+    ac_dashdash=yes ;;
+
+  -bindir | --bindir | --bindi | --bind | --bin | --bi)
+    ac_prev=bindir ;;
+  -bindir=* | --bindir=* | --bindi=* | --bind=* | --bin=* | --bi=*)
+    bindir=$ac_optarg ;;
+
+  -build | --build | --buil | --bui | --bu)
+    ac_prev=build_alias ;;
+  -build=* | --build=* | --buil=* | --bui=* | --bu=*)
+    build_alias=$ac_optarg ;;
+
+  -cache-file | --cache-file | --cache-fil | --cache-fi \
+  | --cache-f | --cache- | --cache | --cach | --cac | --ca | --c)
+    ac_prev=cache_file ;;
+  -cache-file=* | --cache-file=* | --cache-fil=* | --cache-fi=* \
+  | --cache-f=* | --cache-=* | --cache=* | --cach=* | --cac=* | --ca=* | --c=*)
+    cache_file=$ac_optarg ;;
+
+  --config-cache | -C)
+    cache_file=config.cache ;;
+
+  -datadir | --datadir | --datadi | --datad)
+    ac_prev=datadir ;;
+  -datadir=* | --datadir=* | --datadi=* | --datad=*)
+    datadir=$ac_optarg ;;
+
+  -datarootdir | --datarootdir | --datarootdi | --datarootd | --dataroot \
+  | --dataroo | --dataro | --datar)
+    ac_prev=datarootdir ;;
+  -datarootdir=* | --datarootdir=* | --datarootdi=* | --datarootd=* \
+  | --dataroot=* | --dataroo=* | --dataro=* | --datar=*)
+    datarootdir=$ac_optarg ;;
+
+  -disable-* | --disable-*)
+    ac_useropt=`expr "x$ac_option" : 'x-*disable-\(.*\)'`
+    # Reject names that are not valid shell variable names.
+    expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null &&
+      as_fn_error $? "invalid feature name: $ac_useropt"
+    ac_useropt_orig=$ac_useropt
+    ac_useropt=`$as_echo "$ac_useropt" | sed 's/[-+.]/_/g'`
+    case $ac_user_opts in
+      *"
+"enable_$ac_useropt"
+"*) ;;
+      *) ac_unrecognized_opts="$ac_unrecognized_opts$ac_unrecognized_sep--disable-$ac_useropt_orig"
+	 ac_unrecognized_sep=', ';;
+    esac
+    eval enable_$ac_useropt=no ;;
+
+  -docdir | --docdir | --docdi | --doc | --do)
+    ac_prev=docdir ;;
+  -docdir=* | --docdir=* | --docdi=* | --doc=* | --do=*)
+    docdir=$ac_optarg ;;
+
+  -dvidir | --dvidir | --dvidi | --dvid | --dvi | --dv)
+    ac_prev=dvidir ;;
+  -dvidir=* | --dvidir=* | --dvidi=* | --dvid=* | --dvi=* | --dv=*)
+    dvidir=$ac_optarg ;;
+
+  -enable-* | --enable-*)
+    ac_useropt=`expr "x$ac_option" : 'x-*enable-\([^=]*\)'`
+    # Reject names that are not valid shell variable names.
+    expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null &&
+      as_fn_error $? "invalid feature name: $ac_useropt"
+    ac_useropt_orig=$ac_useropt
+    ac_useropt=`$as_echo "$ac_useropt" | sed 's/[-+.]/_/g'`
+    case $ac_user_opts in
+      *"
+"enable_$ac_useropt"
+"*) ;;
+      *) ac_unrecognized_opts="$ac_unrecognized_opts$ac_unrecognized_sep--enable-$ac_useropt_orig"
+	 ac_unrecognized_sep=', ';;
+    esac
+    eval enable_$ac_useropt=\$ac_optarg ;;
+
+  -exec-prefix | --exec_prefix | --exec-prefix | --exec-prefi \
+  | --exec-pref | --exec-pre | --exec-pr | --exec-p | --exec- \
+  | --exec | --exe | --ex)
+    ac_prev=exec_prefix ;;
+  -exec-prefix=* | --exec_prefix=* | --exec-prefix=* | --exec-prefi=* \
+  | --exec-pref=* | --exec-pre=* | --exec-pr=* | --exec-p=* | --exec-=* \
+  | --exec=* | --exe=* | --ex=*)
+    exec_prefix=$ac_optarg ;;
+
+  -gas | --gas | --ga | --g)
+    # Obsolete; use --with-gas.
+    with_gas=yes ;;
+
+  -help | --help | --hel | --he | -h)
+    ac_init_help=long ;;
+  -help=r* | --help=r* | --hel=r* | --he=r* | -hr*)
+    ac_init_help=recursive ;;
+  -help=s* | --help=s* | --hel=s* | --he=s* | -hs*)
+    ac_init_help=short ;;
+
+  -host | --host | --hos | --ho)
+    ac_prev=host_alias ;;
+  -host=* | --host=* | --hos=* | --ho=*)
+    host_alias=$ac_optarg ;;
+
+  -htmldir | --htmldir | --htmldi | --htmld | --html | --htm | --ht)
+    ac_prev=htmldir ;;
+  -htmldir=* | --htmldir=* | --htmldi=* | --htmld=* | --html=* | --htm=* \
+  | --ht=*)
+    htmldir=$ac_optarg ;;
+
+  -includedir | --includedir | --includedi | --included | --include \
+  | --includ | --inclu | --incl | --inc)
+    ac_prev=includedir ;;
+  -includedir=* | --includedir=* | --includedi=* | --included=* | --include=* \
+  | --includ=* | --inclu=* | --incl=* | --inc=*)
+    includedir=$ac_optarg ;;
+
+  -infodir | --infodir | --infodi | --infod | --info | --inf)
+    ac_prev=infodir ;;
+  -infodir=* | --infodir=* | --infodi=* | --infod=* | --info=* | --inf=*)
+    infodir=$ac_optarg ;;
+
+  -libdir | --libdir | --libdi | --libd)
+    ac_prev=libdir ;;
+  -libdir=* | --libdir=* | --libdi=* | --libd=*)
+    libdir=$ac_optarg ;;
+
+  -libexecdir | --libexecdir | --libexecdi | --libexecd | --libexec \
+  | --libexe | --libex | --libe)
+    ac_prev=libexecdir ;;
+  -libexecdir=* | --libexecdir=* | --libexecdi=* | --libexecd=* | --libexec=* \
+  | --libexe=* | --libex=* | --libe=*)
+    libexecdir=$ac_optarg ;;
+
+  -localedir | --localedir | --localedi | --localed | --locale)
+    ac_prev=localedir ;;
+  -localedir=* | --localedir=* | --localedi=* | --localed=* | --locale=*)
+    localedir=$ac_optarg ;;
+
+  -localstatedir | --localstatedir | --localstatedi | --localstated \
+  | --localstate | --localstat | --localsta | --localst | --locals)
+    ac_prev=localstatedir ;;
+  -localstatedir=* | --localstatedir=* | --localstatedi=* | --localstated=* \
+  | --localstate=* | --localstat=* | --localsta=* | --localst=* | --locals=*)
+    localstatedir=$ac_optarg ;;
+
+  -mandir | --mandir | --mandi | --mand | --man | --ma | --m)
+    ac_prev=mandir ;;
+  -mandir=* | --mandir=* | --mandi=* | --mand=* | --man=* | --ma=* | --m=*)
+    mandir=$ac_optarg ;;
+
+  -nfp | --nfp | --nf)
+    # Obsolete; use --without-fp.
+    with_fp=no ;;
+
+  -no-create | --no-create | --no-creat | --no-crea | --no-cre \
+  | --no-cr | --no-c | -n)
+    no_create=yes ;;
+
+  -no-recursion | --no-recursion | --no-recursio | --no-recursi \
+  | --no-recurs | --no-recur | --no-recu | --no-rec | --no-re | --no-r)
+    no_recursion=yes ;;
+
+  -oldincludedir | --oldincludedir | --oldincludedi | --oldincluded \
+  | --oldinclude | --oldinclud | --oldinclu | --oldincl | --oldinc \
+  | --oldin | --oldi | --old | --ol | --o)
+    ac_prev=oldincludedir ;;
+  -oldincludedir=* | --oldincludedir=* | --oldincludedi=* | --oldincluded=* \
+  | --oldinclude=* | --oldinclud=* | --oldinclu=* | --oldincl=* | --oldinc=* \
+  | --oldin=* | --oldi=* | --old=* | --ol=* | --o=*)
+    oldincludedir=$ac_optarg ;;
+
+  -prefix | --prefix | --prefi | --pref | --pre | --pr | --p)
+    ac_prev=prefix ;;
+  -prefix=* | --prefix=* | --prefi=* | --pref=* | --pre=* | --pr=* | --p=*)
+    prefix=$ac_optarg ;;
+
+  -program-prefix | --program-prefix | --program-prefi | --program-pref \
+  | --program-pre | --program-pr | --program-p)
+    ac_prev=program_prefix ;;
+  -program-prefix=* | --program-prefix=* | --program-prefi=* \
+  | --program-pref=* | --program-pre=* | --program-pr=* | --program-p=*)
+    program_prefix=$ac_optarg ;;
+
+  -program-suffix | --program-suffix | --program-suffi | --program-suff \
+  | --program-suf | --program-su | --program-s)
+    ac_prev=program_suffix ;;
+  -program-suffix=* | --program-suffix=* | --program-suffi=* \
+  | --program-suff=* | --program-suf=* | --program-su=* | --program-s=*)
+    program_suffix=$ac_optarg ;;
+
+  -program-transform-name | --program-transform-name \
+  | --program-transform-nam | --program-transform-na \
+  | --program-transform-n | --program-transform- \
+  | --program-transform | --program-transfor \
+  | --program-transfo | --program-transf \
+  | --program-trans | --program-tran \
+  | --progr-tra | --program-tr | --program-t)
+    ac_prev=program_transform_name ;;
+  -program-transform-name=* | --program-transform-name=* \
+  | --program-transform-nam=* | --program-transform-na=* \
+  | --program-transform-n=* | --program-transform-=* \
+  | --program-transform=* | --program-transfor=* \
+  | --program-transfo=* | --program-transf=* \
+  | --program-trans=* | --program-tran=* \
+  | --progr-tra=* | --program-tr=* | --program-t=*)
+    program_transform_name=$ac_optarg ;;
+
+  -pdfdir | --pdfdir | --pdfdi | --pdfd | --pdf | --pd)
+    ac_prev=pdfdir ;;
+  -pdfdir=* | --pdfdir=* | --pdfdi=* | --pdfd=* | --pdf=* | --pd=*)
+    pdfdir=$ac_optarg ;;
+
+  -psdir | --psdir | --psdi | --psd | --ps)
+    ac_prev=psdir ;;
+  -psdir=* | --psdir=* | --psdi=* | --psd=* | --ps=*)
+    psdir=$ac_optarg ;;
+
+  -q | -quiet | --quiet | --quie | --qui | --qu | --q \
+  | -silent | --silent | --silen | --sile | --sil)
+    silent=yes ;;
+
+  -sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb)
+    ac_prev=sbindir ;;
+  -sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \
+  | --sbi=* | --sb=*)
+    sbindir=$ac_optarg ;;
+
+  -sharedstatedir | --sharedstatedir | --sharedstatedi \
+  | --sharedstated | --sharedstate | --sharedstat | --sharedsta \
+  | --sharedst | --shareds | --shared | --share | --shar \
+  | --sha | --sh)
+    ac_prev=sharedstatedir ;;
+  -sharedstatedir=* | --sharedstatedir=* | --sharedstatedi=* \
+  | --sharedstated=* | --sharedstate=* | --sharedstat=* | --sharedsta=* \
+  | --sharedst=* | --shareds=* | --shared=* | --share=* | --shar=* \
+  | --sha=* | --sh=*)
+    sharedstatedir=$ac_optarg ;;
+
+  -site | --site | --sit)
+    ac_prev=site ;;
+  -site=* | --site=* | --sit=*)
+    site=$ac_optarg ;;
+
+  -srcdir | --srcdir | --srcdi | --srcd | --src | --sr)
+    ac_prev=srcdir ;;
+  -srcdir=* | --srcdir=* | --srcdi=* | --srcd=* | --src=* | --sr=*)
+    srcdir=$ac_optarg ;;
+
+  -sysconfdir | --sysconfdir | --sysconfdi | --sysconfd | --sysconf \
+  | --syscon | --sysco | --sysc | --sys | --sy)
+    ac_prev=sysconfdir ;;
+  -sysconfdir=* | --sysconfdir=* | --sysconfdi=* | --sysconfd=* | --sysconf=* \
+  | --syscon=* | --sysco=* | --sysc=* | --sys=* | --sy=*)
+    sysconfdir=$ac_optarg ;;
+
+  -target | --target | --targe | --targ | --tar | --ta | --t)
+    ac_prev=target_alias ;;
+  -target=* | --target=* | --targe=* | --targ=* | --tar=* | --ta=* | --t=*)
+    target_alias=$ac_optarg ;;
+
+  -v | -verbose | --verbose | --verbos | --verbo | --verb)
+    verbose=yes ;;
+
+  -version | --version | --versio | --versi | --vers | -V)
+    ac_init_version=: ;;
+
+  -with-* | --with-*)
+    ac_useropt=`expr "x$ac_option" : 'x-*with-\([^=]*\)'`
+    # Reject names that are not valid shell variable names.
+    expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null &&
+      as_fn_error $? "invalid package name: $ac_useropt"
+    ac_useropt_orig=$ac_useropt
+    ac_useropt=`$as_echo "$ac_useropt" | sed 's/[-+.]/_/g'`
+    case $ac_user_opts in
+      *"
+"with_$ac_useropt"
+"*) ;;
+      *) ac_unrecognized_opts="$ac_unrecognized_opts$ac_unrecognized_sep--with-$ac_useropt_orig"
+	 ac_unrecognized_sep=', ';;
+    esac
+    eval with_$ac_useropt=\$ac_optarg ;;
+
+  -without-* | --without-*)
+    ac_useropt=`expr "x$ac_option" : 'x-*without-\(.*\)'`
+    # Reject names that are not valid shell variable names.
+    expr "x$ac_useropt" : ".*[^-+._$as_cr_alnum]" >/dev/null &&
+      as_fn_error $? "invalid package name: $ac_useropt"
+    ac_useropt_orig=$ac_useropt
+    ac_useropt=`$as_echo "$ac_useropt" | sed 's/[-+.]/_/g'`
+    case $ac_user_opts in
+      *"
+"with_$ac_useropt"
+"*) ;;
+      *) ac_unrecognized_opts="$ac_unrecognized_opts$ac_unrecognized_sep--without-$ac_useropt_orig"
+	 ac_unrecognized_sep=', ';;
+    esac
+    eval with_$ac_useropt=no ;;
+
+  --x)
+    # Obsolete; use --with-x.
+    with_x=yes ;;
+
+  -x-includes | --x-includes | --x-include | --x-includ | --x-inclu \
+  | --x-incl | --x-inc | --x-in | --x-i)
+    ac_prev=x_includes ;;
+  -x-includes=* | --x-includes=* | --x-include=* | --x-includ=* | --x-inclu=* \
+  | --x-incl=* | --x-inc=* | --x-in=* | --x-i=*)
+    x_includes=$ac_optarg ;;
+
+  -x-libraries | --x-libraries | --x-librarie | --x-librari \
+  | --x-librar | --x-libra | --x-libr | --x-lib | --x-li | --x-l)
+    ac_prev=x_libraries ;;
+  -x-libraries=* | --x-libraries=* | --x-librarie=* | --x-librari=* \
+  | --x-librar=* | --x-libra=* | --x-libr=* | --x-lib=* | --x-li=* | --x-l=*)
+    x_libraries=$ac_optarg ;;
+
+  -*) as_fn_error $? "unrecognized option: \`$ac_option'
+Try \`$0 --help' for more information"
+    ;;
+
+  *=*)
+    ac_envvar=`expr "x$ac_option" : 'x\([^=]*\)='`
+    # Reject names that are not valid shell variable names.
+    case $ac_envvar in #(
+      '' | [0-9]* | *[!_$as_cr_alnum]* )
+      as_fn_error $? "invalid variable name: \`$ac_envvar'" ;;
+    esac
+    eval $ac_envvar=\$ac_optarg
+    export $ac_envvar ;;
+
+  *)
+    # FIXME: should be removed in autoconf 3.0.
+    $as_echo "$as_me: WARNING: you should use --build, --host, --target" >&2
+    expr "x$ac_option" : ".*[^-._$as_cr_alnum]" >/dev/null &&
+      $as_echo "$as_me: WARNING: invalid host type: $ac_option" >&2
+    : "${build_alias=$ac_option} ${host_alias=$ac_option} ${target_alias=$ac_option}"
+    ;;
+
+  esac
+done
+
+if test -n "$ac_prev"; then
+  ac_option=--`echo $ac_prev | sed 's/_/-/g'`
+  as_fn_error $? "missing argument to $ac_option"
+fi
+
+if test -n "$ac_unrecognized_opts"; then
+  case $enable_option_checking in
+    no) ;;
+    fatal) as_fn_error $? "unrecognized options: $ac_unrecognized_opts" ;;
+    *)     $as_echo "$as_me: WARNING: unrecognized options: $ac_unrecognized_opts" >&2 ;;
+  esac
+fi
+
+# Check all directory arguments for consistency.
+for ac_var in	exec_prefix prefix bindir sbindir libexecdir datarootdir \
+		datadir sysconfdir sharedstatedir localstatedir includedir \
+		oldincludedir docdir infodir htmldir dvidir pdfdir psdir \
+		libdir localedir mandir
+do
+  eval ac_val=\$$ac_var
+  # Remove trailing slashes.
+  case $ac_val in
+    */ )
+      ac_val=`expr "X$ac_val" : 'X\(.*[^/]\)' \| "X$ac_val" : 'X\(.*\)'`
+      eval $ac_var=\$ac_val;;
+  esac
+  # Be sure to have absolute directory names.
+  case $ac_val in
+    [\\/$]* | ?:[\\/]* )  continue;;
+    NONE | '' ) case $ac_var in *prefix ) continue;; esac;;
+  esac
+  as_fn_error $? "expected an absolute directory name for --$ac_var: $ac_val"
+done
+
+# There might be people who depend on the old broken behavior: `$host'
+# used to hold the argument of --host etc.
+# FIXME: To remove some day.
+build=$build_alias
+host=$host_alias
+target=$target_alias
+
+# FIXME: To remove some day.
+if test "x$host_alias" != x; then
+  if test "x$build_alias" = x; then
+    cross_compiling=maybe
+  elif test "x$build_alias" != "x$host_alias"; then
+    cross_compiling=yes
+  fi
+fi
+
+ac_tool_prefix=
+test -n "$host_alias" && ac_tool_prefix=$host_alias-
+
+test "$silent" = yes && exec 6>/dev/null
+
+
+ac_pwd=`pwd` && test -n "$ac_pwd" &&
+ac_ls_di=`ls -di .` &&
+ac_pwd_ls_di=`cd "$ac_pwd" && ls -di .` ||
+  as_fn_error $? "working directory cannot be determined"
+test "X$ac_ls_di" = "X$ac_pwd_ls_di" ||
+  as_fn_error $? "pwd does not report name of working directory"
+
+
+# Find the source files, if location was not specified.
+if test -z "$srcdir"; then
+  ac_srcdir_defaulted=yes
+  # Try the directory containing this script, then the parent directory.
+  ac_confdir=`$as_dirname -- "$as_myself" ||
+$as_expr X"$as_myself" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$as_myself" : 'X\(//\)[^/]' \| \
+	 X"$as_myself" : 'X\(//\)$' \| \
+	 X"$as_myself" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$as_myself" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+  srcdir=$ac_confdir
+  if test ! -r "$srcdir/$ac_unique_file"; then
+    srcdir=..
+  fi
+else
+  ac_srcdir_defaulted=no
+fi
+if test ! -r "$srcdir/$ac_unique_file"; then
+  test "$ac_srcdir_defaulted" = yes && srcdir="$ac_confdir or .."
+  as_fn_error $? "cannot find sources ($ac_unique_file) in $srcdir"
+fi
+ac_msg="sources are in $srcdir, but \`cd $srcdir' does not work"
+ac_abs_confdir=`(
+	cd "$srcdir" && test -r "./$ac_unique_file" || as_fn_error $? "$ac_msg"
+	pwd)`
+# When building in place, set srcdir=.
+if test "$ac_abs_confdir" = "$ac_pwd"; then
+  srcdir=.
+fi
+# Remove unnecessary trailing slashes from srcdir.
+# Double slashes in file names in object file debugging info
+# mess up M-x gdb in Emacs.
+case $srcdir in
+*/) srcdir=`expr "X$srcdir" : 'X\(.*[^/]\)' \| "X$srcdir" : 'X\(.*\)'`;;
+esac
+for ac_var in $ac_precious_vars; do
+  eval ac_env_${ac_var}_set=\${${ac_var}+set}
+  eval ac_env_${ac_var}_value=\$${ac_var}
+  eval ac_cv_env_${ac_var}_set=\${${ac_var}+set}
+  eval ac_cv_env_${ac_var}_value=\$${ac_var}
+done
+
+#
+# Report the --help message.
+#
+if test "$ac_init_help" = "long"; then
+  # Omit some internal or obsolete options to make the list less imposing.
+  # This message is too long to be a string in the A/UX 3.1 sh.
+  cat <<_ACEOF
+\`configure' configures stunnel 5.22 to adapt to many kinds of systems.
+
+Usage: $0 [OPTION]... [VAR=VALUE]...
+
+To assign environment variables (e.g., CC, CFLAGS...), specify them as
+VAR=VALUE.  See below for descriptions of some of the useful variables.
+
+Defaults for the options are specified in brackets.
+
+Configuration:
+  -h, --help              display this help and exit
+      --help=short        display options specific to this package
+      --help=recursive    display the short help of all the included packages
+  -V, --version           display version information and exit
+  -q, --quiet, --silent   do not print \`checking ...' messages
+      --cache-file=FILE   cache test results in FILE [disabled]
+  -C, --config-cache      alias for \`--cache-file=config.cache'
+  -n, --no-create         do not create output files
+      --srcdir=DIR        find the sources in DIR [configure dir or \`..']
+
+Installation directories:
+  --prefix=PREFIX         install architecture-independent files in PREFIX
+                          [$ac_default_prefix]
+  --exec-prefix=EPREFIX   install architecture-dependent files in EPREFIX
+                          [PREFIX]
+
+By default, \`make install' will install all the files in
+\`$ac_default_prefix/bin', \`$ac_default_prefix/lib' etc.  You can specify
+an installation prefix other than \`$ac_default_prefix' using \`--prefix',
+for instance \`--prefix=\$HOME'.
+
+For better control, use the options below.
+
+Fine tuning of the installation directories:
+  --bindir=DIR            user executables [EPREFIX/bin]
+  --sbindir=DIR           system admin executables [EPREFIX/sbin]
+  --libexecdir=DIR        program executables [EPREFIX/libexec]
+  --sysconfdir=DIR        read-only single-machine data [PREFIX/etc]
+  --sharedstatedir=DIR    modifiable architecture-independent data [PREFIX/com]
+  --localstatedir=DIR     modifiable single-machine data [PREFIX/var]
+  --libdir=DIR            object code libraries [EPREFIX/lib]
+  --includedir=DIR        C header files [PREFIX/include]
+  --oldincludedir=DIR     C header files for non-gcc [/usr/include]
+  --datarootdir=DIR       read-only arch.-independent data root [PREFIX/share]
+  --datadir=DIR           read-only architecture-independent data [DATAROOTDIR]
+  --infodir=DIR           info documentation [DATAROOTDIR/info]
+  --localedir=DIR         locale-dependent data [DATAROOTDIR/locale]
+  --mandir=DIR            man documentation [DATAROOTDIR/man]
+  --docdir=DIR            documentation root [DATAROOTDIR/doc/stunnel]
+  --htmldir=DIR           html documentation [DOCDIR]
+  --dvidir=DIR            dvi documentation [DOCDIR]
+  --pdfdir=DIR            pdf documentation [DOCDIR]
+  --psdir=DIR             ps documentation [DOCDIR]
+_ACEOF
+
+  cat <<\_ACEOF
+
+Program names:
+  --program-prefix=PREFIX            prepend PREFIX to installed program names
+  --program-suffix=SUFFIX            append SUFFIX to installed program names
+  --program-transform-name=PROGRAM   run sed PROGRAM on installed program names
+
+System types:
+  --build=BUILD     configure for building on BUILD [guessed]
+  --host=HOST       cross-compile to build programs to run on HOST [BUILD]
+_ACEOF
+fi
+
+if test -n "$ac_init_help"; then
+  case $ac_init_help in
+     short | recursive ) echo "Configuration of stunnel 5.22:";;
+   esac
+  cat <<\_ACEOF
+
+Optional Features:
+  --disable-option-checking  ignore unrecognized --enable/--with options
+  --disable-FEATURE       do not include FEATURE (same as --enable-FEATURE=no)
+  --enable-FEATURE[=ARG]  include FEATURE [ARG=yes]
+  --enable-silent-rules   less verbose build output (undo: "make V=1")
+  --disable-silent-rules  verbose build output (undo: "make V=0")
+  --enable-dependency-tracking
+                          do not reject slow dependency extractors
+  --disable-dependency-tracking
+                          speeds up one-time build
+  --enable-static[=PKGS]  build static libraries [default=no]
+  --enable-shared[=PKGS]  build shared libraries [default=yes]
+  --enable-fast-install[=PKGS]
+                          optimize for fast installation [default=yes]
+  --disable-libtool-lock  avoid locking (might break parallel builds)
+  --disable-ipv6          disable IPv6 support
+  --disable-fips          disable OpenSSL FIPS support
+  --disable-systemd       disable systemd socket activation support
+  --disable-libwrap       disable TCP wrappers support
+
+Optional Packages:
+  --with-PACKAGE[=ARG]    use PACKAGE [ARG=yes]
+  --without-PACKAGE       do not use PACKAGE (same as --with-PACKAGE=no)
+  --with-threads=model    select threading model (ucontext/pthread/fork)
+  --with-pic[=PKGS]       try to use only PIC/non-PIC objects [default=use
+                          both]
+  --with-gnu-ld           assume the C compiler uses GNU ld [default=no]
+  --with-sysroot=DIR Search for dependent libraries within DIR
+                        (or the compiler's sysroot if not specified).
+  --with-egd-socket=FILE  Entropy Gathering Daemon socket path
+  --with-random=FILE      read randomness from file (default=/dev/urandom)
+  --with-ssl=DIR          location of installed SSL libraries/include files
+
+Some influential environment variables:
+  CC          C compiler command
+  CFLAGS      C compiler flags
+  LDFLAGS     linker flags, e.g. -L<lib dir> if you have libraries in a
+              nonstandard directory <lib dir>
+  LIBS        libraries to pass to the linker, e.g. -l<library>
+  CPPFLAGS    (Objective) C/C++ preprocessor flags, e.g. -I<include dir> if
+              you have headers in a nonstandard directory <include dir>
+  CPP         C preprocessor
+
+Use these variables to override the choices made by `configure' or to help
+it to find libraries and programs with nonstandard names/locations.
+
+Report bugs to the package provider.
+_ACEOF
+ac_status=$?
+fi
+
+if test "$ac_init_help" = "recursive"; then
+  # If there are subdirs, report their specific --help.
+  for ac_dir in : $ac_subdirs_all; do test "x$ac_dir" = x: && continue
+    test -d "$ac_dir" ||
+      { cd "$srcdir" && ac_pwd=`pwd` && srcdir=. && test -d "$ac_dir"; } ||
+      continue
+    ac_builddir=.
+
+case "$ac_dir" in
+.) ac_dir_suffix= ac_top_builddir_sub=. ac_top_build_prefix= ;;
+*)
+  ac_dir_suffix=/`$as_echo "$ac_dir" | sed 's|^\.[\\/]||'`
+  # A ".." for each directory in $ac_dir_suffix.
+  ac_top_builddir_sub=`$as_echo "$ac_dir_suffix" | sed 's|/[^\\/]*|/..|g;s|/||'`
+  case $ac_top_builddir_sub in
+  "") ac_top_builddir_sub=. ac_top_build_prefix= ;;
+  *)  ac_top_build_prefix=$ac_top_builddir_sub/ ;;
+  esac ;;
+esac
+ac_abs_top_builddir=$ac_pwd
+ac_abs_builddir=$ac_pwd$ac_dir_suffix
+# for backward compatibility:
+ac_top_builddir=$ac_top_build_prefix
+
+case $srcdir in
+  .)  # We are building in place.
+    ac_srcdir=.
+    ac_top_srcdir=$ac_top_builddir_sub
+    ac_abs_top_srcdir=$ac_pwd ;;
+  [\\/]* | ?:[\\/]* )  # Absolute name.
+    ac_srcdir=$srcdir$ac_dir_suffix;
+    ac_top_srcdir=$srcdir
+    ac_abs_top_srcdir=$srcdir ;;
+  *) # Relative name.
+    ac_srcdir=$ac_top_build_prefix$srcdir$ac_dir_suffix
+    ac_top_srcdir=$ac_top_build_prefix$srcdir
+    ac_abs_top_srcdir=$ac_pwd/$srcdir ;;
+esac
+ac_abs_srcdir=$ac_abs_top_srcdir$ac_dir_suffix
+
+    cd "$ac_dir" || { ac_status=$?; continue; }
+    # Check for guested configure.
+    if test -f "$ac_srcdir/configure.gnu"; then
+      echo &&
+      $SHELL "$ac_srcdir/configure.gnu" --help=recursive
+    elif test -f "$ac_srcdir/configure"; then
+      echo &&
+      $SHELL "$ac_srcdir/configure" --help=recursive
+    else
+      $as_echo "$as_me: WARNING: no configuration information is in $ac_dir" >&2
+    fi || ac_status=$?
+    cd "$ac_pwd" || { ac_status=$?; break; }
+  done
+fi
+
+test -n "$ac_init_help" && exit $ac_status
+if $ac_init_version; then
+  cat <<\_ACEOF
+stunnel configure 5.22
+generated by GNU Autoconf 2.69
+
+Copyright (C) 2012 Free Software Foundation, Inc.
+This configure script is free software; the Free Software Foundation
+gives unlimited permission to copy, distribute and modify it.
+_ACEOF
+  exit
+fi
+
+## ------------------------ ##
+## Autoconf initialization. ##
+## ------------------------ ##
+
+# ac_fn_c_try_compile LINENO
+# --------------------------
+# Try to compile conftest.$ac_ext, and return whether this succeeded.
+ac_fn_c_try_compile ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  rm -f conftest.$ac_objext
+  if { { ac_try="$ac_compile"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_compile") 2>conftest.err
+  ac_status=$?
+  if test -s conftest.err; then
+    grep -v '^ *+' conftest.err >conftest.er1
+    cat conftest.er1 >&5
+    mv -f conftest.er1 conftest.err
+  fi
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && {
+	 test -z "$ac_c_werror_flag" ||
+	 test ! -s conftest.err
+       } && test -s conftest.$ac_objext; then :
+  ac_retval=0
+else
+  $as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+	ac_retval=1
+fi
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+  as_fn_set_status $ac_retval
+
+} # ac_fn_c_try_compile
+
+# ac_fn_c_try_link LINENO
+# -----------------------
+# Try to link conftest.$ac_ext, and return whether this succeeded.
+ac_fn_c_try_link ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  rm -f conftest.$ac_objext conftest$ac_exeext
+  if { { ac_try="$ac_link"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_link") 2>conftest.err
+  ac_status=$?
+  if test -s conftest.err; then
+    grep -v '^ *+' conftest.err >conftest.er1
+    cat conftest.er1 >&5
+    mv -f conftest.er1 conftest.err
+  fi
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && {
+	 test -z "$ac_c_werror_flag" ||
+	 test ! -s conftest.err
+       } && test -s conftest$ac_exeext && {
+	 test "$cross_compiling" = yes ||
+	 test -x conftest$ac_exeext
+       }; then :
+  ac_retval=0
+else
+  $as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+	ac_retval=1
+fi
+  # Delete the IPA/IPO (Inter Procedural Analysis/Optimization) information
+  # created by the PGI compiler (conftest_ipa8_conftest.oo), as it would
+  # interfere with the next link command; also delete a directory that is
+  # left behind by Apple's compiler.  We do this before executing the actions.
+  rm -rf conftest.dSYM conftest_ipa8_conftest.oo
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+  as_fn_set_status $ac_retval
+
+} # ac_fn_c_try_link
+
+# ac_fn_c_check_header_compile LINENO HEADER VAR INCLUDES
+# -------------------------------------------------------
+# Tests whether HEADER exists and can be compiled using the include files in
+# INCLUDES, setting the cache variable VAR accordingly.
+ac_fn_c_check_header_compile ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2" >&5
+$as_echo_n "checking for $2... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$4
+#include <$2>
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$3=yes"
+else
+  eval "$3=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_check_header_compile
+
+# ac_fn_c_try_cpp LINENO
+# ----------------------
+# Try to preprocess conftest.$ac_ext, and return whether this succeeded.
+ac_fn_c_try_cpp ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  if { { ac_try="$ac_cpp conftest.$ac_ext"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_cpp conftest.$ac_ext") 2>conftest.err
+  ac_status=$?
+  if test -s conftest.err; then
+    grep -v '^ *+' conftest.err >conftest.er1
+    cat conftest.er1 >&5
+    mv -f conftest.er1 conftest.err
+  fi
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } > conftest.i && {
+	 test -z "$ac_c_preproc_warn_flag$ac_c_werror_flag" ||
+	 test ! -s conftest.err
+       }; then :
+  ac_retval=0
+else
+  $as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+    ac_retval=1
+fi
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+  as_fn_set_status $ac_retval
+
+} # ac_fn_c_try_cpp
+
+# ac_fn_c_try_run LINENO
+# ----------------------
+# Try to link conftest.$ac_ext, and return whether this succeeded. Assumes
+# that executables *can* be run.
+ac_fn_c_try_run ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  if { { ac_try="$ac_link"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_link") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && { ac_try='./conftest$ac_exeext'
+  { { case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_try") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; }; then :
+  ac_retval=0
+else
+  $as_echo "$as_me: program exited with status $ac_status" >&5
+       $as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+       ac_retval=$ac_status
+fi
+  rm -rf conftest.dSYM conftest_ipa8_conftest.oo
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+  as_fn_set_status $ac_retval
+
+} # ac_fn_c_try_run
+
+# ac_fn_c_check_func LINENO FUNC VAR
+# ----------------------------------
+# Tests whether FUNC exists, setting the cache variable VAR accordingly
+ac_fn_c_check_func ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2" >&5
+$as_echo_n "checking for $2... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+/* Define $2 to an innocuous variant, in case <limits.h> declares $2.
+   For example, HP-UX 11i <limits.h> declares gettimeofday.  */
+#define $2 innocuous_$2
+
+/* System header to define __stub macros and hopefully few prototypes,
+    which can conflict with char $2 (); below.
+    Prefer <limits.h> to <assert.h> if __STDC__ is defined, since
+    <limits.h> exists even on freestanding compilers.  */
+
+#ifdef __STDC__
+# include <limits.h>
+#else
+# include <assert.h>
+#endif
+
+#undef $2
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char $2 ();
+/* The GNU C library defines this for functions which it implements
+    to always fail with ENOSYS.  Some functions are actually named
+    something starting with __ and the normal name is an alias.  */
+#if defined __stub_$2 || defined __stub___$2
+choke me
+#endif
+
+int
+main ()
+{
+return $2 ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  eval "$3=yes"
+else
+  eval "$3=no"
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_check_func
+
+# ac_fn_c_find_intX_t LINENO BITS VAR
+# -----------------------------------
+# Finds a signed integer type with width BITS, setting cache variable VAR
+# accordingly.
+ac_fn_c_find_intX_t ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for int$2_t" >&5
+$as_echo_n "checking for int$2_t... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  eval "$3=no"
+     # Order is important - never check a type that is potentially smaller
+     # than half of the expected target width.
+     for ac_type in int$2_t 'int' 'long int' \
+	 'long long int' 'short int' 'signed char'; do
+       cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$ac_includes_default
+	     enum { N = $2 / 2 - 1 };
+int
+main ()
+{
+static int test_array [1 - 2 * !(0 < ($ac_type) ((((($ac_type) 1 << N) << N) - 1) * 2 + 1))];
+test_array [0] = 0;
+return test_array [0];
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$ac_includes_default
+	        enum { N = $2 / 2 - 1 };
+int
+main ()
+{
+static int test_array [1 - 2 * !(($ac_type) ((((($ac_type) 1 << N) << N) - 1) * 2 + 1)
+		 < ($ac_type) ((((($ac_type) 1 << N) << N) - 1) * 2 + 2))];
+test_array [0] = 0;
+return test_array [0];
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+
+else
+  case $ac_type in #(
+  int$2_t) :
+    eval "$3=yes" ;; #(
+  *) :
+    eval "$3=\$ac_type" ;;
+esac
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+       if eval test \"x\$"$3"\" = x"no"; then :
+
+else
+  break
+fi
+     done
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_find_intX_t
+
+# ac_fn_c_find_uintX_t LINENO BITS VAR
+# ------------------------------------
+# Finds an unsigned integer type with width BITS, setting cache variable VAR
+# accordingly.
+ac_fn_c_find_uintX_t ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for uint$2_t" >&5
+$as_echo_n "checking for uint$2_t... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  eval "$3=no"
+     # Order is important - never check a type that is potentially smaller
+     # than half of the expected target width.
+     for ac_type in uint$2_t 'unsigned int' 'unsigned long int' \
+	 'unsigned long long int' 'unsigned short int' 'unsigned char'; do
+       cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$ac_includes_default
+int
+main ()
+{
+static int test_array [1 - 2 * !((($ac_type) -1 >> ($2 / 2 - 1)) >> ($2 / 2 - 1) == 3)];
+test_array [0] = 0;
+return test_array [0];
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  case $ac_type in #(
+  uint$2_t) :
+    eval "$3=yes" ;; #(
+  *) :
+    eval "$3=\$ac_type" ;;
+esac
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+       if eval test \"x\$"$3"\" = x"no"; then :
+
+else
+  break
+fi
+     done
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_find_uintX_t
+
+# ac_fn_c_check_type LINENO TYPE VAR INCLUDES
+# -------------------------------------------
+# Tests whether TYPE exists after having included INCLUDES, setting cache
+# variable VAR accordingly.
+ac_fn_c_check_type ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2" >&5
+$as_echo_n "checking for $2... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  eval "$3=no"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$4
+int
+main ()
+{
+if (sizeof ($2))
+	 return 0;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$4
+int
+main ()
+{
+if (sizeof (($2)))
+	    return 0;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+
+else
+  eval "$3=yes"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_check_type
+
+# ac_fn_c_check_header_mongrel LINENO HEADER VAR INCLUDES
+# -------------------------------------------------------
+# Tests whether HEADER exists, giving a warning if it cannot be compiled using
+# the include files in INCLUDES and setting the cache variable VAR
+# accordingly.
+ac_fn_c_check_header_mongrel ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  if eval \${$3+:} false; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2" >&5
+$as_echo_n "checking for $2... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+else
+  # Is the header compilable?
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking $2 usability" >&5
+$as_echo_n "checking $2 usability... " >&6; }
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$4
+#include <$2>
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  ac_header_compiler=yes
+else
+  ac_header_compiler=no
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_header_compiler" >&5
+$as_echo "$ac_header_compiler" >&6; }
+
+# Is the header present?
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking $2 presence" >&5
+$as_echo_n "checking $2 presence... " >&6; }
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <$2>
+_ACEOF
+if ac_fn_c_try_cpp "$LINENO"; then :
+  ac_header_preproc=yes
+else
+  ac_header_preproc=no
+fi
+rm -f conftest.err conftest.i conftest.$ac_ext
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_header_preproc" >&5
+$as_echo "$ac_header_preproc" >&6; }
+
+# So?  What about this header?
+case $ac_header_compiler:$ac_header_preproc:$ac_c_preproc_warn_flag in #((
+  yes:no: )
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2: accepted by the compiler, rejected by the preprocessor!" >&5
+$as_echo "$as_me: WARNING: $2: accepted by the compiler, rejected by the preprocessor!" >&2;}
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2: proceeding with the compiler's result" >&5
+$as_echo "$as_me: WARNING: $2: proceeding with the compiler's result" >&2;}
+    ;;
+  no:yes:* )
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2: present but cannot be compiled" >&5
+$as_echo "$as_me: WARNING: $2: present but cannot be compiled" >&2;}
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2:     check for missing prerequisite headers?" >&5
+$as_echo "$as_me: WARNING: $2:     check for missing prerequisite headers?" >&2;}
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2: see the Autoconf documentation" >&5
+$as_echo "$as_me: WARNING: $2: see the Autoconf documentation" >&2;}
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2:     section \"Present But Cannot Be Compiled\"" >&5
+$as_echo "$as_me: WARNING: $2:     section \"Present But Cannot Be Compiled\"" >&2;}
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $2: proceeding with the compiler's result" >&5
+$as_echo "$as_me: WARNING: $2: proceeding with the compiler's result" >&2;}
+    ;;
+esac
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2" >&5
+$as_echo_n "checking for $2... " >&6; }
+if eval \${$3+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  eval "$3=\$ac_header_compiler"
+fi
+eval ac_res=\$$3
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+fi
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_check_header_mongrel
+
+# ac_fn_c_check_member LINENO AGGR MEMBER VAR INCLUDES
+# ----------------------------------------------------
+# Tries to find if the field MEMBER exists in type AGGR, after including
+# INCLUDES, setting cache variable VAR accordingly.
+ac_fn_c_check_member ()
+{
+  as_lineno=${as_lineno-"$1"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for $2.$3" >&5
+$as_echo_n "checking for $2.$3... " >&6; }
+if eval \${$4+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$5
+int
+main ()
+{
+static $2 ac_aggr;
+if (ac_aggr.$3)
+return 0;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$4=yes"
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+$5
+int
+main ()
+{
+static $2 ac_aggr;
+if (sizeof ac_aggr.$3)
+return 0;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$4=yes"
+else
+  eval "$4=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+eval ac_res=\$$4
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+  eval $as_lineno_stack; ${as_lineno_stack:+:} unset as_lineno
+
+} # ac_fn_c_check_member
+cat >config.log <<_ACEOF
+This file contains any messages produced by compilers while
+running configure, to aid debugging if configure makes a mistake.
+
+It was created by stunnel $as_me 5.22, which was
+generated by GNU Autoconf 2.69.  Invocation command line was
+
+  $ $0 $@
+
+_ACEOF
+exec 5>>config.log
+{
+cat <<_ASUNAME
+## --------- ##
+## Platform. ##
+## --------- ##
+
+hostname = `(hostname || uname -n) 2>/dev/null | sed 1q`
+uname -m = `(uname -m) 2>/dev/null || echo unknown`
+uname -r = `(uname -r) 2>/dev/null || echo unknown`
+uname -s = `(uname -s) 2>/dev/null || echo unknown`
+uname -v = `(uname -v) 2>/dev/null || echo unknown`
+
+/usr/bin/uname -p = `(/usr/bin/uname -p) 2>/dev/null || echo unknown`
+/bin/uname -X     = `(/bin/uname -X) 2>/dev/null     || echo unknown`
+
+/bin/arch              = `(/bin/arch) 2>/dev/null              || echo unknown`
+/usr/bin/arch -k       = `(/usr/bin/arch -k) 2>/dev/null       || echo unknown`
+/usr/convex/getsysinfo = `(/usr/convex/getsysinfo) 2>/dev/null || echo unknown`
+/usr/bin/hostinfo      = `(/usr/bin/hostinfo) 2>/dev/null      || echo unknown`
+/bin/machine           = `(/bin/machine) 2>/dev/null           || echo unknown`
+/usr/bin/oslevel       = `(/usr/bin/oslevel) 2>/dev/null       || echo unknown`
+/bin/universe          = `(/bin/universe) 2>/dev/null          || echo unknown`
+
+_ASUNAME
+
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    $as_echo "PATH: $as_dir"
+  done
+IFS=$as_save_IFS
+
+} >&5
+
+cat >&5 <<_ACEOF
+
+
+## ----------- ##
+## Core tests. ##
+## ----------- ##
+
+_ACEOF
+
+
+# Keep a trace of the command line.
+# Strip out --no-create and --no-recursion so they do not pile up.
+# Strip out --silent because we don't want to record it for future runs.
+# Also quote any args containing shell meta-characters.
+# Make two passes to allow for proper duplicate-argument suppression.
+ac_configure_args=
+ac_configure_args0=
+ac_configure_args1=
+ac_must_keep_next=false
+for ac_pass in 1 2
+do
+  for ac_arg
+  do
+    case $ac_arg in
+    -no-create | --no-c* | -n | -no-recursion | --no-r*) continue ;;
+    -q | -quiet | --quiet | --quie | --qui | --qu | --q \
+    | -silent | --silent | --silen | --sile | --sil)
+      continue ;;
+    *\'*)
+      ac_arg=`$as_echo "$ac_arg" | sed "s/'/'\\\\\\\\''/g"` ;;
+    esac
+    case $ac_pass in
+    1) as_fn_append ac_configure_args0 " '$ac_arg'" ;;
+    2)
+      as_fn_append ac_configure_args1 " '$ac_arg'"
+      if test $ac_must_keep_next = true; then
+	ac_must_keep_next=false # Got value, back to normal.
+      else
+	case $ac_arg in
+	  *=* | --config-cache | -C | -disable-* | --disable-* \
+	  | -enable-* | --enable-* | -gas | --g* | -nfp | --nf* \
+	  | -q | -quiet | --q* | -silent | --sil* | -v | -verb* \
+	  | -with-* | --with-* | -without-* | --without-* | --x)
+	    case "$ac_configure_args0 " in
+	      "$ac_configure_args1"*" '$ac_arg' "* ) continue ;;
+	    esac
+	    ;;
+	  -* ) ac_must_keep_next=true ;;
+	esac
+      fi
+      as_fn_append ac_configure_args " '$ac_arg'"
+      ;;
+    esac
+  done
+done
+{ ac_configure_args0=; unset ac_configure_args0;}
+{ ac_configure_args1=; unset ac_configure_args1;}
+
+# When interrupted or exit'd, cleanup temporary files, and complete
+# config.log.  We remove comments because anyway the quotes in there
+# would cause problems or look ugly.
+# WARNING: Use '\'' to represent an apostrophe within the trap.
+# WARNING: Do not start the trap code with a newline, due to a FreeBSD 4.0 bug.
+trap 'exit_status=$?
+  # Save into config.log some information that might help in debugging.
+  {
+    echo
+
+    $as_echo "## ---------------- ##
+## Cache variables. ##
+## ---------------- ##"
+    echo
+    # The following way of writing the cache mishandles newlines in values,
+(
+  for ac_var in `(set) 2>&1 | sed -n '\''s/^\([a-zA-Z_][a-zA-Z0-9_]*\)=.*/\1/p'\''`; do
+    eval ac_val=\$$ac_var
+    case $ac_val in #(
+    *${as_nl}*)
+      case $ac_var in #(
+      *_cv_*) { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: cache variable $ac_var contains a newline" >&5
+$as_echo "$as_me: WARNING: cache variable $ac_var contains a newline" >&2;} ;;
+      esac
+      case $ac_var in #(
+      _ | IFS | as_nl) ;; #(
+      BASH_ARGV | BASH_SOURCE) eval $ac_var= ;; #(
+      *) { eval $ac_var=; unset $ac_var;} ;;
+      esac ;;
+    esac
+  done
+  (set) 2>&1 |
+    case $as_nl`(ac_space='\'' '\''; set) 2>&1` in #(
+    *${as_nl}ac_space=\ *)
+      sed -n \
+	"s/'\''/'\''\\\\'\'''\''/g;
+	  s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='\''\\2'\''/p"
+      ;; #(
+    *)
+      sed -n "/^[_$as_cr_alnum]*_cv_[_$as_cr_alnum]*=/p"
+      ;;
+    esac |
+    sort
+)
+    echo
+
+    $as_echo "## ----------------- ##
+## Output variables. ##
+## ----------------- ##"
+    echo
+    for ac_var in $ac_subst_vars
+    do
+      eval ac_val=\$$ac_var
+      case $ac_val in
+      *\'\''*) ac_val=`$as_echo "$ac_val" | sed "s/'\''/'\''\\\\\\\\'\'''\''/g"`;;
+      esac
+      $as_echo "$ac_var='\''$ac_val'\''"
+    done | sort
+    echo
+
+    if test -n "$ac_subst_files"; then
+      $as_echo "## ------------------- ##
+## File substitutions. ##
+## ------------------- ##"
+      echo
+      for ac_var in $ac_subst_files
+      do
+	eval ac_val=\$$ac_var
+	case $ac_val in
+	*\'\''*) ac_val=`$as_echo "$ac_val" | sed "s/'\''/'\''\\\\\\\\'\'''\''/g"`;;
+	esac
+	$as_echo "$ac_var='\''$ac_val'\''"
+      done | sort
+      echo
+    fi
+
+    if test -s confdefs.h; then
+      $as_echo "## ----------- ##
+## confdefs.h. ##
+## ----------- ##"
+      echo
+      cat confdefs.h
+      echo
+    fi
+    test "$ac_signal" != 0 &&
+      $as_echo "$as_me: caught signal $ac_signal"
+    $as_echo "$as_me: exit $exit_status"
+  } >&5
+  rm -f core *.core core.conftest.* &&
+    rm -f -r conftest* confdefs* conf$$* $ac_clean_files &&
+    exit $exit_status
+' 0
+for ac_signal in 1 2 13 15; do
+  trap 'ac_signal='$ac_signal'; as_fn_exit 1' $ac_signal
+done
+ac_signal=0
+
+# confdefs.h avoids OS command line length limits that DEFS can exceed.
+rm -f -r conftest* confdefs.h
+
+$as_echo "/* confdefs.h */" > confdefs.h
+
+# Predefined preprocessor variables.
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_NAME "$PACKAGE_NAME"
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_TARNAME "$PACKAGE_TARNAME"
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_VERSION "$PACKAGE_VERSION"
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_STRING "$PACKAGE_STRING"
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_BUGREPORT "$PACKAGE_BUGREPORT"
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE_URL "$PACKAGE_URL"
+_ACEOF
+
+
+# Let the site file select an alternate cache file if it wants to.
+# Prefer an explicitly selected file to automatically selected ones.
+ac_site_file1=NONE
+ac_site_file2=NONE
+if test -n "$CONFIG_SITE"; then
+  # We do not want a PATH search for config.site.
+  case $CONFIG_SITE in #((
+    -*)  ac_site_file1=./$CONFIG_SITE;;
+    */*) ac_site_file1=$CONFIG_SITE;;
+    *)   ac_site_file1=./$CONFIG_SITE;;
+  esac
+elif test "x$prefix" != xNONE; then
+  ac_site_file1=$prefix/share/config.site
+  ac_site_file2=$prefix/etc/config.site
+else
+  ac_site_file1=$ac_default_prefix/share/config.site
+  ac_site_file2=$ac_default_prefix/etc/config.site
+fi
+for ac_site_file in "$ac_site_file1" "$ac_site_file2"
+do
+  test "x$ac_site_file" = xNONE && continue
+  if test /dev/null != "$ac_site_file" && test -r "$ac_site_file"; then
+    { $as_echo "$as_me:${as_lineno-$LINENO}: loading site script $ac_site_file" >&5
+$as_echo "$as_me: loading site script $ac_site_file" >&6;}
+    sed 's/^/| /' "$ac_site_file" >&5
+    . "$ac_site_file" \
+      || { { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "failed to load site script $ac_site_file
+See \`config.log' for more details" "$LINENO" 5; }
+  fi
+done
+
+if test -r "$cache_file"; then
+  # Some versions of bash will fail to source /dev/null (special files
+  # actually), so we avoid doing that.  DJGPP emulates it as a regular file.
+  if test /dev/null != "$cache_file" && test -f "$cache_file"; then
+    { $as_echo "$as_me:${as_lineno-$LINENO}: loading cache $cache_file" >&5
+$as_echo "$as_me: loading cache $cache_file" >&6;}
+    case $cache_file in
+      [\\/]* | ?:[\\/]* ) . "$cache_file";;
+      *)                      . "./$cache_file";;
+    esac
+  fi
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: creating cache $cache_file" >&5
+$as_echo "$as_me: creating cache $cache_file" >&6;}
+  >$cache_file
+fi
+
+# Check that the precious variables saved in the cache have kept the same
+# value.
+ac_cache_corrupted=false
+for ac_var in $ac_precious_vars; do
+  eval ac_old_set=\$ac_cv_env_${ac_var}_set
+  eval ac_new_set=\$ac_env_${ac_var}_set
+  eval ac_old_val=\$ac_cv_env_${ac_var}_value
+  eval ac_new_val=\$ac_env_${ac_var}_value
+  case $ac_old_set,$ac_new_set in
+    set,)
+      { $as_echo "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&5
+$as_echo "$as_me: error: \`$ac_var' was set to \`$ac_old_val' in the previous run" >&2;}
+      ac_cache_corrupted=: ;;
+    ,set)
+      { $as_echo "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' was not set in the previous run" >&5
+$as_echo "$as_me: error: \`$ac_var' was not set in the previous run" >&2;}
+      ac_cache_corrupted=: ;;
+    ,);;
+    *)
+      if test "x$ac_old_val" != "x$ac_new_val"; then
+	# differences in whitespace do not lead to failure.
+	ac_old_val_w=`echo x $ac_old_val`
+	ac_new_val_w=`echo x $ac_new_val`
+	if test "$ac_old_val_w" != "$ac_new_val_w"; then
+	  { $as_echo "$as_me:${as_lineno-$LINENO}: error: \`$ac_var' has changed since the previous run:" >&5
+$as_echo "$as_me: error: \`$ac_var' has changed since the previous run:" >&2;}
+	  ac_cache_corrupted=:
+	else
+	  { $as_echo "$as_me:${as_lineno-$LINENO}: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&5
+$as_echo "$as_me: warning: ignoring whitespace changes in \`$ac_var' since the previous run:" >&2;}
+	  eval $ac_var=\$ac_old_val
+	fi
+	{ $as_echo "$as_me:${as_lineno-$LINENO}:   former value:  \`$ac_old_val'" >&5
+$as_echo "$as_me:   former value:  \`$ac_old_val'" >&2;}
+	{ $as_echo "$as_me:${as_lineno-$LINENO}:   current value: \`$ac_new_val'" >&5
+$as_echo "$as_me:   current value: \`$ac_new_val'" >&2;}
+      fi;;
+  esac
+  # Pass precious variables to config.status.
+  if test "$ac_new_set" = set; then
+    case $ac_new_val in
+    *\'*) ac_arg=$ac_var=`$as_echo "$ac_new_val" | sed "s/'/'\\\\\\\\''/g"` ;;
+    *) ac_arg=$ac_var=$ac_new_val ;;
+    esac
+    case " $ac_configure_args " in
+      *" '$ac_arg' "*) ;; # Avoid dups.  Use of quotes ensures accuracy.
+      *) as_fn_append ac_configure_args " '$ac_arg'" ;;
+    esac
+  fi
+done
+if $ac_cache_corrupted; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+  { $as_echo "$as_me:${as_lineno-$LINENO}: error: changes in the environment can compromise the build" >&5
+$as_echo "$as_me: error: changes in the environment can compromise the build" >&2;}
+  as_fn_error $? "run \`make distclean' and/or \`rm $cache_file' and start over" "$LINENO" 5
+fi
+## -------------------- ##
+## Main body of script. ##
+## -------------------- ##
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** initialization" >&5
+$as_echo "$as_me: **************************************** initialization" >&6;}
+ac_aux_dir=
+for ac_dir in auto "$srcdir"/auto; do
+  if test -f "$ac_dir/install-sh"; then
+    ac_aux_dir=$ac_dir
+    ac_install_sh="$ac_aux_dir/install-sh -c"
+    break
+  elif test -f "$ac_dir/install.sh"; then
+    ac_aux_dir=$ac_dir
+    ac_install_sh="$ac_aux_dir/install.sh -c"
+    break
+  elif test -f "$ac_dir/shtool"; then
+    ac_aux_dir=$ac_dir
+    ac_install_sh="$ac_aux_dir/shtool install -c"
+    break
+  fi
+done
+if test -z "$ac_aux_dir"; then
+  as_fn_error $? "cannot find install-sh, install.sh, or shtool in auto \"$srcdir\"/auto" "$LINENO" 5
+fi
+
+# These three variables are undocumented and unsupported,
+# and are intended to be withdrawn in a future Autoconf release.
+# They can cause serious problems if a builder's source tree is in a directory
+# whose full name contains unusual characters.
+ac_config_guess="$SHELL $ac_aux_dir/config.guess"  # Please don't use this var.
+ac_config_sub="$SHELL $ac_aux_dir/config.sub"  # Please don't use this var.
+ac_configure="$SHELL $ac_aux_dir/configure"  # Please don't use this var.
+
+
+
+ac_config_headers="$ac_config_headers src/config.h"
+
+
+am__api_version='1.14'
+
+# Find a good install program.  We prefer a C program (faster),
+# so one script is as good as another.  But avoid the broken or
+# incompatible versions:
+# SysV /etc/install, /usr/sbin/install
+# SunOS /usr/etc/install
+# IRIX /sbin/install
+# AIX /bin/install
+# AmigaOS /C/install, which installs bootblocks on floppy discs
+# AIX 4 /usr/bin/installbsd, which doesn't work without a -g flag
+# AFS /usr/afsws/bin/install, which mishandles nonexistent args
+# SVR4 /usr/ucb/install, which tries to use the nonexistent group "staff"
+# OS/2's system install, which has a completely different semantic
+# ./install, which can be erroneously created by make from ./install.sh.
+# Reject install programs that cannot install multiple files.
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for a BSD-compatible install" >&5
+$as_echo_n "checking for a BSD-compatible install... " >&6; }
+if test -z "$INSTALL"; then
+if ${ac_cv_path_install+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    # Account for people who put trailing slashes in PATH elements.
+case $as_dir/ in #((
+  ./ | .// | /[cC]/* | \
+  /etc/* | /usr/sbin/* | /usr/etc/* | /sbin/* | /usr/afsws/bin/* | \
+  ?:[\\/]os2[\\/]install[\\/]* | ?:[\\/]OS2[\\/]INSTALL[\\/]* | \
+  /usr/ucb/* ) ;;
+  *)
+    # OSF1 and SCO ODT 3.0 have their own names for install.
+    # Don't use installbsd from OSF since it installs stuff as root
+    # by default.
+    for ac_prog in ginstall scoinst install; do
+      for ac_exec_ext in '' $ac_executable_extensions; do
+	if as_fn_executable_p "$as_dir/$ac_prog$ac_exec_ext"; then
+	  if test $ac_prog = install &&
+	    grep dspmsg "$as_dir/$ac_prog$ac_exec_ext" >/dev/null 2>&1; then
+	    # AIX install.  It has an incompatible calling convention.
+	    :
+	  elif test $ac_prog = install &&
+	    grep pwplus "$as_dir/$ac_prog$ac_exec_ext" >/dev/null 2>&1; then
+	    # program-specific install script used by HP pwplus--don't use.
+	    :
+	  else
+	    rm -rf conftest.one conftest.two conftest.dir
+	    echo one > conftest.one
+	    echo two > conftest.two
+	    mkdir conftest.dir
+	    if "$as_dir/$ac_prog$ac_exec_ext" -c conftest.one conftest.two "`pwd`/conftest.dir" &&
+	      test -s conftest.one && test -s conftest.two &&
+	      test -s conftest.dir/conftest.one &&
+	      test -s conftest.dir/conftest.two
+	    then
+	      ac_cv_path_install="$as_dir/$ac_prog$ac_exec_ext -c"
+	      break 3
+	    fi
+	  fi
+	fi
+      done
+    done
+    ;;
+esac
+
+  done
+IFS=$as_save_IFS
+
+rm -rf conftest.one conftest.two conftest.dir
+
+fi
+  if test "${ac_cv_path_install+set}" = set; then
+    INSTALL=$ac_cv_path_install
+  else
+    # As a last resort, use the slow shell script.  Don't cache a
+    # value for INSTALL within a source directory, because that will
+    # break other packages using the cache if that directory is
+    # removed, or if the value is a relative name.
+    INSTALL=$ac_install_sh
+  fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $INSTALL" >&5
+$as_echo "$INSTALL" >&6; }
+
+# Use test -z because SunOS4 sh mishandles braces in ${var-val}.
+# It thinks the first close brace ends the variable substitution.
+test -z "$INSTALL_PROGRAM" && INSTALL_PROGRAM='${INSTALL}'
+
+test -z "$INSTALL_SCRIPT" && INSTALL_SCRIPT='${INSTALL}'
+
+test -z "$INSTALL_DATA" && INSTALL_DATA='${INSTALL} -m 644'
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether build environment is sane" >&5
+$as_echo_n "checking whether build environment is sane... " >&6; }
+# Reject unsafe characters in $srcdir or the absolute working directory
+# name.  Accept space and tab only in the latter.
+am_lf='
+'
+case `pwd` in
+  *[\\\"\#\$\&\'\`$am_lf]*)
+    as_fn_error $? "unsafe absolute working directory name" "$LINENO" 5;;
+esac
+case $srcdir in
+  *[\\\"\#\$\&\'\`$am_lf\ \	]*)
+    as_fn_error $? "unsafe srcdir value: '$srcdir'" "$LINENO" 5;;
+esac
+
+# Do 'set' in a subshell so we don't clobber the current shell's
+# arguments.  Must try -L first in case configure is actually a
+# symlink; some systems play weird games with the mod time of symlinks
+# (eg FreeBSD returns the mod time of the symlink's containing
+# directory).
+if (
+   am_has_slept=no
+   for am_try in 1 2; do
+     echo "timestamp, slept: $am_has_slept" > conftest.file
+     set X `ls -Lt "$srcdir/configure" conftest.file 2> /dev/null`
+     if test "$*" = "X"; then
+	# -L didn't work.
+	set X `ls -t "$srcdir/configure" conftest.file`
+     fi
+     if test "$*" != "X $srcdir/configure conftest.file" \
+	&& test "$*" != "X conftest.file $srcdir/configure"; then
+
+	# If neither matched, then we have a broken ls.  This can happen
+	# if, for instance, CONFIG_SHELL is bash and it inherits a
+	# broken ls alias from the environment.  This has actually
+	# happened.  Such a system could not be considered "sane".
+	as_fn_error $? "ls -t appears to fail.  Make sure there is not a broken
+  alias in your environment" "$LINENO" 5
+     fi
+     if test "$2" = conftest.file || test $am_try -eq 2; then
+       break
+     fi
+     # Just in case.
+     sleep 1
+     am_has_slept=yes
+   done
+   test "$2" = conftest.file
+   )
+then
+   # Ok.
+   :
+else
+   as_fn_error $? "newly created file is older than distributed files!
+Check your system clock" "$LINENO" 5
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+# If we didn't sleep, we still need to ensure time stamps of config.status and
+# generated files are strictly newer.
+am_sleep_pid=
+if grep 'slept: no' conftest.file >/dev/null 2>&1; then
+  ( sleep 1 ) &
+  am_sleep_pid=$!
+fi
+
+rm -f conftest.file
+
+test "$program_prefix" != NONE &&
+  program_transform_name="s&^&$program_prefix&;$program_transform_name"
+# Use a double $ so make ignores it.
+test "$program_suffix" != NONE &&
+  program_transform_name="s&\$&$program_suffix&;$program_transform_name"
+# Double any \ or $.
+# By default was `s,x,x', remove it if useless.
+ac_script='s/[\\$]/&&/g;s/;s,x,x,$//'
+program_transform_name=`$as_echo "$program_transform_name" | sed "$ac_script"`
+
+# Expand $ac_aux_dir to an absolute path.
+am_aux_dir=`cd "$ac_aux_dir" && pwd`
+
+if test x"${MISSING+set}" != xset; then
+  case $am_aux_dir in
+  *\ * | *\	*)
+    MISSING="\${SHELL} \"$am_aux_dir/missing\"" ;;
+  *)
+    MISSING="\${SHELL} $am_aux_dir/missing" ;;
+  esac
+fi
+# Use eval to expand $SHELL
+if eval "$MISSING --is-lightweight"; then
+  am_missing_run="$MISSING "
+else
+  am_missing_run=
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: 'missing' script is too old or missing" >&5
+$as_echo "$as_me: WARNING: 'missing' script is too old or missing" >&2;}
+fi
+
+if test x"${install_sh}" != xset; then
+  case $am_aux_dir in
+  *\ * | *\	*)
+    install_sh="\${SHELL} '$am_aux_dir/install-sh'" ;;
+  *)
+    install_sh="\${SHELL} $am_aux_dir/install-sh"
+  esac
+fi
+
+# Installed binaries are usually stripped using 'strip' when the user
+# run "make install-strip".  However 'strip' might not be the right
+# tool to use in cross-compilation environments, therefore Automake
+# will honor the 'STRIP' environment variable to overrule this program.
+if test "$cross_compiling" != no; then
+  if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}strip", so it can be a program name with args.
+set dummy ${ac_tool_prefix}strip; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_STRIP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$STRIP"; then
+  ac_cv_prog_STRIP="$STRIP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_STRIP="${ac_tool_prefix}strip"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+STRIP=$ac_cv_prog_STRIP
+if test -n "$STRIP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $STRIP" >&5
+$as_echo "$STRIP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_STRIP"; then
+  ac_ct_STRIP=$STRIP
+  # Extract the first word of "strip", so it can be a program name with args.
+set dummy strip; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_STRIP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_STRIP"; then
+  ac_cv_prog_ac_ct_STRIP="$ac_ct_STRIP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_STRIP="strip"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_STRIP=$ac_cv_prog_ac_ct_STRIP
+if test -n "$ac_ct_STRIP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_STRIP" >&5
+$as_echo "$ac_ct_STRIP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_STRIP" = x; then
+    STRIP=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    STRIP=$ac_ct_STRIP
+  fi
+else
+  STRIP="$ac_cv_prog_STRIP"
+fi
+
+fi
+INSTALL_STRIP_PROGRAM="\$(install_sh) -c -s"
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for a thread-safe mkdir -p" >&5
+$as_echo_n "checking for a thread-safe mkdir -p... " >&6; }
+if test -z "$MKDIR_P"; then
+  if ${ac_cv_path_mkdir+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH$PATH_SEPARATOR/opt/sfw/bin
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_prog in mkdir gmkdir; do
+	 for ac_exec_ext in '' $ac_executable_extensions; do
+	   as_fn_executable_p "$as_dir/$ac_prog$ac_exec_ext" || continue
+	   case `"$as_dir/$ac_prog$ac_exec_ext" --version 2>&1` in #(
+	     'mkdir (GNU coreutils) '* | \
+	     'mkdir (coreutils) '* | \
+	     'mkdir (fileutils) '4.1*)
+	       ac_cv_path_mkdir=$as_dir/$ac_prog$ac_exec_ext
+	       break 3;;
+	   esac
+	 done
+       done
+  done
+IFS=$as_save_IFS
+
+fi
+
+  test -d ./--version && rmdir ./--version
+  if test "${ac_cv_path_mkdir+set}" = set; then
+    MKDIR_P="$ac_cv_path_mkdir -p"
+  else
+    # As a last resort, use the slow shell script.  Don't cache a
+    # value for MKDIR_P within a source directory, because that will
+    # break other packages using the cache if that directory is
+    # removed, or if the value is a relative name.
+    MKDIR_P="$ac_install_sh -d"
+  fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $MKDIR_P" >&5
+$as_echo "$MKDIR_P" >&6; }
+
+for ac_prog in gawk mawk nawk awk
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_AWK+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$AWK"; then
+  ac_cv_prog_AWK="$AWK" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_AWK="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+AWK=$ac_cv_prog_AWK
+if test -n "$AWK"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $AWK" >&5
+$as_echo "$AWK" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$AWK" && break
+done
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether ${MAKE-make} sets \$(MAKE)" >&5
+$as_echo_n "checking whether ${MAKE-make} sets \$(MAKE)... " >&6; }
+set x ${MAKE-make}
+ac_make=`$as_echo "$2" | sed 's/+/p/g; s/[^a-zA-Z0-9_]/_/g'`
+if eval \${ac_cv_prog_make_${ac_make}_set+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat >conftest.make <<\_ACEOF
+SHELL = /bin/sh
+all:
+	@echo '@@@%%%=$(MAKE)=@@@%%%'
+_ACEOF
+# GNU make sometimes prints "make[1]: Entering ...", which would confuse us.
+case `${MAKE-make} -f conftest.make 2>/dev/null` in
+  *@@@%%%=?*=@@@%%%*)
+    eval ac_cv_prog_make_${ac_make}_set=yes;;
+  *)
+    eval ac_cv_prog_make_${ac_make}_set=no;;
+esac
+rm -f conftest.make
+fi
+if eval test \$ac_cv_prog_make_${ac_make}_set = yes; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+  SET_MAKE=
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+  SET_MAKE="MAKE=${MAKE-make}"
+fi
+
+rm -rf .tst 2>/dev/null
+mkdir .tst 2>/dev/null
+if test -d .tst; then
+  am__leading_dot=.
+else
+  am__leading_dot=_
+fi
+rmdir .tst 2>/dev/null
+
+# Check whether --enable-silent-rules was given.
+if test "${enable_silent_rules+set}" = set; then :
+  enableval=$enable_silent_rules;
+fi
+
+case $enable_silent_rules in # (((
+  yes) AM_DEFAULT_VERBOSITY=0;;
+   no) AM_DEFAULT_VERBOSITY=1;;
+    *) AM_DEFAULT_VERBOSITY=1;;
+esac
+am_make=${MAKE-make}
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether $am_make supports nested variables" >&5
+$as_echo_n "checking whether $am_make supports nested variables... " >&6; }
+if ${am_cv_make_support_nested_variables+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if $as_echo 'TRUE=$(BAR$(V))
+BAR0=false
+BAR1=true
+V=1
+am__doit:
+	@$(TRUE)
+.PHONY: am__doit' | $am_make -f - >/dev/null 2>&1; then
+  am_cv_make_support_nested_variables=yes
+else
+  am_cv_make_support_nested_variables=no
+fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $am_cv_make_support_nested_variables" >&5
+$as_echo "$am_cv_make_support_nested_variables" >&6; }
+if test $am_cv_make_support_nested_variables = yes; then
+    AM_V='$(V)'
+  AM_DEFAULT_V='$(AM_DEFAULT_VERBOSITY)'
+else
+  AM_V=$AM_DEFAULT_VERBOSITY
+  AM_DEFAULT_V=$AM_DEFAULT_VERBOSITY
+fi
+AM_BACKSLASH='\'
+
+if test "`cd $srcdir && pwd`" != "`pwd`"; then
+  # Use -I$(srcdir) only when $(srcdir) != ., so that make's output
+  # is not polluted with repeated "-I."
+  am__isrc=' -I$(srcdir)'
+  # test to see if srcdir already configured
+  if test -f $srcdir/config.status; then
+    as_fn_error $? "source directory already configured; run \"make distclean\" there first" "$LINENO" 5
+  fi
+fi
+
+# test whether we have cygpath
+if test -z "$CYGPATH_W"; then
+  if (cygpath --version) >/dev/null 2>/dev/null; then
+    CYGPATH_W='cygpath -w'
+  else
+    CYGPATH_W=echo
+  fi
+fi
+
+
+# Define the identity of the package.
+ PACKAGE='stunnel'
+ VERSION='5.22'
+
+
+cat >>confdefs.h <<_ACEOF
+#define PACKAGE "$PACKAGE"
+_ACEOF
+
+
+cat >>confdefs.h <<_ACEOF
+#define VERSION "$VERSION"
+_ACEOF
+
+# Some tools Automake needs.
+
+ACLOCAL=${ACLOCAL-"${am_missing_run}aclocal-${am__api_version}"}
+
+
+AUTOCONF=${AUTOCONF-"${am_missing_run}autoconf"}
+
+
+AUTOMAKE=${AUTOMAKE-"${am_missing_run}automake-${am__api_version}"}
+
+
+AUTOHEADER=${AUTOHEADER-"${am_missing_run}autoheader"}
+
+
+MAKEINFO=${MAKEINFO-"${am_missing_run}makeinfo"}
+
+# For better backward compatibility.  To be removed once Automake 1.9.x
+# dies out for good.  For more background, see:
+# <http://lists.gnu.org/archive/html/automake/2012-07/msg00001.html>
+# <http://lists.gnu.org/archive/html/automake/2012-07/msg00014.html>
+mkdir_p='$(MKDIR_P)'
+
+# We need awk for the "check" target.  The system "awk" is bad on
+# some platforms.
+# Always define AMTAR for backward compatibility.  Yes, it's still used
+# in the wild :-(  We should find a proper way to deprecate it ...
+AMTAR='$${TAR-tar}'
+
+
+# We'll loop over all known methods to create a tar archive until one works.
+_am_tools='gnutar  pax cpio none'
+
+am__tar='$${TAR-tar} chof - "$$tardir"' am__untar='$${TAR-tar} xf -'
+
+
+
+
+
+
+# POSIX will say in a future version that running "rm -f" with no argument
+# is OK; and we want to be able to make that assumption in our Makefile
+# recipes.  So use an aggressive probe to check that the usage we want is
+# actually supported "in the wild" to an acceptable degree.
+# See automake bug#10828.
+# To make any issue more visible, cause the running configure to be aborted
+# by default if the 'rm' program in use doesn't match our expectations; the
+# user can still override this though.
+if rm -f && rm -fr && rm -rf; then : OK; else
+  cat >&2 <<'END'
+Oops!
+
+Your 'rm' program seems unable to run without file operands specified
+on the command line, even when the '-f' option is present.  This is contrary
+to the behaviour of most rm programs out there, and not conforming with
+the upcoming POSIX standard: <http://austingroupbugs.net/view.php?id=542>
+
+Please tell bug-automake@gnu.org about your system, including the value
+of your $PATH and any error possibly output before this message.  This
+can help us improve future automake versions.
+
+END
+  if test x"$ACCEPT_INFERIOR_RM_PROGRAM" = x"yes"; then
+    echo 'Configuration will proceed anyway, since you have set the' >&2
+    echo 'ACCEPT_INFERIOR_RM_PROGRAM variable to "yes"' >&2
+    echo >&2
+  else
+    cat >&2 <<'END'
+Aborting the configuration process, to ensure you take notice of the issue.
+
+You can download and install GNU coreutils to get an 'rm' implementation
+that behaves properly: <http://www.gnu.org/software/coreutils/>.
+
+If you want to complete the configuration process using your problematic
+'rm' anyway, export the environment variable ACCEPT_INFERIOR_RM_PROGRAM
+to "yes", and re-run configure.
+
+END
+    as_fn_error $? "Your 'rm' program is bad, sorry." "$LINENO" 5
+  fi
+fi
+
+
+$as_echo "#define _GNU_SOURCE 1" >>confdefs.h
+
+
+ if test -d ".git"; then
+  AUTHOR_TESTS_TRUE=
+  AUTHOR_TESTS_FALSE='#'
+else
+  AUTHOR_TESTS_TRUE='#'
+  AUTHOR_TESTS_FALSE=
+fi
+
+# Make sure we can run config.sub.
+$SHELL "$ac_aux_dir/config.sub" sun4 >/dev/null 2>&1 ||
+  as_fn_error $? "cannot run $SHELL $ac_aux_dir/config.sub" "$LINENO" 5
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking build system type" >&5
+$as_echo_n "checking build system type... " >&6; }
+if ${ac_cv_build+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_build_alias=$build_alias
+test "x$ac_build_alias" = x &&
+  ac_build_alias=`$SHELL "$ac_aux_dir/config.guess"`
+test "x$ac_build_alias" = x &&
+  as_fn_error $? "cannot guess build type; you must specify one" "$LINENO" 5
+ac_cv_build=`$SHELL "$ac_aux_dir/config.sub" $ac_build_alias` ||
+  as_fn_error $? "$SHELL $ac_aux_dir/config.sub $ac_build_alias failed" "$LINENO" 5
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_build" >&5
+$as_echo "$ac_cv_build" >&6; }
+case $ac_cv_build in
+*-*-*) ;;
+*) as_fn_error $? "invalid value of canonical build" "$LINENO" 5;;
+esac
+build=$ac_cv_build
+ac_save_IFS=$IFS; IFS='-'
+set x $ac_cv_build
+shift
+build_cpu=$1
+build_vendor=$2
+shift; shift
+# Remember, the first character of IFS is used to create $*,
+# except with old shells:
+build_os=$*
+IFS=$ac_save_IFS
+case $build_os in *\ *) build_os=`echo "$build_os" | sed 's/ /-/g'`;; esac
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking host system type" >&5
+$as_echo_n "checking host system type... " >&6; }
+if ${ac_cv_host+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test "x$host_alias" = x; then
+  ac_cv_host=$ac_cv_build
+else
+  ac_cv_host=`$SHELL "$ac_aux_dir/config.sub" $host_alias` ||
+    as_fn_error $? "$SHELL $ac_aux_dir/config.sub $host_alias failed" "$LINENO" 5
+fi
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_host" >&5
+$as_echo "$ac_cv_host" >&6; }
+case $ac_cv_host in
+*-*-*) ;;
+*) as_fn_error $? "invalid value of canonical host" "$LINENO" 5;;
+esac
+host=$ac_cv_host
+ac_save_IFS=$IFS; IFS='-'
+set x $ac_cv_host
+shift
+host_cpu=$1
+host_vendor=$2
+shift; shift
+# Remember, the first character of IFS is used to create $*,
+# except with old shells:
+host_os=$*
+IFS=$ac_save_IFS
+case $host_os in *\ *) host_os=`echo "$host_os" | sed 's/ /-/g'`;; esac
+
+
+
+
+cat >>confdefs.h <<_ACEOF
+#define HOST "$host"
+_ACEOF
+
+
+cat >>confdefs.h <<_ACEOF
+#define `echo CPU_$host_cpu | tr abcdefghijklmnopqrstuvwxyz.- ABCDEFGHIJKLMNOPQRSTUVWXYZ__ | tr -dc ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890_` 1
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define `echo VENDOR_$host_vendor | tr abcdefghijklmnopqrstuvwxyz.- ABCDEFGHIJKLMNOPQRSTUVWXYZ__ | tr -dc ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890_` 1
+_ACEOF
+
+cat >>confdefs.h <<_ACEOF
+#define `echo OS_$host_os | tr abcdefghijklmnopqrstuvwxyz.- ABCDEFGHIJKLMNOPQRSTUVWXYZ__ | tr -dc ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890_` 1
+_ACEOF
+
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}gcc", so it can be a program name with args.
+set dummy ${ac_tool_prefix}gcc; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$CC"; then
+  ac_cv_prog_CC="$CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_CC="${ac_tool_prefix}gcc"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+CC=$ac_cv_prog_CC
+if test -n "$CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $CC" >&5
+$as_echo "$CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_CC"; then
+  ac_ct_CC=$CC
+  # Extract the first word of "gcc", so it can be a program name with args.
+set dummy gcc; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_CC"; then
+  ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_CC="gcc"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_CC=$ac_cv_prog_ac_ct_CC
+if test -n "$ac_ct_CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_CC" >&5
+$as_echo "$ac_ct_CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_CC" = x; then
+    CC=""
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    CC=$ac_ct_CC
+  fi
+else
+  CC="$ac_cv_prog_CC"
+fi
+
+if test -z "$CC"; then
+          if test -n "$ac_tool_prefix"; then
+    # Extract the first word of "${ac_tool_prefix}cc", so it can be a program name with args.
+set dummy ${ac_tool_prefix}cc; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$CC"; then
+  ac_cv_prog_CC="$CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_CC="${ac_tool_prefix}cc"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+CC=$ac_cv_prog_CC
+if test -n "$CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $CC" >&5
+$as_echo "$CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  fi
+fi
+if test -z "$CC"; then
+  # Extract the first word of "cc", so it can be a program name with args.
+set dummy cc; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$CC"; then
+  ac_cv_prog_CC="$CC" # Let the user override the test.
+else
+  ac_prog_rejected=no
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    if test "$as_dir/$ac_word$ac_exec_ext" = "/usr/ucb/cc"; then
+       ac_prog_rejected=yes
+       continue
+     fi
+    ac_cv_prog_CC="cc"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+if test $ac_prog_rejected = yes; then
+  # We found a bogon in the path, so make sure we never use it.
+  set dummy $ac_cv_prog_CC
+  shift
+  if test $# != 0; then
+    # We chose a different compiler from the bogus one.
+    # However, it has the same basename, so the bogon will be chosen
+    # first if we set CC to just the basename; use the full file name.
+    shift
+    ac_cv_prog_CC="$as_dir/$ac_word${1+' '}$@"
+  fi
+fi
+fi
+fi
+CC=$ac_cv_prog_CC
+if test -n "$CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $CC" >&5
+$as_echo "$CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$CC"; then
+  if test -n "$ac_tool_prefix"; then
+  for ac_prog in cl.exe
+  do
+    # Extract the first word of "$ac_tool_prefix$ac_prog", so it can be a program name with args.
+set dummy $ac_tool_prefix$ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$CC"; then
+  ac_cv_prog_CC="$CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_CC="$ac_tool_prefix$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+CC=$ac_cv_prog_CC
+if test -n "$CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $CC" >&5
+$as_echo "$CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+    test -n "$CC" && break
+  done
+fi
+if test -z "$CC"; then
+  ac_ct_CC=$CC
+  for ac_prog in cl.exe
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_CC"; then
+  ac_cv_prog_ac_ct_CC="$ac_ct_CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_CC="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_CC=$ac_cv_prog_ac_ct_CC
+if test -n "$ac_ct_CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_CC" >&5
+$as_echo "$ac_ct_CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$ac_ct_CC" && break
+done
+
+  if test "x$ac_ct_CC" = x; then
+    CC=""
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    CC=$ac_ct_CC
+  fi
+fi
+
+fi
+
+
+test -z "$CC" && { { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "no acceptable C compiler found in \$PATH
+See \`config.log' for more details" "$LINENO" 5; }
+
+# Provide some information about the compiler.
+$as_echo "$as_me:${as_lineno-$LINENO}: checking for C compiler version" >&5
+set X $ac_compile
+ac_compiler=$2
+for ac_option in --version -v -V -qversion; do
+  { { ac_try="$ac_compiler $ac_option >&5"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_compiler $ac_option >&5") 2>conftest.err
+  ac_status=$?
+  if test -s conftest.err; then
+    sed '10a\
+... rest of stderr output deleted ...
+         10q' conftest.err >conftest.er1
+    cat conftest.er1 >&5
+  fi
+  rm -f conftest.er1 conftest.err
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+done
+
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+ac_clean_files_save=$ac_clean_files
+ac_clean_files="$ac_clean_files a.out a.out.dSYM a.exe b.out"
+# Try to create an executable without -o first, disregard a.out.
+# It will help us diagnose broken compilers, and finding out an intuition
+# of exeext.
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the C compiler works" >&5
+$as_echo_n "checking whether the C compiler works... " >&6; }
+ac_link_default=`$as_echo "$ac_link" | sed 's/ -o *conftest[^ ]*//'`
+
+# The possible output files:
+ac_files="a.out conftest.exe conftest a.exe a_out.exe b.out conftest.*"
+
+ac_rmfiles=
+for ac_file in $ac_files
+do
+  case $ac_file in
+    *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.map | *.inf | *.dSYM | *.o | *.obj ) ;;
+    * ) ac_rmfiles="$ac_rmfiles $ac_file";;
+  esac
+done
+rm -f $ac_rmfiles
+
+if { { ac_try="$ac_link_default"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_link_default") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then :
+  # Autoconf-2.13 could set the ac_cv_exeext variable to `no'.
+# So ignore a value of `no', otherwise this would lead to `EXEEXT = no'
+# in a Makefile.  We should not override ac_cv_exeext if it was cached,
+# so that the user can short-circuit this test for compilers unknown to
+# Autoconf.
+for ac_file in $ac_files ''
+do
+  test -f "$ac_file" || continue
+  case $ac_file in
+    *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.map | *.inf | *.dSYM | *.o | *.obj )
+	;;
+    [ab].out )
+	# We found the default executable, but exeext='' is most
+	# certainly right.
+	break;;
+    *.* )
+	if test "${ac_cv_exeext+set}" = set && test "$ac_cv_exeext" != no;
+	then :; else
+	   ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'`
+	fi
+	# We set ac_cv_exeext here because the later test for it is not
+	# safe: cross compilers may not add the suffix if given an `-o'
+	# argument, so we may need to know it at that point already.
+	# Even if this section looks crufty: it has the advantage of
+	# actually working.
+	break;;
+    * )
+	break;;
+  esac
+done
+test "$ac_cv_exeext" = no && ac_cv_exeext=
+
+else
+  ac_file=''
+fi
+if test -z "$ac_file"; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+$as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+{ { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error 77 "C compiler cannot create executables
+See \`config.log' for more details" "$LINENO" 5; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for C compiler default output file name" >&5
+$as_echo_n "checking for C compiler default output file name... " >&6; }
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_file" >&5
+$as_echo "$ac_file" >&6; }
+ac_exeext=$ac_cv_exeext
+
+rm -f -r a.out a.out.dSYM a.exe conftest$ac_cv_exeext b.out
+ac_clean_files=$ac_clean_files_save
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for suffix of executables" >&5
+$as_echo_n "checking for suffix of executables... " >&6; }
+if { { ac_try="$ac_link"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_link") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then :
+  # If both `conftest.exe' and `conftest' are `present' (well, observable)
+# catch `conftest.exe'.  For instance with Cygwin, `ls conftest' will
+# work properly (i.e., refer to `conftest.exe'), while it won't with
+# `rm'.
+for ac_file in conftest.exe conftest conftest.*; do
+  test -f "$ac_file" || continue
+  case $ac_file in
+    *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.map | *.inf | *.dSYM | *.o | *.obj ) ;;
+    *.* ) ac_cv_exeext=`expr "$ac_file" : '[^.]*\(\..*\)'`
+	  break;;
+    * ) break;;
+  esac
+done
+else
+  { { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "cannot compute suffix of executables: cannot compile and link
+See \`config.log' for more details" "$LINENO" 5; }
+fi
+rm -f conftest conftest$ac_cv_exeext
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_exeext" >&5
+$as_echo "$ac_cv_exeext" >&6; }
+
+rm -f conftest.$ac_ext
+EXEEXT=$ac_cv_exeext
+ac_exeext=$EXEEXT
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <stdio.h>
+int
+main ()
+{
+FILE *f = fopen ("conftest.out", "w");
+ return ferror (f) || fclose (f) != 0;
+
+  ;
+  return 0;
+}
+_ACEOF
+ac_clean_files="$ac_clean_files conftest.out"
+# Check that the compiler produces executables we can run.  If not, either
+# the compiler is broken, or we cross compile.
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether we are cross compiling" >&5
+$as_echo_n "checking whether we are cross compiling... " >&6; }
+if test "$cross_compiling" != yes; then
+  { { ac_try="$ac_link"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_link") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+  if { ac_try='./conftest$ac_cv_exeext'
+  { { case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_try") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; }; then
+    cross_compiling=no
+  else
+    if test "$cross_compiling" = maybe; then
+	cross_compiling=yes
+    else
+	{ { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "cannot run C compiled programs.
+If you meant to cross compile, use \`--host'.
+See \`config.log' for more details" "$LINENO" 5; }
+    fi
+  fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $cross_compiling" >&5
+$as_echo "$cross_compiling" >&6; }
+
+rm -f conftest.$ac_ext conftest$ac_cv_exeext conftest.out
+ac_clean_files=$ac_clean_files_save
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for suffix of object files" >&5
+$as_echo_n "checking for suffix of object files... " >&6; }
+if ${ac_cv_objext+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+rm -f conftest.o conftest.obj
+if { { ac_try="$ac_compile"
+case "(($ac_try" in
+  *\"* | *\`* | *\\*) ac_try_echo=\$ac_try;;
+  *) ac_try_echo=$ac_try;;
+esac
+eval ac_try_echo="\"\$as_me:${as_lineno-$LINENO}: $ac_try_echo\""
+$as_echo "$ac_try_echo"; } >&5
+  (eval "$ac_compile") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then :
+  for ac_file in conftest.o conftest.obj conftest.*; do
+  test -f "$ac_file" || continue;
+  case $ac_file in
+    *.$ac_ext | *.xcoff | *.tds | *.d | *.pdb | *.xSYM | *.bb | *.bbg | *.map | *.inf | *.dSYM ) ;;
+    *) ac_cv_objext=`expr "$ac_file" : '.*\.\(.*\)'`
+       break;;
+  esac
+done
+else
+  $as_echo "$as_me: failed program was:" >&5
+sed 's/^/| /' conftest.$ac_ext >&5
+
+{ { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "cannot compute suffix of object files: cannot compile
+See \`config.log' for more details" "$LINENO" 5; }
+fi
+rm -f conftest.$ac_cv_objext conftest.$ac_ext
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_objext" >&5
+$as_echo "$ac_cv_objext" >&6; }
+OBJEXT=$ac_cv_objext
+ac_objext=$OBJEXT
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether we are using the GNU C compiler" >&5
+$as_echo_n "checking whether we are using the GNU C compiler... " >&6; }
+if ${ac_cv_c_compiler_gnu+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+#ifndef __GNUC__
+       choke me
+#endif
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  ac_compiler_gnu=yes
+else
+  ac_compiler_gnu=no
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+ac_cv_c_compiler_gnu=$ac_compiler_gnu
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_c_compiler_gnu" >&5
+$as_echo "$ac_cv_c_compiler_gnu" >&6; }
+if test $ac_compiler_gnu = yes; then
+  GCC=yes
+else
+  GCC=
+fi
+ac_test_CFLAGS=${CFLAGS+set}
+ac_save_CFLAGS=$CFLAGS
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether $CC accepts -g" >&5
+$as_echo_n "checking whether $CC accepts -g... " >&6; }
+if ${ac_cv_prog_cc_g+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_save_c_werror_flag=$ac_c_werror_flag
+   ac_c_werror_flag=yes
+   ac_cv_prog_cc_g=no
+   CFLAGS="-g"
+   cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  ac_cv_prog_cc_g=yes
+else
+  CFLAGS=""
+      cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+
+else
+  ac_c_werror_flag=$ac_save_c_werror_flag
+	 CFLAGS="-g"
+	 cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  ac_cv_prog_cc_g=yes
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+   ac_c_werror_flag=$ac_save_c_werror_flag
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_g" >&5
+$as_echo "$ac_cv_prog_cc_g" >&6; }
+if test "$ac_test_CFLAGS" = set; then
+  CFLAGS=$ac_save_CFLAGS
+elif test $ac_cv_prog_cc_g = yes; then
+  if test "$GCC" = yes; then
+    CFLAGS="-g -O2"
+  else
+    CFLAGS="-g"
+  fi
+else
+  if test "$GCC" = yes; then
+    CFLAGS="-O2"
+  else
+    CFLAGS=
+  fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $CC option to accept ISO C89" >&5
+$as_echo_n "checking for $CC option to accept ISO C89... " >&6; }
+if ${ac_cv_prog_cc_c89+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_cv_prog_cc_c89=no
+ac_save_CC=$CC
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <stdarg.h>
+#include <stdio.h>
+struct stat;
+/* Most of the following tests are stolen from RCS 5.7's src/conf.sh.  */
+struct buf { int x; };
+FILE * (*rcsopen) (struct buf *, struct stat *, int);
+static char *e (p, i)
+     char **p;
+     int i;
+{
+  return p[i];
+}
+static char *f (char * (*g) (char **, int), char **p, ...)
+{
+  char *s;
+  va_list v;
+  va_start (v,p);
+  s = g (p, va_arg (v,int));
+  va_end (v);
+  return s;
+}
+
+/* OSF 4.0 Compaq cc is some sort of almost-ANSI by default.  It has
+   function prototypes and stuff, but not '\xHH' hex character constants.
+   These don't provoke an error unfortunately, instead are silently treated
+   as 'x'.  The following induces an error, until -std is added to get
+   proper ANSI mode.  Curiously '\x00'!='x' always comes out true, for an
+   array size at least.  It's necessary to write '\x00'==0 to get something
+   that's true only with -std.  */
+int osf4_cc_array ['\x00' == 0 ? 1 : -1];
+
+/* IBM C 6 for AIX is almost-ANSI by default, but it replaces macro parameters
+   inside strings and character constants.  */
+#define FOO(x) 'x'
+int xlc6_cc_array[FOO(a) == 'x' ? 1 : -1];
+
+int test (int i, double x);
+struct s1 {int (*f) (int a);};
+struct s2 {int (*f) (double a);};
+int pairnames (int, char **, FILE *(*)(struct buf *, struct stat *, int), int, int);
+int argc;
+char **argv;
+int
+main ()
+{
+return f (e, argv, 0) != argv[0]  ||  f (e, argv, 1) != argv[1];
+  ;
+  return 0;
+}
+_ACEOF
+for ac_arg in '' -qlanglvl=extc89 -qlanglvl=ansi -std \
+	-Ae "-Aa -D_HPUX_SOURCE" "-Xc -D__EXTENSIONS__"
+do
+  CC="$ac_save_CC $ac_arg"
+  if ac_fn_c_try_compile "$LINENO"; then :
+  ac_cv_prog_cc_c89=$ac_arg
+fi
+rm -f core conftest.err conftest.$ac_objext
+  test "x$ac_cv_prog_cc_c89" != "xno" && break
+done
+rm -f conftest.$ac_ext
+CC=$ac_save_CC
+
+fi
+# AC_CACHE_VAL
+case "x$ac_cv_prog_cc_c89" in
+  x)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: none needed" >&5
+$as_echo "none needed" >&6; } ;;
+  xno)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: unsupported" >&5
+$as_echo "unsupported" >&6; } ;;
+  *)
+    CC="$CC $ac_cv_prog_cc_c89"
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_prog_cc_c89" >&5
+$as_echo "$ac_cv_prog_cc_c89" >&6; } ;;
+esac
+if test "x$ac_cv_prog_cc_c89" != xno; then :
+
+fi
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether $CC understands -c and -o together" >&5
+$as_echo_n "checking whether $CC understands -c and -o together... " >&6; }
+if ${am_cv_prog_cc_c_o+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+  # Make sure it works both with $CC and with simple cc.
+  # Following AC_PROG_CC_C_O, we do the test twice because some
+  # compilers refuse to overwrite an existing .o file with -o,
+  # though they will create one.
+  am_cv_prog_cc_c_o=yes
+  for am_i in 1 2; do
+    if { echo "$as_me:$LINENO: $CC -c conftest.$ac_ext -o conftest2.$ac_objext" >&5
+   ($CC -c conftest.$ac_ext -o conftest2.$ac_objext) >&5 2>&5
+   ac_status=$?
+   echo "$as_me:$LINENO: \$? = $ac_status" >&5
+   (exit $ac_status); } \
+         && test -f conftest2.$ac_objext; then
+      : OK
+    else
+      am_cv_prog_cc_c_o=no
+      break
+    fi
+  done
+  rm -f core conftest*
+  unset am_i
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $am_cv_prog_cc_c_o" >&5
+$as_echo "$am_cv_prog_cc_c_o" >&6; }
+if test "$am_cv_prog_cc_c_o" != yes; then
+   # Losing compiler, so override with the script.
+   # FIXME: It is wrong to rewrite CC.
+   # But if we don't then we get into trouble of one sort or another.
+   # A longer-term fix would be to have automake use am__CC in this case,
+   # and then we could set am__CC="\$(top_srcdir)/compile \$(CC)"
+   CC="$am_aux_dir/compile $CC"
+fi
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+DEPDIR="${am__leading_dot}deps"
+
+ac_config_commands="$ac_config_commands depfiles"
+
+
+am_make=${MAKE-make}
+cat > confinc << 'END'
+am__doit:
+	@echo this is the am__doit target
+.PHONY: am__doit
+END
+# If we don't find an include directive, just comment out the code.
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for style of include used by $am_make" >&5
+$as_echo_n "checking for style of include used by $am_make... " >&6; }
+am__include="#"
+am__quote=
+_am_result=none
+# First try GNU make style include.
+echo "include confinc" > confmf
+# Ignore all kinds of additional output from 'make'.
+case `$am_make -s -f confmf 2> /dev/null` in #(
+*the\ am__doit\ target*)
+  am__include=include
+  am__quote=
+  _am_result=GNU
+  ;;
+esac
+# Now try BSD make style include.
+if test "$am__include" = "#"; then
+   echo '.include "confinc"' > confmf
+   case `$am_make -s -f confmf 2> /dev/null` in #(
+   *the\ am__doit\ target*)
+     am__include=.include
+     am__quote="\""
+     _am_result=BSD
+     ;;
+   esac
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $_am_result" >&5
+$as_echo "$_am_result" >&6; }
+rm -f confinc confmf
+
+# Check whether --enable-dependency-tracking was given.
+if test "${enable_dependency_tracking+set}" = set; then :
+  enableval=$enable_dependency_tracking;
+fi
+
+if test "x$enable_dependency_tracking" != xno; then
+  am_depcomp="$ac_aux_dir/depcomp"
+  AMDEPBACKSLASH='\'
+  am__nodep='_no'
+fi
+ if test "x$enable_dependency_tracking" != xno; then
+  AMDEP_TRUE=
+  AMDEP_FALSE='#'
+else
+  AMDEP_TRUE='#'
+  AMDEP_FALSE=
+fi
+
+
+
+depcc="$CC"   am_compiler_list=
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking dependency style of $depcc" >&5
+$as_echo_n "checking dependency style of $depcc... " >&6; }
+if ${am_cv_CC_dependencies_compiler_type+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -z "$AMDEP_TRUE" && test -f "$am_depcomp"; then
+  # We make a subdir and do the tests there.  Otherwise we can end up
+  # making bogus files that we don't know about and never remove.  For
+  # instance it was reported that on HP-UX the gcc test will end up
+  # making a dummy file named 'D' -- because '-MD' means "put the output
+  # in D".
+  rm -rf conftest.dir
+  mkdir conftest.dir
+  # Copy depcomp to subdir because otherwise we won't find it if we're
+  # using a relative directory.
+  cp "$am_depcomp" conftest.dir
+  cd conftest.dir
+  # We will build objects and dependencies in a subdirectory because
+  # it helps to detect inapplicable dependency modes.  For instance
+  # both Tru64's cc and ICC support -MD to output dependencies as a
+  # side effect of compilation, but ICC will put the dependencies in
+  # the current directory while Tru64 will put them in the object
+  # directory.
+  mkdir sub
+
+  am_cv_CC_dependencies_compiler_type=none
+  if test "$am_compiler_list" = ""; then
+     am_compiler_list=`sed -n 's/^#*\([a-zA-Z0-9]*\))$/\1/p' < ./depcomp`
+  fi
+  am__universal=false
+  case " $depcc " in #(
+     *\ -arch\ *\ -arch\ *) am__universal=true ;;
+     esac
+
+  for depmode in $am_compiler_list; do
+    # Setup a source with many dependencies, because some compilers
+    # like to wrap large dependency lists on column 80 (with \), and
+    # we should not choose a depcomp mode which is confused by this.
+    #
+    # We need to recreate these files for each test, as the compiler may
+    # overwrite some of them when testing with obscure command lines.
+    # This happens at least with the AIX C compiler.
+    : > sub/conftest.c
+    for i in 1 2 3 4 5 6; do
+      echo '#include "conftst'$i'.h"' >> sub/conftest.c
+      # Using ": > sub/conftst$i.h" creates only sub/conftst1.h with
+      # Solaris 10 /bin/sh.
+      echo '/* dummy */' > sub/conftst$i.h
+    done
+    echo "${am__include} ${am__quote}sub/conftest.Po${am__quote}" > confmf
+
+    # We check with '-c' and '-o' for the sake of the "dashmstdout"
+    # mode.  It turns out that the SunPro C++ compiler does not properly
+    # handle '-M -o', and we need to detect this.  Also, some Intel
+    # versions had trouble with output in subdirs.
+    am__obj=sub/conftest.${OBJEXT-o}
+    am__minus_obj="-o $am__obj"
+    case $depmode in
+    gcc)
+      # This depmode causes a compiler race in universal mode.
+      test "$am__universal" = false || continue
+      ;;
+    nosideeffect)
+      # After this tag, mechanisms are not by side-effect, so they'll
+      # only be used when explicitly requested.
+      if test "x$enable_dependency_tracking" = xyes; then
+	continue
+      else
+	break
+      fi
+      ;;
+    msvc7 | msvc7msys | msvisualcpp | msvcmsys)
+      # This compiler won't grok '-c -o', but also, the minuso test has
+      # not run yet.  These depmodes are late enough in the game, and
+      # so weak that their functioning should not be impacted.
+      am__obj=conftest.${OBJEXT-o}
+      am__minus_obj=
+      ;;
+    none) break ;;
+    esac
+    if depmode=$depmode \
+       source=sub/conftest.c object=$am__obj \
+       depfile=sub/conftest.Po tmpdepfile=sub/conftest.TPo \
+       $SHELL ./depcomp $depcc -c $am__minus_obj sub/conftest.c \
+         >/dev/null 2>conftest.err &&
+       grep sub/conftst1.h sub/conftest.Po > /dev/null 2>&1 &&
+       grep sub/conftst6.h sub/conftest.Po > /dev/null 2>&1 &&
+       grep $am__obj sub/conftest.Po > /dev/null 2>&1 &&
+       ${MAKE-make} -s -f confmf > /dev/null 2>&1; then
+      # icc doesn't choke on unknown options, it will just issue warnings
+      # or remarks (even with -Werror).  So we grep stderr for any message
+      # that says an option was ignored or not supported.
+      # When given -MP, icc 7.0 and 7.1 complain thusly:
+      #   icc: Command line warning: ignoring option '-M'; no argument required
+      # The diagnosis changed in icc 8.0:
+      #   icc: Command line remark: option '-MP' not supported
+      if (grep 'ignoring option' conftest.err ||
+          grep 'not supported' conftest.err) >/dev/null 2>&1; then :; else
+        am_cv_CC_dependencies_compiler_type=$depmode
+        break
+      fi
+    fi
+  done
+
+  cd ..
+  rm -rf conftest.dir
+else
+  am_cv_CC_dependencies_compiler_type=none
+fi
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $am_cv_CC_dependencies_compiler_type" >&5
+$as_echo "$am_cv_CC_dependencies_compiler_type" >&6; }
+CCDEPMODE=depmode=$am_cv_CC_dependencies_compiler_type
+
+ if
+  test "x$enable_dependency_tracking" != xno \
+  && test "$am_cv_CC_dependencies_compiler_type" = gcc3; then
+  am__fastdepCC_TRUE=
+  am__fastdepCC_FALSE='#'
+else
+  am__fastdepCC_TRUE='#'
+  am__fastdepCC_FALSE=
+fi
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether ${MAKE-make} sets \$(MAKE)" >&5
+$as_echo_n "checking whether ${MAKE-make} sets \$(MAKE)... " >&6; }
+set x ${MAKE-make}
+ac_make=`$as_echo "$2" | sed 's/+/p/g; s/[^a-zA-Z0-9_]/_/g'`
+if eval \${ac_cv_prog_make_${ac_make}_set+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat >conftest.make <<\_ACEOF
+SHELL = /bin/sh
+all:
+	@echo '@@@%%%=$(MAKE)=@@@%%%'
+_ACEOF
+# GNU make sometimes prints "make[1]: Entering ...", which would confuse us.
+case `${MAKE-make} -f conftest.make 2>/dev/null` in
+  *@@@%%%=?*=@@@%%%*)
+    eval ac_cv_prog_make_${ac_make}_set=yes;;
+  *)
+    eval ac_cv_prog_make_${ac_make}_set=no;;
+esac
+rm -f conftest.make
+fi
+if eval test \$ac_cv_prog_make_${ac_make}_set = yes; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+  SET_MAKE=
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+  SET_MAKE="MAKE=${MAKE-make}"
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** thread model" >&5
+$as_echo "$as_me: **************************************** thread model" >&6;}
+# thread detection should be done first, as it may change the CC variable
+
+
+
+# Check whether --with-threads was given.
+if test "${with_threads+set}" = set; then :
+  withval=$with_threads;
+    case "$withval" in
+        ucontext)
+            { $as_echo "$as_me:${as_lineno-$LINENO}: UCONTEXT mode selected" >&5
+$as_echo "$as_me: UCONTEXT mode selected" >&6;}
+
+$as_echo "#define USE_UCONTEXT 1" >>confdefs.h
+
+            ;;
+        pthread)
+            { $as_echo "$as_me:${as_lineno-$LINENO}: PTHREAD mode selected" >&5
+$as_echo "$as_me: PTHREAD mode selected" >&6;}
+
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+ax_pthread_ok=no
+
+# We used to check for pthread.h first, but this fails if pthread.h
+# requires special compiler flags (e.g. on True64 or Sequent).
+# It gets checked for in the link test anyway.
+
+# First of all, check if the user has set any of the PTHREAD_LIBS,
+# etcetera environment variables, and if threads linking works using
+# them:
+if test x"$PTHREAD_LIBS$PTHREAD_CFLAGS" != x; then
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS" >&5
+$as_echo_n "checking for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS... " >&6; }
+        cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char pthread_join ();
+int
+main ()
+{
+return pthread_join ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_pthread_ok=yes
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_ok" >&5
+$as_echo "$ax_pthread_ok" >&6; }
+        if test x"$ax_pthread_ok" = xno; then
+                PTHREAD_LIBS=""
+                PTHREAD_CFLAGS=""
+        fi
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+fi
+
+# We must check for the threads library under a number of different
+# names; the ordering is very important because some systems
+# (e.g. DEC) have both -lpthread and -lpthreads, where one of the
+# libraries is broken (non-POSIX).
+
+# Create a list of thread flags to try.  Items starting with a "-" are
+# C compiler flags, and other items are library names, except for "none"
+# which indicates that we try without any flags at all, and "pthread-config"
+# which is a program returning the flags for the Pth emulation library.
+
+ax_pthread_flags="pthreads none -Kthread -kthread lthread -pthread -pthreads -mthreads pthread --thread-safe -mt pthread-config"
+
+# The ordering *is* (sometimes) important.  Some notes on the
+# individual items follow:
+
+# pthreads: AIX (must check this before -lpthread)
+# none: in case threads are in libc; should be tried before -Kthread and
+#       other compiler flags to prevent continual compiler warnings
+# -Kthread: Sequent (threads in libc, but -Kthread needed for pthread.h)
+# -kthread: FreeBSD kernel threads (preferred to -pthread since SMP-able)
+# lthread: LinuxThreads port on FreeBSD (also preferred to -pthread)
+# -pthread: Linux/gcc (kernel threads), BSD/gcc (userland threads)
+# -pthreads: Solaris/gcc
+# -mthreads: Mingw32/gcc, Lynx/gcc
+# -mt: Sun Workshop C (may only link SunOS threads [-lthread], but it
+#      doesn't hurt to check since this sometimes defines pthreads too;
+#      also defines -D_REENTRANT)
+#      ... -mt is also the pthreads flag for HP/aCC
+# pthread: Linux, etcetera
+# --thread-safe: KAI C++
+# pthread-config: use pthread-config program (for GNU Pth library)
+
+case ${host_os} in
+        solaris*)
+
+        # On Solaris (at least, for some versions), libc contains stubbed
+        # (non-functional) versions of the pthreads routines, so link-based
+        # tests will erroneously succeed.  (We need to link with -pthreads/-mt/
+        # -lpthread.)  (The stubs are missing pthread_cleanup_push, or rather
+        # a function called by this macro, so we could check for that, but
+        # who knows whether they'll stub that too in a future libc.)  So,
+        # we'll just look for -pthreads and -lpthread first:
+
+        ax_pthread_flags="-pthreads pthread -mt -pthread $ax_pthread_flags"
+        ;;
+
+        darwin*)
+        ax_pthread_flags="-pthread $ax_pthread_flags"
+        ;;
+esac
+
+# Clang doesn't consider unrecognized options an error unless we specify
+# -Werror. We throw in some extra Clang-specific options to ensure that
+# this doesn't happen for GCC, which also accepts -Werror.
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if compiler needs -Werror to reject unknown flags" >&5
+$as_echo_n "checking if compiler needs -Werror to reject unknown flags... " >&6; }
+save_CFLAGS="$CFLAGS"
+ax_pthread_extra_flags="-Werror"
+CFLAGS="$CFLAGS $ax_pthread_extra_flags -Wunknown-warning-option -Wsizeof-array-argument"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+int foo(void);
+int
+main ()
+{
+foo()
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+else
+  ax_pthread_extra_flags=
+                   { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+CFLAGS="$save_CFLAGS"
+
+if test x"$ax_pthread_ok" = xno; then
+for flag in $ax_pthread_flags; do
+
+        case $flag in
+                none)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether pthreads work without any flags" >&5
+$as_echo_n "checking whether pthreads work without any flags... " >&6; }
+                ;;
+
+                -*)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether pthreads work with $flag" >&5
+$as_echo_n "checking whether pthreads work with $flag... " >&6; }
+                PTHREAD_CFLAGS="$flag"
+                ;;
+
+                pthread-config)
+                # Extract the first word of "pthread-config", so it can be a program name with args.
+set dummy pthread-config; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ax_pthread_config+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ax_pthread_config"; then
+  ac_cv_prog_ax_pthread_config="$ax_pthread_config" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ax_pthread_config="yes"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+  test -z "$ac_cv_prog_ax_pthread_config" && ac_cv_prog_ax_pthread_config="no"
+fi
+fi
+ax_pthread_config=$ac_cv_prog_ax_pthread_config
+if test -n "$ax_pthread_config"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_config" >&5
+$as_echo "$ax_pthread_config" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+                if test x"$ax_pthread_config" = xno; then continue; fi
+                PTHREAD_CFLAGS="`pthread-config --cflags`"
+                PTHREAD_LIBS="`pthread-config --ldflags` `pthread-config --libs`"
+                ;;
+
+                *)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking for the pthreads library -l$flag" >&5
+$as_echo_n "checking for the pthreads library -l$flag... " >&6; }
+                PTHREAD_LIBS="-l$flag"
+                ;;
+        esac
+
+        save_LIBS="$LIBS"
+        save_CFLAGS="$CFLAGS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS $ax_pthread_extra_flags"
+
+        # Check for various functions.  We must include pthread.h,
+        # since some functions may be macros.  (On the Sequent, we
+        # need a special flag -Kthread to make this header compile.)
+        # We check for pthread_join because it is in -lpthread on IRIX
+        # while pthread_create is in libc.  We check for pthread_attr_init
+        # due to DEC craziness with -lpthreads.  We check for
+        # pthread_cleanup_push because it is one of the few pthread
+        # functions on Solaris that doesn't have a non-functional libc stub.
+        # We try pthread_create on general principles.
+        cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+                        static void routine(void *a) { a = 0; }
+                        static void *start_routine(void *a) { return a; }
+int
+main ()
+{
+pthread_t th; pthread_attr_t attr;
+                        pthread_create(&th, 0, start_routine, 0);
+                        pthread_join(th, 0);
+                        pthread_attr_init(&attr);
+                        pthread_cleanup_push(routine, 0);
+                        pthread_cleanup_pop(0) /* ; */
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_pthread_ok=yes
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_ok" >&5
+$as_echo "$ax_pthread_ok" >&6; }
+        if test "x$ax_pthread_ok" = xyes; then
+                break;
+        fi
+
+        PTHREAD_LIBS=""
+        PTHREAD_CFLAGS=""
+done
+fi
+
+# Various other checks:
+if test "x$ax_pthread_ok" = xyes; then
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+
+        # Detect AIX lossage: JOINABLE attribute is called UNDETACHED.
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for joinable pthread attribute" >&5
+$as_echo_n "checking for joinable pthread attribute... " >&6; }
+        attr_name=unknown
+        for attr in PTHREAD_CREATE_JOINABLE PTHREAD_CREATE_UNDETACHED; do
+            cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+int
+main ()
+{
+int attr = $attr; return attr /* ; */
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  attr_name=$attr; break
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+        done
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $attr_name" >&5
+$as_echo "$attr_name" >&6; }
+        if test "$attr_name" != PTHREAD_CREATE_JOINABLE; then
+
+cat >>confdefs.h <<_ACEOF
+#define PTHREAD_CREATE_JOINABLE $attr_name
+_ACEOF
+
+        fi
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking if more special flags are required for pthreads" >&5
+$as_echo_n "checking if more special flags are required for pthreads... " >&6; }
+        flag=no
+        case ${host_os} in
+            aix* | freebsd* | darwin*) flag="-D_THREAD_SAFE";;
+            osf* | hpux*) flag="-D_REENTRANT";;
+            solaris*)
+            if test "$GCC" = "yes"; then
+                flag="-D_REENTRANT"
+            else
+                # TODO: What about Clang on Solaris?
+                flag="-mt -D_REENTRANT"
+            fi
+            ;;
+        esac
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $flag" >&5
+$as_echo "$flag" >&6; }
+        if test "x$flag" != xno; then
+            PTHREAD_CFLAGS="$flag $PTHREAD_CFLAGS"
+        fi
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for PTHREAD_PRIO_INHERIT" >&5
+$as_echo_n "checking for PTHREAD_PRIO_INHERIT... " >&6; }
+if ${ax_cv_PTHREAD_PRIO_INHERIT+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+                cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+int
+main ()
+{
+int i = PTHREAD_PRIO_INHERIT;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_cv_PTHREAD_PRIO_INHERIT=yes
+else
+  ax_cv_PTHREAD_PRIO_INHERIT=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_cv_PTHREAD_PRIO_INHERIT" >&5
+$as_echo "$ax_cv_PTHREAD_PRIO_INHERIT" >&6; }
+        if test "x$ax_cv_PTHREAD_PRIO_INHERIT" = "xyes"; then :
+
+$as_echo "#define HAVE_PTHREAD_PRIO_INHERIT 1" >>confdefs.h
+
+fi
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        # More AIX lossage: compile with *_r variant
+        if test "x$GCC" != xyes; then
+            case $host_os in
+                aix*)
+                case "x/$CC" in #(
+  x*/c89|x*/c89_128|x*/c99|x*/c99_128|x*/cc|x*/cc128|x*/xlc|x*/xlc_v6|x*/xlc128|x*/xlc128_v6) :
+    #handle absolute path differently from PATH based program lookup
+                   case "x$CC" in #(
+  x/*) :
+    if as_fn_executable_p ${CC}_r; then :
+  PTHREAD_CC="${CC}_r"
+fi ;; #(
+  *) :
+    for ac_prog in ${CC}_r
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_PTHREAD_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$PTHREAD_CC"; then
+  ac_cv_prog_PTHREAD_CC="$PTHREAD_CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_PTHREAD_CC="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+PTHREAD_CC=$ac_cv_prog_PTHREAD_CC
+if test -n "$PTHREAD_CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $PTHREAD_CC" >&5
+$as_echo "$PTHREAD_CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$PTHREAD_CC" && break
+done
+test -n "$PTHREAD_CC" || PTHREAD_CC="$CC"
+ ;;
+esac ;; #(
+  *) :
+     ;;
+esac
+                ;;
+            esac
+        fi
+fi
+
+test -n "$PTHREAD_CC" || PTHREAD_CC="$CC"
+
+
+
+
+
+# Finally, execute ACTION-IF-FOUND/ACTION-IF-NOT-FOUND:
+if test x"$ax_pthread_ok" = xyes; then
+
+$as_echo "#define HAVE_PTHREAD 1" >>confdefs.h
+
+        :
+else
+        ax_pthread_ok=no
+
+fi
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+
+            LIBS="$PTHREAD_LIBS $LIBS"
+            CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+            CC="$PTHREAD_CC"
+
+$as_echo "#define USE_PTHREAD 1" >>confdefs.h
+
+            ;;
+        fork)
+            { $as_echo "$as_me:${as_lineno-$LINENO}: FORK mode selected" >&5
+$as_echo "$as_me: FORK mode selected" >&6;}
+
+$as_echo "#define USE_FORK 1" >>confdefs.h
+
+            ;;
+        *)
+            as_fn_error $? "Unknown thread model \"${withval}\"" "$LINENO" 5
+            ;;
+    esac
+
+else
+
+    # do not attempt to autodetect UCONTEXT threading
+
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+ax_pthread_ok=no
+
+# We used to check for pthread.h first, but this fails if pthread.h
+# requires special compiler flags (e.g. on True64 or Sequent).
+# It gets checked for in the link test anyway.
+
+# First of all, check if the user has set any of the PTHREAD_LIBS,
+# etcetera environment variables, and if threads linking works using
+# them:
+if test x"$PTHREAD_LIBS$PTHREAD_CFLAGS" != x; then
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS" >&5
+$as_echo_n "checking for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS... " >&6; }
+        cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char pthread_join ();
+int
+main ()
+{
+return pthread_join ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_pthread_ok=yes
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_ok" >&5
+$as_echo "$ax_pthread_ok" >&6; }
+        if test x"$ax_pthread_ok" = xno; then
+                PTHREAD_LIBS=""
+                PTHREAD_CFLAGS=""
+        fi
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+fi
+
+# We must check for the threads library under a number of different
+# names; the ordering is very important because some systems
+# (e.g. DEC) have both -lpthread and -lpthreads, where one of the
+# libraries is broken (non-POSIX).
+
+# Create a list of thread flags to try.  Items starting with a "-" are
+# C compiler flags, and other items are library names, except for "none"
+# which indicates that we try without any flags at all, and "pthread-config"
+# which is a program returning the flags for the Pth emulation library.
+
+ax_pthread_flags="pthreads none -Kthread -kthread lthread -pthread -pthreads -mthreads pthread --thread-safe -mt pthread-config"
+
+# The ordering *is* (sometimes) important.  Some notes on the
+# individual items follow:
+
+# pthreads: AIX (must check this before -lpthread)
+# none: in case threads are in libc; should be tried before -Kthread and
+#       other compiler flags to prevent continual compiler warnings
+# -Kthread: Sequent (threads in libc, but -Kthread needed for pthread.h)
+# -kthread: FreeBSD kernel threads (preferred to -pthread since SMP-able)
+# lthread: LinuxThreads port on FreeBSD (also preferred to -pthread)
+# -pthread: Linux/gcc (kernel threads), BSD/gcc (userland threads)
+# -pthreads: Solaris/gcc
+# -mthreads: Mingw32/gcc, Lynx/gcc
+# -mt: Sun Workshop C (may only link SunOS threads [-lthread], but it
+#      doesn't hurt to check since this sometimes defines pthreads too;
+#      also defines -D_REENTRANT)
+#      ... -mt is also the pthreads flag for HP/aCC
+# pthread: Linux, etcetera
+# --thread-safe: KAI C++
+# pthread-config: use pthread-config program (for GNU Pth library)
+
+case ${host_os} in
+        solaris*)
+
+        # On Solaris (at least, for some versions), libc contains stubbed
+        # (non-functional) versions of the pthreads routines, so link-based
+        # tests will erroneously succeed.  (We need to link with -pthreads/-mt/
+        # -lpthread.)  (The stubs are missing pthread_cleanup_push, or rather
+        # a function called by this macro, so we could check for that, but
+        # who knows whether they'll stub that too in a future libc.)  So,
+        # we'll just look for -pthreads and -lpthread first:
+
+        ax_pthread_flags="-pthreads pthread -mt -pthread $ax_pthread_flags"
+        ;;
+
+        darwin*)
+        ax_pthread_flags="-pthread $ax_pthread_flags"
+        ;;
+esac
+
+# Clang doesn't consider unrecognized options an error unless we specify
+# -Werror. We throw in some extra Clang-specific options to ensure that
+# this doesn't happen for GCC, which also accepts -Werror.
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if compiler needs -Werror to reject unknown flags" >&5
+$as_echo_n "checking if compiler needs -Werror to reject unknown flags... " >&6; }
+save_CFLAGS="$CFLAGS"
+ax_pthread_extra_flags="-Werror"
+CFLAGS="$CFLAGS $ax_pthread_extra_flags -Wunknown-warning-option -Wsizeof-array-argument"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+int foo(void);
+int
+main ()
+{
+foo()
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+else
+  ax_pthread_extra_flags=
+                   { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+CFLAGS="$save_CFLAGS"
+
+if test x"$ax_pthread_ok" = xno; then
+for flag in $ax_pthread_flags; do
+
+        case $flag in
+                none)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether pthreads work without any flags" >&5
+$as_echo_n "checking whether pthreads work without any flags... " >&6; }
+                ;;
+
+                -*)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether pthreads work with $flag" >&5
+$as_echo_n "checking whether pthreads work with $flag... " >&6; }
+                PTHREAD_CFLAGS="$flag"
+                ;;
+
+                pthread-config)
+                # Extract the first word of "pthread-config", so it can be a program name with args.
+set dummy pthread-config; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ax_pthread_config+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ax_pthread_config"; then
+  ac_cv_prog_ax_pthread_config="$ax_pthread_config" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ax_pthread_config="yes"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+  test -z "$ac_cv_prog_ax_pthread_config" && ac_cv_prog_ax_pthread_config="no"
+fi
+fi
+ax_pthread_config=$ac_cv_prog_ax_pthread_config
+if test -n "$ax_pthread_config"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_config" >&5
+$as_echo "$ax_pthread_config" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+                if test x"$ax_pthread_config" = xno; then continue; fi
+                PTHREAD_CFLAGS="`pthread-config --cflags`"
+                PTHREAD_LIBS="`pthread-config --ldflags` `pthread-config --libs`"
+                ;;
+
+                *)
+                { $as_echo "$as_me:${as_lineno-$LINENO}: checking for the pthreads library -l$flag" >&5
+$as_echo_n "checking for the pthreads library -l$flag... " >&6; }
+                PTHREAD_LIBS="-l$flag"
+                ;;
+        esac
+
+        save_LIBS="$LIBS"
+        save_CFLAGS="$CFLAGS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS $ax_pthread_extra_flags"
+
+        # Check for various functions.  We must include pthread.h,
+        # since some functions may be macros.  (On the Sequent, we
+        # need a special flag -Kthread to make this header compile.)
+        # We check for pthread_join because it is in -lpthread on IRIX
+        # while pthread_create is in libc.  We check for pthread_attr_init
+        # due to DEC craziness with -lpthreads.  We check for
+        # pthread_cleanup_push because it is one of the few pthread
+        # functions on Solaris that doesn't have a non-functional libc stub.
+        # We try pthread_create on general principles.
+        cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+                        static void routine(void *a) { a = 0; }
+                        static void *start_routine(void *a) { return a; }
+int
+main ()
+{
+pthread_t th; pthread_attr_t attr;
+                        pthread_create(&th, 0, start_routine, 0);
+                        pthread_join(th, 0);
+                        pthread_attr_init(&attr);
+                        pthread_cleanup_push(routine, 0);
+                        pthread_cleanup_pop(0) /* ; */
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_pthread_ok=yes
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_pthread_ok" >&5
+$as_echo "$ax_pthread_ok" >&6; }
+        if test "x$ax_pthread_ok" = xyes; then
+                break;
+        fi
+
+        PTHREAD_LIBS=""
+        PTHREAD_CFLAGS=""
+done
+fi
+
+# Various other checks:
+if test "x$ax_pthread_ok" = xyes; then
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+
+        # Detect AIX lossage: JOINABLE attribute is called UNDETACHED.
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for joinable pthread attribute" >&5
+$as_echo_n "checking for joinable pthread attribute... " >&6; }
+        attr_name=unknown
+        for attr in PTHREAD_CREATE_JOINABLE PTHREAD_CREATE_UNDETACHED; do
+            cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+int
+main ()
+{
+int attr = $attr; return attr /* ; */
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  attr_name=$attr; break
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+        done
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $attr_name" >&5
+$as_echo "$attr_name" >&6; }
+        if test "$attr_name" != PTHREAD_CREATE_JOINABLE; then
+
+cat >>confdefs.h <<_ACEOF
+#define PTHREAD_CREATE_JOINABLE $attr_name
+_ACEOF
+
+        fi
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking if more special flags are required for pthreads" >&5
+$as_echo_n "checking if more special flags are required for pthreads... " >&6; }
+        flag=no
+        case ${host_os} in
+            aix* | freebsd* | darwin*) flag="-D_THREAD_SAFE";;
+            osf* | hpux*) flag="-D_REENTRANT";;
+            solaris*)
+            if test "$GCC" = "yes"; then
+                flag="-D_REENTRANT"
+            else
+                # TODO: What about Clang on Solaris?
+                flag="-mt -D_REENTRANT"
+            fi
+            ;;
+        esac
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: $flag" >&5
+$as_echo "$flag" >&6; }
+        if test "x$flag" != xno; then
+            PTHREAD_CFLAGS="$flag $PTHREAD_CFLAGS"
+        fi
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for PTHREAD_PRIO_INHERIT" >&5
+$as_echo_n "checking for PTHREAD_PRIO_INHERIT... " >&6; }
+if ${ax_cv_PTHREAD_PRIO_INHERIT+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+                cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <pthread.h>
+int
+main ()
+{
+int i = PTHREAD_PRIO_INHERIT;
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ax_cv_PTHREAD_PRIO_INHERIT=yes
+else
+  ax_cv_PTHREAD_PRIO_INHERIT=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ax_cv_PTHREAD_PRIO_INHERIT" >&5
+$as_echo "$ax_cv_PTHREAD_PRIO_INHERIT" >&6; }
+        if test "x$ax_cv_PTHREAD_PRIO_INHERIT" = "xyes"; then :
+
+$as_echo "#define HAVE_PTHREAD_PRIO_INHERIT 1" >>confdefs.h
+
+fi
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        # More AIX lossage: compile with *_r variant
+        if test "x$GCC" != xyes; then
+            case $host_os in
+                aix*)
+                case "x/$CC" in #(
+  x*/c89|x*/c89_128|x*/c99|x*/c99_128|x*/cc|x*/cc128|x*/xlc|x*/xlc_v6|x*/xlc128|x*/xlc128_v6) :
+    #handle absolute path differently from PATH based program lookup
+                   case "x$CC" in #(
+  x/*) :
+    if as_fn_executable_p ${CC}_r; then :
+  PTHREAD_CC="${CC}_r"
+fi ;; #(
+  *) :
+    for ac_prog in ${CC}_r
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_PTHREAD_CC+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$PTHREAD_CC"; then
+  ac_cv_prog_PTHREAD_CC="$PTHREAD_CC" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_PTHREAD_CC="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+PTHREAD_CC=$ac_cv_prog_PTHREAD_CC
+if test -n "$PTHREAD_CC"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $PTHREAD_CC" >&5
+$as_echo "$PTHREAD_CC" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$PTHREAD_CC" && break
+done
+test -n "$PTHREAD_CC" || PTHREAD_CC="$CC"
+ ;;
+esac ;; #(
+  *) :
+     ;;
+esac
+                ;;
+            esac
+        fi
+fi
+
+test -n "$PTHREAD_CC" || PTHREAD_CC="$CC"
+
+
+
+
+
+# Finally, execute ACTION-IF-FOUND/ACTION-IF-NOT-FOUND:
+if test x"$ax_pthread_ok" = xyes; then
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: PTHREAD thread model detected" >&5
+$as_echo "$as_me: PTHREAD thread model detected" >&6;}
+        LIBS="$PTHREAD_LIBS $LIBS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+        CC="$PTHREAD_CC"
+
+$as_echo "#define USE_PTHREAD 1" >>confdefs.h
+
+
+        :
+else
+        ax_pthread_ok=no
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: FORK thread model detected" >&5
+$as_echo "$as_me: FORK thread model detected" >&6;}
+
+$as_echo "#define USE_FORK 1" >>confdefs.h
+
+
+fi
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+
+
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** compiler/linker flags" >&5
+$as_echo "$as_me: **************************************** compiler/linker flags" >&6;}
+
+
+
+
+for flag in -Wall; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wextra; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wpedantic; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wformat=2; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wconversion; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wno-long-long; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wno-deprecated-declarations; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -fstack-protector; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -fPIE; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -D_FORTIFY_SOURCE=2; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_cflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether C compiler accepts $flag" >&5
+$as_echo_n "checking whether C compiler accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$CFLAGS
+  CFLAGS="$CFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+  CFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${CFLAGS+:} false; then :
+  case " $CFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS already contains \$flag"; } >&5
+  (: CFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : CFLAGS=\"\$CFLAGS \$flag\""; } >&5
+  (: CFLAGS="$CFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      CFLAGS="$CFLAGS $flag"
+      ;;
+   esac
+else
+  CFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -fPIE -pie; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_ldflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the linker accepts $flag" >&5
+$as_echo_n "checking whether the linker accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$LDFLAGS
+  LDFLAGS="$LDFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  LDFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${LDFLAGS+:} false; then :
+  case " $LDFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS already contains \$flag"; } >&5
+  (: LDFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS=\"\$LDFLAGS \$flag\""; } >&5
+  (: LDFLAGS="$LDFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      LDFLAGS="$LDFLAGS $flag"
+      ;;
+   esac
+else
+  LDFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wl,-z,relro; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_ldflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the linker accepts $flag" >&5
+$as_echo_n "checking whether the linker accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$LDFLAGS
+  LDFLAGS="$LDFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  LDFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${LDFLAGS+:} false; then :
+  case " $LDFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS already contains \$flag"; } >&5
+  (: LDFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS=\"\$LDFLAGS \$flag\""; } >&5
+  (: LDFLAGS="$LDFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      LDFLAGS="$LDFLAGS $flag"
+      ;;
+   esac
+else
+  LDFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wl,-z,now; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_ldflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the linker accepts $flag" >&5
+$as_echo_n "checking whether the linker accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$LDFLAGS
+  LDFLAGS="$LDFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  LDFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${LDFLAGS+:} false; then :
+  case " $LDFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS already contains \$flag"; } >&5
+  (: LDFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS=\"\$LDFLAGS \$flag\""; } >&5
+  (: LDFLAGS="$LDFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      LDFLAGS="$LDFLAGS $flag"
+      ;;
+   esac
+else
+  LDFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+
+
+
+for flag in -Wl,-z,noexecstack; do
+  as_CACHEVAR=`$as_echo "ax_cv_check_ldflags__$flag" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the linker accepts $flag" >&5
+$as_echo_n "checking whether the linker accepts $flag... " >&6; }
+if eval \${$as_CACHEVAR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+  ax_check_save_flags=$LDFLAGS
+  LDFLAGS="$LDFLAGS  $flag"
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  eval "$as_CACHEVAR=yes"
+else
+  eval "$as_CACHEVAR=no"
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  LDFLAGS=$ax_check_save_flags
+fi
+eval ac_res=\$$as_CACHEVAR
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if test x"`eval 'as_val=${'$as_CACHEVAR'};$as_echo "$as_val"'`" = xyes; then :
+  if ${LDFLAGS+:} false; then :
+  case " $LDFLAGS " in
+    *" $flag "*)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS already contains \$flag"; } >&5
+  (: LDFLAGS already contains $flag) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      ;;
+    *)
+      { { $as_echo "$as_me:${as_lineno-$LINENO}: : LDFLAGS=\"\$LDFLAGS \$flag\""; } >&5
+  (: LDFLAGS="$LDFLAGS $flag") 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      LDFLAGS="$LDFLAGS $flag"
+      ;;
+   esac
+else
+  LDFLAGS="$flag"
+fi
+
+else
+  :
+fi
+
+done
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** libtool" >&5
+$as_echo "$as_me: **************************************** libtool" >&6;}
+case `pwd` in
+  *\ * | *\	*)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: Libtool does not cope well with whitespace in \`pwd\`" >&5
+$as_echo "$as_me: WARNING: Libtool does not cope well with whitespace in \`pwd\`" >&2;} ;;
+esac
+
+
+
+macro_version='2.4.2'
+macro_revision='1.3337'
+
+
+
+
+
+
+
+
+
+
+
+
+
+ltmain="$ac_aux_dir/ltmain.sh"
+
+# Backslashify metacharacters that are still active within
+# double-quoted strings.
+sed_quote_subst='s/\(["`$\\]\)/\\\1/g'
+
+# Same as above, but do not quote variable references.
+double_quote_subst='s/\(["`\\]\)/\\\1/g'
+
+# Sed substitution to delay expansion of an escaped shell variable in a
+# double_quote_subst'ed string.
+delay_variable_subst='s/\\\\\\\\\\\$/\\\\\\$/g'
+
+# Sed substitution to delay expansion of an escaped single quote.
+delay_single_quote_subst='s/'\''/'\'\\\\\\\'\''/g'
+
+# Sed substitution to avoid accidental globbing in evaled expressions
+no_glob_subst='s/\*/\\\*/g'
+
+ECHO='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO
+ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO$ECHO
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to print strings" >&5
+$as_echo_n "checking how to print strings... " >&6; }
+# Test print first, because it will be a builtin if present.
+if test "X`( print -r -- -n ) 2>/dev/null`" = X-n && \
+   test "X`print -r -- $ECHO 2>/dev/null`" = "X$ECHO"; then
+  ECHO='print -r --'
+elif test "X`printf %s $ECHO 2>/dev/null`" = "X$ECHO"; then
+  ECHO='printf %s\n'
+else
+  # Use this function as a fallback that always works.
+  func_fallback_echo ()
+  {
+    eval 'cat <<_LTECHO_EOF
+$1
+_LTECHO_EOF'
+  }
+  ECHO='func_fallback_echo'
+fi
+
+# func_echo_all arg...
+# Invoke $ECHO with all args, space-separated.
+func_echo_all ()
+{
+    $ECHO ""
+}
+
+case "$ECHO" in
+  printf*) { $as_echo "$as_me:${as_lineno-$LINENO}: result: printf" >&5
+$as_echo "printf" >&6; } ;;
+  print*) { $as_echo "$as_me:${as_lineno-$LINENO}: result: print -r" >&5
+$as_echo "print -r" >&6; } ;;
+  *) { $as_echo "$as_me:${as_lineno-$LINENO}: result: cat" >&5
+$as_echo "cat" >&6; } ;;
+esac
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for a sed that does not truncate output" >&5
+$as_echo_n "checking for a sed that does not truncate output... " >&6; }
+if ${ac_cv_path_SED+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+            ac_script=s/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa/bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb/
+     for ac_i in 1 2 3 4 5 6 7; do
+       ac_script="$ac_script$as_nl$ac_script"
+     done
+     echo "$ac_script" 2>/dev/null | sed 99q >conftest.sed
+     { ac_script=; unset ac_script;}
+     if test -z "$SED"; then
+  ac_path_SED_found=false
+  # Loop through the user's path and test for each of PROGNAME-LIST
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_prog in sed gsed; do
+    for ac_exec_ext in '' $ac_executable_extensions; do
+      ac_path_SED="$as_dir/$ac_prog$ac_exec_ext"
+      as_fn_executable_p "$ac_path_SED" || continue
+# Check for GNU ac_path_SED and select it if it is found.
+  # Check for GNU $ac_path_SED
+case `"$ac_path_SED" --version 2>&1` in
+*GNU*)
+  ac_cv_path_SED="$ac_path_SED" ac_path_SED_found=:;;
+*)
+  ac_count=0
+  $as_echo_n 0123456789 >"conftest.in"
+  while :
+  do
+    cat "conftest.in" "conftest.in" >"conftest.tmp"
+    mv "conftest.tmp" "conftest.in"
+    cp "conftest.in" "conftest.nl"
+    $as_echo '' >> "conftest.nl"
+    "$ac_path_SED" -f conftest.sed < "conftest.nl" >"conftest.out" 2>/dev/null || break
+    diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break
+    as_fn_arith $ac_count + 1 && ac_count=$as_val
+    if test $ac_count -gt ${ac_path_SED_max-0}; then
+      # Best one so far, save it but keep looking for a better one
+      ac_cv_path_SED="$ac_path_SED"
+      ac_path_SED_max=$ac_count
+    fi
+    # 10*(2^10) chars as input seems more than enough
+    test $ac_count -gt 10 && break
+  done
+  rm -f conftest.in conftest.tmp conftest.nl conftest.out;;
+esac
+
+      $ac_path_SED_found && break 3
+    done
+  done
+  done
+IFS=$as_save_IFS
+  if test -z "$ac_cv_path_SED"; then
+    as_fn_error $? "no acceptable sed could be found in \$PATH" "$LINENO" 5
+  fi
+else
+  ac_cv_path_SED=$SED
+fi
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_SED" >&5
+$as_echo "$ac_cv_path_SED" >&6; }
+ SED="$ac_cv_path_SED"
+  rm -f conftest.sed
+
+test -z "$SED" && SED=sed
+Xsed="$SED -e 1s/^X//"
+
+
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for grep that handles long lines and -e" >&5
+$as_echo_n "checking for grep that handles long lines and -e... " >&6; }
+if ${ac_cv_path_GREP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -z "$GREP"; then
+  ac_path_GREP_found=false
+  # Loop through the user's path and test for each of PROGNAME-LIST
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH$PATH_SEPARATOR/usr/xpg4/bin
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_prog in grep ggrep; do
+    for ac_exec_ext in '' $ac_executable_extensions; do
+      ac_path_GREP="$as_dir/$ac_prog$ac_exec_ext"
+      as_fn_executable_p "$ac_path_GREP" || continue
+# Check for GNU ac_path_GREP and select it if it is found.
+  # Check for GNU $ac_path_GREP
+case `"$ac_path_GREP" --version 2>&1` in
+*GNU*)
+  ac_cv_path_GREP="$ac_path_GREP" ac_path_GREP_found=:;;
+*)
+  ac_count=0
+  $as_echo_n 0123456789 >"conftest.in"
+  while :
+  do
+    cat "conftest.in" "conftest.in" >"conftest.tmp"
+    mv "conftest.tmp" "conftest.in"
+    cp "conftest.in" "conftest.nl"
+    $as_echo 'GREP' >> "conftest.nl"
+    "$ac_path_GREP" -e 'GREP$' -e '-(cannot match)-' < "conftest.nl" >"conftest.out" 2>/dev/null || break
+    diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break
+    as_fn_arith $ac_count + 1 && ac_count=$as_val
+    if test $ac_count -gt ${ac_path_GREP_max-0}; then
+      # Best one so far, save it but keep looking for a better one
+      ac_cv_path_GREP="$ac_path_GREP"
+      ac_path_GREP_max=$ac_count
+    fi
+    # 10*(2^10) chars as input seems more than enough
+    test $ac_count -gt 10 && break
+  done
+  rm -f conftest.in conftest.tmp conftest.nl conftest.out;;
+esac
+
+      $ac_path_GREP_found && break 3
+    done
+  done
+  done
+IFS=$as_save_IFS
+  if test -z "$ac_cv_path_GREP"; then
+    as_fn_error $? "no acceptable grep could be found in $PATH$PATH_SEPARATOR/usr/xpg4/bin" "$LINENO" 5
+  fi
+else
+  ac_cv_path_GREP=$GREP
+fi
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_GREP" >&5
+$as_echo "$ac_cv_path_GREP" >&6; }
+ GREP="$ac_cv_path_GREP"
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for egrep" >&5
+$as_echo_n "checking for egrep... " >&6; }
+if ${ac_cv_path_EGREP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if echo a | $GREP -E '(a|b)' >/dev/null 2>&1
+   then ac_cv_path_EGREP="$GREP -E"
+   else
+     if test -z "$EGREP"; then
+  ac_path_EGREP_found=false
+  # Loop through the user's path and test for each of PROGNAME-LIST
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH$PATH_SEPARATOR/usr/xpg4/bin
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_prog in egrep; do
+    for ac_exec_ext in '' $ac_executable_extensions; do
+      ac_path_EGREP="$as_dir/$ac_prog$ac_exec_ext"
+      as_fn_executable_p "$ac_path_EGREP" || continue
+# Check for GNU ac_path_EGREP and select it if it is found.
+  # Check for GNU $ac_path_EGREP
+case `"$ac_path_EGREP" --version 2>&1` in
+*GNU*)
+  ac_cv_path_EGREP="$ac_path_EGREP" ac_path_EGREP_found=:;;
+*)
+  ac_count=0
+  $as_echo_n 0123456789 >"conftest.in"
+  while :
+  do
+    cat "conftest.in" "conftest.in" >"conftest.tmp"
+    mv "conftest.tmp" "conftest.in"
+    cp "conftest.in" "conftest.nl"
+    $as_echo 'EGREP' >> "conftest.nl"
+    "$ac_path_EGREP" 'EGREP$' < "conftest.nl" >"conftest.out" 2>/dev/null || break
+    diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break
+    as_fn_arith $ac_count + 1 && ac_count=$as_val
+    if test $ac_count -gt ${ac_path_EGREP_max-0}; then
+      # Best one so far, save it but keep looking for a better one
+      ac_cv_path_EGREP="$ac_path_EGREP"
+      ac_path_EGREP_max=$ac_count
+    fi
+    # 10*(2^10) chars as input seems more than enough
+    test $ac_count -gt 10 && break
+  done
+  rm -f conftest.in conftest.tmp conftest.nl conftest.out;;
+esac
+
+      $ac_path_EGREP_found && break 3
+    done
+  done
+  done
+IFS=$as_save_IFS
+  if test -z "$ac_cv_path_EGREP"; then
+    as_fn_error $? "no acceptable egrep could be found in $PATH$PATH_SEPARATOR/usr/xpg4/bin" "$LINENO" 5
+  fi
+else
+  ac_cv_path_EGREP=$EGREP
+fi
+
+   fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_EGREP" >&5
+$as_echo "$ac_cv_path_EGREP" >&6; }
+ EGREP="$ac_cv_path_EGREP"
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for fgrep" >&5
+$as_echo_n "checking for fgrep... " >&6; }
+if ${ac_cv_path_FGREP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if echo 'ab*c' | $GREP -F 'ab*c' >/dev/null 2>&1
+   then ac_cv_path_FGREP="$GREP -F"
+   else
+     if test -z "$FGREP"; then
+  ac_path_FGREP_found=false
+  # Loop through the user's path and test for each of PROGNAME-LIST
+  as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH$PATH_SEPARATOR/usr/xpg4/bin
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_prog in fgrep; do
+    for ac_exec_ext in '' $ac_executable_extensions; do
+      ac_path_FGREP="$as_dir/$ac_prog$ac_exec_ext"
+      as_fn_executable_p "$ac_path_FGREP" || continue
+# Check for GNU ac_path_FGREP and select it if it is found.
+  # Check for GNU $ac_path_FGREP
+case `"$ac_path_FGREP" --version 2>&1` in
+*GNU*)
+  ac_cv_path_FGREP="$ac_path_FGREP" ac_path_FGREP_found=:;;
+*)
+  ac_count=0
+  $as_echo_n 0123456789 >"conftest.in"
+  while :
+  do
+    cat "conftest.in" "conftest.in" >"conftest.tmp"
+    mv "conftest.tmp" "conftest.in"
+    cp "conftest.in" "conftest.nl"
+    $as_echo 'FGREP' >> "conftest.nl"
+    "$ac_path_FGREP" FGREP < "conftest.nl" >"conftest.out" 2>/dev/null || break
+    diff "conftest.out" "conftest.nl" >/dev/null 2>&1 || break
+    as_fn_arith $ac_count + 1 && ac_count=$as_val
+    if test $ac_count -gt ${ac_path_FGREP_max-0}; then
+      # Best one so far, save it but keep looking for a better one
+      ac_cv_path_FGREP="$ac_path_FGREP"
+      ac_path_FGREP_max=$ac_count
+    fi
+    # 10*(2^10) chars as input seems more than enough
+    test $ac_count -gt 10 && break
+  done
+  rm -f conftest.in conftest.tmp conftest.nl conftest.out;;
+esac
+
+      $ac_path_FGREP_found && break 3
+    done
+  done
+  done
+IFS=$as_save_IFS
+  if test -z "$ac_cv_path_FGREP"; then
+    as_fn_error $? "no acceptable fgrep could be found in $PATH$PATH_SEPARATOR/usr/xpg4/bin" "$LINENO" 5
+  fi
+else
+  ac_cv_path_FGREP=$FGREP
+fi
+
+   fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_path_FGREP" >&5
+$as_echo "$ac_cv_path_FGREP" >&6; }
+ FGREP="$ac_cv_path_FGREP"
+
+
+test -z "$GREP" && GREP=grep
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+# Check whether --with-gnu-ld was given.
+if test "${with_gnu_ld+set}" = set; then :
+  withval=$with_gnu_ld; test "$withval" = no || with_gnu_ld=yes
+else
+  with_gnu_ld=no
+fi
+
+ac_prog=ld
+if test "$GCC" = yes; then
+  # Check if gcc -print-prog-name=ld gives a path.
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for ld used by $CC" >&5
+$as_echo_n "checking for ld used by $CC... " >&6; }
+  case $host in
+  *-*-mingw*)
+    # gcc leaves a trailing carriage return which upsets mingw
+    ac_prog=`($CC -print-prog-name=ld) 2>&5 | tr -d '\015'` ;;
+  *)
+    ac_prog=`($CC -print-prog-name=ld) 2>&5` ;;
+  esac
+  case $ac_prog in
+    # Accept absolute paths.
+    [\\/]* | ?:[\\/]*)
+      re_direlt='/[^/][^/]*/\.\./'
+      # Canonicalize the pathname of ld
+      ac_prog=`$ECHO "$ac_prog"| $SED 's%\\\\%/%g'`
+      while $ECHO "$ac_prog" | $GREP "$re_direlt" > /dev/null 2>&1; do
+	ac_prog=`$ECHO $ac_prog| $SED "s%$re_direlt%/%"`
+      done
+      test -z "$LD" && LD="$ac_prog"
+      ;;
+  "")
+    # If it fails, then pretend we aren't using GCC.
+    ac_prog=ld
+    ;;
+  *)
+    # If it is relative, then search for the first ld in PATH.
+    with_gnu_ld=unknown
+    ;;
+  esac
+elif test "$with_gnu_ld" = yes; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for GNU ld" >&5
+$as_echo_n "checking for GNU ld... " >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for non-GNU ld" >&5
+$as_echo_n "checking for non-GNU ld... " >&6; }
+fi
+if ${lt_cv_path_LD+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -z "$LD"; then
+  lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+  for ac_dir in $PATH; do
+    IFS="$lt_save_ifs"
+    test -z "$ac_dir" && ac_dir=.
+    if test -f "$ac_dir/$ac_prog" || test -f "$ac_dir/$ac_prog$ac_exeext"; then
+      lt_cv_path_LD="$ac_dir/$ac_prog"
+      # Check to see if the program is GNU ld.  I'd rather use --version,
+      # but apparently some variants of GNU ld only accept -v.
+      # Break only if it was the GNU/non-GNU ld that we prefer.
+      case `"$lt_cv_path_LD" -v 2>&1 </dev/null` in
+      *GNU* | *'with BFD'*)
+	test "$with_gnu_ld" != no && break
+	;;
+      *)
+	test "$with_gnu_ld" != yes && break
+	;;
+      esac
+    fi
+  done
+  IFS="$lt_save_ifs"
+else
+  lt_cv_path_LD="$LD" # Let the user override the test with a path.
+fi
+fi
+
+LD="$lt_cv_path_LD"
+if test -n "$LD"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $LD" >&5
+$as_echo "$LD" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+test -z "$LD" && as_fn_error $? "no acceptable ld found in \$PATH" "$LINENO" 5
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if the linker ($LD) is GNU ld" >&5
+$as_echo_n "checking if the linker ($LD) is GNU ld... " >&6; }
+if ${lt_cv_prog_gnu_ld+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  # I'd rather use --version here, but apparently some GNU lds only accept -v.
+case `$LD -v 2>&1 </dev/null` in
+*GNU* | *'with BFD'*)
+  lt_cv_prog_gnu_ld=yes
+  ;;
+*)
+  lt_cv_prog_gnu_ld=no
+  ;;
+esac
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_gnu_ld" >&5
+$as_echo "$lt_cv_prog_gnu_ld" >&6; }
+with_gnu_ld=$lt_cv_prog_gnu_ld
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for BSD- or MS-compatible name lister (nm)" >&5
+$as_echo_n "checking for BSD- or MS-compatible name lister (nm)... " >&6; }
+if ${lt_cv_path_NM+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$NM"; then
+  # Let the user override the test.
+  lt_cv_path_NM="$NM"
+else
+  lt_nm_to_check="${ac_tool_prefix}nm"
+  if test -n "$ac_tool_prefix" && test "$build" = "$host"; then
+    lt_nm_to_check="$lt_nm_to_check nm"
+  fi
+  for lt_tmp_nm in $lt_nm_to_check; do
+    lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+    for ac_dir in $PATH /usr/ccs/bin/elf /usr/ccs/bin /usr/ucb /bin; do
+      IFS="$lt_save_ifs"
+      test -z "$ac_dir" && ac_dir=.
+      tmp_nm="$ac_dir/$lt_tmp_nm"
+      if test -f "$tmp_nm" || test -f "$tmp_nm$ac_exeext" ; then
+	# Check to see if the nm accepts a BSD-compat flag.
+	# Adding the `sed 1q' prevents false positives on HP-UX, which says:
+	#   nm: unknown option "B" ignored
+	# Tru64's nm complains that /dev/null is an invalid object file
+	case `"$tmp_nm" -B /dev/null 2>&1 | sed '1q'` in
+	*/dev/null* | *'Invalid file or object type'*)
+	  lt_cv_path_NM="$tmp_nm -B"
+	  break
+	  ;;
+	*)
+	  case `"$tmp_nm" -p /dev/null 2>&1 | sed '1q'` in
+	  */dev/null*)
+	    lt_cv_path_NM="$tmp_nm -p"
+	    break
+	    ;;
+	  *)
+	    lt_cv_path_NM=${lt_cv_path_NM="$tmp_nm"} # keep the first match, but
+	    continue # so that we can try to find one that supports BSD flags
+	    ;;
+	  esac
+	  ;;
+	esac
+      fi
+    done
+    IFS="$lt_save_ifs"
+  done
+  : ${lt_cv_path_NM=no}
+fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_path_NM" >&5
+$as_echo "$lt_cv_path_NM" >&6; }
+if test "$lt_cv_path_NM" != "no"; then
+  NM="$lt_cv_path_NM"
+else
+  # Didn't find any BSD compatible name lister, look for dumpbin.
+  if test -n "$DUMPBIN"; then :
+    # Let the user override the test.
+  else
+    if test -n "$ac_tool_prefix"; then
+  for ac_prog in dumpbin "link -dump"
+  do
+    # Extract the first word of "$ac_tool_prefix$ac_prog", so it can be a program name with args.
+set dummy $ac_tool_prefix$ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_DUMPBIN+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$DUMPBIN"; then
+  ac_cv_prog_DUMPBIN="$DUMPBIN" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_DUMPBIN="$ac_tool_prefix$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+DUMPBIN=$ac_cv_prog_DUMPBIN
+if test -n "$DUMPBIN"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $DUMPBIN" >&5
+$as_echo "$DUMPBIN" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+    test -n "$DUMPBIN" && break
+  done
+fi
+if test -z "$DUMPBIN"; then
+  ac_ct_DUMPBIN=$DUMPBIN
+  for ac_prog in dumpbin "link -dump"
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_DUMPBIN+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_DUMPBIN"; then
+  ac_cv_prog_ac_ct_DUMPBIN="$ac_ct_DUMPBIN" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_DUMPBIN="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_DUMPBIN=$ac_cv_prog_ac_ct_DUMPBIN
+if test -n "$ac_ct_DUMPBIN"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_DUMPBIN" >&5
+$as_echo "$ac_ct_DUMPBIN" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$ac_ct_DUMPBIN" && break
+done
+
+  if test "x$ac_ct_DUMPBIN" = x; then
+    DUMPBIN=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    DUMPBIN=$ac_ct_DUMPBIN
+  fi
+fi
+
+    case `$DUMPBIN -symbols /dev/null 2>&1 | sed '1q'` in
+    *COFF*)
+      DUMPBIN="$DUMPBIN -symbols"
+      ;;
+    *)
+      DUMPBIN=:
+      ;;
+    esac
+  fi
+
+  if test "$DUMPBIN" != ":"; then
+    NM="$DUMPBIN"
+  fi
+fi
+test -z "$NM" && NM=nm
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking the name lister ($NM) interface" >&5
+$as_echo_n "checking the name lister ($NM) interface... " >&6; }
+if ${lt_cv_nm_interface+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_nm_interface="BSD nm"
+  echo "int some_variable = 0;" > conftest.$ac_ext
+  (eval echo "\"\$as_me:$LINENO: $ac_compile\"" >&5)
+  (eval "$ac_compile" 2>conftest.err)
+  cat conftest.err >&5
+  (eval echo "\"\$as_me:$LINENO: $NM \\\"conftest.$ac_objext\\\"\"" >&5)
+  (eval "$NM \"conftest.$ac_objext\"" 2>conftest.err > conftest.out)
+  cat conftest.err >&5
+  (eval echo "\"\$as_me:$LINENO: output\"" >&5)
+  cat conftest.out >&5
+  if $GREP 'External.*some_variable' conftest.out > /dev/null; then
+    lt_cv_nm_interface="MS dumpbin"
+  fi
+  rm -f conftest*
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_nm_interface" >&5
+$as_echo "$lt_cv_nm_interface" >&6; }
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether ln -s works" >&5
+$as_echo_n "checking whether ln -s works... " >&6; }
+LN_S=$as_ln_s
+if test "$LN_S" = "ln -s"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no, using $LN_S" >&5
+$as_echo "no, using $LN_S" >&6; }
+fi
+
+# find the maximum length of command line arguments
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking the maximum length of command line arguments" >&5
+$as_echo_n "checking the maximum length of command line arguments... " >&6; }
+if ${lt_cv_sys_max_cmd_len+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+    i=0
+  teststring="ABCD"
+
+  case $build_os in
+  msdosdjgpp*)
+    # On DJGPP, this test can blow up pretty badly due to problems in libc
+    # (any single argument exceeding 2000 bytes causes a buffer overrun
+    # during glob expansion).  Even if it were fixed, the result of this
+    # check would be larger than it should be.
+    lt_cv_sys_max_cmd_len=12288;    # 12K is about right
+    ;;
+
+  gnu*)
+    # Under GNU Hurd, this test is not required because there is
+    # no limit to the length of command line arguments.
+    # Libtool will interpret -1 as no limit whatsoever
+    lt_cv_sys_max_cmd_len=-1;
+    ;;
+
+  cygwin* | mingw* | cegcc*)
+    # On Win9x/ME, this test blows up -- it succeeds, but takes
+    # about 5 minutes as the teststring grows exponentially.
+    # Worse, since 9x/ME are not pre-emptively multitasking,
+    # you end up with a "frozen" computer, even though with patience
+    # the test eventually succeeds (with a max line length of 256k).
+    # Instead, let's just punt: use the minimum linelength reported by
+    # all of the supported platforms: 8192 (on NT/2K/XP).
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  mint*)
+    # On MiNT this can take a long time and run out of memory.
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  amigaos*)
+    # On AmigaOS with pdksh, this test takes hours, literally.
+    # So we just punt and use a minimum line length of 8192.
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  netbsd* | freebsd* | openbsd* | darwin* | dragonfly*)
+    # This has been around since 386BSD, at least.  Likely further.
+    if test -x /sbin/sysctl; then
+      lt_cv_sys_max_cmd_len=`/sbin/sysctl -n kern.argmax`
+    elif test -x /usr/sbin/sysctl; then
+      lt_cv_sys_max_cmd_len=`/usr/sbin/sysctl -n kern.argmax`
+    else
+      lt_cv_sys_max_cmd_len=65536	# usable default for all BSDs
+    fi
+    # And add a safety zone
+    lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 4`
+    lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \* 3`
+    ;;
+
+  interix*)
+    # We know the value 262144 and hardcode it with a safety zone (like BSD)
+    lt_cv_sys_max_cmd_len=196608
+    ;;
+
+  os2*)
+    # The test takes a long time on OS/2.
+    lt_cv_sys_max_cmd_len=8192
+    ;;
+
+  osf*)
+    # Dr. Hans Ekkehard Plesser reports seeing a kernel panic running configure
+    # due to this test when exec_disable_arg_limit is 1 on Tru64. It is not
+    # nice to cause kernel panics so lets avoid the loop below.
+    # First set a reasonable default.
+    lt_cv_sys_max_cmd_len=16384
+    #
+    if test -x /sbin/sysconfig; then
+      case `/sbin/sysconfig -q proc exec_disable_arg_limit` in
+        *1*) lt_cv_sys_max_cmd_len=-1 ;;
+      esac
+    fi
+    ;;
+  sco3.2v5*)
+    lt_cv_sys_max_cmd_len=102400
+    ;;
+  sysv5* | sco5v6* | sysv4.2uw2*)
+    kargmax=`grep ARG_MAX /etc/conf/cf.d/stune 2>/dev/null`
+    if test -n "$kargmax"; then
+      lt_cv_sys_max_cmd_len=`echo $kargmax | sed 's/.*[	 ]//'`
+    else
+      lt_cv_sys_max_cmd_len=32768
+    fi
+    ;;
+  *)
+    lt_cv_sys_max_cmd_len=`(getconf ARG_MAX) 2> /dev/null`
+    if test -n "$lt_cv_sys_max_cmd_len" && \
+	test undefined != "$lt_cv_sys_max_cmd_len"; then
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 4`
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \* 3`
+    else
+      # Make teststring a little bigger before we do anything with it.
+      # a 1K string should be a reasonable start.
+      for i in 1 2 3 4 5 6 7 8 ; do
+        teststring=$teststring$teststring
+      done
+      SHELL=${SHELL-${CONFIG_SHELL-/bin/sh}}
+      # If test is not a shell built-in, we'll probably end up computing a
+      # maximum length that is only half of the actual maximum length, but
+      # we can't tell.
+      while { test "X"`env echo "$teststring$teststring" 2>/dev/null` \
+	         = "X$teststring$teststring"; } >/dev/null 2>&1 &&
+	      test $i != 17 # 1/2 MB should be enough
+      do
+        i=`expr $i + 1`
+        teststring=$teststring$teststring
+      done
+      # Only check the string length outside the loop.
+      lt_cv_sys_max_cmd_len=`expr "X$teststring" : ".*" 2>&1`
+      teststring=
+      # Add a significant safety factor because C++ compilers can tack on
+      # massive amounts of additional arguments before passing them to the
+      # linker.  It appears as though 1/2 is a usable value.
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 2`
+    fi
+    ;;
+  esac
+
+fi
+
+if test -n $lt_cv_sys_max_cmd_len ; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_sys_max_cmd_len" >&5
+$as_echo "$lt_cv_sys_max_cmd_len" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: none" >&5
+$as_echo "none" >&6; }
+fi
+max_cmd_len=$lt_cv_sys_max_cmd_len
+
+
+
+
+
+
+: ${CP="cp -f"}
+: ${MV="mv -f"}
+: ${RM="rm -f"}
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the shell understands some XSI constructs" >&5
+$as_echo_n "checking whether the shell understands some XSI constructs... " >&6; }
+# Try some XSI features
+xsi_shell=no
+( _lt_dummy="a/b/c"
+  test "${_lt_dummy##*/},${_lt_dummy%/*},${_lt_dummy#??}"${_lt_dummy%"$_lt_dummy"}, \
+      = c,a/b,b/c, \
+    && eval 'test $(( 1 + 1 )) -eq 2 \
+    && test "${#_lt_dummy}" -eq 5' ) >/dev/null 2>&1 \
+  && xsi_shell=yes
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $xsi_shell" >&5
+$as_echo "$xsi_shell" >&6; }
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the shell understands \"+=\"" >&5
+$as_echo_n "checking whether the shell understands \"+=\"... " >&6; }
+lt_shell_append=no
+( foo=bar; set foo baz; eval "$1+=\$2" && test "$foo" = barbaz ) \
+    >/dev/null 2>&1 \
+  && lt_shell_append=yes
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_shell_append" >&5
+$as_echo "$lt_shell_append" >&6; }
+
+
+if ( (MAIL=60; unset MAIL) || exit) >/dev/null 2>&1; then
+  lt_unset=unset
+else
+  lt_unset=false
+fi
+
+
+
+
+
+# test EBCDIC or ASCII
+case `echo X|tr X '\101'` in
+ A) # ASCII based system
+    # \n is not interpreted correctly by Solaris 8 /usr/ucb/tr
+  lt_SP2NL='tr \040 \012'
+  lt_NL2SP='tr \015\012 \040\040'
+  ;;
+ *) # EBCDIC based system
+  lt_SP2NL='tr \100 \n'
+  lt_NL2SP='tr \r\n \100\100'
+  ;;
+esac
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to convert $build file names to $host format" >&5
+$as_echo_n "checking how to convert $build file names to $host format... " >&6; }
+if ${lt_cv_to_host_file_cmd+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  case $host in
+  *-*-mingw* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_host_file_cmd=func_convert_file_msys_to_w32
+        ;;
+      *-*-cygwin* )
+        lt_cv_to_host_file_cmd=func_convert_file_cygwin_to_w32
+        ;;
+      * ) # otherwise, assume *nix
+        lt_cv_to_host_file_cmd=func_convert_file_nix_to_w32
+        ;;
+    esac
+    ;;
+  *-*-cygwin* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_host_file_cmd=func_convert_file_msys_to_cygwin
+        ;;
+      *-*-cygwin* )
+        lt_cv_to_host_file_cmd=func_convert_file_noop
+        ;;
+      * ) # otherwise, assume *nix
+        lt_cv_to_host_file_cmd=func_convert_file_nix_to_cygwin
+        ;;
+    esac
+    ;;
+  * ) # unhandled hosts (and "normal" native builds)
+    lt_cv_to_host_file_cmd=func_convert_file_noop
+    ;;
+esac
+
+fi
+
+to_host_file_cmd=$lt_cv_to_host_file_cmd
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_to_host_file_cmd" >&5
+$as_echo "$lt_cv_to_host_file_cmd" >&6; }
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to convert $build file names to toolchain format" >&5
+$as_echo_n "checking how to convert $build file names to toolchain format... " >&6; }
+if ${lt_cv_to_tool_file_cmd+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  #assume ordinary cross tools, or native build.
+lt_cv_to_tool_file_cmd=func_convert_file_noop
+case $host in
+  *-*-mingw* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_tool_file_cmd=func_convert_file_msys_to_w32
+        ;;
+    esac
+    ;;
+esac
+
+fi
+
+to_tool_file_cmd=$lt_cv_to_tool_file_cmd
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_to_tool_file_cmd" >&5
+$as_echo "$lt_cv_to_tool_file_cmd" >&6; }
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $LD option to reload object files" >&5
+$as_echo_n "checking for $LD option to reload object files... " >&6; }
+if ${lt_cv_ld_reload_flag+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_ld_reload_flag='-r'
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_ld_reload_flag" >&5
+$as_echo "$lt_cv_ld_reload_flag" >&6; }
+reload_flag=$lt_cv_ld_reload_flag
+case $reload_flag in
+"" | " "*) ;;
+*) reload_flag=" $reload_flag" ;;
+esac
+reload_cmds='$LD$reload_flag -o $output$reload_objs'
+case $host_os in
+  cygwin* | mingw* | pw32* | cegcc*)
+    if test "$GCC" != yes; then
+      reload_cmds=false
+    fi
+    ;;
+  darwin*)
+    if test "$GCC" = yes; then
+      reload_cmds='$LTCC $LTCFLAGS -nostdlib ${wl}-r -o $output$reload_objs'
+    else
+      reload_cmds='$LD$reload_flag -o $output$reload_objs'
+    fi
+    ;;
+esac
+
+
+
+
+
+
+
+
+
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}objdump", so it can be a program name with args.
+set dummy ${ac_tool_prefix}objdump; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_OBJDUMP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$OBJDUMP"; then
+  ac_cv_prog_OBJDUMP="$OBJDUMP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_OBJDUMP="${ac_tool_prefix}objdump"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+OBJDUMP=$ac_cv_prog_OBJDUMP
+if test -n "$OBJDUMP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $OBJDUMP" >&5
+$as_echo "$OBJDUMP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_OBJDUMP"; then
+  ac_ct_OBJDUMP=$OBJDUMP
+  # Extract the first word of "objdump", so it can be a program name with args.
+set dummy objdump; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_OBJDUMP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_OBJDUMP"; then
+  ac_cv_prog_ac_ct_OBJDUMP="$ac_ct_OBJDUMP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_OBJDUMP="objdump"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_OBJDUMP=$ac_cv_prog_ac_ct_OBJDUMP
+if test -n "$ac_ct_OBJDUMP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_OBJDUMP" >&5
+$as_echo "$ac_ct_OBJDUMP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_OBJDUMP" = x; then
+    OBJDUMP="false"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    OBJDUMP=$ac_ct_OBJDUMP
+  fi
+else
+  OBJDUMP="$ac_cv_prog_OBJDUMP"
+fi
+
+test -z "$OBJDUMP" && OBJDUMP=objdump
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to recognize dependent libraries" >&5
+$as_echo_n "checking how to recognize dependent libraries... " >&6; }
+if ${lt_cv_deplibs_check_method+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_file_magic_cmd='$MAGIC_CMD'
+lt_cv_file_magic_test_file=
+lt_cv_deplibs_check_method='unknown'
+# Need to set the preceding variable on all platforms that support
+# interlibrary dependencies.
+# 'none' -- dependencies not supported.
+# `unknown' -- same as none, but documents that we really don't know.
+# 'pass_all' -- all dependencies passed with no checks.
+# 'test_compile' -- check by making test program.
+# 'file_magic [[regex]]' -- check by looking for files in library path
+# which responds to the $file_magic_cmd with a given extended regex.
+# If you have `file' or equivalent on your system and you're not sure
+# whether `pass_all' will *always* work, you probably want this one.
+
+case $host_os in
+aix[4-9]*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+beos*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+bsdi[45]*)
+  lt_cv_deplibs_check_method='file_magic ELF [0-9][0-9]*-bit [ML]SB (shared object|dynamic lib)'
+  lt_cv_file_magic_cmd='/usr/bin/file -L'
+  lt_cv_file_magic_test_file=/shlib/libc.so
+  ;;
+
+cygwin*)
+  # func_win32_libid is a shell function defined in ltmain.sh
+  lt_cv_deplibs_check_method='file_magic ^x86 archive import|^x86 DLL'
+  lt_cv_file_magic_cmd='func_win32_libid'
+  ;;
+
+mingw* | pw32*)
+  # Base MSYS/MinGW do not provide the 'file' command needed by
+  # func_win32_libid shell function, so use a weaker test based on 'objdump',
+  # unless we find 'file', for example because we are cross-compiling.
+  # func_win32_libid assumes BSD nm, so disallow it if using MS dumpbin.
+  if ( test "$lt_cv_nm_interface" = "BSD nm" && file / ) >/dev/null 2>&1; then
+    lt_cv_deplibs_check_method='file_magic ^x86 archive import|^x86 DLL'
+    lt_cv_file_magic_cmd='func_win32_libid'
+  else
+    # Keep this pattern in sync with the one in func_win32_libid.
+    lt_cv_deplibs_check_method='file_magic file format (pei*-i386(.*architecture: i386)?|pe-arm-wince|pe-x86-64)'
+    lt_cv_file_magic_cmd='$OBJDUMP -f'
+  fi
+  ;;
+
+cegcc*)
+  # use the weaker test based on 'objdump'. See mingw*.
+  lt_cv_deplibs_check_method='file_magic file format pe-arm-.*little(.*architecture: arm)?'
+  lt_cv_file_magic_cmd='$OBJDUMP -f'
+  ;;
+
+darwin* | rhapsody*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+freebsd* | dragonfly*)
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ > /dev/null; then
+    case $host_cpu in
+    i*86 )
+      # Not sure whether the presence of OpenBSD here was a mistake.
+      # Let's accept both of them until this is cleared up.
+      lt_cv_deplibs_check_method='file_magic (FreeBSD|OpenBSD|DragonFly)/i[3-9]86 (compact )?demand paged shared library'
+      lt_cv_file_magic_cmd=/usr/bin/file
+      lt_cv_file_magic_test_file=`echo /usr/lib/libc.so.*`
+      ;;
+    esac
+  else
+    lt_cv_deplibs_check_method=pass_all
+  fi
+  ;;
+
+haiku*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+hpux10.20* | hpux11*)
+  lt_cv_file_magic_cmd=/usr/bin/file
+  case $host_cpu in
+  ia64*)
+    lt_cv_deplibs_check_method='file_magic (s[0-9][0-9][0-9]|ELF-[0-9][0-9]) shared object file - IA64'
+    lt_cv_file_magic_test_file=/usr/lib/hpux32/libc.so
+    ;;
+  hppa*64*)
+    lt_cv_deplibs_check_method='file_magic (s[0-9][0-9][0-9]|ELF[ -][0-9][0-9])(-bit)?( [LM]SB)? shared object( file)?[, -]* PA-RISC [0-9]\.[0-9]'
+    lt_cv_file_magic_test_file=/usr/lib/pa20_64/libc.sl
+    ;;
+  *)
+    lt_cv_deplibs_check_method='file_magic (s[0-9][0-9][0-9]|PA-RISC[0-9]\.[0-9]) shared library'
+    lt_cv_file_magic_test_file=/usr/lib/libc.sl
+    ;;
+  esac
+  ;;
+
+interix[3-9]*)
+  # PIC code is broken on Interix 3.x, that's why |\.a not |_pic\.a here
+  lt_cv_deplibs_check_method='match_pattern /lib[^/]+(\.so|\.a)$'
+  ;;
+
+irix5* | irix6* | nonstopux*)
+  case $LD in
+  *-32|*"-32 ") libmagic=32-bit;;
+  *-n32|*"-n32 ") libmagic=N32;;
+  *-64|*"-64 ") libmagic=64-bit;;
+  *) libmagic=never-match;;
+  esac
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+# This must be glibc/ELF.
+linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+netbsd* | netbsdelf*-gnu)
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ > /dev/null; then
+    lt_cv_deplibs_check_method='match_pattern /lib[^/]+(\.so\.[0-9]+\.[0-9]+|_pic\.a)$'
+  else
+    lt_cv_deplibs_check_method='match_pattern /lib[^/]+(\.so|_pic\.a)$'
+  fi
+  ;;
+
+newos6*)
+  lt_cv_deplibs_check_method='file_magic ELF [0-9][0-9]*-bit [ML]SB (executable|dynamic lib)'
+  lt_cv_file_magic_cmd=/usr/bin/file
+  lt_cv_file_magic_test_file=/usr/lib/libnls.so
+  ;;
+
+*nto* | *qnx*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+openbsd*)
+  if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+    lt_cv_deplibs_check_method='match_pattern /lib[^/]+(\.so\.[0-9]+\.[0-9]+|\.so|_pic\.a)$'
+  else
+    lt_cv_deplibs_check_method='match_pattern /lib[^/]+(\.so\.[0-9]+\.[0-9]+|_pic\.a)$'
+  fi
+  ;;
+
+osf3* | osf4* | osf5*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+rdos*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+solaris*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX* | sysv4*uw2*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+sysv4 | sysv4.3*)
+  case $host_vendor in
+  motorola)
+    lt_cv_deplibs_check_method='file_magic ELF [0-9][0-9]*-bit [ML]SB (shared object|dynamic lib) M[0-9][0-9]* Version [0-9]'
+    lt_cv_file_magic_test_file=`echo /usr/lib/libc.so*`
+    ;;
+  ncr)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  sequent)
+    lt_cv_file_magic_cmd='/bin/file'
+    lt_cv_deplibs_check_method='file_magic ELF [0-9][0-9]*-bit [LM]SB (shared object|dynamic lib )'
+    ;;
+  sni)
+    lt_cv_file_magic_cmd='/bin/file'
+    lt_cv_deplibs_check_method="file_magic ELF [0-9][0-9]*-bit [LM]SB dynamic lib"
+    lt_cv_file_magic_test_file=/lib/libc.so
+    ;;
+  siemens)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  pc)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  esac
+  ;;
+
+tpf*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+esac
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_deplibs_check_method" >&5
+$as_echo "$lt_cv_deplibs_check_method" >&6; }
+
+file_magic_glob=
+want_nocaseglob=no
+if test "$build" = "$host"; then
+  case $host_os in
+  mingw* | pw32*)
+    if ( shopt | grep nocaseglob ) >/dev/null 2>&1; then
+      want_nocaseglob=yes
+    else
+      file_magic_glob=`echo aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ | $SED -e "s/\(..\)/s\/[\1]\/[\1]\/g;/g"`
+    fi
+    ;;
+  esac
+fi
+
+file_magic_cmd=$lt_cv_file_magic_cmd
+deplibs_check_method=$lt_cv_deplibs_check_method
+test -z "$deplibs_check_method" && deplibs_check_method=unknown
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}dlltool", so it can be a program name with args.
+set dummy ${ac_tool_prefix}dlltool; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_DLLTOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$DLLTOOL"; then
+  ac_cv_prog_DLLTOOL="$DLLTOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_DLLTOOL="${ac_tool_prefix}dlltool"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+DLLTOOL=$ac_cv_prog_DLLTOOL
+if test -n "$DLLTOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $DLLTOOL" >&5
+$as_echo "$DLLTOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_DLLTOOL"; then
+  ac_ct_DLLTOOL=$DLLTOOL
+  # Extract the first word of "dlltool", so it can be a program name with args.
+set dummy dlltool; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_DLLTOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_DLLTOOL"; then
+  ac_cv_prog_ac_ct_DLLTOOL="$ac_ct_DLLTOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_DLLTOOL="dlltool"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_DLLTOOL=$ac_cv_prog_ac_ct_DLLTOOL
+if test -n "$ac_ct_DLLTOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_DLLTOOL" >&5
+$as_echo "$ac_ct_DLLTOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_DLLTOOL" = x; then
+    DLLTOOL="false"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    DLLTOOL=$ac_ct_DLLTOOL
+  fi
+else
+  DLLTOOL="$ac_cv_prog_DLLTOOL"
+fi
+
+test -z "$DLLTOOL" && DLLTOOL=dlltool
+
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to associate runtime and link libraries" >&5
+$as_echo_n "checking how to associate runtime and link libraries... " >&6; }
+if ${lt_cv_sharedlib_from_linklib_cmd+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_sharedlib_from_linklib_cmd='unknown'
+
+case $host_os in
+cygwin* | mingw* | pw32* | cegcc*)
+  # two different shell functions defined in ltmain.sh
+  # decide which to use based on capabilities of $DLLTOOL
+  case `$DLLTOOL --help 2>&1` in
+  *--identify-strict*)
+    lt_cv_sharedlib_from_linklib_cmd=func_cygming_dll_for_implib
+    ;;
+  *)
+    lt_cv_sharedlib_from_linklib_cmd=func_cygming_dll_for_implib_fallback
+    ;;
+  esac
+  ;;
+*)
+  # fallback: assume linklib IS sharedlib
+  lt_cv_sharedlib_from_linklib_cmd="$ECHO"
+  ;;
+esac
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_sharedlib_from_linklib_cmd" >&5
+$as_echo "$lt_cv_sharedlib_from_linklib_cmd" >&6; }
+sharedlib_from_linklib_cmd=$lt_cv_sharedlib_from_linklib_cmd
+test -z "$sharedlib_from_linklib_cmd" && sharedlib_from_linklib_cmd=$ECHO
+
+
+
+
+
+
+
+if test -n "$ac_tool_prefix"; then
+  for ac_prog in ar
+  do
+    # Extract the first word of "$ac_tool_prefix$ac_prog", so it can be a program name with args.
+set dummy $ac_tool_prefix$ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_AR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$AR"; then
+  ac_cv_prog_AR="$AR" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_AR="$ac_tool_prefix$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+AR=$ac_cv_prog_AR
+if test -n "$AR"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $AR" >&5
+$as_echo "$AR" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+    test -n "$AR" && break
+  done
+fi
+if test -z "$AR"; then
+  ac_ct_AR=$AR
+  for ac_prog in ar
+do
+  # Extract the first word of "$ac_prog", so it can be a program name with args.
+set dummy $ac_prog; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_AR+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_AR"; then
+  ac_cv_prog_ac_ct_AR="$ac_ct_AR" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_AR="$ac_prog"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_AR=$ac_cv_prog_ac_ct_AR
+if test -n "$ac_ct_AR"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_AR" >&5
+$as_echo "$ac_ct_AR" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  test -n "$ac_ct_AR" && break
+done
+
+  if test "x$ac_ct_AR" = x; then
+    AR="false"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    AR=$ac_ct_AR
+  fi
+fi
+
+: ${AR=ar}
+: ${AR_FLAGS=cru}
+
+
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for archiver @FILE support" >&5
+$as_echo_n "checking for archiver @FILE support... " >&6; }
+if ${lt_cv_ar_at_file+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_ar_at_file=no
+   cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  echo conftest.$ac_objext > conftest.lst
+      lt_ar_try='$AR $AR_FLAGS libconftest.a @conftest.lst >&5'
+      { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$lt_ar_try\""; } >&5
+  (eval $lt_ar_try) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+      if test "$ac_status" -eq 0; then
+	# Ensure the archiver fails upon bogus file names.
+	rm -f conftest.$ac_objext libconftest.a
+	{ { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$lt_ar_try\""; } >&5
+  (eval $lt_ar_try) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+	if test "$ac_status" -ne 0; then
+          lt_cv_ar_at_file=@
+        fi
+      fi
+      rm -f conftest.* libconftest.a
+
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_ar_at_file" >&5
+$as_echo "$lt_cv_ar_at_file" >&6; }
+
+if test "x$lt_cv_ar_at_file" = xno; then
+  archiver_list_spec=
+else
+  archiver_list_spec=$lt_cv_ar_at_file
+fi
+
+
+
+
+
+
+
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}strip", so it can be a program name with args.
+set dummy ${ac_tool_prefix}strip; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_STRIP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$STRIP"; then
+  ac_cv_prog_STRIP="$STRIP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_STRIP="${ac_tool_prefix}strip"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+STRIP=$ac_cv_prog_STRIP
+if test -n "$STRIP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $STRIP" >&5
+$as_echo "$STRIP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_STRIP"; then
+  ac_ct_STRIP=$STRIP
+  # Extract the first word of "strip", so it can be a program name with args.
+set dummy strip; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_STRIP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_STRIP"; then
+  ac_cv_prog_ac_ct_STRIP="$ac_ct_STRIP" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_STRIP="strip"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_STRIP=$ac_cv_prog_ac_ct_STRIP
+if test -n "$ac_ct_STRIP"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_STRIP" >&5
+$as_echo "$ac_ct_STRIP" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_STRIP" = x; then
+    STRIP=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    STRIP=$ac_ct_STRIP
+  fi
+else
+  STRIP="$ac_cv_prog_STRIP"
+fi
+
+test -z "$STRIP" && STRIP=:
+
+
+
+
+
+
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}ranlib", so it can be a program name with args.
+set dummy ${ac_tool_prefix}ranlib; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_RANLIB+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$RANLIB"; then
+  ac_cv_prog_RANLIB="$RANLIB" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_RANLIB="${ac_tool_prefix}ranlib"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+RANLIB=$ac_cv_prog_RANLIB
+if test -n "$RANLIB"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $RANLIB" >&5
+$as_echo "$RANLIB" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_RANLIB"; then
+  ac_ct_RANLIB=$RANLIB
+  # Extract the first word of "ranlib", so it can be a program name with args.
+set dummy ranlib; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_RANLIB+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_RANLIB"; then
+  ac_cv_prog_ac_ct_RANLIB="$ac_ct_RANLIB" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_RANLIB="ranlib"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_RANLIB=$ac_cv_prog_ac_ct_RANLIB
+if test -n "$ac_ct_RANLIB"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_RANLIB" >&5
+$as_echo "$ac_ct_RANLIB" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_RANLIB" = x; then
+    RANLIB=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    RANLIB=$ac_ct_RANLIB
+  fi
+else
+  RANLIB="$ac_cv_prog_RANLIB"
+fi
+
+test -z "$RANLIB" && RANLIB=:
+
+
+
+
+
+
+# Determine commands to create old-style static archives.
+old_archive_cmds='$AR $AR_FLAGS $oldlib$oldobjs'
+old_postinstall_cmds='chmod 644 $oldlib'
+old_postuninstall_cmds=
+
+if test -n "$RANLIB"; then
+  case $host_os in
+  openbsd*)
+    old_postinstall_cmds="$old_postinstall_cmds~\$RANLIB -t \$tool_oldlib"
+    ;;
+  *)
+    old_postinstall_cmds="$old_postinstall_cmds~\$RANLIB \$tool_oldlib"
+    ;;
+  esac
+  old_archive_cmds="$old_archive_cmds~\$RANLIB \$tool_oldlib"
+fi
+
+case $host_os in
+  darwin*)
+    lock_old_archive_extraction=yes ;;
+  *)
+    lock_old_archive_extraction=no ;;
+esac
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+# If no C compiler was specified, use CC.
+LTCC=${LTCC-"$CC"}
+
+# If no C compiler flags were specified, use CFLAGS.
+LTCFLAGS=${LTCFLAGS-"$CFLAGS"}
+
+# Allow CC to be a program name with arguments.
+compiler=$CC
+
+
+# Check for command to grab the raw symbol name followed by C symbol from nm.
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking command to parse $NM output from $compiler object" >&5
+$as_echo_n "checking command to parse $NM output from $compiler object... " >&6; }
+if ${lt_cv_sys_global_symbol_pipe+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+
+# These are sane defaults that work on at least a few old systems.
+# [They come from Ultrix.  What could be older than Ultrix?!! ;)]
+
+# Character class describing NM global symbol codes.
+symcode='[BCDEGRST]'
+
+# Regexp to match symbols that can be accessed directly from C.
+sympat='\([_A-Za-z][_A-Za-z0-9]*\)'
+
+# Define system-specific variables.
+case $host_os in
+aix*)
+  symcode='[BCDT]'
+  ;;
+cygwin* | mingw* | pw32* | cegcc*)
+  symcode='[ABCDGISTW]'
+  ;;
+hpux*)
+  if test "$host_cpu" = ia64; then
+    symcode='[ABCDEGRST]'
+  fi
+  ;;
+irix* | nonstopux*)
+  symcode='[BCDEGRST]'
+  ;;
+osf*)
+  symcode='[BCDEGQRST]'
+  ;;
+solaris*)
+  symcode='[BDRT]'
+  ;;
+sco3.2v5*)
+  symcode='[DT]'
+  ;;
+sysv4.2uw2*)
+  symcode='[DT]'
+  ;;
+sysv5* | sco5v6* | unixware* | OpenUNIX*)
+  symcode='[ABDT]'
+  ;;
+sysv4)
+  symcode='[DFNSTU]'
+  ;;
+esac
+
+# If we're using GNU nm, then use its standard symbol codes.
+case `$NM -V 2>&1` in
+*GNU* | *'with BFD'*)
+  symcode='[ABCDGIRSTW]' ;;
+esac
+
+# Transform an extracted symbol line into a proper C declaration.
+# Some systems (esp. on ia64) link data and code symbols differently,
+# so use this general approach.
+lt_cv_sys_global_symbol_to_cdecl="sed -n -e 's/^T .* \(.*\)$/extern int \1();/p' -e 's/^$symcode* .* \(.*\)$/extern char \1;/p'"
+
+# Transform an extracted symbol line into symbol name and symbol address
+lt_cv_sys_global_symbol_to_c_name_address="sed -n -e 's/^: \([^ ]*\)[ ]*$/  {\\\"\1\\\", (void *) 0},/p' -e 's/^$symcode* \([^ ]*\) \([^ ]*\)$/  {\"\2\", (void *) \&\2},/p'"
+lt_cv_sys_global_symbol_to_c_name_address_lib_prefix="sed -n -e 's/^: \([^ ]*\)[ ]*$/  {\\\"\1\\\", (void *) 0},/p' -e 's/^$symcode* \([^ ]*\) \(lib[^ ]*\)$/  {\"\2\", (void *) \&\2},/p' -e 's/^$symcode* \([^ ]*\) \([^ ]*\)$/  {\"lib\2\", (void *) \&\2},/p'"
+
+# Handle CRLF in mingw tool chain
+opt_cr=
+case $build_os in
+mingw*)
+  opt_cr=`$ECHO 'x\{0,1\}' | tr x '\015'` # option cr in regexp
+  ;;
+esac
+
+# Try without a prefix underscore, then with it.
+for ac_symprfx in "" "_"; do
+
+  # Transform symcode, sympat, and symprfx into a raw symbol and a C symbol.
+  symxfrm="\\1 $ac_symprfx\\2 \\2"
+
+  # Write the raw and C identifiers.
+  if test "$lt_cv_nm_interface" = "MS dumpbin"; then
+    # Fake it for dumpbin and say T for any non-static function
+    # and D for any global variable.
+    # Also find C++ and __fastcall symbols from MSVC++,
+    # which start with @ or ?.
+    lt_cv_sys_global_symbol_pipe="$AWK '"\
+"     {last_section=section; section=\$ 3};"\
+"     /^COFF SYMBOL TABLE/{for(i in hide) delete hide[i]};"\
+"     /Section length .*#relocs.*(pick any)/{hide[last_section]=1};"\
+"     \$ 0!~/External *\|/{next};"\
+"     / 0+ UNDEF /{next}; / UNDEF \([^|]\)*()/{next};"\
+"     {if(hide[section]) next};"\
+"     {f=0}; \$ 0~/\(\).*\|/{f=1}; {printf f ? \"T \" : \"D \"};"\
+"     {split(\$ 0, a, /\||\r/); split(a[2], s)};"\
+"     s[1]~/^[@?]/{print s[1], s[1]; next};"\
+"     s[1]~prfx {split(s[1],t,\"@\"); print t[1], substr(t[1],length(prfx))}"\
+"     ' prfx=^$ac_symprfx"
+  else
+    lt_cv_sys_global_symbol_pipe="sed -n -e 's/^.*[	 ]\($symcode$symcode*\)[	 ][	 ]*$ac_symprfx$sympat$opt_cr$/$symxfrm/p'"
+  fi
+  lt_cv_sys_global_symbol_pipe="$lt_cv_sys_global_symbol_pipe | sed '/ __gnu_lto/d'"
+
+  # Check to see that the pipe works correctly.
+  pipe_works=no
+
+  rm -f conftest*
+  cat > conftest.$ac_ext <<_LT_EOF
+#ifdef __cplusplus
+extern "C" {
+#endif
+char nm_test_var;
+void nm_test_func(void);
+void nm_test_func(void){}
+#ifdef __cplusplus
+}
+#endif
+int main(){nm_test_var='a';nm_test_func();return(0);}
+_LT_EOF
+
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then
+    # Now try to grab the symbols.
+    nlist=conftest.nm
+    if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$NM conftest.$ac_objext \| "$lt_cv_sys_global_symbol_pipe" \> $nlist\""; } >&5
+  (eval $NM conftest.$ac_objext \| "$lt_cv_sys_global_symbol_pipe" \> $nlist) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && test -s "$nlist"; then
+      # Try sorting and uniquifying the output.
+      if sort "$nlist" | uniq > "$nlist"T; then
+	mv -f "$nlist"T "$nlist"
+      else
+	rm -f "$nlist"T
+      fi
+
+      # Make sure that we snagged all the symbols we need.
+      if $GREP ' nm_test_var$' "$nlist" >/dev/null; then
+	if $GREP ' nm_test_func$' "$nlist" >/dev/null; then
+	  cat <<_LT_EOF > conftest.$ac_ext
+/* Keep this code in sync between libtool.m4, ltmain, lt_system.h, and tests.  */
+#if defined(_WIN32) || defined(__CYGWIN__) || defined(_WIN32_WCE)
+/* DATA imports from DLLs on WIN32 con't be const, because runtime
+   relocations are performed -- see ld's documentation on pseudo-relocs.  */
+# define LT_DLSYM_CONST
+#elif defined(__osf__)
+/* This system does not cope well with relocations in const data.  */
+# define LT_DLSYM_CONST
+#else
+# define LT_DLSYM_CONST const
+#endif
+
+#ifdef __cplusplus
+extern "C" {
+#endif
+
+_LT_EOF
+	  # Now generate the symbol file.
+	  eval "$lt_cv_sys_global_symbol_to_cdecl"' < "$nlist" | $GREP -v main >> conftest.$ac_ext'
+
+	  cat <<_LT_EOF >> conftest.$ac_ext
+
+/* The mapping between symbol names and symbols.  */
+LT_DLSYM_CONST struct {
+  const char *name;
+  void       *address;
+}
+lt__PROGRAM__LTX_preloaded_symbols[] =
+{
+  { "@PROGRAM@", (void *) 0 },
+_LT_EOF
+	  $SED "s/^$symcode$symcode* \(.*\) \(.*\)$/  {\"\2\", (void *) \&\2},/" < "$nlist" | $GREP -v main >> conftest.$ac_ext
+	  cat <<\_LT_EOF >> conftest.$ac_ext
+  {0, (void *) 0}
+};
+
+/* This works around a problem in FreeBSD linker */
+#ifdef FREEBSD_WORKAROUND
+static const void *lt_preloaded_setup() {
+  return lt__PROGRAM__LTX_preloaded_symbols;
+}
+#endif
+
+#ifdef __cplusplus
+}
+#endif
+_LT_EOF
+	  # Now try linking the two files.
+	  mv conftest.$ac_objext conftstm.$ac_objext
+	  lt_globsym_save_LIBS=$LIBS
+	  lt_globsym_save_CFLAGS=$CFLAGS
+	  LIBS="conftstm.$ac_objext"
+	  CFLAGS="$CFLAGS$lt_prog_compiler_no_builtin_flag"
+	  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_link\""; } >&5
+  (eval $ac_link) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && test -s conftest${ac_exeext}; then
+	    pipe_works=yes
+	  fi
+	  LIBS=$lt_globsym_save_LIBS
+	  CFLAGS=$lt_globsym_save_CFLAGS
+	else
+	  echo "cannot find nm_test_func in $nlist" >&5
+	fi
+      else
+	echo "cannot find nm_test_var in $nlist" >&5
+      fi
+    else
+      echo "cannot run $lt_cv_sys_global_symbol_pipe" >&5
+    fi
+  else
+    echo "$progname: failed program was:" >&5
+    cat conftest.$ac_ext >&5
+  fi
+  rm -rf conftest* conftst*
+
+  # Do not use the global_symbol_pipe unless it works.
+  if test "$pipe_works" = yes; then
+    break
+  else
+    lt_cv_sys_global_symbol_pipe=
+  fi
+done
+
+fi
+
+if test -z "$lt_cv_sys_global_symbol_pipe"; then
+  lt_cv_sys_global_symbol_to_cdecl=
+fi
+if test -z "$lt_cv_sys_global_symbol_pipe$lt_cv_sys_global_symbol_to_cdecl"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: failed" >&5
+$as_echo "failed" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: ok" >&5
+$as_echo "ok" >&6; }
+fi
+
+# Response file support.
+if test "$lt_cv_nm_interface" = "MS dumpbin"; then
+  nm_file_list_spec='@'
+elif $NM --help 2>/dev/null | grep '[@]FILE' >/dev/null; then
+  nm_file_list_spec='@'
+fi
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for sysroot" >&5
+$as_echo_n "checking for sysroot... " >&6; }
+
+# Check whether --with-sysroot was given.
+if test "${with_sysroot+set}" = set; then :
+  withval=$with_sysroot;
+else
+  with_sysroot=no
+fi
+
+
+lt_sysroot=
+case ${with_sysroot} in #(
+ yes)
+   if test "$GCC" = yes; then
+     lt_sysroot=`$CC --print-sysroot 2>/dev/null`
+   fi
+   ;; #(
+ /*)
+   lt_sysroot=`echo "$with_sysroot" | sed -e "$sed_quote_subst"`
+   ;; #(
+ no|'')
+   ;; #(
+ *)
+   { $as_echo "$as_me:${as_lineno-$LINENO}: result: ${with_sysroot}" >&5
+$as_echo "${with_sysroot}" >&6; }
+   as_fn_error $? "The sysroot must be an absolute path." "$LINENO" 5
+   ;;
+esac
+
+ { $as_echo "$as_me:${as_lineno-$LINENO}: result: ${lt_sysroot:-no}" >&5
+$as_echo "${lt_sysroot:-no}" >&6; }
+
+
+
+
+
+# Check whether --enable-libtool-lock was given.
+if test "${enable_libtool_lock+set}" = set; then :
+  enableval=$enable_libtool_lock;
+fi
+
+test "x$enable_libtool_lock" != xno && enable_libtool_lock=yes
+
+# Some flags need to be propagated to the compiler or linker for good
+# libtool support.
+case $host in
+ia64-*-hpux*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then
+    case `/usr/bin/file conftest.$ac_objext` in
+      *ELF-32*)
+	HPUX_IA64_MODE="32"
+	;;
+      *ELF-64*)
+	HPUX_IA64_MODE="64"
+	;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+*-*-irix6*)
+  # Find out which ABI we are using.
+  echo '#line '$LINENO' "configure"' > conftest.$ac_ext
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then
+    if test "$lt_cv_prog_gnu_ld" = yes; then
+      case `/usr/bin/file conftest.$ac_objext` in
+	*32-bit*)
+	  LD="${LD-ld} -melf32bsmip"
+	  ;;
+	*N32*)
+	  LD="${LD-ld} -melf32bmipn32"
+	  ;;
+	*64-bit*)
+	  LD="${LD-ld} -melf64bmip"
+	;;
+      esac
+    else
+      case `/usr/bin/file conftest.$ac_objext` in
+	*32-bit*)
+	  LD="${LD-ld} -32"
+	  ;;
+	*N32*)
+	  LD="${LD-ld} -n32"
+	  ;;
+	*64-bit*)
+	  LD="${LD-ld} -64"
+	  ;;
+      esac
+    fi
+  fi
+  rm -rf conftest*
+  ;;
+
+x86_64-*kfreebsd*-gnu|x86_64-*linux*|powerpc*-*linux*| \
+s390*-*linux*|s390*-*tpf*|sparc*-*linux*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then
+    case `/usr/bin/file conftest.o` in
+      *32-bit*)
+	case $host in
+	  x86_64-*kfreebsd*-gnu)
+	    LD="${LD-ld} -m elf_i386_fbsd"
+	    ;;
+	  x86_64-*linux*)
+	    case `/usr/bin/file conftest.o` in
+	      *x86-64*)
+		LD="${LD-ld} -m elf32_x86_64"
+		;;
+	      *)
+		LD="${LD-ld} -m elf_i386"
+		;;
+	    esac
+	    ;;
+	  powerpc64le-*)
+	    LD="${LD-ld} -m elf32lppclinux"
+	    ;;
+	  powerpc64-*)
+	    LD="${LD-ld} -m elf32ppclinux"
+	    ;;
+	  s390x-*linux*)
+	    LD="${LD-ld} -m elf_s390"
+	    ;;
+	  sparc64-*linux*)
+	    LD="${LD-ld} -m elf32_sparc"
+	    ;;
+	esac
+	;;
+      *64-bit*)
+	case $host in
+	  x86_64-*kfreebsd*-gnu)
+	    LD="${LD-ld} -m elf_x86_64_fbsd"
+	    ;;
+	  x86_64-*linux*)
+	    LD="${LD-ld} -m elf_x86_64"
+	    ;;
+	  powerpcle-*)
+	    LD="${LD-ld} -m elf64lppc"
+	    ;;
+	  powerpc-*)
+	    LD="${LD-ld} -m elf64ppc"
+	    ;;
+	  s390*-*linux*|s390*-*tpf*)
+	    LD="${LD-ld} -m elf64_s390"
+	    ;;
+	  sparc*-*linux*)
+	    LD="${LD-ld} -m elf64_sparc"
+	    ;;
+	esac
+	;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+
+*-*-sco3.2v5*)
+  # On SCO OpenServer 5, we need -belf to get full-featured binaries.
+  SAVE_CFLAGS="$CFLAGS"
+  CFLAGS="$CFLAGS -belf"
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the C compiler needs -belf" >&5
+$as_echo_n "checking whether the C compiler needs -belf... " >&6; }
+if ${lt_cv_cc_needs_belf+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+     cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  lt_cv_cc_needs_belf=yes
+else
+  lt_cv_cc_needs_belf=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+     ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_cc_needs_belf" >&5
+$as_echo "$lt_cv_cc_needs_belf" >&6; }
+  if test x"$lt_cv_cc_needs_belf" != x"yes"; then
+    # this is probably gcc 2.8.0, egcs 1.0 or newer; no need for -belf
+    CFLAGS="$SAVE_CFLAGS"
+  fi
+  ;;
+*-*solaris*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }; then
+    case `/usr/bin/file conftest.o` in
+    *64-bit*)
+      case $lt_cv_prog_gnu_ld in
+      yes*)
+        case $host in
+        i?86-*-solaris*)
+          LD="${LD-ld} -m elf_x86_64"
+          ;;
+        sparc*-*-solaris*)
+          LD="${LD-ld} -m elf64_sparc"
+          ;;
+        esac
+        # GNU ld 2.21 introduced _sol2 emulations.  Use them if available.
+        if ${LD-ld} -V | grep _sol2 >/dev/null 2>&1; then
+          LD="${LD-ld}_sol2"
+        fi
+        ;;
+      *)
+	if ${LD-ld} -64 -r -o conftest2.o conftest.o >/dev/null 2>&1; then
+	  LD="${LD-ld} -64"
+	fi
+	;;
+      esac
+      ;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+esac
+
+need_locks="$enable_libtool_lock"
+
+if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}mt", so it can be a program name with args.
+set dummy ${ac_tool_prefix}mt; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_MANIFEST_TOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$MANIFEST_TOOL"; then
+  ac_cv_prog_MANIFEST_TOOL="$MANIFEST_TOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_MANIFEST_TOOL="${ac_tool_prefix}mt"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+MANIFEST_TOOL=$ac_cv_prog_MANIFEST_TOOL
+if test -n "$MANIFEST_TOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $MANIFEST_TOOL" >&5
+$as_echo "$MANIFEST_TOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_MANIFEST_TOOL"; then
+  ac_ct_MANIFEST_TOOL=$MANIFEST_TOOL
+  # Extract the first word of "mt", so it can be a program name with args.
+set dummy mt; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_MANIFEST_TOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_MANIFEST_TOOL"; then
+  ac_cv_prog_ac_ct_MANIFEST_TOOL="$ac_ct_MANIFEST_TOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_MANIFEST_TOOL="mt"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_MANIFEST_TOOL=$ac_cv_prog_ac_ct_MANIFEST_TOOL
+if test -n "$ac_ct_MANIFEST_TOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_MANIFEST_TOOL" >&5
+$as_echo "$ac_ct_MANIFEST_TOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_MANIFEST_TOOL" = x; then
+    MANIFEST_TOOL=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    MANIFEST_TOOL=$ac_ct_MANIFEST_TOOL
+  fi
+else
+  MANIFEST_TOOL="$ac_cv_prog_MANIFEST_TOOL"
+fi
+
+test -z "$MANIFEST_TOOL" && MANIFEST_TOOL=mt
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if $MANIFEST_TOOL is a manifest tool" >&5
+$as_echo_n "checking if $MANIFEST_TOOL is a manifest tool... " >&6; }
+if ${lt_cv_path_mainfest_tool+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_path_mainfest_tool=no
+  echo "$as_me:$LINENO: $MANIFEST_TOOL '-?'" >&5
+  $MANIFEST_TOOL '-?' 2>conftest.err > conftest.out
+  cat conftest.err >&5
+  if $GREP 'Manifest Tool' conftest.out > /dev/null; then
+    lt_cv_path_mainfest_tool=yes
+  fi
+  rm -f conftest*
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_path_mainfest_tool" >&5
+$as_echo "$lt_cv_path_mainfest_tool" >&6; }
+if test "x$lt_cv_path_mainfest_tool" != xyes; then
+  MANIFEST_TOOL=:
+fi
+
+
+
+
+
+
+  case $host_os in
+    rhapsody* | darwin*)
+    if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}dsymutil", so it can be a program name with args.
+set dummy ${ac_tool_prefix}dsymutil; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_DSYMUTIL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$DSYMUTIL"; then
+  ac_cv_prog_DSYMUTIL="$DSYMUTIL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_DSYMUTIL="${ac_tool_prefix}dsymutil"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+DSYMUTIL=$ac_cv_prog_DSYMUTIL
+if test -n "$DSYMUTIL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $DSYMUTIL" >&5
+$as_echo "$DSYMUTIL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_DSYMUTIL"; then
+  ac_ct_DSYMUTIL=$DSYMUTIL
+  # Extract the first word of "dsymutil", so it can be a program name with args.
+set dummy dsymutil; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_DSYMUTIL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_DSYMUTIL"; then
+  ac_cv_prog_ac_ct_DSYMUTIL="$ac_ct_DSYMUTIL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_DSYMUTIL="dsymutil"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_DSYMUTIL=$ac_cv_prog_ac_ct_DSYMUTIL
+if test -n "$ac_ct_DSYMUTIL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_DSYMUTIL" >&5
+$as_echo "$ac_ct_DSYMUTIL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_DSYMUTIL" = x; then
+    DSYMUTIL=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    DSYMUTIL=$ac_ct_DSYMUTIL
+  fi
+else
+  DSYMUTIL="$ac_cv_prog_DSYMUTIL"
+fi
+
+    if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}nmedit", so it can be a program name with args.
+set dummy ${ac_tool_prefix}nmedit; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_NMEDIT+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$NMEDIT"; then
+  ac_cv_prog_NMEDIT="$NMEDIT" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_NMEDIT="${ac_tool_prefix}nmedit"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+NMEDIT=$ac_cv_prog_NMEDIT
+if test -n "$NMEDIT"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $NMEDIT" >&5
+$as_echo "$NMEDIT" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_NMEDIT"; then
+  ac_ct_NMEDIT=$NMEDIT
+  # Extract the first word of "nmedit", so it can be a program name with args.
+set dummy nmedit; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_NMEDIT+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_NMEDIT"; then
+  ac_cv_prog_ac_ct_NMEDIT="$ac_ct_NMEDIT" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_NMEDIT="nmedit"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_NMEDIT=$ac_cv_prog_ac_ct_NMEDIT
+if test -n "$ac_ct_NMEDIT"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_NMEDIT" >&5
+$as_echo "$ac_ct_NMEDIT" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_NMEDIT" = x; then
+    NMEDIT=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    NMEDIT=$ac_ct_NMEDIT
+  fi
+else
+  NMEDIT="$ac_cv_prog_NMEDIT"
+fi
+
+    if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}lipo", so it can be a program name with args.
+set dummy ${ac_tool_prefix}lipo; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_LIPO+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$LIPO"; then
+  ac_cv_prog_LIPO="$LIPO" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_LIPO="${ac_tool_prefix}lipo"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+LIPO=$ac_cv_prog_LIPO
+if test -n "$LIPO"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $LIPO" >&5
+$as_echo "$LIPO" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_LIPO"; then
+  ac_ct_LIPO=$LIPO
+  # Extract the first word of "lipo", so it can be a program name with args.
+set dummy lipo; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_LIPO+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_LIPO"; then
+  ac_cv_prog_ac_ct_LIPO="$ac_ct_LIPO" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_LIPO="lipo"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_LIPO=$ac_cv_prog_ac_ct_LIPO
+if test -n "$ac_ct_LIPO"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_LIPO" >&5
+$as_echo "$ac_ct_LIPO" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_LIPO" = x; then
+    LIPO=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    LIPO=$ac_ct_LIPO
+  fi
+else
+  LIPO="$ac_cv_prog_LIPO"
+fi
+
+    if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}otool", so it can be a program name with args.
+set dummy ${ac_tool_prefix}otool; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_OTOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$OTOOL"; then
+  ac_cv_prog_OTOOL="$OTOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_OTOOL="${ac_tool_prefix}otool"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+OTOOL=$ac_cv_prog_OTOOL
+if test -n "$OTOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $OTOOL" >&5
+$as_echo "$OTOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_OTOOL"; then
+  ac_ct_OTOOL=$OTOOL
+  # Extract the first word of "otool", so it can be a program name with args.
+set dummy otool; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_OTOOL+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_OTOOL"; then
+  ac_cv_prog_ac_ct_OTOOL="$ac_ct_OTOOL" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_OTOOL="otool"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_OTOOL=$ac_cv_prog_ac_ct_OTOOL
+if test -n "$ac_ct_OTOOL"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_OTOOL" >&5
+$as_echo "$ac_ct_OTOOL" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_OTOOL" = x; then
+    OTOOL=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    OTOOL=$ac_ct_OTOOL
+  fi
+else
+  OTOOL="$ac_cv_prog_OTOOL"
+fi
+
+    if test -n "$ac_tool_prefix"; then
+  # Extract the first word of "${ac_tool_prefix}otool64", so it can be a program name with args.
+set dummy ${ac_tool_prefix}otool64; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_OTOOL64+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$OTOOL64"; then
+  ac_cv_prog_OTOOL64="$OTOOL64" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_OTOOL64="${ac_tool_prefix}otool64"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+OTOOL64=$ac_cv_prog_OTOOL64
+if test -n "$OTOOL64"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $OTOOL64" >&5
+$as_echo "$OTOOL64" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+fi
+if test -z "$ac_cv_prog_OTOOL64"; then
+  ac_ct_OTOOL64=$OTOOL64
+  # Extract the first word of "otool64", so it can be a program name with args.
+set dummy otool64; ac_word=$2
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $ac_word" >&5
+$as_echo_n "checking for $ac_word... " >&6; }
+if ${ac_cv_prog_ac_ct_OTOOL64+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  if test -n "$ac_ct_OTOOL64"; then
+  ac_cv_prog_ac_ct_OTOOL64="$ac_ct_OTOOL64" # Let the user override the test.
+else
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    for ac_exec_ext in '' $ac_executable_extensions; do
+  if as_fn_executable_p "$as_dir/$ac_word$ac_exec_ext"; then
+    ac_cv_prog_ac_ct_OTOOL64="otool64"
+    $as_echo "$as_me:${as_lineno-$LINENO}: found $as_dir/$ac_word$ac_exec_ext" >&5
+    break 2
+  fi
+done
+  done
+IFS=$as_save_IFS
+
+fi
+fi
+ac_ct_OTOOL64=$ac_cv_prog_ac_ct_OTOOL64
+if test -n "$ac_ct_OTOOL64"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_ct_OTOOL64" >&5
+$as_echo "$ac_ct_OTOOL64" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+  if test "x$ac_ct_OTOOL64" = x; then
+    OTOOL64=":"
+  else
+    case $cross_compiling:$ac_tool_warned in
+yes:)
+{ $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: using cross tools not prefixed with host triplet" >&5
+$as_echo "$as_me: WARNING: using cross tools not prefixed with host triplet" >&2;}
+ac_tool_warned=yes ;;
+esac
+    OTOOL64=$ac_ct_OTOOL64
+  fi
+else
+  OTOOL64="$ac_cv_prog_OTOOL64"
+fi
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for -single_module linker flag" >&5
+$as_echo_n "checking for -single_module linker flag... " >&6; }
+if ${lt_cv_apple_cc_single_mod+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_apple_cc_single_mod=no
+      if test -z "${LT_MULTI_MODULE}"; then
+	# By default we will add the -single_module flag. You can override
+	# by either setting the environment variable LT_MULTI_MODULE
+	# non-empty at configure time, or by adding -multi_module to the
+	# link flags.
+	rm -rf libconftest.dylib*
+	echo "int foo(void){return 1;}" > conftest.c
+	echo "$LTCC $LTCFLAGS $LDFLAGS -o libconftest.dylib \
+-dynamiclib -Wl,-single_module conftest.c" >&5
+	$LTCC $LTCFLAGS $LDFLAGS -o libconftest.dylib \
+	  -dynamiclib -Wl,-single_module conftest.c 2>conftest.err
+        _lt_result=$?
+	# If there is a non-empty error log, and "single_module"
+	# appears in it, assume the flag caused a linker warning
+        if test -s conftest.err && $GREP single_module conftest.err; then
+	  cat conftest.err >&5
+	# Otherwise, if the output was created with a 0 exit code from
+	# the compiler, it worked.
+	elif test -f libconftest.dylib && test $_lt_result -eq 0; then
+	  lt_cv_apple_cc_single_mod=yes
+	else
+	  cat conftest.err >&5
+	fi
+	rm -rf libconftest.dylib*
+	rm -f conftest.*
+      fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_apple_cc_single_mod" >&5
+$as_echo "$lt_cv_apple_cc_single_mod" >&6; }
+
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for -exported_symbols_list linker flag" >&5
+$as_echo_n "checking for -exported_symbols_list linker flag... " >&6; }
+if ${lt_cv_ld_exported_symbols_list+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_ld_exported_symbols_list=no
+      save_LDFLAGS=$LDFLAGS
+      echo "_main" > conftest.sym
+      LDFLAGS="$LDFLAGS -Wl,-exported_symbols_list,conftest.sym"
+      cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  lt_cv_ld_exported_symbols_list=yes
+else
+  lt_cv_ld_exported_symbols_list=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+	LDFLAGS="$save_LDFLAGS"
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_ld_exported_symbols_list" >&5
+$as_echo "$lt_cv_ld_exported_symbols_list" >&6; }
+
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for -force_load linker flag" >&5
+$as_echo_n "checking for -force_load linker flag... " >&6; }
+if ${lt_cv_ld_force_load+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_ld_force_load=no
+      cat > conftest.c << _LT_EOF
+int forced_loaded() { return 2;}
+_LT_EOF
+      echo "$LTCC $LTCFLAGS -c -o conftest.o conftest.c" >&5
+      $LTCC $LTCFLAGS -c -o conftest.o conftest.c 2>&5
+      echo "$AR cru libconftest.a conftest.o" >&5
+      $AR cru libconftest.a conftest.o 2>&5
+      echo "$RANLIB libconftest.a" >&5
+      $RANLIB libconftest.a 2>&5
+      cat > conftest.c << _LT_EOF
+int main() { return 0;}
+_LT_EOF
+      echo "$LTCC $LTCFLAGS $LDFLAGS -o conftest conftest.c -Wl,-force_load,./libconftest.a" >&5
+      $LTCC $LTCFLAGS $LDFLAGS -o conftest conftest.c -Wl,-force_load,./libconftest.a 2>conftest.err
+      _lt_result=$?
+      if test -s conftest.err && $GREP force_load conftest.err; then
+	cat conftest.err >&5
+      elif test -f conftest && test $_lt_result -eq 0 && $GREP forced_load conftest >/dev/null 2>&1 ; then
+	lt_cv_ld_force_load=yes
+      else
+	cat conftest.err >&5
+      fi
+        rm -f conftest.err libconftest.a conftest conftest.c
+        rm -rf conftest.dSYM
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_ld_force_load" >&5
+$as_echo "$lt_cv_ld_force_load" >&6; }
+    case $host_os in
+    rhapsody* | darwin1.[012])
+      _lt_dar_allow_undefined='${wl}-undefined ${wl}suppress' ;;
+    darwin1.*)
+      _lt_dar_allow_undefined='${wl}-flat_namespace ${wl}-undefined ${wl}suppress' ;;
+    darwin*) # darwin 5.x on
+      # if running on 10.5 or later, the deployment target defaults
+      # to the OS version, if on x86, and 10.4, the deployment
+      # target defaults to 10.4. Don't you love it?
+      case ${MACOSX_DEPLOYMENT_TARGET-10.0},$host in
+	10.0,*86*-darwin8*|10.0,*-darwin[91]*)
+	  _lt_dar_allow_undefined='${wl}-undefined ${wl}dynamic_lookup' ;;
+	10.[012]*)
+	  _lt_dar_allow_undefined='${wl}-flat_namespace ${wl}-undefined ${wl}suppress' ;;
+	10.*)
+	  _lt_dar_allow_undefined='${wl}-undefined ${wl}dynamic_lookup' ;;
+      esac
+    ;;
+  esac
+    if test "$lt_cv_apple_cc_single_mod" = "yes"; then
+      _lt_dar_single_mod='$single_module'
+    fi
+    if test "$lt_cv_ld_exported_symbols_list" = "yes"; then
+      _lt_dar_export_syms=' ${wl}-exported_symbols_list,$output_objdir/${libname}-symbols.expsym'
+    else
+      _lt_dar_export_syms='~$NMEDIT -s $output_objdir/${libname}-symbols.expsym ${lib}'
+    fi
+    if test "$DSYMUTIL" != ":" && test "$lt_cv_ld_force_load" = "no"; then
+      _lt_dsymutil='~$DSYMUTIL $lib || :'
+    else
+      _lt_dsymutil=
+    fi
+    ;;
+  esac
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking how to run the C preprocessor" >&5
+$as_echo_n "checking how to run the C preprocessor... " >&6; }
+# On Suns, sometimes $CPP names a directory.
+if test -n "$CPP" && test -d "$CPP"; then
+  CPP=
+fi
+if test -z "$CPP"; then
+  if ${ac_cv_prog_CPP+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+      # Double quotes because CPP needs to be expanded
+    for CPP in "$CC -E" "$CC -E -traditional-cpp" "/lib/cpp"
+    do
+      ac_preproc_ok=false
+for ac_c_preproc_warn_flag in '' yes
+do
+  # Use a header file that comes with gcc, so configuring glibc
+  # with a fresh cross-compiler works.
+  # Prefer <limits.h> to <assert.h> if __STDC__ is defined, since
+  # <limits.h> exists even on freestanding compilers.
+  # On the NeXT, cc -E runs the code through the compiler's parser,
+  # not just through cpp. "Syntax error" is here to catch this case.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#ifdef __STDC__
+# include <limits.h>
+#else
+# include <assert.h>
+#endif
+		     Syntax error
+_ACEOF
+if ac_fn_c_try_cpp "$LINENO"; then :
+
+else
+  # Broken: fails on valid input.
+continue
+fi
+rm -f conftest.err conftest.i conftest.$ac_ext
+
+  # OK, works on sane cases.  Now check whether nonexistent headers
+  # can be detected and how.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <ac_nonexistent.h>
+_ACEOF
+if ac_fn_c_try_cpp "$LINENO"; then :
+  # Broken: success on invalid input.
+continue
+else
+  # Passes both tests.
+ac_preproc_ok=:
+break
+fi
+rm -f conftest.err conftest.i conftest.$ac_ext
+
+done
+# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped.
+rm -f conftest.i conftest.err conftest.$ac_ext
+if $ac_preproc_ok; then :
+  break
+fi
+
+    done
+    ac_cv_prog_CPP=$CPP
+
+fi
+  CPP=$ac_cv_prog_CPP
+else
+  ac_cv_prog_CPP=$CPP
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $CPP" >&5
+$as_echo "$CPP" >&6; }
+ac_preproc_ok=false
+for ac_c_preproc_warn_flag in '' yes
+do
+  # Use a header file that comes with gcc, so configuring glibc
+  # with a fresh cross-compiler works.
+  # Prefer <limits.h> to <assert.h> if __STDC__ is defined, since
+  # <limits.h> exists even on freestanding compilers.
+  # On the NeXT, cc -E runs the code through the compiler's parser,
+  # not just through cpp. "Syntax error" is here to catch this case.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#ifdef __STDC__
+# include <limits.h>
+#else
+# include <assert.h>
+#endif
+		     Syntax error
+_ACEOF
+if ac_fn_c_try_cpp "$LINENO"; then :
+
+else
+  # Broken: fails on valid input.
+continue
+fi
+rm -f conftest.err conftest.i conftest.$ac_ext
+
+  # OK, works on sane cases.  Now check whether nonexistent headers
+  # can be detected and how.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <ac_nonexistent.h>
+_ACEOF
+if ac_fn_c_try_cpp "$LINENO"; then :
+  # Broken: success on invalid input.
+continue
+else
+  # Passes both tests.
+ac_preproc_ok=:
+break
+fi
+rm -f conftest.err conftest.i conftest.$ac_ext
+
+done
+# Because of `break', _AC_PREPROC_IFELSE's cleaning code was skipped.
+rm -f conftest.i conftest.err conftest.$ac_ext
+if $ac_preproc_ok; then :
+
+else
+  { { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5
+$as_echo "$as_me: error: in \`$ac_pwd':" >&2;}
+as_fn_error $? "C preprocessor \"$CPP\" fails sanity check
+See \`config.log' for more details" "$LINENO" 5; }
+fi
+
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for ANSI C header files" >&5
+$as_echo_n "checking for ANSI C header files... " >&6; }
+if ${ac_cv_header_stdc+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <stdlib.h>
+#include <stdarg.h>
+#include <string.h>
+#include <float.h>
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"; then :
+  ac_cv_header_stdc=yes
+else
+  ac_cv_header_stdc=no
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
+
+if test $ac_cv_header_stdc = yes; then
+  # SunOS 4.x string.h does not declare mem*, contrary to ANSI.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <string.h>
+
+_ACEOF
+if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
+  $EGREP "memchr" >/dev/null 2>&1; then :
+
+else
+  ac_cv_header_stdc=no
+fi
+rm -f conftest*
+
+fi
+
+if test $ac_cv_header_stdc = yes; then
+  # ISC 2.0.2 stdlib.h does not declare free, contrary to ANSI.
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <stdlib.h>
+
+_ACEOF
+if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
+  $EGREP "free" >/dev/null 2>&1; then :
+
+else
+  ac_cv_header_stdc=no
+fi
+rm -f conftest*
+
+fi
+
+if test $ac_cv_header_stdc = yes; then
+  # /bin/cc in Irix-4.0.5 gets non-ANSI ctype macros unless using -ansi.
+  if test "$cross_compiling" = yes; then :
+  :
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <ctype.h>
+#include <stdlib.h>
+#if ((' ' & 0x0FF) == 0x020)
+# define ISLOWER(c) ('a' <= (c) && (c) <= 'z')
+# define TOUPPER(c) (ISLOWER(c) ? 'A' + ((c) - 'a') : (c))
+#else
+# define ISLOWER(c) \
+		   (('a' <= (c) && (c) <= 'i') \
+		     || ('j' <= (c) && (c) <= 'r') \
+		     || ('s' <= (c) && (c) <= 'z'))
+# define TOUPPER(c) (ISLOWER(c) ? ((c) | 0x40) : (c))
+#endif
+
+#define XOR(e, f) (((e) && !(f)) || (!(e) && (f)))
+int
+main ()
+{
+  int i;
+  for (i = 0; i < 256; i++)
+    if (XOR (islower (i), ISLOWER (i))
+	|| toupper (i) != TOUPPER (i))
+      return 2;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_run "$LINENO"; then :
+
+else
+  ac_cv_header_stdc=no
+fi
+rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \
+  conftest.$ac_objext conftest.beam conftest.$ac_ext
+fi
+
+fi
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_header_stdc" >&5
+$as_echo "$ac_cv_header_stdc" >&6; }
+if test $ac_cv_header_stdc = yes; then
+
+$as_echo "#define STDC_HEADERS 1" >>confdefs.h
+
+fi
+
+# On IRIX 5.3, sys/types and inttypes.h are conflicting.
+for ac_header in sys/types.h sys/stat.h stdlib.h string.h memory.h strings.h \
+		  inttypes.h stdint.h unistd.h
+do :
+  as_ac_Header=`$as_echo "ac_cv_header_$ac_header" | $as_tr_sh`
+ac_fn_c_check_header_compile "$LINENO" "$ac_header" "$as_ac_Header" "$ac_includes_default
+"
+if eval test \"x\$"$as_ac_Header"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_header" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+
+done
+
+
+for ac_header in dlfcn.h
+do :
+  ac_fn_c_check_header_compile "$LINENO" "dlfcn.h" "ac_cv_header_dlfcn_h" "$ac_includes_default
+"
+if test "x$ac_cv_header_dlfcn_h" = xyes; then :
+  cat >>confdefs.h <<_ACEOF
+#define HAVE_DLFCN_H 1
+_ACEOF
+
+fi
+
+done
+
+
+
+
+
+# Set options
+# Check whether --enable-static was given.
+if test "${enable_static+set}" = set; then :
+  enableval=$enable_static; p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_static=yes ;;
+    no) enable_static=no ;;
+    *)
+     enable_static=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_static=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac
+else
+  enable_static=no
+fi
+
+
+
+
+
+
+
+
+
+
+        enable_dlopen=no
+
+
+  enable_win32_dll=no
+
+
+            # Check whether --enable-shared was given.
+if test "${enable_shared+set}" = set; then :
+  enableval=$enable_shared; p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_shared=yes ;;
+    no) enable_shared=no ;;
+    *)
+      enable_shared=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_shared=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac
+else
+  enable_shared=yes
+fi
+
+
+
+
+
+
+
+
+
+
+
+# Check whether --with-pic was given.
+if test "${with_pic+set}" = set; then :
+  withval=$with_pic; lt_p=${PACKAGE-default}
+    case $withval in
+    yes|no) pic_mode=$withval ;;
+    *)
+      pic_mode=default
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for lt_pkg in $withval; do
+	IFS="$lt_save_ifs"
+	if test "X$lt_pkg" = "X$lt_p"; then
+	  pic_mode=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac
+else
+  pic_mode=default
+fi
+
+
+test -z "$pic_mode" && pic_mode=default
+
+
+
+
+
+
+
+  # Check whether --enable-fast-install was given.
+if test "${enable_fast_install+set}" = set; then :
+  enableval=$enable_fast_install; p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_fast_install=yes ;;
+    no) enable_fast_install=no ;;
+    *)
+      enable_fast_install=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_fast_install=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac
+else
+  enable_fast_install=yes
+fi
+
+
+
+
+
+
+
+
+
+
+
+# This can be used to rebuild libtool when needed
+LIBTOOL_DEPS="$ltmain"
+
+# Always use our own libtool.
+LIBTOOL='$(SHELL) $(top_builddir)/libtool'
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+test -z "$LN_S" && LN_S="ln -s"
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+if test -n "${ZSH_VERSION+set}" ; then
+   setopt NO_GLOB_SUBST
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for objdir" >&5
+$as_echo_n "checking for objdir... " >&6; }
+if ${lt_cv_objdir+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  rm -f .libs 2>/dev/null
+mkdir .libs 2>/dev/null
+if test -d .libs; then
+  lt_cv_objdir=.libs
+else
+  # MS-DOS does not allow filenames that begin with a dot.
+  lt_cv_objdir=_libs
+fi
+rmdir .libs 2>/dev/null
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_objdir" >&5
+$as_echo "$lt_cv_objdir" >&6; }
+objdir=$lt_cv_objdir
+
+
+
+
+
+cat >>confdefs.h <<_ACEOF
+#define LT_OBJDIR "$lt_cv_objdir/"
+_ACEOF
+
+
+
+
+case $host_os in
+aix3*)
+  # AIX sometimes has problems with the GCC collect2 program.  For some
+  # reason, if we set the COLLECT_NAMES environment variable, the problems
+  # vanish in a puff of smoke.
+  if test "X${COLLECT_NAMES+set}" != Xset; then
+    COLLECT_NAMES=
+    export COLLECT_NAMES
+  fi
+  ;;
+esac
+
+# Global variables:
+ofile=libtool
+can_build_shared=yes
+
+# All known linkers require a `.a' archive for static linking (except MSVC,
+# which needs '.lib').
+libext=a
+
+with_gnu_ld="$lt_cv_prog_gnu_ld"
+
+old_CC="$CC"
+old_CFLAGS="$CFLAGS"
+
+# Set sane defaults for various variables
+test -z "$CC" && CC=cc
+test -z "$LTCC" && LTCC=$CC
+test -z "$LTCFLAGS" && LTCFLAGS=$CFLAGS
+test -z "$LD" && LD=ld
+test -z "$ac_objext" && ac_objext=o
+
+for cc_temp in $compiler""; do
+  case $cc_temp in
+    compile | *[\\/]compile | ccache | *[\\/]ccache ) ;;
+    distcc | *[\\/]distcc | purify | *[\\/]purify ) ;;
+    \-*) ;;
+    *) break;;
+  esac
+done
+cc_basename=`$ECHO "$cc_temp" | $SED "s%.*/%%; s%^$host_alias-%%"`
+
+
+# Only perform the check for file, if the check method requires it
+test -z "$MAGIC_CMD" && MAGIC_CMD=file
+case $deplibs_check_method in
+file_magic*)
+  if test "$file_magic_cmd" = '$MAGIC_CMD'; then
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for ${ac_tool_prefix}file" >&5
+$as_echo_n "checking for ${ac_tool_prefix}file... " >&6; }
+if ${lt_cv_path_MAGIC_CMD+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  case $MAGIC_CMD in
+[\\/*] |  ?:[\\/]*)
+  lt_cv_path_MAGIC_CMD="$MAGIC_CMD" # Let the user override the test with a path.
+  ;;
+*)
+  lt_save_MAGIC_CMD="$MAGIC_CMD"
+  lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+  ac_dummy="/usr/bin$PATH_SEPARATOR$PATH"
+  for ac_dir in $ac_dummy; do
+    IFS="$lt_save_ifs"
+    test -z "$ac_dir" && ac_dir=.
+    if test -f $ac_dir/${ac_tool_prefix}file; then
+      lt_cv_path_MAGIC_CMD="$ac_dir/${ac_tool_prefix}file"
+      if test -n "$file_magic_test_file"; then
+	case $deplibs_check_method in
+	"file_magic "*)
+	  file_magic_regex=`expr "$deplibs_check_method" : "file_magic \(.*\)"`
+	  MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+	  if eval $file_magic_cmd \$file_magic_test_file 2> /dev/null |
+	    $EGREP "$file_magic_regex" > /dev/null; then
+	    :
+	  else
+	    cat <<_LT_EOF 1>&2
+
+*** Warning: the command libtool uses to detect shared libraries,
+*** $file_magic_cmd, produces output that libtool cannot recognize.
+*** The result is that libtool may fail to recognize shared libraries
+*** as such.  This will affect the creation of libtool libraries that
+*** depend on shared libraries, but programs linked with such libtool
+*** libraries will work regardless of this problem.  Nevertheless, you
+*** may want to report the problem to your system manager and/or to
+*** bug-libtool@gnu.org
+
+_LT_EOF
+	  fi ;;
+	esac
+      fi
+      break
+    fi
+  done
+  IFS="$lt_save_ifs"
+  MAGIC_CMD="$lt_save_MAGIC_CMD"
+  ;;
+esac
+fi
+
+MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+if test -n "$MAGIC_CMD"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $MAGIC_CMD" >&5
+$as_echo "$MAGIC_CMD" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+
+
+
+if test -z "$lt_cv_path_MAGIC_CMD"; then
+  if test -n "$ac_tool_prefix"; then
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for file" >&5
+$as_echo_n "checking for file... " >&6; }
+if ${lt_cv_path_MAGIC_CMD+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  case $MAGIC_CMD in
+[\\/*] |  ?:[\\/]*)
+  lt_cv_path_MAGIC_CMD="$MAGIC_CMD" # Let the user override the test with a path.
+  ;;
+*)
+  lt_save_MAGIC_CMD="$MAGIC_CMD"
+  lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+  ac_dummy="/usr/bin$PATH_SEPARATOR$PATH"
+  for ac_dir in $ac_dummy; do
+    IFS="$lt_save_ifs"
+    test -z "$ac_dir" && ac_dir=.
+    if test -f $ac_dir/file; then
+      lt_cv_path_MAGIC_CMD="$ac_dir/file"
+      if test -n "$file_magic_test_file"; then
+	case $deplibs_check_method in
+	"file_magic "*)
+	  file_magic_regex=`expr "$deplibs_check_method" : "file_magic \(.*\)"`
+	  MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+	  if eval $file_magic_cmd \$file_magic_test_file 2> /dev/null |
+	    $EGREP "$file_magic_regex" > /dev/null; then
+	    :
+	  else
+	    cat <<_LT_EOF 1>&2
+
+*** Warning: the command libtool uses to detect shared libraries,
+*** $file_magic_cmd, produces output that libtool cannot recognize.
+*** The result is that libtool may fail to recognize shared libraries
+*** as such.  This will affect the creation of libtool libraries that
+*** depend on shared libraries, but programs linked with such libtool
+*** libraries will work regardless of this problem.  Nevertheless, you
+*** may want to report the problem to your system manager and/or to
+*** bug-libtool@gnu.org
+
+_LT_EOF
+	  fi ;;
+	esac
+      fi
+      break
+    fi
+  done
+  IFS="$lt_save_ifs"
+  MAGIC_CMD="$lt_save_MAGIC_CMD"
+  ;;
+esac
+fi
+
+MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+if test -n "$MAGIC_CMD"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $MAGIC_CMD" >&5
+$as_echo "$MAGIC_CMD" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+
+
+  else
+    MAGIC_CMD=:
+  fi
+fi
+
+  fi
+  ;;
+esac
+
+# Use C for the default configuration in the libtool script
+
+lt_save_CC="$CC"
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+
+# Source file extension for C test sources.
+ac_ext=c
+
+# Object file extension for compiled C test sources.
+objext=o
+objext=$objext
+
+# Code to be used in simple compile tests
+lt_simple_compile_test_code="int some_variable = 0;"
+
+# Code to be used in simple link tests
+lt_simple_link_test_code='int main(){return(0);}'
+
+
+
+
+
+
+
+# If no C compiler was specified, use CC.
+LTCC=${LTCC-"$CC"}
+
+# If no C compiler flags were specified, use CFLAGS.
+LTCFLAGS=${LTCFLAGS-"$CFLAGS"}
+
+# Allow CC to be a program name with arguments.
+compiler=$CC
+
+# Save the default compiler, since it gets overwritten when the other
+# tags are being tested, and _LT_TAGVAR(compiler, []) is a NOP.
+compiler_DEFAULT=$CC
+
+# save warnings/boilerplate of simple test code
+ac_outfile=conftest.$ac_objext
+echo "$lt_simple_compile_test_code" >conftest.$ac_ext
+eval "$ac_compile" 2>&1 >/dev/null | $SED '/^$/d; /^ *+/d' >conftest.err
+_lt_compiler_boilerplate=`cat conftest.err`
+$RM conftest*
+
+ac_outfile=conftest.$ac_objext
+echo "$lt_simple_link_test_code" >conftest.$ac_ext
+eval "$ac_link" 2>&1 >/dev/null | $SED '/^$/d; /^ *+/d' >conftest.err
+_lt_linker_boilerplate=`cat conftest.err`
+$RM -r conftest*
+
+
+## CAVEAT EMPTOR:
+## There is no encapsulation within the following macros, do not change
+## the running order or otherwise move them around unless you know exactly
+## what you are doing...
+if test -n "$compiler"; then
+
+lt_prog_compiler_no_builtin_flag=
+
+if test "$GCC" = yes; then
+  case $cc_basename in
+  nvcc*)
+    lt_prog_compiler_no_builtin_flag=' -Xcompiler -fno-builtin' ;;
+  *)
+    lt_prog_compiler_no_builtin_flag=' -fno-builtin' ;;
+  esac
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if $compiler supports -fno-rtti -fno-exceptions" >&5
+$as_echo_n "checking if $compiler supports -fno-rtti -fno-exceptions... " >&6; }
+if ${lt_cv_prog_compiler_rtti_exceptions+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_rtti_exceptions=no
+   ac_outfile=conftest.$ac_objext
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+   lt_compiler_flag="-fno-rtti -fno-exceptions"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   # The option is referenced via a variable to avoid confusing sed.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&5)
+   (eval "$lt_compile" 2>conftest.err)
+   ac_status=$?
+   cat conftest.err >&5
+   echo "$as_me:$LINENO: \$? = $ac_status" >&5
+   if (exit $ac_status) && test -s "$ac_outfile"; then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings other than the usual output.
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' >conftest.exp
+     $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+     if test ! -s conftest.er2 || diff conftest.exp conftest.er2 >/dev/null; then
+       lt_cv_prog_compiler_rtti_exceptions=yes
+     fi
+   fi
+   $RM conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_rtti_exceptions" >&5
+$as_echo "$lt_cv_prog_compiler_rtti_exceptions" >&6; }
+
+if test x"$lt_cv_prog_compiler_rtti_exceptions" = xyes; then
+    lt_prog_compiler_no_builtin_flag="$lt_prog_compiler_no_builtin_flag -fno-rtti -fno-exceptions"
+else
+    :
+fi
+
+fi
+
+
+
+
+
+
+  lt_prog_compiler_wl=
+lt_prog_compiler_pic=
+lt_prog_compiler_static=
+
+
+  if test "$GCC" = yes; then
+    lt_prog_compiler_wl='-Wl,'
+    lt_prog_compiler_static='-static'
+
+    case $host_os in
+      aix*)
+      # All AIX code is PIC.
+      if test "$host_cpu" = ia64; then
+	# AIX 5 now supports IA64 processor
+	lt_prog_compiler_static='-Bstatic'
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            lt_prog_compiler_pic='-fPIC'
+        ;;
+      m68k)
+            # FIXME: we need at least 68020 code to build shared libraries, but
+            # adding the `-m68020' flag to GCC prevents building anything better,
+            # like `-m68040'.
+            lt_prog_compiler_pic='-m68020 -resident32 -malways-restore-a4'
+        ;;
+      esac
+      ;;
+
+    beos* | irix5* | irix6* | nonstopux* | osf3* | osf4* | osf5*)
+      # PIC is the default for these OSes.
+      ;;
+
+    mingw* | cygwin* | pw32* | os2* | cegcc*)
+      # This hack is so that the source file can tell whether it is being
+      # built for inclusion in a dll (and should export symbols for example).
+      # Although the cygwin gcc ignores -fPIC, still need this for old-style
+      # (--disable-auto-import) libraries
+      lt_prog_compiler_pic='-DDLL_EXPORT'
+      ;;
+
+    darwin* | rhapsody*)
+      # PIC is the default on this platform
+      # Common symbols not allowed in MH_DYLIB files
+      lt_prog_compiler_pic='-fno-common'
+      ;;
+
+    haiku*)
+      # PIC is the default for Haiku.
+      # The "-static" flag exists, but is broken.
+      lt_prog_compiler_static=
+      ;;
+
+    hpux*)
+      # PIC is the default for 64-bit PA HP-UX, but not for 32-bit
+      # PA HP-UX.  On IA64 HP-UX, PIC is the default but the pic flag
+      # sets the default TLS model and affects inlining.
+      case $host_cpu in
+      hppa*64*)
+	# +Z the default
+	;;
+      *)
+	lt_prog_compiler_pic='-fPIC'
+	;;
+      esac
+      ;;
+
+    interix[3-9]*)
+      # Interix 3.x gcc -fpic/-fPIC options generate broken code.
+      # Instead, we relocate shared libraries at runtime.
+      ;;
+
+    msdosdjgpp*)
+      # Just because we use GCC doesn't mean we suddenly get shared libraries
+      # on systems that don't support them.
+      lt_prog_compiler_can_build_shared=no
+      enable_shared=no
+      ;;
+
+    *nto* | *qnx*)
+      # QNX uses GNU C++, but need to define -shared option too, otherwise
+      # it will coredump.
+      lt_prog_compiler_pic='-fPIC -shared'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec; then
+	lt_prog_compiler_pic=-Kconform_pic
+      fi
+      ;;
+
+    *)
+      lt_prog_compiler_pic='-fPIC'
+      ;;
+    esac
+
+    case $cc_basename in
+    nvcc*) # Cuda Compiler Driver 2.2
+      lt_prog_compiler_wl='-Xlinker '
+      if test -n "$lt_prog_compiler_pic"; then
+        lt_prog_compiler_pic="-Xcompiler $lt_prog_compiler_pic"
+      fi
+      ;;
+    esac
+  else
+    # PORTME Check for flag to pass linker flags through the system compiler.
+    case $host_os in
+    aix*)
+      lt_prog_compiler_wl='-Wl,'
+      if test "$host_cpu" = ia64; then
+	# AIX 5 now supports IA64 processor
+	lt_prog_compiler_static='-Bstatic'
+      else
+	lt_prog_compiler_static='-bnso -bI:/lib/syscalls.exp'
+      fi
+      ;;
+
+    mingw* | cygwin* | pw32* | os2* | cegcc*)
+      # This hack is so that the source file can tell whether it is being
+      # built for inclusion in a dll (and should export symbols for example).
+      lt_prog_compiler_pic='-DDLL_EXPORT'
+      ;;
+
+    hpux9* | hpux10* | hpux11*)
+      lt_prog_compiler_wl='-Wl,'
+      # PIC is the default for IA64 HP-UX and 64-bit HP-UX, but
+      # not for PA HP-UX.
+      case $host_cpu in
+      hppa*64*|ia64*)
+	# +Z the default
+	;;
+      *)
+	lt_prog_compiler_pic='+Z'
+	;;
+      esac
+      # Is there a better lt_prog_compiler_static that works with the bundled CC?
+      lt_prog_compiler_static='${wl}-a ${wl}archive'
+      ;;
+
+    irix5* | irix6* | nonstopux*)
+      lt_prog_compiler_wl='-Wl,'
+      # PIC (with -KPIC) is the default.
+      lt_prog_compiler_static='-non_shared'
+      ;;
+
+    linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+      case $cc_basename in
+      # old Intel for x86_64 which still supported -KPIC.
+      ecc*)
+	lt_prog_compiler_wl='-Wl,'
+	lt_prog_compiler_pic='-KPIC'
+	lt_prog_compiler_static='-static'
+        ;;
+      # icc used to be incompatible with GCC.
+      # ICC 10 doesn't accept -KPIC any more.
+      icc* | ifort*)
+	lt_prog_compiler_wl='-Wl,'
+	lt_prog_compiler_pic='-fPIC'
+	lt_prog_compiler_static='-static'
+        ;;
+      # Lahey Fortran 8.1.
+      lf95*)
+	lt_prog_compiler_wl='-Wl,'
+	lt_prog_compiler_pic='--shared'
+	lt_prog_compiler_static='--static'
+	;;
+      nagfor*)
+	# NAG Fortran compiler
+	lt_prog_compiler_wl='-Wl,-Wl,,'
+	lt_prog_compiler_pic='-PIC'
+	lt_prog_compiler_static='-Bstatic'
+	;;
+      pgcc* | pgf77* | pgf90* | pgf95* | pgfortran*)
+        # Portland Group compilers (*not* the Pentium gcc compiler,
+	# which looks to be a dead project)
+	lt_prog_compiler_wl='-Wl,'
+	lt_prog_compiler_pic='-fpic'
+	lt_prog_compiler_static='-Bstatic'
+        ;;
+      ccc*)
+        lt_prog_compiler_wl='-Wl,'
+        # All Alpha code is PIC.
+        lt_prog_compiler_static='-non_shared'
+        ;;
+      xl* | bgxl* | bgf* | mpixl*)
+	# IBM XL C 8.0/Fortran 10.1, 11.1 on PPC and BlueGene
+	lt_prog_compiler_wl='-Wl,'
+	lt_prog_compiler_pic='-qpic'
+	lt_prog_compiler_static='-qstaticlink'
+	;;
+      *)
+	case `$CC -V 2>&1 | sed 5q` in
+	*Sun\ Ceres\ Fortran* | *Sun*Fortran*\ [1-7].* | *Sun*Fortran*\ 8.[0-3]*)
+	  # Sun Fortran 8.3 passes all unrecognized flags to the linker
+	  lt_prog_compiler_pic='-KPIC'
+	  lt_prog_compiler_static='-Bstatic'
+	  lt_prog_compiler_wl=''
+	  ;;
+	*Sun\ F* | *Sun*Fortran*)
+	  lt_prog_compiler_pic='-KPIC'
+	  lt_prog_compiler_static='-Bstatic'
+	  lt_prog_compiler_wl='-Qoption ld '
+	  ;;
+	*Sun\ C*)
+	  # Sun C 5.9
+	  lt_prog_compiler_pic='-KPIC'
+	  lt_prog_compiler_static='-Bstatic'
+	  lt_prog_compiler_wl='-Wl,'
+	  ;;
+        *Intel*\ [CF]*Compiler*)
+	  lt_prog_compiler_wl='-Wl,'
+	  lt_prog_compiler_pic='-fPIC'
+	  lt_prog_compiler_static='-static'
+	  ;;
+	*Portland\ Group*)
+	  lt_prog_compiler_wl='-Wl,'
+	  lt_prog_compiler_pic='-fpic'
+	  lt_prog_compiler_static='-Bstatic'
+	  ;;
+	esac
+	;;
+      esac
+      ;;
+
+    newsos6)
+      lt_prog_compiler_pic='-KPIC'
+      lt_prog_compiler_static='-Bstatic'
+      ;;
+
+    *nto* | *qnx*)
+      # QNX uses GNU C++, but need to define -shared option too, otherwise
+      # it will coredump.
+      lt_prog_compiler_pic='-fPIC -shared'
+      ;;
+
+    osf3* | osf4* | osf5*)
+      lt_prog_compiler_wl='-Wl,'
+      # All OSF/1 code is PIC.
+      lt_prog_compiler_static='-non_shared'
+      ;;
+
+    rdos*)
+      lt_prog_compiler_static='-non_shared'
+      ;;
+
+    solaris*)
+      lt_prog_compiler_pic='-KPIC'
+      lt_prog_compiler_static='-Bstatic'
+      case $cc_basename in
+      f77* | f90* | f95* | sunf77* | sunf90* | sunf95*)
+	lt_prog_compiler_wl='-Qoption ld ';;
+      *)
+	lt_prog_compiler_wl='-Wl,';;
+      esac
+      ;;
+
+    sunos4*)
+      lt_prog_compiler_wl='-Qoption ld '
+      lt_prog_compiler_pic='-PIC'
+      lt_prog_compiler_static='-Bstatic'
+      ;;
+
+    sysv4 | sysv4.2uw2* | sysv4.3*)
+      lt_prog_compiler_wl='-Wl,'
+      lt_prog_compiler_pic='-KPIC'
+      lt_prog_compiler_static='-Bstatic'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec ;then
+	lt_prog_compiler_pic='-Kconform_pic'
+	lt_prog_compiler_static='-Bstatic'
+      fi
+      ;;
+
+    sysv5* | unixware* | sco3.2v5* | sco5v6* | OpenUNIX*)
+      lt_prog_compiler_wl='-Wl,'
+      lt_prog_compiler_pic='-KPIC'
+      lt_prog_compiler_static='-Bstatic'
+      ;;
+
+    unicos*)
+      lt_prog_compiler_wl='-Wl,'
+      lt_prog_compiler_can_build_shared=no
+      ;;
+
+    uts4*)
+      lt_prog_compiler_pic='-pic'
+      lt_prog_compiler_static='-Bstatic'
+      ;;
+
+    *)
+      lt_prog_compiler_can_build_shared=no
+      ;;
+    esac
+  fi
+
+case $host_os in
+  # For platforms which do not support PIC, -DPIC is meaningless:
+  *djgpp*)
+    lt_prog_compiler_pic=
+    ;;
+  *)
+    lt_prog_compiler_pic="$lt_prog_compiler_pic -DPIC"
+    ;;
+esac
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for $compiler option to produce PIC" >&5
+$as_echo_n "checking for $compiler option to produce PIC... " >&6; }
+if ${lt_cv_prog_compiler_pic+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_pic=$lt_prog_compiler_pic
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_pic" >&5
+$as_echo "$lt_cv_prog_compiler_pic" >&6; }
+lt_prog_compiler_pic=$lt_cv_prog_compiler_pic
+
+#
+# Check to make sure the PIC flag actually works.
+#
+if test -n "$lt_prog_compiler_pic"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if $compiler PIC flag $lt_prog_compiler_pic works" >&5
+$as_echo_n "checking if $compiler PIC flag $lt_prog_compiler_pic works... " >&6; }
+if ${lt_cv_prog_compiler_pic_works+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_pic_works=no
+   ac_outfile=conftest.$ac_objext
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+   lt_compiler_flag="$lt_prog_compiler_pic -DPIC"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   # The option is referenced via a variable to avoid confusing sed.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&5)
+   (eval "$lt_compile" 2>conftest.err)
+   ac_status=$?
+   cat conftest.err >&5
+   echo "$as_me:$LINENO: \$? = $ac_status" >&5
+   if (exit $ac_status) && test -s "$ac_outfile"; then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings other than the usual output.
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' >conftest.exp
+     $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+     if test ! -s conftest.er2 || diff conftest.exp conftest.er2 >/dev/null; then
+       lt_cv_prog_compiler_pic_works=yes
+     fi
+   fi
+   $RM conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_pic_works" >&5
+$as_echo "$lt_cv_prog_compiler_pic_works" >&6; }
+
+if test x"$lt_cv_prog_compiler_pic_works" = xyes; then
+    case $lt_prog_compiler_pic in
+     "" | " "*) ;;
+     *) lt_prog_compiler_pic=" $lt_prog_compiler_pic" ;;
+     esac
+else
+    lt_prog_compiler_pic=
+     lt_prog_compiler_can_build_shared=no
+fi
+
+fi
+
+
+
+
+
+
+
+
+
+
+
+#
+# Check to make sure the static flag actually works.
+#
+wl=$lt_prog_compiler_wl eval lt_tmp_static_flag=\"$lt_prog_compiler_static\"
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking if $compiler static flag $lt_tmp_static_flag works" >&5
+$as_echo_n "checking if $compiler static flag $lt_tmp_static_flag works... " >&6; }
+if ${lt_cv_prog_compiler_static_works+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_static_works=no
+   save_LDFLAGS="$LDFLAGS"
+   LDFLAGS="$LDFLAGS $lt_tmp_static_flag"
+   echo "$lt_simple_link_test_code" > conftest.$ac_ext
+   if (eval $ac_link 2>conftest.err) && test -s conftest$ac_exeext; then
+     # The linker can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     if test -s conftest.err; then
+       # Append any errors to the config.log.
+       cat conftest.err 1>&5
+       $ECHO "$_lt_linker_boilerplate" | $SED '/^$/d' > conftest.exp
+       $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+       if diff conftest.exp conftest.er2 >/dev/null; then
+         lt_cv_prog_compiler_static_works=yes
+       fi
+     else
+       lt_cv_prog_compiler_static_works=yes
+     fi
+   fi
+   $RM -r conftest*
+   LDFLAGS="$save_LDFLAGS"
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_static_works" >&5
+$as_echo "$lt_cv_prog_compiler_static_works" >&6; }
+
+if test x"$lt_cv_prog_compiler_static_works" = xyes; then
+    :
+else
+    lt_prog_compiler_static=
+fi
+
+
+
+
+
+
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if $compiler supports -c -o file.$ac_objext" >&5
+$as_echo_n "checking if $compiler supports -c -o file.$ac_objext... " >&6; }
+if ${lt_cv_prog_compiler_c_o+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_c_o=no
+   $RM -r conftest 2>/dev/null
+   mkdir conftest
+   cd conftest
+   mkdir out
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+
+   lt_compiler_flag="-o out/conftest2.$ac_objext"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&5)
+   (eval "$lt_compile" 2>out/conftest.err)
+   ac_status=$?
+   cat out/conftest.err >&5
+   echo "$as_me:$LINENO: \$? = $ac_status" >&5
+   if (exit $ac_status) && test -s out/conftest2.$ac_objext
+   then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' > out/conftest.exp
+     $SED '/^$/d; /^ *+/d' out/conftest.err >out/conftest.er2
+     if test ! -s out/conftest.er2 || diff out/conftest.exp out/conftest.er2 >/dev/null; then
+       lt_cv_prog_compiler_c_o=yes
+     fi
+   fi
+   chmod u+w . 2>&5
+   $RM conftest*
+   # SGI C++ compiler will create directory out/ii_files/ for
+   # template instantiation
+   test -d out/ii_files && $RM out/ii_files/* && rmdir out/ii_files
+   $RM out/* && rmdir out
+   cd ..
+   $RM -r conftest
+   $RM conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_c_o" >&5
+$as_echo "$lt_cv_prog_compiler_c_o" >&6; }
+
+
+
+
+
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if $compiler supports -c -o file.$ac_objext" >&5
+$as_echo_n "checking if $compiler supports -c -o file.$ac_objext... " >&6; }
+if ${lt_cv_prog_compiler_c_o+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler_c_o=no
+   $RM -r conftest 2>/dev/null
+   mkdir conftest
+   cd conftest
+   mkdir out
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+
+   lt_compiler_flag="-o out/conftest2.$ac_objext"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [^ ]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&5)
+   (eval "$lt_compile" 2>out/conftest.err)
+   ac_status=$?
+   cat out/conftest.err >&5
+   echo "$as_me:$LINENO: \$? = $ac_status" >&5
+   if (exit $ac_status) && test -s out/conftest2.$ac_objext
+   then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' > out/conftest.exp
+     $SED '/^$/d; /^ *+/d' out/conftest.err >out/conftest.er2
+     if test ! -s out/conftest.er2 || diff out/conftest.exp out/conftest.er2 >/dev/null; then
+       lt_cv_prog_compiler_c_o=yes
+     fi
+   fi
+   chmod u+w . 2>&5
+   $RM conftest*
+   # SGI C++ compiler will create directory out/ii_files/ for
+   # template instantiation
+   test -d out/ii_files && $RM out/ii_files/* && rmdir out/ii_files
+   $RM out/* && rmdir out
+   cd ..
+   $RM -r conftest
+   $RM conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler_c_o" >&5
+$as_echo "$lt_cv_prog_compiler_c_o" >&6; }
+
+
+
+
+hard_links="nottested"
+if test "$lt_cv_prog_compiler_c_o" = no && test "$need_locks" != no; then
+  # do not overwrite the value of need_locks provided by the user
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if we can lock with hard links" >&5
+$as_echo_n "checking if we can lock with hard links... " >&6; }
+  hard_links=yes
+  $RM conftest*
+  ln conftest.a conftest.b 2>/dev/null && hard_links=no
+  touch conftest.a
+  ln conftest.a conftest.b 2>&5 || hard_links=no
+  ln conftest.a conftest.b 2>/dev/null && hard_links=no
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $hard_links" >&5
+$as_echo "$hard_links" >&6; }
+  if test "$hard_links" = no; then
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: \`$CC' does not support \`-c -o', so \`make -j' may be unsafe" >&5
+$as_echo "$as_me: WARNING: \`$CC' does not support \`-c -o', so \`make -j' may be unsafe" >&2;}
+    need_locks=warn
+  fi
+else
+  need_locks=no
+fi
+
+
+
+
+
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the $compiler linker ($LD) supports shared libraries" >&5
+$as_echo_n "checking whether the $compiler linker ($LD) supports shared libraries... " >&6; }
+
+  runpath_var=
+  allow_undefined_flag=
+  always_export_symbols=no
+  archive_cmds=
+  archive_expsym_cmds=
+  compiler_needs_object=no
+  enable_shared_with_static_runtimes=no
+  export_dynamic_flag_spec=
+  export_symbols_cmds='$NM $libobjs $convenience | $global_symbol_pipe | $SED '\''s/.* //'\'' | sort | uniq > $export_symbols'
+  hardcode_automatic=no
+  hardcode_direct=no
+  hardcode_direct_absolute=no
+  hardcode_libdir_flag_spec=
+  hardcode_libdir_separator=
+  hardcode_minus_L=no
+  hardcode_shlibpath_var=unsupported
+  inherit_rpath=no
+  link_all_deplibs=unknown
+  module_cmds=
+  module_expsym_cmds=
+  old_archive_from_new_cmds=
+  old_archive_from_expsyms_cmds=
+  thread_safe_flag_spec=
+  whole_archive_flag_spec=
+  # include_expsyms should be a list of space-separated symbols to be *always*
+  # included in the symbol list
+  include_expsyms=
+  # exclude_expsyms can be an extended regexp of symbols to exclude
+  # it will be wrapped by ` (' and `)$', so one must not match beginning or
+  # end of line.  Example: `a|bc|.*d.*' will exclude the symbols `a' and `bc',
+  # as well as any symbol that contains `d'.
+  exclude_expsyms='_GLOBAL_OFFSET_TABLE_|_GLOBAL__F[ID]_.*'
+  # Although _GLOBAL_OFFSET_TABLE_ is a valid symbol C name, most a.out
+  # platforms (ab)use it in PIC code, but their linkers get confused if
+  # the symbol is explicitly referenced.  Since portable code cannot
+  # rely on this symbol name, it's probably fine to never include it in
+  # preloaded symbol tables.
+  # Exclude shared library initialization/finalization symbols.
+  extract_expsyms_cmds=
+
+  case $host_os in
+  cygwin* | mingw* | pw32* | cegcc*)
+    # FIXME: the MSVC++ port hasn't been tested in a loooong time
+    # When not using gcc, we currently assume that we are using
+    # Microsoft Visual C++.
+    if test "$GCC" != yes; then
+      with_gnu_ld=no
+    fi
+    ;;
+  interix*)
+    # we just hope/assume this is gcc and not c89 (= MSVC++)
+    with_gnu_ld=yes
+    ;;
+  openbsd*)
+    with_gnu_ld=no
+    ;;
+  linux* | k*bsd*-gnu | gnu*)
+    link_all_deplibs=no
+    ;;
+  esac
+
+  ld_shlibs=yes
+
+  # On some targets, GNU ld is compatible enough with the native linker
+  # that we're better off using the native interface for both.
+  lt_use_gnu_ld_interface=no
+  if test "$with_gnu_ld" = yes; then
+    case $host_os in
+      aix*)
+	# The AIX port of GNU ld has always aspired to compatibility
+	# with the native linker.  However, as the warning in the GNU ld
+	# block says, versions before 2.19.5* couldn't really create working
+	# shared libraries, regardless of the interface used.
+	case `$LD -v 2>&1` in
+	  *\ \(GNU\ Binutils\)\ 2.19.5*) ;;
+	  *\ \(GNU\ Binutils\)\ 2.[2-9]*) ;;
+	  *\ \(GNU\ Binutils\)\ [3-9]*) ;;
+	  *)
+	    lt_use_gnu_ld_interface=yes
+	    ;;
+	esac
+	;;
+      *)
+	lt_use_gnu_ld_interface=yes
+	;;
+    esac
+  fi
+
+  if test "$lt_use_gnu_ld_interface" = yes; then
+    # If archive_cmds runs LD, not CC, wlarc should be empty
+    wlarc='${wl}'
+
+    # Set some defaults for GNU ld with shared library support. These
+    # are reset later if shared libraries are not supported. Putting them
+    # here allows them to be overridden if necessary.
+    runpath_var=LD_RUN_PATH
+    hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+    export_dynamic_flag_spec='${wl}--export-dynamic'
+    # ancient GNU ld didn't support --whole-archive et. al.
+    if $LD --help 2>&1 | $GREP 'no-whole-archive' > /dev/null; then
+      whole_archive_flag_spec="$wlarc"'--whole-archive$convenience '"$wlarc"'--no-whole-archive'
+    else
+      whole_archive_flag_spec=
+    fi
+    supports_anon_versioning=no
+    case `$LD -v 2>&1` in
+      *GNU\ gold*) supports_anon_versioning=yes ;;
+      *\ [01].* | *\ 2.[0-9].* | *\ 2.10.*) ;; # catch versions < 2.11
+      *\ 2.11.93.0.2\ *) supports_anon_versioning=yes ;; # RH7.3 ...
+      *\ 2.11.92.0.12\ *) supports_anon_versioning=yes ;; # Mandrake 8.2 ...
+      *\ 2.11.*) ;; # other 2.11 versions
+      *) supports_anon_versioning=yes ;;
+    esac
+
+    # See if GNU ld supports shared libraries.
+    case $host_os in
+    aix[3-9]*)
+      # On AIX/PPC, the GNU linker is very broken
+      if test "$host_cpu" != ia64; then
+	ld_shlibs=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: the GNU linker, at least up to release 2.19, is reported
+*** to be unable to reliably create shared libraries on AIX.
+*** Therefore, libtool is disabling shared libraries support.  If you
+*** really care for shared libraries, you may want to install binutils
+*** 2.20 or above, or modify your PATH so that a non-GNU linker is found.
+*** You will then need to restart the configuration process.
+
+_LT_EOF
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+            archive_expsym_cmds=''
+        ;;
+      m68k)
+            archive_cmds='$RM $output_objdir/a2ixlibrary.data~$ECHO "#define NAME $libname" > $output_objdir/a2ixlibrary.data~$ECHO "#define LIBRARY_ID 1" >> $output_objdir/a2ixlibrary.data~$ECHO "#define VERSION $major" >> $output_objdir/a2ixlibrary.data~$ECHO "#define REVISION $revision" >> $output_objdir/a2ixlibrary.data~$AR $AR_FLAGS $lib $libobjs~$RANLIB $lib~(cd $output_objdir && a2ixlibrary -32)'
+            hardcode_libdir_flag_spec='-L$libdir'
+            hardcode_minus_L=yes
+        ;;
+      esac
+      ;;
+
+    beos*)
+      if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	allow_undefined_flag=unsupported
+	# Joseph Beckenbach <jrb3@best.com> says some releases of gcc
+	# support --undefined.  This deserves some investigation.  FIXME
+	archive_cmds='$CC -nostart $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+      else
+	ld_shlibs=no
+      fi
+      ;;
+
+    cygwin* | mingw* | pw32* | cegcc*)
+      # _LT_TAGVAR(hardcode_libdir_flag_spec, ) is actually meaningless,
+      # as there is no search path for DLLs.
+      hardcode_libdir_flag_spec='-L$libdir'
+      export_dynamic_flag_spec='${wl}--export-all-symbols'
+      allow_undefined_flag=unsupported
+      always_export_symbols=no
+      enable_shared_with_static_runtimes=yes
+      export_symbols_cmds='$NM $libobjs $convenience | $global_symbol_pipe | $SED -e '\''/^[BCDGRS][ ]/s/.*[ ]\([^ ]*\)/\1 DATA/;s/^.*[ ]__nm__\([^ ]*\)[ ][^ ]*/\1 DATA/;/^I[ ]/d;/^[AITW][ ]/s/.* //'\'' | sort | uniq > $export_symbols'
+      exclude_expsyms='[_]+GLOBAL_OFFSET_TABLE_|[_]+GLOBAL__[FID]_.*|[_]+head_[A-Za-z0-9_]+_dll|[A-Za-z0-9_]+_dll_iname'
+
+      if $LD --help 2>&1 | $GREP 'auto-import' > /dev/null; then
+        archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+	# If the export-symbols file already is a .def file (1st line
+	# is EXPORTS), use it as is; otherwise, prepend...
+	archive_expsym_cmds='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	  cp $export_symbols $output_objdir/$soname.def;
+	else
+	  echo EXPORTS > $output_objdir/$soname.def;
+	  cat $export_symbols >> $output_objdir/$soname.def;
+	fi~
+	$CC -shared $output_objdir/$soname.def $libobjs $deplibs $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+      else
+	ld_shlibs=no
+      fi
+      ;;
+
+    haiku*)
+      archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+      link_all_deplibs=yes
+      ;;
+
+    interix[3-9]*)
+      hardcode_direct=no
+      hardcode_shlibpath_var=no
+      hardcode_libdir_flag_spec='${wl}-rpath,$libdir'
+      export_dynamic_flag_spec='${wl}-E'
+      # Hack: On Interix 3.x, we cannot compile PIC because of a broken gcc.
+      # Instead, shared libraries are loaded at an image base (0x10000000 by
+      # default) and relocated if they conflict, which is a slow very memory
+      # consuming and fragmenting process.  To avoid this, we pick a random,
+      # 256 KiB-aligned image base between 0x50000000 and 0x6FFC0000 at link
+      # time.  Moving up from 0x10000000 also allows more sbrk(2) space.
+      archive_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+      archive_expsym_cmds='sed "s,^,_," $export_symbols >$output_objdir/$soname.expsym~$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--retain-symbols-file,$output_objdir/$soname.expsym ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+      ;;
+
+    gnu* | linux* | tpf* | k*bsd*-gnu | kopensolaris*-gnu)
+      tmp_diet=no
+      if test "$host_os" = linux-dietlibc; then
+	case $cc_basename in
+	  diet\ *) tmp_diet=yes;;	# linux-dietlibc with static linking (!diet-dyn)
+	esac
+      fi
+      if $LD --help 2>&1 | $EGREP ': supported targets:.* elf' > /dev/null \
+	 && test "$tmp_diet" = no
+      then
+	tmp_addflag=' $pic_flag'
+	tmp_sharedflag='-shared'
+	case $cc_basename,$host_cpu in
+        pgcc*)				# Portland Group C compiler
+	  whole_archive_flag_spec='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  tmp_addflag=' $pic_flag'
+	  ;;
+	pgf77* | pgf90* | pgf95* | pgfortran*)
+					# Portland Group f77 and f90 compilers
+	  whole_archive_flag_spec='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  tmp_addflag=' $pic_flag -Mnomain' ;;
+	ecc*,ia64* | icc*,ia64*)	# Intel C compiler on ia64
+	  tmp_addflag=' -i_dynamic' ;;
+	efc*,ia64* | ifort*,ia64*)	# Intel Fortran compiler on ia64
+	  tmp_addflag=' -i_dynamic -nofor_main' ;;
+	ifc* | ifort*)			# Intel Fortran compiler
+	  tmp_addflag=' -nofor_main' ;;
+	lf95*)				# Lahey Fortran 8.1
+	  whole_archive_flag_spec=
+	  tmp_sharedflag='--shared' ;;
+	xl[cC]* | bgxl[cC]* | mpixl[cC]*) # IBM XL C 8.0 on PPC (deal with xlf below)
+	  tmp_sharedflag='-qmkshrobj'
+	  tmp_addflag= ;;
+	nvcc*)	# Cuda Compiler Driver 2.2
+	  whole_archive_flag_spec='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  compiler_needs_object=yes
+	  ;;
+	esac
+	case `$CC -V 2>&1 | sed 5q` in
+	*Sun\ C*)			# Sun C 5.9
+	  whole_archive_flag_spec='${wl}--whole-archive`new_convenience=; for conv in $convenience\"\"; do test -z \"$conv\" || new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  compiler_needs_object=yes
+	  tmp_sharedflag='-G' ;;
+	*Sun\ F*)			# Sun Fortran 8.3
+	  tmp_sharedflag='-G' ;;
+	esac
+	archive_cmds='$CC '"$tmp_sharedflag""$tmp_addflag"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+
+        if test "x$supports_anon_versioning" = xyes; then
+          archive_expsym_cmds='echo "{ global:" > $output_objdir/$libname.ver~
+	    cat $export_symbols | sed -e "s/\(.*\)/\1;/" >> $output_objdir/$libname.ver~
+	    echo "local: *; };" >> $output_objdir/$libname.ver~
+	    $CC '"$tmp_sharedflag""$tmp_addflag"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-version-script ${wl}$output_objdir/$libname.ver -o $lib'
+        fi
+
+	case $cc_basename in
+	xlf* | bgf* | bgxlf* | mpixlf*)
+	  # IBM XL Fortran 10.1 on PPC cannot create shared libs itself
+	  whole_archive_flag_spec='--whole-archive$convenience --no-whole-archive'
+	  hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+	  archive_cmds='$LD -shared $libobjs $deplibs $linker_flags -soname $soname -o $lib'
+	  if test "x$supports_anon_versioning" = xyes; then
+	    archive_expsym_cmds='echo "{ global:" > $output_objdir/$libname.ver~
+	      cat $export_symbols | sed -e "s/\(.*\)/\1;/" >> $output_objdir/$libname.ver~
+	      echo "local: *; };" >> $output_objdir/$libname.ver~
+	      $LD -shared $libobjs $deplibs $linker_flags -soname $soname -version-script $output_objdir/$libname.ver -o $lib'
+	  fi
+	  ;;
+	esac
+      else
+        ld_shlibs=no
+      fi
+      ;;
+
+    netbsd* | netbsdelf*-gnu)
+      if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+	archive_cmds='$LD -Bshareable $libobjs $deplibs $linker_flags -o $lib'
+	wlarc=
+      else
+	archive_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	archive_expsym_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      fi
+      ;;
+
+    solaris*)
+      if $LD -v 2>&1 | $GREP 'BFD 2\.8' > /dev/null; then
+	ld_shlibs=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: The releases 2.8.* of the GNU linker cannot reliably
+*** create shared libraries on Solaris systems.  Therefore, libtool
+*** is disabling shared libraries support.  We urge you to upgrade GNU
+*** binutils to release 2.9.1 or newer.  Another option is to modify
+*** your PATH or compiler configuration so that the native linker is
+*** used, and then restart.
+
+_LT_EOF
+      elif $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	archive_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	archive_expsym_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      else
+	ld_shlibs=no
+      fi
+      ;;
+
+    sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX*)
+      case `$LD -v 2>&1` in
+        *\ [01].* | *\ 2.[0-9].* | *\ 2.1[0-5].*)
+	ld_shlibs=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: Releases of the GNU linker prior to 2.16.91.0.3 can not
+*** reliably create shared libraries on SCO systems.  Therefore, libtool
+*** is disabling shared libraries support.  We urge you to upgrade GNU
+*** binutils to release 2.16.91.0.3 or newer.  Another option is to modify
+*** your PATH or compiler configuration so that the native linker is
+*** used, and then restart.
+
+_LT_EOF
+	;;
+	*)
+	  # For security reasons, it is highly recommended that you always
+	  # use absolute paths for naming shared libraries, and exclude the
+	  # DT_RUNPATH tag from executables and libraries.  But doing so
+	  # requires that you compile everything twice, which is a pain.
+	  if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	    hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+	    archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	    archive_expsym_cmds='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+	  else
+	    ld_shlibs=no
+	  fi
+	;;
+      esac
+      ;;
+
+    sunos4*)
+      archive_cmds='$LD -assert pure-text -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+      wlarc=
+      hardcode_direct=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    *)
+      if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	archive_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	archive_expsym_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      else
+	ld_shlibs=no
+      fi
+      ;;
+    esac
+
+    if test "$ld_shlibs" = no; then
+      runpath_var=
+      hardcode_libdir_flag_spec=
+      export_dynamic_flag_spec=
+      whole_archive_flag_spec=
+    fi
+  else
+    # PORTME fill in a description of your system's linker (not GNU ld)
+    case $host_os in
+    aix3*)
+      allow_undefined_flag=unsupported
+      always_export_symbols=yes
+      archive_expsym_cmds='$LD -o $output_objdir/$soname $libobjs $deplibs $linker_flags -bE:$export_symbols -T512 -H512 -bM:SRE~$AR $AR_FLAGS $lib $output_objdir/$soname'
+      # Note: this linker hardcodes the directories in LIBPATH if there
+      # are no directories specified by -L.
+      hardcode_minus_L=yes
+      if test "$GCC" = yes && test -z "$lt_prog_compiler_static"; then
+	# Neither direct hardcoding nor static linking is supported with a
+	# broken collect2.
+	hardcode_direct=unsupported
+      fi
+      ;;
+
+    aix[4-9]*)
+      if test "$host_cpu" = ia64; then
+	# On IA64, the linker does run time linking by default, so we don't
+	# have to do anything special.
+	aix_use_runtimelinking=no
+	exp_sym_flag='-Bexport'
+	no_entry_flag=""
+      else
+	# If we're using GNU nm, then we don't want the "-C" option.
+	# -C means demangle to AIX nm, but means don't demangle with GNU nm
+	# Also, AIX nm treats weak defined symbols like other global
+	# defined symbols, whereas GNU nm marks them as "W".
+	if $NM -V 2>&1 | $GREP 'GNU' > /dev/null; then
+	  export_symbols_cmds='$NM -Bpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B") || (\$ 2 == "W")) && (substr(\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+	else
+	  export_symbols_cmds='$NM -BCpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B")) && (substr(\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+	fi
+	aix_use_runtimelinking=no
+
+	# Test if we are trying to use run time linking or normal
+	# AIX style linking. If -brtl is somewhere in LDFLAGS, we
+	# need to do runtime linking.
+	case $host_os in aix4.[23]|aix4.[23].*|aix[5-9]*)
+	  for ld_flag in $LDFLAGS; do
+	  if (test $ld_flag = "-brtl" || test $ld_flag = "-Wl,-brtl"); then
+	    aix_use_runtimelinking=yes
+	    break
+	  fi
+	  done
+	  ;;
+	esac
+
+	exp_sym_flag='-bexport'
+	no_entry_flag='-bnoentry'
+      fi
+
+      # When large executables or shared objects are built, AIX ld can
+      # have problems creating the table of contents.  If linking a library
+      # or program results in "error TOC overflow" add -mminimal-toc to
+      # CXXFLAGS/CFLAGS for g++/gcc.  In the cases where that is not
+      # enough to fix the problem, add -Wl,-bbigtoc to LDFLAGS.
+
+      archive_cmds=''
+      hardcode_direct=yes
+      hardcode_direct_absolute=yes
+      hardcode_libdir_separator=':'
+      link_all_deplibs=yes
+      file_list_spec='${wl}-f,'
+
+      if test "$GCC" = yes; then
+	case $host_os in aix4.[012]|aix4.[012].*)
+	# We only want to do this on AIX 4.2 and lower, the check
+	# below for broken collect2 doesn't work under 4.3+
+	  collect2name=`${CC} -print-prog-name=collect2`
+	  if test -f "$collect2name" &&
+	   strings "$collect2name" | $GREP resolve_lib_name >/dev/null
+	  then
+	  # We have reworked collect2
+	  :
+	  else
+	  # We have old collect2
+	  hardcode_direct=unsupported
+	  # It fails to find uninstalled libraries when the uninstalled
+	  # path is not listed in the libpath.  Setting hardcode_minus_L
+	  # to unsupported forces relinking
+	  hardcode_minus_L=yes
+	  hardcode_libdir_flag_spec='-L$libdir'
+	  hardcode_libdir_separator=
+	  fi
+	  ;;
+	esac
+	shared_flag='-shared'
+	if test "$aix_use_runtimelinking" = yes; then
+	  shared_flag="$shared_flag "'${wl}-G'
+	fi
+	link_all_deplibs=no
+      else
+	# not using gcc
+	if test "$host_cpu" = ia64; then
+	# VisualAge C++, Version 5.5 for AIX 5L for IA-64, Beta 3 Release
+	# chokes on -Wl,-G. The following line is correct:
+	  shared_flag='-G'
+	else
+	  if test "$aix_use_runtimelinking" = yes; then
+	    shared_flag='${wl}-G'
+	  else
+	    shared_flag='${wl}-bM:SRE'
+	  fi
+	fi
+      fi
+
+      export_dynamic_flag_spec='${wl}-bexpall'
+      # It seems that -bexpall does not export symbols beginning with
+      # underscore (_), so it is better to generate a list of symbols to export.
+      always_export_symbols=yes
+      if test "$aix_use_runtimelinking" = yes; then
+	# Warning - without using the other runtime loading flags (-brtl),
+	# -berok will link without error, but may produce a broken library.
+	allow_undefined_flag='-berok'
+        # Determine the default libpath from the value encoded in an
+        # empty executable.
+        if test "${lt_cv_aix_libpath+set}" = set; then
+  aix_libpath=$lt_cv_aix_libpath
+else
+  if ${lt_cv_aix_libpath_+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+
+  lt_aix_libpath_sed='
+      /Import File Strings/,/^$/ {
+	  /^0/ {
+	      s/^0  *\([^ ]*\) *$/\1/
+	      p
+	  }
+      }'
+  lt_cv_aix_libpath_=`dump -H conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  # Check for a 64-bit object if we didn't find anything.
+  if test -z "$lt_cv_aix_libpath_"; then
+    lt_cv_aix_libpath_=`dump -HX64 conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  fi
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  if test -z "$lt_cv_aix_libpath_"; then
+    lt_cv_aix_libpath_="/usr/lib:/lib"
+  fi
+
+fi
+
+  aix_libpath=$lt_cv_aix_libpath_
+fi
+
+        hardcode_libdir_flag_spec='${wl}-blibpath:$libdir:'"$aix_libpath"
+        archive_expsym_cmds='$CC -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags `if test "x${allow_undefined_flag}" != "x"; then func_echo_all "${wl}${allow_undefined_flag}"; else :; fi` '"\${wl}$exp_sym_flag:\$export_symbols $shared_flag"
+      else
+	if test "$host_cpu" = ia64; then
+	  hardcode_libdir_flag_spec='${wl}-R $libdir:/usr/lib:/lib'
+	  allow_undefined_flag="-z nodefs"
+	  archive_expsym_cmds="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags ${wl}${allow_undefined_flag} '"\${wl}$exp_sym_flag:\$export_symbols"
+	else
+	 # Determine the default libpath from the value encoded in an
+	 # empty executable.
+	 if test "${lt_cv_aix_libpath+set}" = set; then
+  aix_libpath=$lt_cv_aix_libpath
+else
+  if ${lt_cv_aix_libpath_+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+
+  lt_aix_libpath_sed='
+      /Import File Strings/,/^$/ {
+	  /^0/ {
+	      s/^0  *\([^ ]*\) *$/\1/
+	      p
+	  }
+      }'
+  lt_cv_aix_libpath_=`dump -H conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  # Check for a 64-bit object if we didn't find anything.
+  if test -z "$lt_cv_aix_libpath_"; then
+    lt_cv_aix_libpath_=`dump -HX64 conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  fi
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+  if test -z "$lt_cv_aix_libpath_"; then
+    lt_cv_aix_libpath_="/usr/lib:/lib"
+  fi
+
+fi
+
+  aix_libpath=$lt_cv_aix_libpath_
+fi
+
+	 hardcode_libdir_flag_spec='${wl}-blibpath:$libdir:'"$aix_libpath"
+	  # Warning - without using the other run time loading flags,
+	  # -berok will link without error, but may produce a broken library.
+	  no_undefined_flag=' ${wl}-bernotok'
+	  allow_undefined_flag=' ${wl}-berok'
+	  if test "$with_gnu_ld" = yes; then
+	    # We only use this code for GNU lds that support --whole-archive.
+	    whole_archive_flag_spec='${wl}--whole-archive$convenience ${wl}--no-whole-archive'
+	  else
+	    # Exported symbols can be pulled into shared objects from archives
+	    whole_archive_flag_spec='$convenience'
+	  fi
+	  archive_cmds_need_lc=yes
+	  # This is similar to how AIX traditionally builds its shared libraries.
+	  archive_expsym_cmds="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs ${wl}-bnoentry $compiler_flags ${wl}-bE:$export_symbols${allow_undefined_flag}~$AR $AR_FLAGS $output_objdir/$libname$release.a $output_objdir/$soname'
+	fi
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+            archive_expsym_cmds=''
+        ;;
+      m68k)
+            archive_cmds='$RM $output_objdir/a2ixlibrary.data~$ECHO "#define NAME $libname" > $output_objdir/a2ixlibrary.data~$ECHO "#define LIBRARY_ID 1" >> $output_objdir/a2ixlibrary.data~$ECHO "#define VERSION $major" >> $output_objdir/a2ixlibrary.data~$ECHO "#define REVISION $revision" >> $output_objdir/a2ixlibrary.data~$AR $AR_FLAGS $lib $libobjs~$RANLIB $lib~(cd $output_objdir && a2ixlibrary -32)'
+            hardcode_libdir_flag_spec='-L$libdir'
+            hardcode_minus_L=yes
+        ;;
+      esac
+      ;;
+
+    bsdi[45]*)
+      export_dynamic_flag_spec=-rdynamic
+      ;;
+
+    cygwin* | mingw* | pw32* | cegcc*)
+      # When not using gcc, we currently assume that we are using
+      # Microsoft Visual C++.
+      # hardcode_libdir_flag_spec is actually meaningless, as there is
+      # no search path for DLLs.
+      case $cc_basename in
+      cl*)
+	# Native MSVC
+	hardcode_libdir_flag_spec=' '
+	allow_undefined_flag=unsupported
+	always_export_symbols=yes
+	file_list_spec='@'
+	# Tell ltmain to make .lib files, not .a files.
+	libext=lib
+	# Tell ltmain to make .dll files, not .so files.
+	shrext_cmds=".dll"
+	# FIXME: Setting linknames here is a bad hack.
+	archive_cmds='$CC -o $output_objdir/$soname $libobjs $compiler_flags $deplibs -Wl,-dll~linknames='
+	archive_expsym_cmds='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	    sed -n -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' -e '1\\\!p' < $export_symbols > $output_objdir/$soname.exp;
+	  else
+	    sed -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' < $export_symbols > $output_objdir/$soname.exp;
+	  fi~
+	  $CC -o $tool_output_objdir$soname $libobjs $compiler_flags $deplibs "@$tool_output_objdir$soname.exp" -Wl,-DLL,-IMPLIB:"$tool_output_objdir$libname.dll.lib"~
+	  linknames='
+	# The linker will not automatically build a static lib if we build a DLL.
+	# _LT_TAGVAR(old_archive_from_new_cmds, )='true'
+	enable_shared_with_static_runtimes=yes
+	exclude_expsyms='_NULL_IMPORT_DESCRIPTOR|_IMPORT_DESCRIPTOR_.*'
+	export_symbols_cmds='$NM $libobjs $convenience | $global_symbol_pipe | $SED -e '\''/^[BCDGRS][ ]/s/.*[ ]\([^ ]*\)/\1,DATA/'\'' | $SED -e '\''/^[AITW][ ]/s/.*[ ]//'\'' | sort | uniq > $export_symbols'
+	# Don't use ranlib
+	old_postinstall_cmds='chmod 644 $oldlib'
+	postlink_cmds='lt_outputfile="@OUTPUT@"~
+	  lt_tool_outputfile="@TOOL_OUTPUT@"~
+	  case $lt_outputfile in
+	    *.exe|*.EXE) ;;
+	    *)
+	      lt_outputfile="$lt_outputfile.exe"
+	      lt_tool_outputfile="$lt_tool_outputfile.exe"
+	      ;;
+	  esac~
+	  if test "$MANIFEST_TOOL" != ":" && test -f "$lt_outputfile.manifest"; then
+	    $MANIFEST_TOOL -manifest "$lt_tool_outputfile.manifest" -outputresource:"$lt_tool_outputfile" || exit 1;
+	    $RM "$lt_outputfile.manifest";
+	  fi'
+	;;
+      *)
+	# Assume MSVC wrapper
+	hardcode_libdir_flag_spec=' '
+	allow_undefined_flag=unsupported
+	# Tell ltmain to make .lib files, not .a files.
+	libext=lib
+	# Tell ltmain to make .dll files, not .so files.
+	shrext_cmds=".dll"
+	# FIXME: Setting linknames here is a bad hack.
+	archive_cmds='$CC -o $lib $libobjs $compiler_flags `func_echo_all "$deplibs" | $SED '\''s/ -lc$//'\''` -link -dll~linknames='
+	# The linker will automatically build a .lib file if we build a DLL.
+	old_archive_from_new_cmds='true'
+	# FIXME: Should let the user specify the lib program.
+	old_archive_cmds='lib -OUT:$oldlib$oldobjs$old_deplibs'
+	enable_shared_with_static_runtimes=yes
+	;;
+      esac
+      ;;
+
+    darwin* | rhapsody*)
+
+
+  archive_cmds_need_lc=no
+  hardcode_direct=no
+  hardcode_automatic=yes
+  hardcode_shlibpath_var=unsupported
+  if test "$lt_cv_ld_force_load" = "yes"; then
+    whole_archive_flag_spec='`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience ${wl}-force_load,$conv\"; done; func_echo_all \"$new_convenience\"`'
+
+  else
+    whole_archive_flag_spec=''
+  fi
+  link_all_deplibs=yes
+  allow_undefined_flag="$_lt_dar_allow_undefined"
+  case $cc_basename in
+     ifort*) _lt_dar_can_shared=yes ;;
+     *) _lt_dar_can_shared=$GCC ;;
+  esac
+  if test "$_lt_dar_can_shared" = "yes"; then
+    output_verbose_link_cmd=func_echo_all
+    archive_cmds="\$CC -dynamiclib \$allow_undefined_flag -o \$lib \$libobjs \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring $_lt_dar_single_mod${_lt_dsymutil}"
+    module_cmds="\$CC \$allow_undefined_flag -o \$lib -bundle \$libobjs \$deplibs \$compiler_flags${_lt_dsymutil}"
+    archive_expsym_cmds="sed 's,^,_,' < \$export_symbols > \$output_objdir/\${libname}-symbols.expsym~\$CC -dynamiclib \$allow_undefined_flag -o \$lib \$libobjs \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring ${_lt_dar_single_mod}${_lt_dar_export_syms}${_lt_dsymutil}"
+    module_expsym_cmds="sed -e 's,^,_,' < \$export_symbols > \$output_objdir/\${libname}-symbols.expsym~\$CC \$allow_undefined_flag -o \$lib -bundle \$libobjs \$deplibs \$compiler_flags${_lt_dar_export_syms}${_lt_dsymutil}"
+
+  else
+  ld_shlibs=no
+  fi
+
+      ;;
+
+    dgux*)
+      archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      hardcode_libdir_flag_spec='-L$libdir'
+      hardcode_shlibpath_var=no
+      ;;
+
+    # FreeBSD 2.2.[012] allows us to include c++rt0.o to get C++ constructor
+    # support.  Future versions do this automatically, but an explicit c++rt0.o
+    # does not break anything, and helps significantly (at the cost of a little
+    # extra space).
+    freebsd2.2*)
+      archive_cmds='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags /usr/lib/c++rt0.o'
+      hardcode_libdir_flag_spec='-R$libdir'
+      hardcode_direct=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    # Unfortunately, older versions of FreeBSD 2 do not have this feature.
+    freebsd2.*)
+      archive_cmds='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+      hardcode_direct=yes
+      hardcode_minus_L=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    # FreeBSD 3 and greater uses gcc -shared to do shared libraries.
+    freebsd* | dragonfly*)
+      archive_cmds='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+      hardcode_libdir_flag_spec='-R$libdir'
+      hardcode_direct=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    hpux9*)
+      if test "$GCC" = yes; then
+	archive_cmds='$RM $output_objdir/$soname~$CC -shared $pic_flag ${wl}+b ${wl}$install_libdir -o $output_objdir/$soname $libobjs $deplibs $compiler_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+      else
+	archive_cmds='$RM $output_objdir/$soname~$LD -b +b $install_libdir -o $output_objdir/$soname $libobjs $deplibs $linker_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+      fi
+      hardcode_libdir_flag_spec='${wl}+b ${wl}$libdir'
+      hardcode_libdir_separator=:
+      hardcode_direct=yes
+
+      # hardcode_minus_L: Not really in the search PATH,
+      # but as the default location of the library.
+      hardcode_minus_L=yes
+      export_dynamic_flag_spec='${wl}-E'
+      ;;
+
+    hpux10*)
+      if test "$GCC" = yes && test "$with_gnu_ld" = no; then
+	archive_cmds='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	archive_cmds='$LD -b +h $soname +b $install_libdir -o $lib $libobjs $deplibs $linker_flags'
+      fi
+      if test "$with_gnu_ld" = no; then
+	hardcode_libdir_flag_spec='${wl}+b ${wl}$libdir'
+	hardcode_libdir_separator=:
+	hardcode_direct=yes
+	hardcode_direct_absolute=yes
+	export_dynamic_flag_spec='${wl}-E'
+	# hardcode_minus_L: Not really in the search PATH,
+	# but as the default location of the library.
+	hardcode_minus_L=yes
+      fi
+      ;;
+
+    hpux11*)
+      if test "$GCC" = yes && test "$with_gnu_ld" = no; then
+	case $host_cpu in
+	hppa*64*)
+	  archive_cmds='$CC -shared ${wl}+h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	ia64*)
+	  archive_cmds='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	*)
+	  archive_cmds='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	esac
+      else
+	case $host_cpu in
+	hppa*64*)
+	  archive_cmds='$CC -b ${wl}+h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	ia64*)
+	  archive_cmds='$CC -b ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	*)
+
+	  # Older versions of the 11.00 compiler do not understand -b yet
+	  # (HP92453-01 A.11.01.20 doesn't, HP92453-01 B.11.X.35175-35176.GP does)
+	  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if $CC understands -b" >&5
+$as_echo_n "checking if $CC understands -b... " >&6; }
+if ${lt_cv_prog_compiler__b+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_prog_compiler__b=no
+   save_LDFLAGS="$LDFLAGS"
+   LDFLAGS="$LDFLAGS -b"
+   echo "$lt_simple_link_test_code" > conftest.$ac_ext
+   if (eval $ac_link 2>conftest.err) && test -s conftest$ac_exeext; then
+     # The linker can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     if test -s conftest.err; then
+       # Append any errors to the config.log.
+       cat conftest.err 1>&5
+       $ECHO "$_lt_linker_boilerplate" | $SED '/^$/d' > conftest.exp
+       $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+       if diff conftest.exp conftest.er2 >/dev/null; then
+         lt_cv_prog_compiler__b=yes
+       fi
+     else
+       lt_cv_prog_compiler__b=yes
+     fi
+   fi
+   $RM -r conftest*
+   LDFLAGS="$save_LDFLAGS"
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_prog_compiler__b" >&5
+$as_echo "$lt_cv_prog_compiler__b" >&6; }
+
+if test x"$lt_cv_prog_compiler__b" = xyes; then
+    archive_cmds='$CC -b ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'
+else
+    archive_cmds='$LD -b +h $soname +b $install_libdir -o $lib $libobjs $deplibs $linker_flags'
+fi
+
+	  ;;
+	esac
+      fi
+      if test "$with_gnu_ld" = no; then
+	hardcode_libdir_flag_spec='${wl}+b ${wl}$libdir'
+	hardcode_libdir_separator=:
+
+	case $host_cpu in
+	hppa*64*|ia64*)
+	  hardcode_direct=no
+	  hardcode_shlibpath_var=no
+	  ;;
+	*)
+	  hardcode_direct=yes
+	  hardcode_direct_absolute=yes
+	  export_dynamic_flag_spec='${wl}-E'
+
+	  # hardcode_minus_L: Not really in the search PATH,
+	  # but as the default location of the library.
+	  hardcode_minus_L=yes
+	  ;;
+	esac
+      fi
+      ;;
+
+    irix5* | irix6* | nonstopux*)
+      if test "$GCC" = yes; then
+	archive_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+	# Try to use the -exported_symbol ld option, if it does not
+	# work, assume that -exports_file does not work either and
+	# implicitly export all symbols.
+	# This should be the same for all languages, so no per-tag cache variable.
+	{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether the $host_os linker accepts -exported_symbol" >&5
+$as_echo_n "checking whether the $host_os linker accepts -exported_symbol... " >&6; }
+if ${lt_cv_irix_exported_symbol+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  save_LDFLAGS="$LDFLAGS"
+	   LDFLAGS="$LDFLAGS -shared ${wl}-exported_symbol ${wl}foo ${wl}-update_registry ${wl}/dev/null"
+	   cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+int foo (void) { return 0; }
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  lt_cv_irix_exported_symbol=yes
+else
+  lt_cv_irix_exported_symbol=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+           LDFLAGS="$save_LDFLAGS"
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_irix_exported_symbol" >&5
+$as_echo "$lt_cv_irix_exported_symbol" >&6; }
+	if test "$lt_cv_irix_exported_symbol" = yes; then
+          archive_expsym_cmds='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations ${wl}-exports_file ${wl}$export_symbols -o $lib'
+	fi
+      else
+	archive_cmds='$CC -shared $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	archive_expsym_cmds='$CC -shared $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -exports_file $export_symbols -o $lib'
+      fi
+      archive_cmds_need_lc='no'
+      hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+      hardcode_libdir_separator=:
+      inherit_rpath=yes
+      link_all_deplibs=yes
+      ;;
+
+    netbsd* | netbsdelf*-gnu)
+      if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+	archive_cmds='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'  # a.out
+      else
+	archive_cmds='$LD -shared -o $lib $libobjs $deplibs $linker_flags'      # ELF
+      fi
+      hardcode_libdir_flag_spec='-R$libdir'
+      hardcode_direct=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    newsos6)
+      archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      hardcode_direct=yes
+      hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+      hardcode_libdir_separator=:
+      hardcode_shlibpath_var=no
+      ;;
+
+    *nto* | *qnx*)
+      ;;
+
+    openbsd*)
+      if test -f /usr/libexec/ld.so; then
+	hardcode_direct=yes
+	hardcode_shlibpath_var=no
+	hardcode_direct_absolute=yes
+	if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+	  archive_cmds='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+	  archive_expsym_cmds='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags ${wl}-retain-symbols-file,$export_symbols'
+	  hardcode_libdir_flag_spec='${wl}-rpath,$libdir'
+	  export_dynamic_flag_spec='${wl}-E'
+	else
+	  case $host_os in
+	   openbsd[01].* | openbsd2.[0-7] | openbsd2.[0-7].*)
+	     archive_cmds='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+	     hardcode_libdir_flag_spec='-R$libdir'
+	     ;;
+	   *)
+	     archive_cmds='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+	     hardcode_libdir_flag_spec='${wl}-rpath,$libdir'
+	     ;;
+	  esac
+	fi
+      else
+	ld_shlibs=no
+      fi
+      ;;
+
+    os2*)
+      hardcode_libdir_flag_spec='-L$libdir'
+      hardcode_minus_L=yes
+      allow_undefined_flag=unsupported
+      archive_cmds='$ECHO "LIBRARY $libname INITINSTANCE" > $output_objdir/$libname.def~$ECHO "DESCRIPTION \"$libname\"" >> $output_objdir/$libname.def~echo DATA >> $output_objdir/$libname.def~echo " SINGLE NONSHARED" >> $output_objdir/$libname.def~echo EXPORTS >> $output_objdir/$libname.def~emxexp $libobjs >> $output_objdir/$libname.def~$CC -Zdll -Zcrtdll -o $lib $libobjs $deplibs $compiler_flags $output_objdir/$libname.def'
+      old_archive_from_new_cmds='emximp -o $output_objdir/$libname.a $output_objdir/$libname.def'
+      ;;
+
+    osf3*)
+      if test "$GCC" = yes; then
+	allow_undefined_flag=' ${wl}-expect_unresolved ${wl}\*'
+	archive_cmds='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+      else
+	allow_undefined_flag=' -expect_unresolved \*'
+	archive_cmds='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+      fi
+      archive_cmds_need_lc='no'
+      hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+      hardcode_libdir_separator=:
+      ;;
+
+    osf4* | osf5*)	# as osf3* with the addition of -msym flag
+      if test "$GCC" = yes; then
+	allow_undefined_flag=' ${wl}-expect_unresolved ${wl}\*'
+	archive_cmds='$CC -shared${allow_undefined_flag} $pic_flag $libobjs $deplibs $compiler_flags ${wl}-msym ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+	hardcode_libdir_flag_spec='${wl}-rpath ${wl}$libdir'
+      else
+	allow_undefined_flag=' -expect_unresolved \*'
+	archive_cmds='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags -msym -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	archive_expsym_cmds='for i in `cat $export_symbols`; do printf "%s %s\\n" -exported_symbol "\$i" >> $lib.exp; done; printf "%s\\n" "-hidden">> $lib.exp~
+	$CC -shared${allow_undefined_flag} ${wl}-input ${wl}$lib.exp $compiler_flags $libobjs $deplibs -soname $soname `test -n "$verstring" && $ECHO "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib~$RM $lib.exp'
+
+	# Both c and cxx compiler support -rpath directly
+	hardcode_libdir_flag_spec='-rpath $libdir'
+      fi
+      archive_cmds_need_lc='no'
+      hardcode_libdir_separator=:
+      ;;
+
+    solaris*)
+      no_undefined_flag=' -z defs'
+      if test "$GCC" = yes; then
+	wlarc='${wl}'
+	archive_cmds='$CC -shared $pic_flag ${wl}-z ${wl}text ${wl}-h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	archive_expsym_cmds='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $CC -shared $pic_flag ${wl}-z ${wl}text ${wl}-M ${wl}$lib.exp ${wl}-h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags~$RM $lib.exp'
+      else
+	case `$CC -V 2>&1` in
+	*"Compilers 5.0"*)
+	  wlarc=''
+	  archive_cmds='$LD -G${allow_undefined_flag} -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  archive_expsym_cmds='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $LD -G${allow_undefined_flag} -M $lib.exp -h $soname -o $lib $libobjs $deplibs $linker_flags~$RM $lib.exp'
+	  ;;
+	*)
+	  wlarc='${wl}'
+	  archive_cmds='$CC -G${allow_undefined_flag} -h $soname -o $lib $libobjs $deplibs $compiler_flags'
+	  archive_expsym_cmds='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $CC -G${allow_undefined_flag} -M $lib.exp -h $soname -o $lib $libobjs $deplibs $compiler_flags~$RM $lib.exp'
+	  ;;
+	esac
+      fi
+      hardcode_libdir_flag_spec='-R$libdir'
+      hardcode_shlibpath_var=no
+      case $host_os in
+      solaris2.[0-5] | solaris2.[0-5].*) ;;
+      *)
+	# The compiler driver will combine and reorder linker options,
+	# but understands `-z linker_flag'.  GCC discards it without `$wl',
+	# but is careful enough not to reorder.
+	# Supported since Solaris 2.6 (maybe 2.5.1?)
+	if test "$GCC" = yes; then
+	  whole_archive_flag_spec='${wl}-z ${wl}allextract$convenience ${wl}-z ${wl}defaultextract'
+	else
+	  whole_archive_flag_spec='-z allextract$convenience -z defaultextract'
+	fi
+	;;
+      esac
+      link_all_deplibs=yes
+      ;;
+
+    sunos4*)
+      if test "x$host_vendor" = xsequent; then
+	# Use $CC to link under sequent, because it throws in some extra .o
+	# files that make .init and .fini sections work.
+	archive_cmds='$CC -G ${wl}-h $soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	archive_cmds='$LD -assert pure-text -Bstatic -o $lib $libobjs $deplibs $linker_flags'
+      fi
+      hardcode_libdir_flag_spec='-L$libdir'
+      hardcode_direct=yes
+      hardcode_minus_L=yes
+      hardcode_shlibpath_var=no
+      ;;
+
+    sysv4)
+      case $host_vendor in
+	sni)
+	  archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  hardcode_direct=yes # is this really true???
+	;;
+	siemens)
+	  ## LD is ld it makes a PLAMLIB
+	  ## CC just makes a GrossModule.
+	  archive_cmds='$LD -G -o $lib $libobjs $deplibs $linker_flags'
+	  reload_cmds='$CC -r -o $output$reload_objs'
+	  hardcode_direct=no
+        ;;
+	motorola)
+	  archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  hardcode_direct=no #Motorola manual says yes, but my tests say they lie
+	;;
+      esac
+      runpath_var='LD_RUN_PATH'
+      hardcode_shlibpath_var=no
+      ;;
+
+    sysv4.3*)
+      archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      hardcode_shlibpath_var=no
+      export_dynamic_flag_spec='-Bexport'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec; then
+	archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	hardcode_shlibpath_var=no
+	runpath_var=LD_RUN_PATH
+	hardcode_runpath_var=yes
+	ld_shlibs=yes
+      fi
+      ;;
+
+    sysv4*uw2* | sysv5OpenUNIX* | sysv5UnixWare7.[01].[10]* | unixware7* | sco3.2v5.0.[024]*)
+      no_undefined_flag='${wl}-z,text'
+      archive_cmds_need_lc=no
+      hardcode_shlibpath_var=no
+      runpath_var='LD_RUN_PATH'
+
+      if test "$GCC" = yes; then
+	archive_cmds='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	archive_expsym_cmds='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	archive_cmds='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	archive_expsym_cmds='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      fi
+      ;;
+
+    sysv5* | sco3.2v5* | sco5v6*)
+      # Note: We can NOT use -z defs as we might desire, because we do not
+      # link with -lc, and that would cause any symbols used from libc to
+      # always be unresolved, which means just about no library would
+      # ever link correctly.  If we're not using GNU ld we use -z text
+      # though, which does catch some bad symbols but isn't as heavy-handed
+      # as -z defs.
+      no_undefined_flag='${wl}-z,text'
+      allow_undefined_flag='${wl}-z,nodefs'
+      archive_cmds_need_lc=no
+      hardcode_shlibpath_var=no
+      hardcode_libdir_flag_spec='${wl}-R,$libdir'
+      hardcode_libdir_separator=':'
+      link_all_deplibs=yes
+      export_dynamic_flag_spec='${wl}-Bexport'
+      runpath_var='LD_RUN_PATH'
+
+      if test "$GCC" = yes; then
+	archive_cmds='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	archive_expsym_cmds='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	archive_cmds='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	archive_expsym_cmds='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      fi
+      ;;
+
+    uts4*)
+      archive_cmds='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      hardcode_libdir_flag_spec='-L$libdir'
+      hardcode_shlibpath_var=no
+      ;;
+
+    *)
+      ld_shlibs=no
+      ;;
+    esac
+
+    if test x$host_vendor = xsni; then
+      case $host in
+      sysv4 | sysv4.2uw2* | sysv4.3* | sysv5*)
+	export_dynamic_flag_spec='${wl}-Blargedynsym'
+	;;
+      esac
+    fi
+  fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ld_shlibs" >&5
+$as_echo "$ld_shlibs" >&6; }
+test "$ld_shlibs" = no && can_build_shared=no
+
+with_gnu_ld=$with_gnu_ld
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+#
+# Do we need to explicitly link libc?
+#
+case "x$archive_cmds_need_lc" in
+x|xyes)
+  # Assume -lc should be added
+  archive_cmds_need_lc=yes
+
+  if test "$enable_shared" = yes && test "$GCC" = yes; then
+    case $archive_cmds in
+    *'~'*)
+      # FIXME: we may have to deal with multi-command sequences.
+      ;;
+    '$CC '*)
+      # Test whether the compiler implicitly links with -lc since on some
+      # systems, -lgcc has to come before -lc. If gcc already passes -lc
+      # to ld, don't add -lc before -lgcc.
+      { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether -lc should be explicitly linked in" >&5
+$as_echo_n "checking whether -lc should be explicitly linked in... " >&6; }
+if ${lt_cv_archive_cmds_need_lc+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  $RM conftest*
+	echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+
+	if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_compile\""; } >&5
+  (eval $ac_compile) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } 2>conftest.err; then
+	  soname=conftest
+	  lib=conftest
+	  libobjs=conftest.$ac_objext
+	  deplibs=
+	  wl=$lt_prog_compiler_wl
+	  pic_flag=$lt_prog_compiler_pic
+	  compiler_flags=-v
+	  linker_flags=-v
+	  verstring=
+	  output_objdir=.
+	  libname=conftest
+	  lt_save_allow_undefined_flag=$allow_undefined_flag
+	  allow_undefined_flag=
+	  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$archive_cmds 2\>\&1 \| $GREP \" -lc \" \>/dev/null 2\>\&1\""; } >&5
+  (eval $archive_cmds 2\>\&1 \| $GREP \" -lc \" \>/dev/null 2\>\&1) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; }
+	  then
+	    lt_cv_archive_cmds_need_lc=no
+	  else
+	    lt_cv_archive_cmds_need_lc=yes
+	  fi
+	  allow_undefined_flag=$lt_save_allow_undefined_flag
+	else
+	  cat conftest.err 1>&5
+	fi
+	$RM conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_archive_cmds_need_lc" >&5
+$as_echo "$lt_cv_archive_cmds_need_lc" >&6; }
+      archive_cmds_need_lc=$lt_cv_archive_cmds_need_lc
+      ;;
+    esac
+  fi
+  ;;
+esac
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking dynamic linker characteristics" >&5
+$as_echo_n "checking dynamic linker characteristics... " >&6; }
+
+if test "$GCC" = yes; then
+  case $host_os in
+    darwin*) lt_awk_arg="/^libraries:/,/LR/" ;;
+    *) lt_awk_arg="/^libraries:/" ;;
+  esac
+  case $host_os in
+    mingw* | cegcc*) lt_sed_strip_eq="s,=\([A-Za-z]:\),\1,g" ;;
+    *) lt_sed_strip_eq="s,=/,/,g" ;;
+  esac
+  lt_search_path_spec=`$CC -print-search-dirs | awk $lt_awk_arg | $SED -e "s/^libraries://" -e $lt_sed_strip_eq`
+  case $lt_search_path_spec in
+  *\;*)
+    # if the path contains ";" then we assume it to be the separator
+    # otherwise default to the standard path separator (i.e. ":") - it is
+    # assumed that no part of a normal pathname contains ";" but that should
+    # okay in the real world where ";" in dirpaths is itself problematic.
+    lt_search_path_spec=`$ECHO "$lt_search_path_spec" | $SED 's/;/ /g'`
+    ;;
+  *)
+    lt_search_path_spec=`$ECHO "$lt_search_path_spec" | $SED "s/$PATH_SEPARATOR/ /g"`
+    ;;
+  esac
+  # Ok, now we have the path, separated by spaces, we can step through it
+  # and add multilib dir if necessary.
+  lt_tmp_lt_search_path_spec=
+  lt_multi_os_dir=`$CC $CPPFLAGS $CFLAGS $LDFLAGS -print-multi-os-directory 2>/dev/null`
+  for lt_sys_path in $lt_search_path_spec; do
+    if test -d "$lt_sys_path/$lt_multi_os_dir"; then
+      lt_tmp_lt_search_path_spec="$lt_tmp_lt_search_path_spec $lt_sys_path/$lt_multi_os_dir"
+    else
+      test -d "$lt_sys_path" && \
+	lt_tmp_lt_search_path_spec="$lt_tmp_lt_search_path_spec $lt_sys_path"
+    fi
+  done
+  lt_search_path_spec=`$ECHO "$lt_tmp_lt_search_path_spec" | awk '
+BEGIN {RS=" "; FS="/|\n";} {
+  lt_foo="";
+  lt_count=0;
+  for (lt_i = NF; lt_i > 0; lt_i--) {
+    if ($lt_i != "" && $lt_i != ".") {
+      if ($lt_i == "..") {
+        lt_count++;
+      } else {
+        if (lt_count == 0) {
+          lt_foo="/" $lt_i lt_foo;
+        } else {
+          lt_count--;
+        }
+      }
+    }
+  }
+  if (lt_foo != "") { lt_freq[lt_foo]++; }
+  if (lt_freq[lt_foo] == 1) { print lt_foo; }
+}'`
+  # AWK program above erroneously prepends '/' to C:/dos/paths
+  # for these hosts.
+  case $host_os in
+    mingw* | cegcc*) lt_search_path_spec=`$ECHO "$lt_search_path_spec" |\
+      $SED 's,/\([A-Za-z]:\),\1,g'` ;;
+  esac
+  sys_lib_search_path_spec=`$ECHO "$lt_search_path_spec" | $lt_NL2SP`
+else
+  sys_lib_search_path_spec="/lib /usr/lib /usr/local/lib"
+fi
+library_names_spec=
+libname_spec='lib$name'
+soname_spec=
+shrext_cmds=".so"
+postinstall_cmds=
+postuninstall_cmds=
+finish_cmds=
+finish_eval=
+shlibpath_var=
+shlibpath_overrides_runpath=unknown
+version_type=none
+dynamic_linker="$host_os ld.so"
+sys_lib_dlsearch_path_spec="/lib /usr/lib"
+need_lib_prefix=unknown
+hardcode_into_libs=no
+
+# when you set need_version to no, make sure it does not cause -set_version
+# flags to be left without arguments
+need_version=unknown
+
+case $host_os in
+aix3*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix $libname.a'
+  shlibpath_var=LIBPATH
+
+  # AIX 3 has no versioning support, so we append a major version to the name.
+  soname_spec='${libname}${release}${shared_ext}$major'
+  ;;
+
+aix[4-9]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  hardcode_into_libs=yes
+  if test "$host_cpu" = ia64; then
+    # AIX 5 supports IA64
+    library_names_spec='${libname}${release}${shared_ext}$major ${libname}${release}${shared_ext}$versuffix $libname${shared_ext}'
+    shlibpath_var=LD_LIBRARY_PATH
+  else
+    # With GCC up to 2.95.x, collect2 would create an import file
+    # for dependence libraries.  The import file would start with
+    # the line `#! .'.  This would cause the generated library to
+    # depend on `.', always an invalid library.  This was fixed in
+    # development snapshots of GCC prior to 3.0.
+    case $host_os in
+      aix4 | aix4.[01] | aix4.[01].*)
+      if { echo '#if __GNUC__ > 2 || (__GNUC__ == 2 && __GNUC_MINOR__ >= 97)'
+	   echo ' yes '
+	   echo '#endif'; } | ${CC} -E - | $GREP yes > /dev/null; then
+	:
+      else
+	can_build_shared=no
+      fi
+      ;;
+    esac
+    # AIX (on Power*) has no versioning support, so currently we can not hardcode correct
+    # soname into executable. Probably we can add versioning support to
+    # collect2, so additional links can be useful in future.
+    if test "$aix_use_runtimelinking" = yes; then
+      # If using run time linking (on AIX 4.2 or later) use lib<name>.so
+      # instead of lib<name>.a to let people know that these are not
+      # typical AIX shared libraries.
+      library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    else
+      # We preserve .a as extension for shared libraries through AIX4.2
+      # and later when we are not doing run time linking.
+      library_names_spec='${libname}${release}.a $libname.a'
+      soname_spec='${libname}${release}${shared_ext}$major'
+    fi
+    shlibpath_var=LIBPATH
+  fi
+  ;;
+
+amigaos*)
+  case $host_cpu in
+  powerpc)
+    # Since July 2007 AmigaOS4 officially supports .so libraries.
+    # When compiling the executable, add -use-dynld -Lsobjs: to the compileline.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    ;;
+  m68k)
+    library_names_spec='$libname.ixlibrary $libname.a'
+    # Create ${libname}_ixlibrary.a entries in /sys/libs.
+    finish_eval='for lib in `ls $libdir/*.ixlibrary 2>/dev/null`; do libname=`func_echo_all "$lib" | $SED '\''s%^.*/\([^/]*\)\.ixlibrary$%\1%'\''`; test $RM /sys/libs/${libname}_ixlibrary.a; $show "cd /sys/libs && $LN_S $lib ${libname}_ixlibrary.a"; cd /sys/libs && $LN_S $lib ${libname}_ixlibrary.a || exit 1; done'
+    ;;
+  esac
+  ;;
+
+beos*)
+  library_names_spec='${libname}${shared_ext}'
+  dynamic_linker="$host_os ld.so"
+  shlibpath_var=LIBRARY_PATH
+  ;;
+
+bsdi[45]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  sys_lib_search_path_spec="/shlib /usr/lib /usr/X11/lib /usr/contrib/lib /lib /usr/local/lib"
+  sys_lib_dlsearch_path_spec="/shlib /usr/lib /usr/local/lib"
+  # the default ld.so.conf also contains /usr/contrib/lib and
+  # /usr/X11R6/lib (/usr/X11 is a link to /usr/X11R6), but let us allow
+  # libtool to hard-code these into programs
+  ;;
+
+cygwin* | mingw* | pw32* | cegcc*)
+  version_type=windows
+  shrext_cmds=".dll"
+  need_version=no
+  need_lib_prefix=no
+
+  case $GCC,$cc_basename in
+  yes,*)
+    # gcc
+    library_names_spec='$libname.dll.a'
+    # DLL is installed to $(libdir)/../bin by postinstall_cmds
+    postinstall_cmds='base_file=`basename \${file}`~
+      dlpath=`$SHELL 2>&1 -c '\''. $dir/'\''\${base_file}'\''i; echo \$dlname'\''`~
+      dldir=$destdir/`dirname \$dlpath`~
+      test -d \$dldir || mkdir -p \$dldir~
+      $install_prog $dir/$dlname \$dldir/$dlname~
+      chmod a+x \$dldir/$dlname~
+      if test -n '\''$stripme'\'' && test -n '\''$striplib'\''; then
+        eval '\''$striplib \$dldir/$dlname'\'' || exit \$?;
+      fi'
+    postuninstall_cmds='dldll=`$SHELL 2>&1 -c '\''. $file; echo \$dlname'\''`~
+      dlpath=$dir/\$dldll~
+       $RM \$dlpath'
+    shlibpath_overrides_runpath=yes
+
+    case $host_os in
+    cygwin*)
+      # Cygwin DLLs use 'cyg' prefix rather than 'lib'
+      soname_spec='`echo ${libname} | sed -e 's/^lib/cyg/'``echo ${release} | $SED -e 's/[.]/-/g'`${versuffix}${shared_ext}'
+
+      sys_lib_search_path_spec="$sys_lib_search_path_spec /usr/lib/w32api"
+      ;;
+    mingw* | cegcc*)
+      # MinGW DLLs use traditional 'lib' prefix
+      soname_spec='${libname}`echo ${release} | $SED -e 's/[.]/-/g'`${versuffix}${shared_ext}'
+      ;;
+    pw32*)
+      # pw32 DLLs use 'pw' prefix rather than 'lib'
+      library_names_spec='`echo ${libname} | sed -e 's/^lib/pw/'``echo ${release} | $SED -e 's/[.]/-/g'`${versuffix}${shared_ext}'
+      ;;
+    esac
+    dynamic_linker='Win32 ld.exe'
+    ;;
+
+  *,cl*)
+    # Native MSVC
+    libname_spec='$name'
+    soname_spec='${libname}`echo ${release} | $SED -e 's/[.]/-/g'`${versuffix}${shared_ext}'
+    library_names_spec='${libname}.dll.lib'
+
+    case $build_os in
+    mingw*)
+      sys_lib_search_path_spec=
+      lt_save_ifs=$IFS
+      IFS=';'
+      for lt_path in $LIB
+      do
+        IFS=$lt_save_ifs
+        # Let DOS variable expansion print the short 8.3 style file name.
+        lt_path=`cd "$lt_path" 2>/dev/null && cmd //C "for %i in (".") do @echo %~si"`
+        sys_lib_search_path_spec="$sys_lib_search_path_spec $lt_path"
+      done
+      IFS=$lt_save_ifs
+      # Convert to MSYS style.
+      sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | sed -e 's|\\\\|/|g' -e 's| \\([a-zA-Z]\\):| /\\1|g' -e 's|^ ||'`
+      ;;
+    cygwin*)
+      # Convert to unix form, then to dos form, then back to unix form
+      # but this time dos style (no spaces!) so that the unix form looks
+      # like /cygdrive/c/PROGRA~1:/cygdr...
+      sys_lib_search_path_spec=`cygpath --path --unix "$LIB"`
+      sys_lib_search_path_spec=`cygpath --path --dos "$sys_lib_search_path_spec" 2>/dev/null`
+      sys_lib_search_path_spec=`cygpath --path --unix "$sys_lib_search_path_spec" | $SED -e "s/$PATH_SEPARATOR/ /g"`
+      ;;
+    *)
+      sys_lib_search_path_spec="$LIB"
+      if $ECHO "$sys_lib_search_path_spec" | $GREP ';[c-zC-Z]:/' >/dev/null; then
+        # It is most probably a Windows format PATH.
+        sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | $SED -e 's/;/ /g'`
+      else
+        sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | $SED -e "s/$PATH_SEPARATOR/ /g"`
+      fi
+      # FIXME: find the short name or the path components, as spaces are
+      # common. (e.g. "Program Files" -> "PROGRA~1")
+      ;;
+    esac
+
+    # DLL is installed to $(libdir)/../bin by postinstall_cmds
+    postinstall_cmds='base_file=`basename \${file}`~
+      dlpath=`$SHELL 2>&1 -c '\''. $dir/'\''\${base_file}'\''i; echo \$dlname'\''`~
+      dldir=$destdir/`dirname \$dlpath`~
+      test -d \$dldir || mkdir -p \$dldir~
+      $install_prog $dir/$dlname \$dldir/$dlname'
+    postuninstall_cmds='dldll=`$SHELL 2>&1 -c '\''. $file; echo \$dlname'\''`~
+      dlpath=$dir/\$dldll~
+       $RM \$dlpath'
+    shlibpath_overrides_runpath=yes
+    dynamic_linker='Win32 link.exe'
+    ;;
+
+  *)
+    # Assume MSVC wrapper
+    library_names_spec='${libname}`echo ${release} | $SED -e 's/[.]/-/g'`${versuffix}${shared_ext} $libname.lib'
+    dynamic_linker='Win32 ld.exe'
+    ;;
+  esac
+  # FIXME: first we should search . and the directory the executable is in
+  shlibpath_var=PATH
+  ;;
+
+darwin* | rhapsody*)
+  dynamic_linker="$host_os dyld"
+  version_type=darwin
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${major}$shared_ext ${libname}$shared_ext'
+  soname_spec='${libname}${release}${major}$shared_ext'
+  shlibpath_overrides_runpath=yes
+  shlibpath_var=DYLD_LIBRARY_PATH
+  shrext_cmds='`test .$module = .yes && echo .so || echo .dylib`'
+
+  sys_lib_search_path_spec="$sys_lib_search_path_spec /usr/local/lib"
+  sys_lib_dlsearch_path_spec='/usr/local/lib /lib /usr/lib'
+  ;;
+
+dgux*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname$shared_ext'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  ;;
+
+freebsd* | dragonfly*)
+  # DragonFly does not have aout.  When/if they implement a new
+  # versioning mechanism, adjust this.
+  if test -x /usr/bin/objformat; then
+    objformat=`/usr/bin/objformat`
+  else
+    case $host_os in
+    freebsd[23].*) objformat=aout ;;
+    *) objformat=elf ;;
+    esac
+  fi
+  version_type=freebsd-$objformat
+  case $version_type in
+    freebsd-elf*)
+      library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext} $libname${shared_ext}'
+      need_version=no
+      need_lib_prefix=no
+      ;;
+    freebsd-*)
+      library_names_spec='${libname}${release}${shared_ext}$versuffix $libname${shared_ext}$versuffix'
+      need_version=yes
+      ;;
+  esac
+  shlibpath_var=LD_LIBRARY_PATH
+  case $host_os in
+  freebsd2.*)
+    shlibpath_overrides_runpath=yes
+    ;;
+  freebsd3.[01]* | freebsdelf3.[01]*)
+    shlibpath_overrides_runpath=yes
+    hardcode_into_libs=yes
+    ;;
+  freebsd3.[2-9]* | freebsdelf3.[2-9]* | \
+  freebsd4.[0-5] | freebsdelf4.[0-5] | freebsd4.1.1 | freebsdelf4.1.1)
+    shlibpath_overrides_runpath=no
+    hardcode_into_libs=yes
+    ;;
+  *) # from 4.6 on, and DragonFly
+    shlibpath_overrides_runpath=yes
+    hardcode_into_libs=yes
+    ;;
+  esac
+  ;;
+
+haiku*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  dynamic_linker="$host_os runtime_loader"
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}${major} ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  sys_lib_dlsearch_path_spec='/boot/home/config/lib /boot/common/lib /boot/system/lib'
+  hardcode_into_libs=yes
+  ;;
+
+hpux9* | hpux10* | hpux11*)
+  # Give a soname corresponding to the major version so that dld.sl refuses to
+  # link against other versions.
+  version_type=sunos
+  need_lib_prefix=no
+  need_version=no
+  case $host_cpu in
+  ia64*)
+    shrext_cmds='.so'
+    hardcode_into_libs=yes
+    dynamic_linker="$host_os dld.so"
+    shlibpath_var=LD_LIBRARY_PATH
+    shlibpath_overrides_runpath=yes # Unless +noenvvar is specified.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    if test "X$HPUX_IA64_MODE" = X32; then
+      sys_lib_search_path_spec="/usr/lib/hpux32 /usr/local/lib/hpux32 /usr/local/lib"
+    else
+      sys_lib_search_path_spec="/usr/lib/hpux64 /usr/local/lib/hpux64"
+    fi
+    sys_lib_dlsearch_path_spec=$sys_lib_search_path_spec
+    ;;
+  hppa*64*)
+    shrext_cmds='.sl'
+    hardcode_into_libs=yes
+    dynamic_linker="$host_os dld.sl"
+    shlibpath_var=LD_LIBRARY_PATH # How should we handle SHLIB_PATH
+    shlibpath_overrides_runpath=yes # Unless +noenvvar is specified.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    sys_lib_search_path_spec="/usr/lib/pa20_64 /usr/ccs/lib/pa20_64"
+    sys_lib_dlsearch_path_spec=$sys_lib_search_path_spec
+    ;;
+  *)
+    shrext_cmds='.sl'
+    dynamic_linker="$host_os dld.sl"
+    shlibpath_var=SHLIB_PATH
+    shlibpath_overrides_runpath=no # +s is required to enable SHLIB_PATH
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    ;;
+  esac
+  # HP-UX runs *really* slowly unless shared libraries are mode 555, ...
+  postinstall_cmds='chmod 555 $lib'
+  # or fails outright, so override atomically:
+  install_override_mode=555
+  ;;
+
+interix[3-9]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  dynamic_linker='Interix 3.x ld.so.1 (PE, like ELF)'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  ;;
+
+irix5* | irix6* | nonstopux*)
+  case $host_os in
+    nonstopux*) version_type=nonstopux ;;
+    *)
+	if test "$lt_cv_prog_gnu_ld" = yes; then
+		version_type=linux # correct to gnu/linux during the next big refactor
+	else
+		version_type=irix
+	fi ;;
+  esac
+  need_lib_prefix=no
+  need_version=no
+  soname_spec='${libname}${release}${shared_ext}$major'
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${release}${shared_ext} $libname${shared_ext}'
+  case $host_os in
+  irix5* | nonstopux*)
+    libsuff= shlibsuff=
+    ;;
+  *)
+    case $LD in # libtool.m4 will add one of these switches to LD
+    *-32|*"-32 "|*-melf32bsmip|*"-melf32bsmip ")
+      libsuff= shlibsuff= libmagic=32-bit;;
+    *-n32|*"-n32 "|*-melf32bmipn32|*"-melf32bmipn32 ")
+      libsuff=32 shlibsuff=N32 libmagic=N32;;
+    *-64|*"-64 "|*-melf64bmip|*"-melf64bmip ")
+      libsuff=64 shlibsuff=64 libmagic=64-bit;;
+    *) libsuff= shlibsuff= libmagic=never-match;;
+    esac
+    ;;
+  esac
+  shlibpath_var=LD_LIBRARY${shlibsuff}_PATH
+  shlibpath_overrides_runpath=no
+  sys_lib_search_path_spec="/usr/lib${libsuff} /lib${libsuff} /usr/local/lib${libsuff}"
+  sys_lib_dlsearch_path_spec="/usr/lib${libsuff} /lib${libsuff}"
+  hardcode_into_libs=yes
+  ;;
+
+# No shared lib support for Linux oldld, aout, or coff.
+linux*oldld* | linux*aout* | linux*coff*)
+  dynamic_linker=no
+  ;;
+
+# This must be glibc/ELF.
+linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig -n $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+
+  # Some binutils ld are patched to set DT_RUNPATH
+  if ${lt_cv_shlibpath_overrides_runpath+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  lt_cv_shlibpath_overrides_runpath=no
+    save_LDFLAGS=$LDFLAGS
+    save_libdir=$libdir
+    eval "libdir=/foo; wl=\"$lt_prog_compiler_wl\"; \
+	 LDFLAGS=\"\$LDFLAGS $hardcode_libdir_flag_spec\""
+    cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+int
+main ()
+{
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  if  ($OBJDUMP -p conftest$ac_exeext) 2>/dev/null | grep "RUNPATH.*$libdir" >/dev/null; then :
+  lt_cv_shlibpath_overrides_runpath=yes
+fi
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+    LDFLAGS=$save_LDFLAGS
+    libdir=$save_libdir
+
+fi
+
+  shlibpath_overrides_runpath=$lt_cv_shlibpath_overrides_runpath
+
+  # This implies no fast_install, which is unacceptable.
+  # Some rework will be needed to allow for fast_install
+  # before this can be enabled.
+  hardcode_into_libs=yes
+
+  # Append ld.so.conf contents to the search path
+  if test -f /etc/ld.so.conf; then
+    lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \$2)); skip = 1; } { if (!skip) print \$0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[	 ]*hwcap[	 ]/d;s/[:,	]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
+    sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+  fi
+
+  # We used to test for /lib/ld.so.1 and disable shared libraries on
+  # powerpc, because MkLinux only supported shared libraries with the
+  # GNU dynamic linker.  Since this was broken with cross compilers,
+  # most powerpc-linux boxes support dynamic linking these days and
+  # people can always --disable-shared, the test was removed, and we
+  # assume the GNU/Linux dynamic linker is in use.
+  dynamic_linker='GNU/Linux ld.so'
+  ;;
+
+netbsdelf*-gnu)
+  version_type=linux
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  dynamic_linker='NetBSD ld.elf_so'
+  ;;
+
+netbsd*)
+  version_type=sunos
+  need_lib_prefix=no
+  need_version=no
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+    finish_cmds='PATH="\$PATH:/sbin" ldconfig -m $libdir'
+    dynamic_linker='NetBSD (a.out) ld.so'
+  else
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    dynamic_linker='NetBSD ld.elf_so'
+  fi
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  ;;
+
+newsos6)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  ;;
+
+*nto* | *qnx*)
+  version_type=qnx
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  dynamic_linker='ldqnx.so'
+  ;;
+
+openbsd*)
+  version_type=sunos
+  sys_lib_dlsearch_path_spec="/usr/lib"
+  need_lib_prefix=no
+  # Some older versions of OpenBSD (3.3 at least) *do* need versioned libs.
+  case $host_os in
+    openbsd3.3 | openbsd3.3.*)	need_version=yes ;;
+    *)				need_version=no  ;;
+  esac
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig -m $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+    case $host_os in
+      openbsd2.[89] | openbsd2.[89].*)
+	shlibpath_overrides_runpath=no
+	;;
+      *)
+	shlibpath_overrides_runpath=yes
+	;;
+      esac
+  else
+    shlibpath_overrides_runpath=yes
+  fi
+  ;;
+
+os2*)
+  libname_spec='$name'
+  shrext_cmds=".dll"
+  need_lib_prefix=no
+  library_names_spec='$libname${shared_ext} $libname.a'
+  dynamic_linker='OS/2 ld.exe'
+  shlibpath_var=LIBPATH
+  ;;
+
+osf3* | osf4* | osf5*)
+  version_type=osf
+  need_lib_prefix=no
+  need_version=no
+  soname_spec='${libname}${release}${shared_ext}$major'
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  sys_lib_search_path_spec="/usr/shlib /usr/ccs/lib /usr/lib/cmplrs/cc /usr/lib /usr/local/lib /var/shlib"
+  sys_lib_dlsearch_path_spec="$sys_lib_search_path_spec"
+  ;;
+
+rdos*)
+  dynamic_linker=no
+  ;;
+
+solaris*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  # ldd complains unless libraries are executable
+  postinstall_cmds='chmod +x $lib'
+  ;;
+
+sunos4*)
+  version_type=sunos
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+  finish_cmds='PATH="\$PATH:/usr/etc" ldconfig $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  if test "$with_gnu_ld" = yes; then
+    need_lib_prefix=no
+  fi
+  need_version=yes
+  ;;
+
+sysv4 | sysv4.3*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  case $host_vendor in
+    sni)
+      shlibpath_overrides_runpath=no
+      need_lib_prefix=no
+      runpath_var=LD_RUN_PATH
+      ;;
+    siemens)
+      need_lib_prefix=no
+      ;;
+    motorola)
+      need_lib_prefix=no
+      need_version=no
+      shlibpath_overrides_runpath=no
+      sys_lib_search_path_spec='/lib /usr/lib /usr/ccs/lib'
+      ;;
+  esac
+  ;;
+
+sysv4*MP*)
+  if test -d /usr/nec ;then
+    version_type=linux # correct to gnu/linux during the next big refactor
+    library_names_spec='$libname${shared_ext}.$versuffix $libname${shared_ext}.$major $libname${shared_ext}'
+    soname_spec='$libname${shared_ext}.$major'
+    shlibpath_var=LD_LIBRARY_PATH
+  fi
+  ;;
+
+sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX* | sysv4*uw2*)
+  version_type=freebsd-elf
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext} $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  if test "$with_gnu_ld" = yes; then
+    sys_lib_search_path_spec='/usr/local/lib /usr/gnu/lib /usr/ccs/lib /usr/lib /lib'
+  else
+    sys_lib_search_path_spec='/usr/ccs/lib /usr/lib'
+    case $host_os in
+      sco3.2v5*)
+        sys_lib_search_path_spec="$sys_lib_search_path_spec /lib"
+	;;
+    esac
+  fi
+  sys_lib_dlsearch_path_spec='/usr/lib'
+  ;;
+
+tpf*)
+  # TPF is a cross-target only.  Preferred cross-host = GNU/Linux.
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  ;;
+
+uts4*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  ;;
+
+*)
+  dynamic_linker=no
+  ;;
+esac
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $dynamic_linker" >&5
+$as_echo "$dynamic_linker" >&6; }
+test "$dynamic_linker" = no && can_build_shared=no
+
+variables_saved_for_relink="PATH $shlibpath_var $runpath_var"
+if test "$GCC" = yes; then
+  variables_saved_for_relink="$variables_saved_for_relink GCC_EXEC_PREFIX COMPILER_PATH LIBRARY_PATH"
+fi
+
+if test "${lt_cv_sys_lib_search_path_spec+set}" = set; then
+  sys_lib_search_path_spec="$lt_cv_sys_lib_search_path_spec"
+fi
+if test "${lt_cv_sys_lib_dlsearch_path_spec+set}" = set; then
+  sys_lib_dlsearch_path_spec="$lt_cv_sys_lib_dlsearch_path_spec"
+fi
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking how to hardcode library paths into programs" >&5
+$as_echo_n "checking how to hardcode library paths into programs... " >&6; }
+hardcode_action=
+if test -n "$hardcode_libdir_flag_spec" ||
+   test -n "$runpath_var" ||
+   test "X$hardcode_automatic" = "Xyes" ; then
+
+  # We can hardcode non-existent directories.
+  if test "$hardcode_direct" != no &&
+     # If the only mechanism to avoid hardcoding is shlibpath_var, we
+     # have to relink, otherwise we might link with an installed library
+     # when we should be linking with a yet-to-be-installed one
+     ## test "$_LT_TAGVAR(hardcode_shlibpath_var, )" != no &&
+     test "$hardcode_minus_L" != no; then
+    # Linking always hardcodes the temporary library directory.
+    hardcode_action=relink
+  else
+    # We can link without hardcoding, and we can hardcode nonexisting dirs.
+    hardcode_action=immediate
+  fi
+else
+  # We cannot hardcode anything, or else we can only hardcode existing
+  # directories.
+  hardcode_action=unsupported
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $hardcode_action" >&5
+$as_echo "$hardcode_action" >&6; }
+
+if test "$hardcode_action" = relink ||
+   test "$inherit_rpath" = yes; then
+  # Fast installation is not supported
+  enable_fast_install=no
+elif test "$shlibpath_overrides_runpath" = yes ||
+     test "$enable_shared" = no; then
+  # Fast installation is not necessary
+  enable_fast_install=needless
+fi
+
+
+
+
+
+
+  if test "x$enable_dlopen" != xyes; then
+  enable_dlopen=unknown
+  enable_dlopen_self=unknown
+  enable_dlopen_self_static=unknown
+else
+  lt_cv_dlopen=no
+  lt_cv_dlopen_libs=
+
+  case $host_os in
+  beos*)
+    lt_cv_dlopen="load_add_on"
+    lt_cv_dlopen_libs=
+    lt_cv_dlopen_self=yes
+    ;;
+
+  mingw* | pw32* | cegcc*)
+    lt_cv_dlopen="LoadLibrary"
+    lt_cv_dlopen_libs=
+    ;;
+
+  cygwin*)
+    lt_cv_dlopen="dlopen"
+    lt_cv_dlopen_libs=
+    ;;
+
+  darwin*)
+  # if libdl is installed we need to link against it
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking for dlopen in -ldl" >&5
+$as_echo_n "checking for dlopen in -ldl... " >&6; }
+if ${ac_cv_lib_dl_dlopen+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_check_lib_save_LIBS=$LIBS
+LIBS="-ldl  $LIBS"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char dlopen ();
+int
+main ()
+{
+return dlopen ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_lib_dl_dlopen=yes
+else
+  ac_cv_lib_dl_dlopen=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+LIBS=$ac_check_lib_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_dl_dlopen" >&5
+$as_echo "$ac_cv_lib_dl_dlopen" >&6; }
+if test "x$ac_cv_lib_dl_dlopen" = xyes; then :
+  lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-ldl"
+else
+
+    lt_cv_dlopen="dyld"
+    lt_cv_dlopen_libs=
+    lt_cv_dlopen_self=yes
+
+fi
+
+    ;;
+
+  *)
+    ac_fn_c_check_func "$LINENO" "shl_load" "ac_cv_func_shl_load"
+if test "x$ac_cv_func_shl_load" = xyes; then :
+  lt_cv_dlopen="shl_load"
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for shl_load in -ldld" >&5
+$as_echo_n "checking for shl_load in -ldld... " >&6; }
+if ${ac_cv_lib_dld_shl_load+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_check_lib_save_LIBS=$LIBS
+LIBS="-ldld  $LIBS"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char shl_load ();
+int
+main ()
+{
+return shl_load ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_lib_dld_shl_load=yes
+else
+  ac_cv_lib_dld_shl_load=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+LIBS=$ac_check_lib_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_dld_shl_load" >&5
+$as_echo "$ac_cv_lib_dld_shl_load" >&6; }
+if test "x$ac_cv_lib_dld_shl_load" = xyes; then :
+  lt_cv_dlopen="shl_load" lt_cv_dlopen_libs="-ldld"
+else
+  ac_fn_c_check_func "$LINENO" "dlopen" "ac_cv_func_dlopen"
+if test "x$ac_cv_func_dlopen" = xyes; then :
+  lt_cv_dlopen="dlopen"
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for dlopen in -ldl" >&5
+$as_echo_n "checking for dlopen in -ldl... " >&6; }
+if ${ac_cv_lib_dl_dlopen+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_check_lib_save_LIBS=$LIBS
+LIBS="-ldl  $LIBS"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char dlopen ();
+int
+main ()
+{
+return dlopen ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_lib_dl_dlopen=yes
+else
+  ac_cv_lib_dl_dlopen=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+LIBS=$ac_check_lib_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_dl_dlopen" >&5
+$as_echo "$ac_cv_lib_dl_dlopen" >&6; }
+if test "x$ac_cv_lib_dl_dlopen" = xyes; then :
+  lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-ldl"
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for dlopen in -lsvld" >&5
+$as_echo_n "checking for dlopen in -lsvld... " >&6; }
+if ${ac_cv_lib_svld_dlopen+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_check_lib_save_LIBS=$LIBS
+LIBS="-lsvld  $LIBS"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char dlopen ();
+int
+main ()
+{
+return dlopen ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_lib_svld_dlopen=yes
+else
+  ac_cv_lib_svld_dlopen=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+LIBS=$ac_check_lib_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_svld_dlopen" >&5
+$as_echo "$ac_cv_lib_svld_dlopen" >&6; }
+if test "x$ac_cv_lib_svld_dlopen" = xyes; then :
+  lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-lsvld"
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking for dld_link in -ldld" >&5
+$as_echo_n "checking for dld_link in -ldld... " >&6; }
+if ${ac_cv_lib_dld_dld_link+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_check_lib_save_LIBS=$LIBS
+LIBS="-ldld  $LIBS"
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char dld_link ();
+int
+main ()
+{
+return dld_link ();
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_lib_dld_dld_link=yes
+else
+  ac_cv_lib_dld_dld_link=no
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+LIBS=$ac_check_lib_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_dld_dld_link" >&5
+$as_echo "$ac_cv_lib_dld_dld_link" >&6; }
+if test "x$ac_cv_lib_dld_dld_link" = xyes; then :
+  lt_cv_dlopen="dld_link" lt_cv_dlopen_libs="-ldld"
+fi
+
+
+fi
+
+
+fi
+
+
+fi
+
+
+fi
+
+
+fi
+
+    ;;
+  esac
+
+  if test "x$lt_cv_dlopen" != xno; then
+    enable_dlopen=yes
+  else
+    enable_dlopen=no
+  fi
+
+  case $lt_cv_dlopen in
+  dlopen)
+    save_CPPFLAGS="$CPPFLAGS"
+    test "x$ac_cv_header_dlfcn_h" = xyes && CPPFLAGS="$CPPFLAGS -DHAVE_DLFCN_H"
+
+    save_LDFLAGS="$LDFLAGS"
+    wl=$lt_prog_compiler_wl eval LDFLAGS=\"\$LDFLAGS $export_dynamic_flag_spec\"
+
+    save_LIBS="$LIBS"
+    LIBS="$lt_cv_dlopen_libs $LIBS"
+
+    { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether a program can dlopen itself" >&5
+$as_echo_n "checking whether a program can dlopen itself... " >&6; }
+if ${lt_cv_dlopen_self+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  	  if test "$cross_compiling" = yes; then :
+  lt_cv_dlopen_self=cross
+else
+  lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
+  lt_status=$lt_dlunknown
+  cat > conftest.$ac_ext <<_LT_EOF
+#line $LINENO "configure"
+#include "confdefs.h"
+
+#if HAVE_DLFCN_H
+#include <dlfcn.h>
+#endif
+
+#include <stdio.h>
+
+#ifdef RTLD_GLOBAL
+#  define LT_DLGLOBAL		RTLD_GLOBAL
+#else
+#  ifdef DL_GLOBAL
+#    define LT_DLGLOBAL		DL_GLOBAL
+#  else
+#    define LT_DLGLOBAL		0
+#  endif
+#endif
+
+/* We may have to define LT_DLLAZY_OR_NOW in the command line if we
+   find out it does not work in some platform. */
+#ifndef LT_DLLAZY_OR_NOW
+#  ifdef RTLD_LAZY
+#    define LT_DLLAZY_OR_NOW		RTLD_LAZY
+#  else
+#    ifdef DL_LAZY
+#      define LT_DLLAZY_OR_NOW		DL_LAZY
+#    else
+#      ifdef RTLD_NOW
+#        define LT_DLLAZY_OR_NOW	RTLD_NOW
+#      else
+#        ifdef DL_NOW
+#          define LT_DLLAZY_OR_NOW	DL_NOW
+#        else
+#          define LT_DLLAZY_OR_NOW	0
+#        endif
+#      endif
+#    endif
+#  endif
+#endif
+
+/* When -fvisbility=hidden is used, assume the code has been annotated
+   correspondingly for the symbols needed.  */
+#if defined(__GNUC__) && (((__GNUC__ == 3) && (__GNUC_MINOR__ >= 3)) || (__GNUC__ > 3))
+int fnord () __attribute__((visibility("default")));
+#endif
+
+int fnord () { return 42; }
+int main ()
+{
+  void *self = dlopen (0, LT_DLGLOBAL|LT_DLLAZY_OR_NOW);
+  int status = $lt_dlunknown;
+
+  if (self)
+    {
+      if (dlsym (self,"fnord"))       status = $lt_dlno_uscore;
+      else
+        {
+	  if (dlsym( self,"_fnord"))  status = $lt_dlneed_uscore;
+          else puts (dlerror ());
+	}
+      /* dlclose (self); */
+    }
+  else
+    puts (dlerror ());
+
+  return status;
+}
+_LT_EOF
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_link\""; } >&5
+  (eval $ac_link) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && test -s conftest${ac_exeext} 2>/dev/null; then
+    (./conftest; exit; ) >&5 2>/dev/null
+    lt_status=$?
+    case x$lt_status in
+      x$lt_dlno_uscore) lt_cv_dlopen_self=yes ;;
+      x$lt_dlneed_uscore) lt_cv_dlopen_self=yes ;;
+      x$lt_dlunknown|x*) lt_cv_dlopen_self=no ;;
+    esac
+  else :
+    # compilation failed
+    lt_cv_dlopen_self=no
+  fi
+fi
+rm -fr conftest*
+
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_dlopen_self" >&5
+$as_echo "$lt_cv_dlopen_self" >&6; }
+
+    if test "x$lt_cv_dlopen_self" = xyes; then
+      wl=$lt_prog_compiler_wl eval LDFLAGS=\"\$LDFLAGS $lt_prog_compiler_static\"
+      { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether a statically linked program can dlopen itself" >&5
+$as_echo_n "checking whether a statically linked program can dlopen itself... " >&6; }
+if ${lt_cv_dlopen_self_static+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  	  if test "$cross_compiling" = yes; then :
+  lt_cv_dlopen_self_static=cross
+else
+  lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
+  lt_status=$lt_dlunknown
+  cat > conftest.$ac_ext <<_LT_EOF
+#line $LINENO "configure"
+#include "confdefs.h"
+
+#if HAVE_DLFCN_H
+#include <dlfcn.h>
+#endif
+
+#include <stdio.h>
+
+#ifdef RTLD_GLOBAL
+#  define LT_DLGLOBAL		RTLD_GLOBAL
+#else
+#  ifdef DL_GLOBAL
+#    define LT_DLGLOBAL		DL_GLOBAL
+#  else
+#    define LT_DLGLOBAL		0
+#  endif
+#endif
+
+/* We may have to define LT_DLLAZY_OR_NOW in the command line if we
+   find out it does not work in some platform. */
+#ifndef LT_DLLAZY_OR_NOW
+#  ifdef RTLD_LAZY
+#    define LT_DLLAZY_OR_NOW		RTLD_LAZY
+#  else
+#    ifdef DL_LAZY
+#      define LT_DLLAZY_OR_NOW		DL_LAZY
+#    else
+#      ifdef RTLD_NOW
+#        define LT_DLLAZY_OR_NOW	RTLD_NOW
+#      else
+#        ifdef DL_NOW
+#          define LT_DLLAZY_OR_NOW	DL_NOW
+#        else
+#          define LT_DLLAZY_OR_NOW	0
+#        endif
+#      endif
+#    endif
+#  endif
+#endif
+
+/* When -fvisbility=hidden is used, assume the code has been annotated
+   correspondingly for the symbols needed.  */
+#if defined(__GNUC__) && (((__GNUC__ == 3) && (__GNUC_MINOR__ >= 3)) || (__GNUC__ > 3))
+int fnord () __attribute__((visibility("default")));
+#endif
+
+int fnord () { return 42; }
+int main ()
+{
+  void *self = dlopen (0, LT_DLGLOBAL|LT_DLLAZY_OR_NOW);
+  int status = $lt_dlunknown;
+
+  if (self)
+    {
+      if (dlsym (self,"fnord"))       status = $lt_dlno_uscore;
+      else
+        {
+	  if (dlsym( self,"_fnord"))  status = $lt_dlneed_uscore;
+          else puts (dlerror ());
+	}
+      /* dlclose (self); */
+    }
+  else
+    puts (dlerror ());
+
+  return status;
+}
+_LT_EOF
+  if { { eval echo "\"\$as_me\":${as_lineno-$LINENO}: \"$ac_link\""; } >&5
+  (eval $ac_link) 2>&5
+  ac_status=$?
+  $as_echo "$as_me:${as_lineno-$LINENO}: \$? = $ac_status" >&5
+  test $ac_status = 0; } && test -s conftest${ac_exeext} 2>/dev/null; then
+    (./conftest; exit; ) >&5 2>/dev/null
+    lt_status=$?
+    case x$lt_status in
+      x$lt_dlno_uscore) lt_cv_dlopen_self_static=yes ;;
+      x$lt_dlneed_uscore) lt_cv_dlopen_self_static=yes ;;
+      x$lt_dlunknown|x*) lt_cv_dlopen_self_static=no ;;
+    esac
+  else :
+    # compilation failed
+    lt_cv_dlopen_self_static=no
+  fi
+fi
+rm -fr conftest*
+
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $lt_cv_dlopen_self_static" >&5
+$as_echo "$lt_cv_dlopen_self_static" >&6; }
+    fi
+
+    CPPFLAGS="$save_CPPFLAGS"
+    LDFLAGS="$save_LDFLAGS"
+    LIBS="$save_LIBS"
+    ;;
+  esac
+
+  case $lt_cv_dlopen_self in
+  yes|no) enable_dlopen_self=$lt_cv_dlopen_self ;;
+  *) enable_dlopen_self=unknown ;;
+  esac
+
+  case $lt_cv_dlopen_self_static in
+  yes|no) enable_dlopen_self_static=$lt_cv_dlopen_self_static ;;
+  *) enable_dlopen_self_static=unknown ;;
+  esac
+fi
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+striplib=
+old_striplib=
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether stripping libraries is possible" >&5
+$as_echo_n "checking whether stripping libraries is possible... " >&6; }
+if test -n "$STRIP" && $STRIP -V 2>&1 | $GREP "GNU strip" >/dev/null; then
+  test -z "$old_striplib" && old_striplib="$STRIP --strip-debug"
+  test -z "$striplib" && striplib="$STRIP --strip-unneeded"
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+else
+# FIXME - insert some real tests, host_os isn't really good enough
+  case $host_os in
+  darwin*)
+    if test -n "$STRIP" ; then
+      striplib="$STRIP -x"
+      old_striplib="$STRIP -S"
+      { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+    else
+      { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+    fi
+    ;;
+  *)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+    ;;
+  esac
+fi
+
+
+
+
+
+
+
+
+
+
+
+
+  # Report which library types will actually be built
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking if libtool supports shared libraries" >&5
+$as_echo_n "checking if libtool supports shared libraries... " >&6; }
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $can_build_shared" >&5
+$as_echo "$can_build_shared" >&6; }
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to build shared libraries" >&5
+$as_echo_n "checking whether to build shared libraries... " >&6; }
+  test "$can_build_shared" = "no" && enable_shared=no
+
+  # On AIX, shared libraries and static libraries use the same namespace, and
+  # are all built from PIC.
+  case $host_os in
+  aix3*)
+    test "$enable_shared" = yes && enable_static=no
+    if test -n "$RANLIB"; then
+      archive_cmds="$archive_cmds~\$RANLIB \$lib"
+      postinstall_cmds='$RANLIB $lib'
+    fi
+    ;;
+
+  aix[4-9]*)
+    if test "$host_cpu" != ia64 && test "$aix_use_runtimelinking" = no ; then
+      test "$enable_shared" = yes && enable_static=no
+    fi
+    ;;
+  esac
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $enable_shared" >&5
+$as_echo "$enable_shared" >&6; }
+
+  { $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to build static libraries" >&5
+$as_echo_n "checking whether to build static libraries... " >&6; }
+  # Make sure either enable_shared or enable_static is yes.
+  test "$enable_shared" = yes || enable_static=yes
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: $enable_static" >&5
+$as_echo "$enable_static" >&6; }
+
+
+
+
+fi
+ac_ext=c
+ac_cpp='$CPP $CPPFLAGS'
+ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
+ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
+ac_compiler_gnu=$ac_cv_c_compiler_gnu
+
+CC="$lt_save_CC"
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+        ac_config_commands="$ac_config_commands libtool"
+
+
+
+
+# Only expand once:
+
+
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** types" >&5
+$as_echo "$as_me: **************************************** types" >&6;}
+ac_fn_c_find_intX_t "$LINENO" "8" "ac_cv_c_int8_t"
+case $ac_cv_c_int8_t in #(
+  no|yes) ;; #(
+  *)
+
+cat >>confdefs.h <<_ACEOF
+#define int8_t $ac_cv_c_int8_t
+_ACEOF
+;;
+esac
+
+ac_fn_c_find_intX_t "$LINENO" "16" "ac_cv_c_int16_t"
+case $ac_cv_c_int16_t in #(
+  no|yes) ;; #(
+  *)
+
+cat >>confdefs.h <<_ACEOF
+#define int16_t $ac_cv_c_int16_t
+_ACEOF
+;;
+esac
+
+ac_fn_c_find_intX_t "$LINENO" "32" "ac_cv_c_int32_t"
+case $ac_cv_c_int32_t in #(
+  no|yes) ;; #(
+  *)
+
+cat >>confdefs.h <<_ACEOF
+#define int32_t $ac_cv_c_int32_t
+_ACEOF
+;;
+esac
+
+ac_fn_c_find_intX_t "$LINENO" "64" "ac_cv_c_int64_t"
+case $ac_cv_c_int64_t in #(
+  no|yes) ;; #(
+  *)
+
+cat >>confdefs.h <<_ACEOF
+#define int64_t $ac_cv_c_int64_t
+_ACEOF
+;;
+esac
+
+ac_fn_c_find_uintX_t "$LINENO" "8" "ac_cv_c_uint8_t"
+case $ac_cv_c_uint8_t in #(
+  no|yes) ;; #(
+  *)
+
+$as_echo "#define _UINT8_T 1" >>confdefs.h
+
+
+cat >>confdefs.h <<_ACEOF
+#define uint8_t $ac_cv_c_uint8_t
+_ACEOF
+;;
+  esac
+
+ac_fn_c_find_uintX_t "$LINENO" "16" "ac_cv_c_uint16_t"
+case $ac_cv_c_uint16_t in #(
+  no|yes) ;; #(
+  *)
+
+
+cat >>confdefs.h <<_ACEOF
+#define uint16_t $ac_cv_c_uint16_t
+_ACEOF
+;;
+  esac
+
+ac_fn_c_find_uintX_t "$LINENO" "32" "ac_cv_c_uint32_t"
+case $ac_cv_c_uint32_t in #(
+  no|yes) ;; #(
+  *)
+
+$as_echo "#define _UINT32_T 1" >>confdefs.h
+
+
+cat >>confdefs.h <<_ACEOF
+#define uint32_t $ac_cv_c_uint32_t
+_ACEOF
+;;
+  esac
+
+ac_fn_c_find_uintX_t "$LINENO" "64" "ac_cv_c_uint64_t"
+case $ac_cv_c_uint64_t in #(
+  no|yes) ;; #(
+  *)
+
+$as_echo "#define _UINT64_T 1" >>confdefs.h
+
+
+cat >>confdefs.h <<_ACEOF
+#define uint64_t $ac_cv_c_uint64_t
+_ACEOF
+;;
+  esac
+
+ac_fn_c_check_type "$LINENO" "size_t" "ac_cv_type_size_t" "$ac_includes_default"
+if test "x$ac_cv_type_size_t" = xyes; then :
+
+else
+
+cat >>confdefs.h <<_ACEOF
+#define size_t unsigned int
+_ACEOF
+
+fi
+
+ac_fn_c_check_type "$LINENO" "ssize_t" "ac_cv_type_ssize_t" "$ac_includes_default"
+if test "x$ac_cv_type_ssize_t" = xyes; then :
+
+else
+
+cat >>confdefs.h <<_ACEOF
+#define ssize_t int
+_ACEOF
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for uid_t in sys/types.h" >&5
+$as_echo_n "checking for uid_t in sys/types.h... " >&6; }
+if ${ac_cv_type_uid_t+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <sys/types.h>
+
+_ACEOF
+if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
+  $EGREP "uid_t" >/dev/null 2>&1; then :
+  ac_cv_type_uid_t=yes
+else
+  ac_cv_type_uid_t=no
+fi
+rm -f conftest*
+
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_type_uid_t" >&5
+$as_echo "$ac_cv_type_uid_t" >&6; }
+if test $ac_cv_type_uid_t = no; then
+
+$as_echo "#define uid_t int" >>confdefs.h
+
+
+$as_echo "#define gid_t int" >>confdefs.h
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for socklen_t" >&5
+$as_echo_n "checking for socklen_t... " >&6; }
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+#include <sys/socket.h>
+
+_ACEOF
+if (eval "$ac_cpp conftest.$ac_ext") 2>&5 |
+  $EGREP "socklen_t" >/dev/null 2>&1; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no (defined as int)" >&5
+$as_echo "no (defined as int)" >&6; }
+
+$as_echo "#define socklen_t int" >>confdefs.h
+
+fi
+rm -f conftest*
+
+ac_fn_c_check_type "$LINENO" "struct sockaddr_un" "ac_cv_type_struct_sockaddr_un" "#include <sys/un.h>
+"
+if test "x$ac_cv_type_struct_sockaddr_un" = xyes; then :
+
+cat >>confdefs.h <<_ACEOF
+#define HAVE_STRUCT_SOCKADDR_UN 1
+_ACEOF
+
+
+fi
+
+ac_fn_c_check_type "$LINENO" "struct addrinfo" "ac_cv_type_struct_addrinfo" "#include <netdb.h>
+"
+if test "x$ac_cv_type_struct_addrinfo" = xyes; then :
+
+cat >>confdefs.h <<_ACEOF
+#define HAVE_STRUCT_ADDRINFO 1
+_ACEOF
+
+
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** PTY device files" >&5
+$as_echo "$as_me: **************************************** PTY device files" >&6;}
+if test "x$cross_compiling" = "xno"; then
+    as_ac_File=`$as_echo "ac_cv_file_"/dev/ptmx"" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for \"/dev/ptmx\"" >&5
+$as_echo_n "checking for \"/dev/ptmx\"... " >&6; }
+if eval \${$as_ac_File+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  test "$cross_compiling" = yes &&
+  as_fn_error $? "cannot check for file existence when cross compiling" "$LINENO" 5
+if test -r ""/dev/ptmx""; then
+  eval "$as_ac_File=yes"
+else
+  eval "$as_ac_File=no"
+fi
+fi
+eval ac_res=\$$as_ac_File
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if eval test \"x\$"$as_ac_File"\" = x"yes"; then :
+
+$as_echo "#define HAVE_DEV_PTMX 1" >>confdefs.h
+
+fi
+
+    as_ac_File=`$as_echo "ac_cv_file_"/dev/ptc"" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for \"/dev/ptc\"" >&5
+$as_echo_n "checking for \"/dev/ptc\"... " >&6; }
+if eval \${$as_ac_File+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  test "$cross_compiling" = yes &&
+  as_fn_error $? "cannot check for file existence when cross compiling" "$LINENO" 5
+if test -r ""/dev/ptc""; then
+  eval "$as_ac_File=yes"
+else
+  eval "$as_ac_File=no"
+fi
+fi
+eval ac_res=\$$as_ac_File
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if eval test \"x\$"$as_ac_File"\" = x"yes"; then :
+
+$as_echo "#define HAVE_DEV_PTS_AND_PTC 1" >>confdefs.h
+
+fi
+
+else
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: cross-compilation: assuming /dev/ptmx and /dev/ptc are not available" >&5
+$as_echo "$as_me: WARNING: cross-compilation: assuming /dev/ptmx and /dev/ptc are not available" >&2;}
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** entropy sources" >&5
+$as_echo "$as_me: **************************************** entropy sources" >&6;}
+
+if test "x$cross_compiling" = "xno"; then
+
+# Check whether --with-egd-socket was given.
+if test "${with_egd_socket+set}" = set; then :
+  withval=$with_egd_socket; EGD_SOCKET="$withval"
+
+fi
+
+    if test -n "$EGD_SOCKET"; then
+
+cat >>confdefs.h <<_ACEOF
+#define EGD_SOCKET "$EGD_SOCKET"
+_ACEOF
+
+    fi
+
+    # Check for user-specified random device
+
+# Check whether --with-random was given.
+if test "${with_random+set}" = set; then :
+  withval=$with_random; RANDOM_FILE="$withval"
+else
+
+            # Check for random device
+            as_ac_File=`$as_echo "ac_cv_file_"/dev/urandom"" | $as_tr_sh`
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for \"/dev/urandom\"" >&5
+$as_echo_n "checking for \"/dev/urandom\"... " >&6; }
+if eval \${$as_ac_File+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  test "$cross_compiling" = yes &&
+  as_fn_error $? "cannot check for file existence when cross compiling" "$LINENO" 5
+if test -r ""/dev/urandom""; then
+  eval "$as_ac_File=yes"
+else
+  eval "$as_ac_File=no"
+fi
+fi
+eval ac_res=\$$as_ac_File
+	       { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
+$as_echo "$ac_res" >&6; }
+if eval test \"x\$"$as_ac_File"\" = x"yes"; then :
+  RANDOM_FILE="/dev/urandom"
+fi
+
+
+
+fi
+
+    if test -n "$RANDOM_FILE"; then
+
+
+cat >>confdefs.h <<_ACEOF
+#define RANDOM_FILE "$RANDOM_FILE"
+_ACEOF
+
+    fi
+else
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: cross-compilation: assuming entropy sources are not available" >&5
+$as_echo "$as_me: WARNING: cross-compilation: assuming entropy sources are not available" >&2;}
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** default group" >&5
+$as_echo "$as_me: **************************************** default group" >&6;}
+DEFAULT_GROUP=nobody
+if test "x$cross_compiling" = "xno"; then
+    grep '^nogroup:' /etc/group >/dev/null && DEFAULT_GROUP=nogroup
+else
+    { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: cross-compilation: assuming nogroup is not available" >&5
+$as_echo "$as_me: WARNING: cross-compilation: assuming nogroup is not available" >&2;}
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for default group" >&5
+$as_echo_n "checking for default group... " >&6; }
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $DEFAULT_GROUP" >&5
+$as_echo "$DEFAULT_GROUP" >&6; }
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** header files" >&5
+$as_echo "$as_me: **************************************** header files" >&6;}
+# AC_HEADER_DIRENT
+# AC_HEADER_STDC
+# AC_HEADER_SYS_WAIT
+for ac_header in stdint.h inttypes.h malloc.h ucontext.h pthread.h poll.h tcpd.h stropts.h grp.h unistd.h util.h libutil.h pty.h
+do :
+  as_ac_Header=`$as_echo "ac_cv_header_$ac_header" | $as_tr_sh`
+ac_fn_c_check_header_mongrel "$LINENO" "$ac_header" "$as_ac_Header" "$ac_includes_default"
+if eval test \"x\$"$as_ac_Header"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_header" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+
+done
+
+for ac_header in sys/types.h sys/select.h sys/poll.h sys/socket.h sys/un.h sys/ioctl.h sys/filio.h sys/resource.h sys/uio.h sys/syscall.h
+do :
+  as_ac_Header=`$as_echo "ac_cv_header_$ac_header" | $as_tr_sh`
+ac_fn_c_check_header_mongrel "$LINENO" "$ac_header" "$as_ac_Header" "$ac_includes_default"
+if eval test \"x\$"$as_ac_Header"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_header" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+
+done
+
+for ac_header in linux/sched.h
+do :
+  ac_fn_c_check_header_mongrel "$LINENO" "linux/sched.h" "ac_cv_header_linux_sched_h" "$ac_includes_default"
+if test "x$ac_cv_header_linux_sched_h" = xyes; then :
+  cat >>confdefs.h <<_ACEOF
+#define HAVE_LINUX_SCHED_H 1
+_ACEOF
+
+fi
+
+done
+
+ac_fn_c_check_member "$LINENO" "struct msghdr" "msg_control" "ac_cv_member_struct_msghdr_msg_control" "
+$ac_includes_default
+#include <sys/socket.h>
+
+"
+if test "x$ac_cv_member_struct_msghdr_msg_control" = xyes; then :
+
+cat >>confdefs.h <<_ACEOF
+#define HAVE_STRUCT_MSGHDR_MSG_CONTROL 1
+_ACEOF
+
+
+$as_echo "#define HAVE_MSGHDR_MSG_CONTROL 1" >>confdefs.h
+
+fi
+
+for ac_header in linux/netfilter_ipv4.h
+do :
+  ac_fn_c_check_header_compile "$LINENO" "linux/netfilter_ipv4.h" "ac_cv_header_linux_netfilter_ipv4_h" "
+#include <limits.h>
+#include <linux/types.h>
+#include <sys/socket.h>
+#include <netdb.h>
+
+"
+if test "x$ac_cv_header_linux_netfilter_ipv4_h" = xyes; then :
+  cat >>confdefs.h <<_ACEOF
+#define HAVE_LINUX_NETFILTER_IPV4_H 1
+_ACEOF
+
+fi
+
+done
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** libraries" >&5
+$as_echo "$as_me: **************************************** libraries" >&6;}
+# Checks for standard libraries
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing gethostbyname" >&5
+$as_echo_n "checking for library containing gethostbyname... " >&6; }
+if ${ac_cv_search_gethostbyname+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char gethostbyname ();
+int
+main ()
+{
+return gethostbyname ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' nsl; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_gethostbyname=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_gethostbyname+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_gethostbyname+:} false; then :
+
+else
+  ac_cv_search_gethostbyname=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_gethostbyname" >&5
+$as_echo "$ac_cv_search_gethostbyname" >&6; }
+ac_res=$ac_cv_search_gethostbyname
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing yp_get_default_domain" >&5
+$as_echo_n "checking for library containing yp_get_default_domain... " >&6; }
+if ${ac_cv_search_yp_get_default_domain+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char yp_get_default_domain ();
+int
+main ()
+{
+return yp_get_default_domain ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' nsl; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_yp_get_default_domain=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_yp_get_default_domain+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_yp_get_default_domain+:} false; then :
+
+else
+  ac_cv_search_yp_get_default_domain=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_yp_get_default_domain" >&5
+$as_echo "$ac_cv_search_yp_get_default_domain" >&6; }
+ac_res=$ac_cv_search_yp_get_default_domain
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing socket" >&5
+$as_echo_n "checking for library containing socket... " >&6; }
+if ${ac_cv_search_socket+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char socket ();
+int
+main ()
+{
+return socket ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' socket; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_socket=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_socket+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_socket+:} false; then :
+
+else
+  ac_cv_search_socket=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_socket" >&5
+$as_echo "$ac_cv_search_socket" >&6; }
+ac_res=$ac_cv_search_socket
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing openpty" >&5
+$as_echo_n "checking for library containing openpty... " >&6; }
+if ${ac_cv_search_openpty+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char openpty ();
+int
+main ()
+{
+return openpty ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' util; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_openpty=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_openpty+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_openpty+:} false; then :
+
+else
+  ac_cv_search_openpty=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_openpty" >&5
+$as_echo "$ac_cv_search_openpty" >&6; }
+ac_res=$ac_cv_search_openpty
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+# Checks for dynamic loader and zlib needed by OpenSSL
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing dlopen" >&5
+$as_echo_n "checking for library containing dlopen... " >&6; }
+if ${ac_cv_search_dlopen+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char dlopen ();
+int
+main ()
+{
+return dlopen ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' dl; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_dlopen=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_dlopen+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_dlopen+:} false; then :
+
+else
+  ac_cv_search_dlopen=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_dlopen" >&5
+$as_echo "$ac_cv_search_dlopen" >&6; }
+ac_res=$ac_cv_search_dlopen
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing shl_load" >&5
+$as_echo_n "checking for library containing shl_load... " >&6; }
+if ${ac_cv_search_shl_load+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char shl_load ();
+int
+main ()
+{
+return shl_load ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' dld; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_shl_load=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_shl_load+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_shl_load+:} false; then :
+
+else
+  ac_cv_search_shl_load=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_shl_load" >&5
+$as_echo "$ac_cv_search_shl_load" >&6; }
+ac_res=$ac_cv_search_shl_load
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing inflateEnd" >&5
+$as_echo_n "checking for library containing inflateEnd... " >&6; }
+if ${ac_cv_search_inflateEnd+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char inflateEnd ();
+int
+main ()
+{
+return inflateEnd ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' z; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_inflateEnd=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_inflateEnd+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_inflateEnd+:} false; then :
+
+else
+  ac_cv_search_inflateEnd=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_inflateEnd" >&5
+$as_echo "$ac_cv_search_inflateEnd" >&6; }
+ac_res=$ac_cv_search_inflateEnd
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+
+# Add BeOS libraries
+if test "x$host_os" = "xbeos"; then
+    LIBS="$LIBS -lbe -lroot -lbind"
+fi
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** library functions" >&5
+$as_echo "$as_me: **************************************** library functions" >&6;}
+# safe string operations
+for ac_func in snprintf vsnprintf
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# pseudoterminal
+for ac_func in openpty _getpty
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# Unix
+for ac_func in daemon waitpid wait4 setsid setgroups chroot
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# limits
+for ac_func in sysconf getrlimit
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# threads/reentrant functions
+for ac_func in pthread_sigmask localtime_r
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# threads
+for ac_func in getcontext __makecontext_v2
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+# sockets
+for ac_func in poll gethostbyname2 endhostent getnameinfo
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for getaddrinfo" >&5
+$as_echo_n "checking for getaddrinfo... " >&6; }
+case "$host_os" in
+*androideabi*)
+    # http://stackoverflow.com/questions/7818246/segmentation-fault-in-getaddrinfo
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: no (buggy Android implementation)" >&5
+$as_echo "no (buggy Android implementation)" >&6; }
+    ;;
+*)
+    # Tru64 UNIX has getaddrinfo() but has it renamed in libc as
+    # something else so we must include <netdb.h> to get the
+    # redefinition.
+    cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+$ac_includes_default
+#include <sys/socket.h>
+#include <netdb.h>
+
+int
+main ()
+{
+
+getaddrinfo(NULL, NULL, NULL, NULL);
+
+  ;
+  return 0;
+}
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; };
+$as_echo "#define HAVE_GETADDRINFO 1" >>confdefs.h
+
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+    ;;
+esac
+# poll() is not recommended on Mac OS X <= 10.3 and broken on Mac OS X 10.4
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for broken poll() implementation" >&5
+$as_echo_n "checking for broken poll() implementation... " >&6; }
+case "$host_os" in
+darwin0-8.*)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes (poll() disabled)" >&5
+$as_echo "yes (poll() disabled)" >&6; }
+
+$as_echo "#define BROKEN_POLL 1" >>confdefs.h
+
+    ;;
+*)
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+    ;;
+esac
+# GNU extensions
+for ac_func in pipe2 accept4
+do :
+  as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh`
+ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var"
+if eval test \"x\$"$as_ac_var"\" = x"yes"; then :
+  cat >>confdefs.h <<_ACEOF
+#define `$as_echo "HAVE_$ac_func" | $as_tr_cpp` 1
+_ACEOF
+
+fi
+done
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** optional features" >&5
+$as_echo "$as_me: **************************************** optional features" >&6;}
+# Use IPv6?
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to enable IPv6 support" >&5
+$as_echo_n "checking whether to enable IPv6 support... " >&6; }
+# Check whether --enable-ipv6 was given.
+if test "${enable_ipv6+set}" = set; then :
+  enableval=$enable_ipv6;
+        case "$enableval" in
+            yes) { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+
+$as_echo "#define USE_IPv6 1" >>confdefs.h
+
+                 ;;
+            no)  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                 ;;
+            *)   { $as_echo "$as_me:${as_lineno-$LINENO}: result: error" >&5
+$as_echo "error" >&6; }
+                 as_fn_error $? "bad value \"${enableval}\"" "$LINENO" 5
+                 ;;
+        esac
+
+else
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes (default)" >&5
+$as_echo "yes (default)" >&6; }
+
+$as_echo "#define USE_IPv6 1" >>confdefs.h
+
+
+fi
+
+
+# FIPS Mode
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to enable FIPS support" >&5
+$as_echo_n "checking whether to enable FIPS support... " >&6; }
+# Check whether --enable-fips was given.
+if test "${enable_fips+set}" = set; then :
+  enableval=$enable_fips;
+        case "$enableval" in
+            yes) { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                 use_fips="yes"
+
+$as_echo "#define USE_FIPS 1" >>confdefs.h
+
+                 ;;
+            no)  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                 use_fips="no"
+                 ;;
+            *)   { $as_echo "$as_me:${as_lineno-$LINENO}: result: error" >&5
+$as_echo "error" >&6; }
+                 as_fn_error $? "bad value \"${enableval}\"" "$LINENO" 5
+                 ;;
+        esac
+
+else
+
+        use_fips="auto"
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: autodetecting" >&5
+$as_echo "autodetecting" >&6; }
+
+
+fi
+
+
+# Disable systemd socket activation support
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to enable systemd socket activation support" >&5
+$as_echo_n "checking whether to enable systemd socket activation support... " >&6; }
+# Check whether --enable-systemd was given.
+if test "${enable_systemd+set}" = set; then :
+  enableval=$enable_systemd;
+        case "$enableval" in
+            yes) { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+                 { $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing sd_listen_fds" >&5
+$as_echo_n "checking for library containing sd_listen_fds... " >&6; }
+if ${ac_cv_search_sd_listen_fds+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char sd_listen_fds ();
+int
+main ()
+{
+return sd_listen_fds ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' systemd systemd-daemon; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_sd_listen_fds=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_sd_listen_fds+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_sd_listen_fds+:} false; then :
+
+else
+  ac_cv_search_sd_listen_fds=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_sd_listen_fds" >&5
+$as_echo "$ac_cv_search_sd_listen_fds" >&6; }
+ac_res=$ac_cv_search_sd_listen_fds
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+
+fi
+
+
+$as_echo "#define USE_SYSTEMD 1" >>confdefs.h
+
+                 ;;
+            no)  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                 ;;
+            *)   { $as_echo "$as_me:${as_lineno-$LINENO}: result: error" >&5
+$as_echo "error" >&6; }
+                 as_fn_error $? "Bad value \"${enableval}\"" "$LINENO" 5
+                 ;;
+        esac
+
+else
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: autodetecting" >&5
+$as_echo "autodetecting" >&6; }
+        # the library name has changed to -lsystemd in systemd 209
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for library containing sd_listen_fds" >&5
+$as_echo_n "checking for library containing sd_listen_fds... " >&6; }
+if ${ac_cv_search_sd_listen_fds+:} false; then :
+  $as_echo_n "(cached) " >&6
+else
+  ac_func_search_save_LIBS=$LIBS
+cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+/* Override any GCC internal prototype to avoid an error.
+   Use char because int might match the return type of a GCC
+   builtin and then its argument prototype would still apply.  */
+#ifdef __cplusplus
+extern "C"
+#endif
+char sd_listen_fds ();
+int
+main ()
+{
+return sd_listen_fds ();
+  ;
+  return 0;
+}
+_ACEOF
+for ac_lib in '' systemd systemd-daemon; do
+  if test -z "$ac_lib"; then
+    ac_res="none required"
+  else
+    ac_res=-l$ac_lib
+    LIBS="-l$ac_lib  $ac_func_search_save_LIBS"
+  fi
+  if ac_fn_c_try_link "$LINENO"; then :
+  ac_cv_search_sd_listen_fds=$ac_res
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext
+  if ${ac_cv_search_sd_listen_fds+:} false; then :
+  break
+fi
+done
+if ${ac_cv_search_sd_listen_fds+:} false; then :
+
+else
+  ac_cv_search_sd_listen_fds=no
+fi
+rm conftest.$ac_ext
+LIBS=$ac_func_search_save_LIBS
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_search_sd_listen_fds" >&5
+$as_echo "$ac_cv_search_sd_listen_fds" >&6; }
+ac_res=$ac_cv_search_sd_listen_fds
+if test "$ac_res" != no; then :
+  test "$ac_res" = "none required" || LIBS="$ac_res $LIBS"
+   for ac_header in systemd/sd-daemon.h
+do :
+  ac_fn_c_check_header_mongrel "$LINENO" "systemd/sd-daemon.h" "ac_cv_header_systemd_sd_daemon_h" "$ac_includes_default"
+if test "x$ac_cv_header_systemd_sd_daemon_h" = xyes; then :
+  cat >>confdefs.h <<_ACEOF
+#define HAVE_SYSTEMD_SD_DAEMON_H 1
+_ACEOF
+
+
+$as_echo "#define USE_SYSTEMD 1" >>confdefs.h
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: systemd support enabled" >&5
+$as_echo "$as_me: systemd support enabled" >&6;}
+
+else
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: systemd header not found" >&5
+$as_echo "$as_me: systemd header not found" >&6;}
+
+fi
+
+done
+
+else
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: systemd library not found" >&5
+$as_echo "$as_me: systemd library not found" >&6;}
+
+fi
+
+
+
+fi
+
+
+# Disable use of libwrap (TCP wrappers)
+# it should be the last check!
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether to enable TCP wrappers support" >&5
+$as_echo_n "checking whether to enable TCP wrappers support... " >&6; }
+# Check whether --enable-libwrap was given.
+if test "${enable_libwrap+set}" = set; then :
+  enableval=$enable_libwrap;
+        case "$enableval" in
+            yes) { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; }
+
+$as_echo "#define USE_LIBWRAP 1" >>confdefs.h
+
+                 LIBS="$LIBS -lwrap"
+                 ;;
+            no)  { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                 ;;
+            *)   { $as_echo "$as_me:${as_lineno-$LINENO}: result: error" >&5
+$as_echo "error" >&6; }
+                 as_fn_error $? "Bad value \"${enableval}\"" "$LINENO" 5
+                 ;;
+        esac
+
+else
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: result: autodetecting" >&5
+$as_echo "autodetecting" >&6; }
+        { $as_echo "$as_me:${as_lineno-$LINENO}: checking for hosts_access in -lwrap" >&5
+$as_echo_n "checking for hosts_access in -lwrap... " >&6; }
+        valid_LIBS="$LIBS"
+        LIBS="$valid_LIBS -lwrap"
+        cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h.  */
+
+                int hosts_access(); int allow_severity, deny_severity;
+int
+main ()
+{
+hosts_access()
+  ;
+  return 0;
+}
+
+_ACEOF
+if ac_fn_c_try_link "$LINENO"; then :
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
+$as_echo "yes" >&6; };
+
+$as_echo "#define USE_LIBWRAP 1" >>confdefs.h
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: libwrap support enabled" >&5
+$as_echo "$as_me: libwrap support enabled" >&6;}
+
+else
+
+                { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
+$as_echo "no" >&6; }
+                LIBS="$valid_LIBS"
+                { $as_echo "$as_me:${as_lineno-$LINENO}: libwrap library not found" >&5
+$as_echo "$as_me: libwrap library not found" >&6;}
+
+
+fi
+rm -f core conftest.err conftest.$ac_objext \
+    conftest$ac_exeext conftest.$ac_ext
+
+
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** SSL" >&5
+$as_echo "$as_me: **************************************** SSL" >&6;}
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for compiler sysroot" >&5
+$as_echo_n "checking for compiler sysroot... " >&6; }
+if test "x$GCC" = "xyes"; then
+    sysroot=`$CC --print-sysroot 2>/dev/null`
+fi
+if test -z "$sysroot" -o "x$sysroot" = "x/"; then
+    sysroot=""
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: /" >&5
+$as_echo "/" >&6; }
+else
+    { $as_echo "$as_me:${as_lineno-$LINENO}: result: $sysroot" >&5
+$as_echo "$sysroot" >&6; }
+fi
+
+check_ssl_dir() { :
+    test -n "$1" -a -f "$1/include/openssl/ssl.h" && SSLDIR="$1"
+}
+
+find_ssl_dir() { :
+    stunnel_prefix="$prefix"
+    test "x$stunnel_prefix" = "xNONE" && stunnel_prefix=$ac_default_prefix
+    for main_dir in "$stunnel_prefix" "/usr/local" "/usr/lib" "/usr/pkg" "/opt/local" "/opt" "/usr" ""; do
+        for sub_dir in "/ssl" "/openssl" "/ossl" ""; do
+            check_ssl_dir "$sysroot$main_dir$sub_dir"
+            test -n "$SSLDIR" && return
+        done
+    done
+    if test -x "/usr/bin/xcrun"; then
+        sdk_path=`/usr/bin/xcrun --sdk macosx --show-sdk-path`
+        check_ssl_dir "$sdk_path/usr"
+    fi
+}
+
+SSLDIR=""
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for SSL directory" >&5
+$as_echo_n "checking for SSL directory... " >&6; }
+
+# Check whether --with-ssl was given.
+if test "${with_ssl+set}" = set; then :
+  withval=$with_ssl; check_ssl_dir "$withval"
+else
+  find_ssl_dir
+
+fi
+
+if test -z "$SSLDIR"; then
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: not found" >&5
+$as_echo "not found" >&6; }
+as_fn_error $? "
+Could not find your SSL library installation dir
+Use --with-ssl option to fix this problem
+" "$LINENO" 5
+fi
+{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $SSLDIR" >&5
+$as_echo "$SSLDIR" >&6; }
+
+
+cat >>confdefs.h <<_ACEOF
+#define SSLDIR "$SSLDIR"
+_ACEOF
+
+
+valid_CPPFLAGS="$CPPFLAGS"; CPPFLAGS="$CPPFLAGS -I$SSLDIR/include"
+valid_LIBS="$LIBS"; LIBS="$LIBS -L$SSLDIR/lib64 -L$SSLDIR/lib -lssl -lcrypto"
+
+as_ac_Header=`$as_echo "ac_cv_header_$SSLDIR/include/openssl/engine.h" | $as_tr_sh`
+ac_fn_c_check_header_mongrel "$LINENO" "$SSLDIR/include/openssl/engine.h" "$as_ac_Header" "$ac_includes_default"
+if eval test \"x\$"$as_ac_Header"\" = x"yes"; then :
+
+$as_echo "#define HAVE_OSSL_ENGINE_H 1" >>confdefs.h
+
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: OpenSSL engine header not found" >&5
+$as_echo "$as_me: WARNING: OpenSSL engine header not found" >&2;}
+fi
+
+
+
+as_ac_Header=`$as_echo "ac_cv_header_$SSLDIR/include/openssl/ocsp.h" | $as_tr_sh`
+ac_fn_c_check_header_mongrel "$LINENO" "$SSLDIR/include/openssl/ocsp.h" "$as_ac_Header" "$ac_includes_default"
+if eval test \"x\$"$as_ac_Header"\" = x"yes"; then :
+
+$as_echo "#define HAVE_OSSL_OCSP_H 1" >>confdefs.h
+
+else
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: OpenSSL ocsp header not found" >&5
+$as_echo "$as_me: WARNING: OpenSSL ocsp header not found" >&2;}
+fi
+
+
+
+if test "x$use_fips" = "xauto"; then
+    for ac_func in FIPS_mode_set
+do :
+  ac_fn_c_check_func "$LINENO" "FIPS_mode_set" "ac_cv_func_FIPS_mode_set"
+if test "x$ac_cv_func_FIPS_mode_set" = xyes; then :
+  cat >>confdefs.h <<_ACEOF
+#define HAVE_FIPS_MODE_SET 1
+_ACEOF
+
+
+$as_echo "#define USE_FIPS 1" >>confdefs.h
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: FIPS support enabled" >&5
+$as_echo "$as_me: FIPS support enabled" >&6;}
+
+else
+
+        { $as_echo "$as_me:${as_lineno-$LINENO}: FIPS support not found" >&5
+$as_echo "$as_me: FIPS support not found" >&6;}
+
+fi
+done
+
+fi
+
+CPPFLAGS="$valid_CPPFLAGS"
+LIBS="$valid_LIBS"
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** write the results" >&5
+$as_echo "$as_me: **************************************** write the results" >&6;}
+ac_config_files="$ac_config_files Makefile src/Makefile doc/Makefile tools/Makefile"
+
+cat >confcache <<\_ACEOF
+# This file is a shell script that caches the results of configure
+# tests run on this system so they can be shared between configure
+# scripts and configure runs, see configure's option --config-cache.
+# It is not useful on other systems.  If it contains results you don't
+# want to keep, you may remove or edit it.
+#
+# config.status only pays attention to the cache file if you give it
+# the --recheck option to rerun configure.
+#
+# `ac_cv_env_foo' variables (set or unset) will be overridden when
+# loading this file, other *unset* `ac_cv_foo' will be assigned the
+# following values.
+
+_ACEOF
+
+# The following way of writing the cache mishandles newlines in values,
+# but we know of no workaround that is simple, portable, and efficient.
+# So, we kill variables containing newlines.
+# Ultrix sh set writes to stderr and can't be redirected directly,
+# and sets the high bit in the cache file unless we assign to the vars.
+(
+  for ac_var in `(set) 2>&1 | sed -n 's/^\([a-zA-Z_][a-zA-Z0-9_]*\)=.*/\1/p'`; do
+    eval ac_val=\$$ac_var
+    case $ac_val in #(
+    *${as_nl}*)
+      case $ac_var in #(
+      *_cv_*) { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: cache variable $ac_var contains a newline" >&5
+$as_echo "$as_me: WARNING: cache variable $ac_var contains a newline" >&2;} ;;
+      esac
+      case $ac_var in #(
+      _ | IFS | as_nl) ;; #(
+      BASH_ARGV | BASH_SOURCE) eval $ac_var= ;; #(
+      *) { eval $ac_var=; unset $ac_var;} ;;
+      esac ;;
+    esac
+  done
+
+  (set) 2>&1 |
+    case $as_nl`(ac_space=' '; set) 2>&1` in #(
+    *${as_nl}ac_space=\ *)
+      # `set' does not quote correctly, so add quotes: double-quote
+      # substitution turns \\\\ into \\, and sed turns \\ into \.
+      sed -n \
+	"s/'/'\\\\''/g;
+	  s/^\\([_$as_cr_alnum]*_cv_[_$as_cr_alnum]*\\)=\\(.*\\)/\\1='\\2'/p"
+      ;; #(
+    *)
+      # `set' quotes correctly as required by POSIX, so do not add quotes.
+      sed -n "/^[_$as_cr_alnum]*_cv_[_$as_cr_alnum]*=/p"
+      ;;
+    esac |
+    sort
+) |
+  sed '
+     /^ac_cv_env_/b end
+     t clear
+     :clear
+     s/^\([^=]*\)=\(.*[{}].*\)$/test "${\1+set}" = set || &/
+     t end
+     s/^\([^=]*\)=\(.*\)$/\1=${\1=\2}/
+     :end' >>confcache
+if diff "$cache_file" confcache >/dev/null 2>&1; then :; else
+  if test -w "$cache_file"; then
+    if test "x$cache_file" != "x/dev/null"; then
+      { $as_echo "$as_me:${as_lineno-$LINENO}: updating cache $cache_file" >&5
+$as_echo "$as_me: updating cache $cache_file" >&6;}
+      if test ! -f "$cache_file" || test -h "$cache_file"; then
+	cat confcache >"$cache_file"
+      else
+        case $cache_file in #(
+        */* | ?:*)
+	  mv -f confcache "$cache_file"$$ &&
+	  mv -f "$cache_file"$$ "$cache_file" ;; #(
+        *)
+	  mv -f confcache "$cache_file" ;;
+	esac
+      fi
+    fi
+  else
+    { $as_echo "$as_me:${as_lineno-$LINENO}: not updating unwritable cache $cache_file" >&5
+$as_echo "$as_me: not updating unwritable cache $cache_file" >&6;}
+  fi
+fi
+rm -f confcache
+
+test "x$prefix" = xNONE && prefix=$ac_default_prefix
+# Let make expand exec_prefix.
+test "x$exec_prefix" = xNONE && exec_prefix='${prefix}'
+
+DEFS=-DHAVE_CONFIG_H
+
+ac_libobjs=
+ac_ltlibobjs=
+U=
+for ac_i in : $LIBOBJS; do test "x$ac_i" = x: && continue
+  # 1. Remove the extension, and $U if already installed.
+  ac_script='s/\$U\././;s/\.o$//;s/\.obj$//'
+  ac_i=`$as_echo "$ac_i" | sed "$ac_script"`
+  # 2. Prepend LIBOBJDIR.  When used with automake>=1.10 LIBOBJDIR
+  #    will be set to the directory where LIBOBJS objects are built.
+  as_fn_append ac_libobjs " \${LIBOBJDIR}$ac_i\$U.$ac_objext"
+  as_fn_append ac_ltlibobjs " \${LIBOBJDIR}$ac_i"'$U.lo'
+done
+LIBOBJS=$ac_libobjs
+
+LTLIBOBJS=$ac_ltlibobjs
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: checking that generated files are newer than configure" >&5
+$as_echo_n "checking that generated files are newer than configure... " >&6; }
+   if test -n "$am_sleep_pid"; then
+     # Hide warnings about reused PIDs.
+     wait $am_sleep_pid 2>/dev/null
+   fi
+   { $as_echo "$as_me:${as_lineno-$LINENO}: result: done" >&5
+$as_echo "done" >&6; }
+ if test -n "$EXEEXT"; then
+  am__EXEEXT_TRUE=
+  am__EXEEXT_FALSE='#'
+else
+  am__EXEEXT_TRUE='#'
+  am__EXEEXT_FALSE=
+fi
+
+if test -z "${AUTHOR_TESTS_TRUE}" && test -z "${AUTHOR_TESTS_FALSE}"; then
+  as_fn_error $? "conditional \"AUTHOR_TESTS\" was never defined.
+Usually this means the macro was only invoked conditionally." "$LINENO" 5
+fi
+if test -z "${AMDEP_TRUE}" && test -z "${AMDEP_FALSE}"; then
+  as_fn_error $? "conditional \"AMDEP\" was never defined.
+Usually this means the macro was only invoked conditionally." "$LINENO" 5
+fi
+if test -z "${am__fastdepCC_TRUE}" && test -z "${am__fastdepCC_FALSE}"; then
+  as_fn_error $? "conditional \"am__fastdepCC\" was never defined.
+Usually this means the macro was only invoked conditionally." "$LINENO" 5
+fi
+
+: "${CONFIG_STATUS=./config.status}"
+ac_write_fail=0
+ac_clean_files_save=$ac_clean_files
+ac_clean_files="$ac_clean_files $CONFIG_STATUS"
+{ $as_echo "$as_me:${as_lineno-$LINENO}: creating $CONFIG_STATUS" >&5
+$as_echo "$as_me: creating $CONFIG_STATUS" >&6;}
+as_write_fail=0
+cat >$CONFIG_STATUS <<_ASEOF || as_write_fail=1
+#! $SHELL
+# Generated by $as_me.
+# Run this file to recreate the current configuration.
+# Compiler output produced by configure, useful for debugging
+# configure, is in config.log if it exists.
+
+debug=false
+ac_cs_recheck=false
+ac_cs_silent=false
+
+SHELL=\${CONFIG_SHELL-$SHELL}
+export SHELL
+_ASEOF
+cat >>$CONFIG_STATUS <<\_ASEOF || as_write_fail=1
+## -------------------- ##
+## M4sh Initialization. ##
+## -------------------- ##
+
+# Be more Bourne compatible
+DUALCASE=1; export DUALCASE # for MKS sh
+if test -n "${ZSH_VERSION+set}" && (emulate sh) >/dev/null 2>&1; then :
+  emulate sh
+  NULLCMD=:
+  # Pre-4.2 versions of Zsh do word splitting on ${1+"$@"}, which
+  # is contrary to our usage.  Disable this feature.
+  alias -g '${1+"$@"}'='"$@"'
+  setopt NO_GLOB_SUBST
+else
+  case `(set -o) 2>/dev/null` in #(
+  *posix*) :
+    set -o posix ;; #(
+  *) :
+     ;;
+esac
+fi
+
+
+as_nl='
+'
+export as_nl
+# Printing a long string crashes Solaris 7 /usr/bin/printf.
+as_echo='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+as_echo=$as_echo$as_echo$as_echo$as_echo$as_echo
+as_echo=$as_echo$as_echo$as_echo$as_echo$as_echo$as_echo
+# Prefer a ksh shell builtin over an external printf program on Solaris,
+# but without wasting forks for bash or zsh.
+if test -z "$BASH_VERSION$ZSH_VERSION" \
+    && (test "X`print -r -- $as_echo`" = "X$as_echo") 2>/dev/null; then
+  as_echo='print -r --'
+  as_echo_n='print -rn --'
+elif (test "X`printf %s $as_echo`" = "X$as_echo") 2>/dev/null; then
+  as_echo='printf %s\n'
+  as_echo_n='printf %s'
+else
+  if test "X`(/usr/ucb/echo -n -n $as_echo) 2>/dev/null`" = "X-n $as_echo"; then
+    as_echo_body='eval /usr/ucb/echo -n "$1$as_nl"'
+    as_echo_n='/usr/ucb/echo -n'
+  else
+    as_echo_body='eval expr "X$1" : "X\\(.*\\)"'
+    as_echo_n_body='eval
+      arg=$1;
+      case $arg in #(
+      *"$as_nl"*)
+	expr "X$arg" : "X\\(.*\\)$as_nl";
+	arg=`expr "X$arg" : ".*$as_nl\\(.*\\)"`;;
+      esac;
+      expr "X$arg" : "X\\(.*\\)" | tr -d "$as_nl"
+    '
+    export as_echo_n_body
+    as_echo_n='sh -c $as_echo_n_body as_echo'
+  fi
+  export as_echo_body
+  as_echo='sh -c $as_echo_body as_echo'
+fi
+
+# The user is always right.
+if test "${PATH_SEPARATOR+set}" != set; then
+  PATH_SEPARATOR=:
+  (PATH='/bin;/bin'; FPATH=$PATH; sh -c :) >/dev/null 2>&1 && {
+    (PATH='/bin:/bin'; FPATH=$PATH; sh -c :) >/dev/null 2>&1 ||
+      PATH_SEPARATOR=';'
+  }
+fi
+
+
+# IFS
+# We need space, tab and new line, in precisely that order.  Quoting is
+# there to prevent editors from complaining about space-tab.
+# (If _AS_PATH_WALK were called with IFS unset, it would disable word
+# splitting by setting IFS to empty value.)
+IFS=" ""	$as_nl"
+
+# Find who we are.  Look in the path if we contain no directory separator.
+as_myself=
+case $0 in #((
+  *[\\/]* ) as_myself=$0 ;;
+  *) as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+    test -r "$as_dir/$0" && as_myself=$as_dir/$0 && break
+  done
+IFS=$as_save_IFS
+
+     ;;
+esac
+# We did not find ourselves, most probably we were run as `sh COMMAND'
+# in which case we are not to be found in the path.
+if test "x$as_myself" = x; then
+  as_myself=$0
+fi
+if test ! -f "$as_myself"; then
+  $as_echo "$as_myself: error: cannot find myself; rerun with an absolute file name" >&2
+  exit 1
+fi
+
+# Unset variables that we do not need and which cause bugs (e.g. in
+# pre-3.0 UWIN ksh).  But do not cause bugs in bash 2.01; the "|| exit 1"
+# suppresses any "Segmentation fault" message there.  '((' could
+# trigger a bug in pdksh 5.2.14.
+for as_var in BASH_ENV ENV MAIL MAILPATH
+do eval test x\${$as_var+set} = xset \
+  && ( (unset $as_var) || exit 1) >/dev/null 2>&1 && unset $as_var || :
+done
+PS1='$ '
+PS2='> '
+PS4='+ '
+
+# NLS nuisances.
+LC_ALL=C
+export LC_ALL
+LANGUAGE=C
+export LANGUAGE
+
+# CDPATH.
+(unset CDPATH) >/dev/null 2>&1 && unset CDPATH
+
+
+# as_fn_error STATUS ERROR [LINENO LOG_FD]
+# ----------------------------------------
+# Output "`basename $0`: error: ERROR" to stderr. If LINENO and LOG_FD are
+# provided, also output the error to LOG_FD, referencing LINENO. Then exit the
+# script with STATUS, using 1 if that was 0.
+as_fn_error ()
+{
+  as_status=$1; test $as_status -eq 0 && as_status=1
+  if test "$4"; then
+    as_lineno=${as_lineno-"$3"} as_lineno_stack=as_lineno_stack=$as_lineno_stack
+    $as_echo "$as_me:${as_lineno-$LINENO}: error: $2" >&$4
+  fi
+  $as_echo "$as_me: error: $2" >&2
+  as_fn_exit $as_status
+} # as_fn_error
+
+
+# as_fn_set_status STATUS
+# -----------------------
+# Set $? to STATUS, without forking.
+as_fn_set_status ()
+{
+  return $1
+} # as_fn_set_status
+
+# as_fn_exit STATUS
+# -----------------
+# Exit the shell with STATUS, even in a "trap 0" or "set -e" context.
+as_fn_exit ()
+{
+  set +e
+  as_fn_set_status $1
+  exit $1
+} # as_fn_exit
+
+# as_fn_unset VAR
+# ---------------
+# Portably unset VAR.
+as_fn_unset ()
+{
+  { eval $1=; unset $1;}
+}
+as_unset=as_fn_unset
+# as_fn_append VAR VALUE
+# ----------------------
+# Append the text in VALUE to the end of the definition contained in VAR. Take
+# advantage of any shell optimizations that allow amortized linear growth over
+# repeated appends, instead of the typical quadratic growth present in naive
+# implementations.
+if (eval "as_var=1; as_var+=2; test x\$as_var = x12") 2>/dev/null; then :
+  eval 'as_fn_append ()
+  {
+    eval $1+=\$2
+  }'
+else
+  as_fn_append ()
+  {
+    eval $1=\$$1\$2
+  }
+fi # as_fn_append
+
+# as_fn_arith ARG...
+# ------------------
+# Perform arithmetic evaluation on the ARGs, and store the result in the
+# global $as_val. Take advantage of shells that can avoid forks. The arguments
+# must be portable across $(()) and expr.
+if (eval "test \$(( 1 + 1 )) = 2") 2>/dev/null; then :
+  eval 'as_fn_arith ()
+  {
+    as_val=$(( $* ))
+  }'
+else
+  as_fn_arith ()
+  {
+    as_val=`expr "$@" || test $? -eq 1`
+  }
+fi # as_fn_arith
+
+
+if expr a : '\(a\)' >/dev/null 2>&1 &&
+   test "X`expr 00001 : '.*\(...\)'`" = X001; then
+  as_expr=expr
+else
+  as_expr=false
+fi
+
+if (basename -- /) >/dev/null 2>&1 && test "X`basename -- / 2>&1`" = "X/"; then
+  as_basename=basename
+else
+  as_basename=false
+fi
+
+if (as_dir=`dirname -- /` && test "X$as_dir" = X/) >/dev/null 2>&1; then
+  as_dirname=dirname
+else
+  as_dirname=false
+fi
+
+as_me=`$as_basename -- "$0" ||
+$as_expr X/"$0" : '.*/\([^/][^/]*\)/*$' \| \
+	 X"$0" : 'X\(//\)$' \| \
+	 X"$0" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X/"$0" |
+    sed '/^.*\/\([^/][^/]*\)\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\/\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\/\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+
+# Avoid depending upon Character Ranges.
+as_cr_letters='abcdefghijklmnopqrstuvwxyz'
+as_cr_LETTERS='ABCDEFGHIJKLMNOPQRSTUVWXYZ'
+as_cr_Letters=$as_cr_letters$as_cr_LETTERS
+as_cr_digits='0123456789'
+as_cr_alnum=$as_cr_Letters$as_cr_digits
+
+ECHO_C= ECHO_N= ECHO_T=
+case `echo -n x` in #(((((
+-n*)
+  case `echo 'xy\c'` in
+  *c*) ECHO_T='	';;	# ECHO_T is single tab character.
+  xy)  ECHO_C='\c';;
+  *)   echo `echo ksh88 bug on AIX 6.1` > /dev/null
+       ECHO_T='	';;
+  esac;;
+*)
+  ECHO_N='-n';;
+esac
+
+rm -f conf$$ conf$$.exe conf$$.file
+if test -d conf$$.dir; then
+  rm -f conf$$.dir/conf$$.file
+else
+  rm -f conf$$.dir
+  mkdir conf$$.dir 2>/dev/null
+fi
+if (echo >conf$$.file) 2>/dev/null; then
+  if ln -s conf$$.file conf$$ 2>/dev/null; then
+    as_ln_s='ln -s'
+    # ... but there are two gotchas:
+    # 1) On MSYS, both `ln -s file dir' and `ln file dir' fail.
+    # 2) DJGPP < 2.04 has no symlinks; `ln -s' creates a wrapper executable.
+    # In both cases, we have to default to `cp -pR'.
+    ln -s conf$$.file conf$$.dir 2>/dev/null && test ! -f conf$$.exe ||
+      as_ln_s='cp -pR'
+  elif ln conf$$.file conf$$ 2>/dev/null; then
+    as_ln_s=ln
+  else
+    as_ln_s='cp -pR'
+  fi
+else
+  as_ln_s='cp -pR'
+fi
+rm -f conf$$ conf$$.exe conf$$.dir/conf$$.file conf$$.file
+rmdir conf$$.dir 2>/dev/null
+
+
+# as_fn_mkdir_p
+# -------------
+# Create "$as_dir" as a directory, including parents if necessary.
+as_fn_mkdir_p ()
+{
+
+  case $as_dir in #(
+  -*) as_dir=./$as_dir;;
+  esac
+  test -d "$as_dir" || eval $as_mkdir_p || {
+    as_dirs=
+    while :; do
+      case $as_dir in #(
+      *\'*) as_qdir=`$as_echo "$as_dir" | sed "s/'/'\\\\\\\\''/g"`;; #'(
+      *) as_qdir=$as_dir;;
+      esac
+      as_dirs="'$as_qdir' $as_dirs"
+      as_dir=`$as_dirname -- "$as_dir" ||
+$as_expr X"$as_dir" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$as_dir" : 'X\(//\)[^/]' \| \
+	 X"$as_dir" : 'X\(//\)$' \| \
+	 X"$as_dir" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$as_dir" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+      test -d "$as_dir" && break
+    done
+    test -z "$as_dirs" || eval "mkdir $as_dirs"
+  } || test -d "$as_dir" || as_fn_error $? "cannot create directory $as_dir"
+
+
+} # as_fn_mkdir_p
+if mkdir -p . 2>/dev/null; then
+  as_mkdir_p='mkdir -p "$as_dir"'
+else
+  test -d ./-p && rmdir ./-p
+  as_mkdir_p=false
+fi
+
+
+# as_fn_executable_p FILE
+# -----------------------
+# Test if FILE is an executable regular file.
+as_fn_executable_p ()
+{
+  test -f "$1" && test -x "$1"
+} # as_fn_executable_p
+as_test_x='test -x'
+as_executable_p=as_fn_executable_p
+
+# Sed expression to map a string onto a valid CPP name.
+as_tr_cpp="eval sed 'y%*$as_cr_letters%P$as_cr_LETTERS%;s%[^_$as_cr_alnum]%_%g'"
+
+# Sed expression to map a string onto a valid variable name.
+as_tr_sh="eval sed 'y%*+%pp%;s%[^_$as_cr_alnum]%_%g'"
+
+
+exec 6>&1
+## ----------------------------------- ##
+## Main body of $CONFIG_STATUS script. ##
+## ----------------------------------- ##
+_ASEOF
+test $as_write_fail = 0 && chmod +x $CONFIG_STATUS || ac_write_fail=1
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+# Save the log message, to keep $0 and so on meaningful, and to
+# report actual input values of CONFIG_FILES etc. instead of their
+# values after options handling.
+ac_log="
+This file was extended by stunnel $as_me 5.22, which was
+generated by GNU Autoconf 2.69.  Invocation command line was
+
+  CONFIG_FILES    = $CONFIG_FILES
+  CONFIG_HEADERS  = $CONFIG_HEADERS
+  CONFIG_LINKS    = $CONFIG_LINKS
+  CONFIG_COMMANDS = $CONFIG_COMMANDS
+  $ $0 $@
+
+on `(hostname || uname -n) 2>/dev/null | sed 1q`
+"
+
+_ACEOF
+
+case $ac_config_files in *"
+"*) set x $ac_config_files; shift; ac_config_files=$*;;
+esac
+
+case $ac_config_headers in *"
+"*) set x $ac_config_headers; shift; ac_config_headers=$*;;
+esac
+
+
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+# Files that config.status was made for.
+config_files="$ac_config_files"
+config_headers="$ac_config_headers"
+config_commands="$ac_config_commands"
+
+_ACEOF
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+ac_cs_usage="\
+\`$as_me' instantiates files and other configuration actions
+from templates according to the current configuration.  Unless the files
+and actions are specified as TAGs, all are instantiated by default.
+
+Usage: $0 [OPTION]... [TAG]...
+
+  -h, --help       print this help, then exit
+  -V, --version    print version number and configuration settings, then exit
+      --config     print configuration, then exit
+  -q, --quiet, --silent
+                   do not print progress messages
+  -d, --debug      don't remove temporary files
+      --recheck    update $as_me by reconfiguring in the same conditions
+      --file=FILE[:TEMPLATE]
+                   instantiate the configuration file FILE
+      --header=FILE[:TEMPLATE]
+                   instantiate the configuration header FILE
+
+Configuration files:
+$config_files
+
+Configuration headers:
+$config_headers
+
+Configuration commands:
+$config_commands
+
+Report bugs to the package provider."
+
+_ACEOF
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+ac_cs_config="`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`"
+ac_cs_version="\\
+stunnel config.status 5.22
+configured by $0, generated by GNU Autoconf 2.69,
+  with options \\"\$ac_cs_config\\"
+
+Copyright (C) 2012 Free Software Foundation, Inc.
+This config.status script is free software; the Free Software Foundation
+gives unlimited permission to copy, distribute and modify it."
+
+ac_pwd='$ac_pwd'
+srcdir='$srcdir'
+INSTALL='$INSTALL'
+MKDIR_P='$MKDIR_P'
+AWK='$AWK'
+test -n "\$AWK" || AWK=awk
+_ACEOF
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+# The default lists apply if the user does not specify any file.
+ac_need_defaults=:
+while test $# != 0
+do
+  case $1 in
+  --*=?*)
+    ac_option=`expr "X$1" : 'X\([^=]*\)='`
+    ac_optarg=`expr "X$1" : 'X[^=]*=\(.*\)'`
+    ac_shift=:
+    ;;
+  --*=)
+    ac_option=`expr "X$1" : 'X\([^=]*\)='`
+    ac_optarg=
+    ac_shift=:
+    ;;
+  *)
+    ac_option=$1
+    ac_optarg=$2
+    ac_shift=shift
+    ;;
+  esac
+
+  case $ac_option in
+  # Handling of the options.
+  -recheck | --recheck | --rechec | --reche | --rech | --rec | --re | --r)
+    ac_cs_recheck=: ;;
+  --version | --versio | --versi | --vers | --ver | --ve | --v | -V )
+    $as_echo "$ac_cs_version"; exit ;;
+  --config | --confi | --conf | --con | --co | --c )
+    $as_echo "$ac_cs_config"; exit ;;
+  --debug | --debu | --deb | --de | --d | -d )
+    debug=: ;;
+  --file | --fil | --fi | --f )
+    $ac_shift
+    case $ac_optarg in
+    *\'*) ac_optarg=`$as_echo "$ac_optarg" | sed "s/'/'\\\\\\\\''/g"` ;;
+    '') as_fn_error $? "missing file argument" ;;
+    esac
+    as_fn_append CONFIG_FILES " '$ac_optarg'"
+    ac_need_defaults=false;;
+  --header | --heade | --head | --hea )
+    $ac_shift
+    case $ac_optarg in
+    *\'*) ac_optarg=`$as_echo "$ac_optarg" | sed "s/'/'\\\\\\\\''/g"` ;;
+    esac
+    as_fn_append CONFIG_HEADERS " '$ac_optarg'"
+    ac_need_defaults=false;;
+  --he | --h)
+    # Conflict between --help and --header
+    as_fn_error $? "ambiguous option: \`$1'
+Try \`$0 --help' for more information.";;
+  --help | --hel | -h )
+    $as_echo "$ac_cs_usage"; exit ;;
+  -q | -quiet | --quiet | --quie | --qui | --qu | --q \
+  | -silent | --silent | --silen | --sile | --sil | --si | --s)
+    ac_cs_silent=: ;;
+
+  # This is an error.
+  -*) as_fn_error $? "unrecognized option: \`$1'
+Try \`$0 --help' for more information." ;;
+
+  *) as_fn_append ac_config_targets " $1"
+     ac_need_defaults=false ;;
+
+  esac
+  shift
+done
+
+ac_configure_extra_args=
+
+if $ac_cs_silent; then
+  exec 6>/dev/null
+  ac_configure_extra_args="$ac_configure_extra_args --silent"
+fi
+
+_ACEOF
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+if \$ac_cs_recheck; then
+  set X $SHELL '$0' $ac_configure_args \$ac_configure_extra_args --no-create --no-recursion
+  shift
+  \$as_echo "running CONFIG_SHELL=$SHELL \$*" >&6
+  CONFIG_SHELL='$SHELL'
+  export CONFIG_SHELL
+  exec "\$@"
+fi
+
+_ACEOF
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+exec 5>>config.log
+{
+  echo
+  sed 'h;s/./-/g;s/^.../## /;s/...$/ ##/;p;x;p;x' <<_ASBOX
+## Running $as_me. ##
+_ASBOX
+  $as_echo "$ac_log"
+} >&5
+
+_ACEOF
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+#
+# INIT-COMMANDS
+#
+AMDEP_TRUE="$AMDEP_TRUE" ac_aux_dir="$ac_aux_dir"
+
+
+# The HP-UX ksh and POSIX shell print the target directory to stdout
+# if CDPATH is set.
+(unset CDPATH) >/dev/null 2>&1 && unset CDPATH
+
+sed_quote_subst='$sed_quote_subst'
+double_quote_subst='$double_quote_subst'
+delay_variable_subst='$delay_variable_subst'
+macro_version='`$ECHO "$macro_version" | $SED "$delay_single_quote_subst"`'
+macro_revision='`$ECHO "$macro_revision" | $SED "$delay_single_quote_subst"`'
+enable_static='`$ECHO "$enable_static" | $SED "$delay_single_quote_subst"`'
+enable_shared='`$ECHO "$enable_shared" | $SED "$delay_single_quote_subst"`'
+pic_mode='`$ECHO "$pic_mode" | $SED "$delay_single_quote_subst"`'
+enable_fast_install='`$ECHO "$enable_fast_install" | $SED "$delay_single_quote_subst"`'
+SHELL='`$ECHO "$SHELL" | $SED "$delay_single_quote_subst"`'
+ECHO='`$ECHO "$ECHO" | $SED "$delay_single_quote_subst"`'
+PATH_SEPARATOR='`$ECHO "$PATH_SEPARATOR" | $SED "$delay_single_quote_subst"`'
+host_alias='`$ECHO "$host_alias" | $SED "$delay_single_quote_subst"`'
+host='`$ECHO "$host" | $SED "$delay_single_quote_subst"`'
+host_os='`$ECHO "$host_os" | $SED "$delay_single_quote_subst"`'
+build_alias='`$ECHO "$build_alias" | $SED "$delay_single_quote_subst"`'
+build='`$ECHO "$build" | $SED "$delay_single_quote_subst"`'
+build_os='`$ECHO "$build_os" | $SED "$delay_single_quote_subst"`'
+SED='`$ECHO "$SED" | $SED "$delay_single_quote_subst"`'
+Xsed='`$ECHO "$Xsed" | $SED "$delay_single_quote_subst"`'
+GREP='`$ECHO "$GREP" | $SED "$delay_single_quote_subst"`'
+EGREP='`$ECHO "$EGREP" | $SED "$delay_single_quote_subst"`'
+FGREP='`$ECHO "$FGREP" | $SED "$delay_single_quote_subst"`'
+LD='`$ECHO "$LD" | $SED "$delay_single_quote_subst"`'
+NM='`$ECHO "$NM" | $SED "$delay_single_quote_subst"`'
+LN_S='`$ECHO "$LN_S" | $SED "$delay_single_quote_subst"`'
+max_cmd_len='`$ECHO "$max_cmd_len" | $SED "$delay_single_quote_subst"`'
+ac_objext='`$ECHO "$ac_objext" | $SED "$delay_single_quote_subst"`'
+exeext='`$ECHO "$exeext" | $SED "$delay_single_quote_subst"`'
+lt_unset='`$ECHO "$lt_unset" | $SED "$delay_single_quote_subst"`'
+lt_SP2NL='`$ECHO "$lt_SP2NL" | $SED "$delay_single_quote_subst"`'
+lt_NL2SP='`$ECHO "$lt_NL2SP" | $SED "$delay_single_quote_subst"`'
+lt_cv_to_host_file_cmd='`$ECHO "$lt_cv_to_host_file_cmd" | $SED "$delay_single_quote_subst"`'
+lt_cv_to_tool_file_cmd='`$ECHO "$lt_cv_to_tool_file_cmd" | $SED "$delay_single_quote_subst"`'
+reload_flag='`$ECHO "$reload_flag" | $SED "$delay_single_quote_subst"`'
+reload_cmds='`$ECHO "$reload_cmds" | $SED "$delay_single_quote_subst"`'
+OBJDUMP='`$ECHO "$OBJDUMP" | $SED "$delay_single_quote_subst"`'
+deplibs_check_method='`$ECHO "$deplibs_check_method" | $SED "$delay_single_quote_subst"`'
+file_magic_cmd='`$ECHO "$file_magic_cmd" | $SED "$delay_single_quote_subst"`'
+file_magic_glob='`$ECHO "$file_magic_glob" | $SED "$delay_single_quote_subst"`'
+want_nocaseglob='`$ECHO "$want_nocaseglob" | $SED "$delay_single_quote_subst"`'
+DLLTOOL='`$ECHO "$DLLTOOL" | $SED "$delay_single_quote_subst"`'
+sharedlib_from_linklib_cmd='`$ECHO "$sharedlib_from_linklib_cmd" | $SED "$delay_single_quote_subst"`'
+AR='`$ECHO "$AR" | $SED "$delay_single_quote_subst"`'
+AR_FLAGS='`$ECHO "$AR_FLAGS" | $SED "$delay_single_quote_subst"`'
+archiver_list_spec='`$ECHO "$archiver_list_spec" | $SED "$delay_single_quote_subst"`'
+STRIP='`$ECHO "$STRIP" | $SED "$delay_single_quote_subst"`'
+RANLIB='`$ECHO "$RANLIB" | $SED "$delay_single_quote_subst"`'
+old_postinstall_cmds='`$ECHO "$old_postinstall_cmds" | $SED "$delay_single_quote_subst"`'
+old_postuninstall_cmds='`$ECHO "$old_postuninstall_cmds" | $SED "$delay_single_quote_subst"`'
+old_archive_cmds='`$ECHO "$old_archive_cmds" | $SED "$delay_single_quote_subst"`'
+lock_old_archive_extraction='`$ECHO "$lock_old_archive_extraction" | $SED "$delay_single_quote_subst"`'
+CC='`$ECHO "$CC" | $SED "$delay_single_quote_subst"`'
+CFLAGS='`$ECHO "$CFLAGS" | $SED "$delay_single_quote_subst"`'
+compiler='`$ECHO "$compiler" | $SED "$delay_single_quote_subst"`'
+GCC='`$ECHO "$GCC" | $SED "$delay_single_quote_subst"`'
+lt_cv_sys_global_symbol_pipe='`$ECHO "$lt_cv_sys_global_symbol_pipe" | $SED "$delay_single_quote_subst"`'
+lt_cv_sys_global_symbol_to_cdecl='`$ECHO "$lt_cv_sys_global_symbol_to_cdecl" | $SED "$delay_single_quote_subst"`'
+lt_cv_sys_global_symbol_to_c_name_address='`$ECHO "$lt_cv_sys_global_symbol_to_c_name_address" | $SED "$delay_single_quote_subst"`'
+lt_cv_sys_global_symbol_to_c_name_address_lib_prefix='`$ECHO "$lt_cv_sys_global_symbol_to_c_name_address_lib_prefix" | $SED "$delay_single_quote_subst"`'
+nm_file_list_spec='`$ECHO "$nm_file_list_spec" | $SED "$delay_single_quote_subst"`'
+lt_sysroot='`$ECHO "$lt_sysroot" | $SED "$delay_single_quote_subst"`'
+objdir='`$ECHO "$objdir" | $SED "$delay_single_quote_subst"`'
+MAGIC_CMD='`$ECHO "$MAGIC_CMD" | $SED "$delay_single_quote_subst"`'
+lt_prog_compiler_no_builtin_flag='`$ECHO "$lt_prog_compiler_no_builtin_flag" | $SED "$delay_single_quote_subst"`'
+lt_prog_compiler_pic='`$ECHO "$lt_prog_compiler_pic" | $SED "$delay_single_quote_subst"`'
+lt_prog_compiler_wl='`$ECHO "$lt_prog_compiler_wl" | $SED "$delay_single_quote_subst"`'
+lt_prog_compiler_static='`$ECHO "$lt_prog_compiler_static" | $SED "$delay_single_quote_subst"`'
+lt_cv_prog_compiler_c_o='`$ECHO "$lt_cv_prog_compiler_c_o" | $SED "$delay_single_quote_subst"`'
+need_locks='`$ECHO "$need_locks" | $SED "$delay_single_quote_subst"`'
+MANIFEST_TOOL='`$ECHO "$MANIFEST_TOOL" | $SED "$delay_single_quote_subst"`'
+DSYMUTIL='`$ECHO "$DSYMUTIL" | $SED "$delay_single_quote_subst"`'
+NMEDIT='`$ECHO "$NMEDIT" | $SED "$delay_single_quote_subst"`'
+LIPO='`$ECHO "$LIPO" | $SED "$delay_single_quote_subst"`'
+OTOOL='`$ECHO "$OTOOL" | $SED "$delay_single_quote_subst"`'
+OTOOL64='`$ECHO "$OTOOL64" | $SED "$delay_single_quote_subst"`'
+libext='`$ECHO "$libext" | $SED "$delay_single_quote_subst"`'
+shrext_cmds='`$ECHO "$shrext_cmds" | $SED "$delay_single_quote_subst"`'
+extract_expsyms_cmds='`$ECHO "$extract_expsyms_cmds" | $SED "$delay_single_quote_subst"`'
+archive_cmds_need_lc='`$ECHO "$archive_cmds_need_lc" | $SED "$delay_single_quote_subst"`'
+enable_shared_with_static_runtimes='`$ECHO "$enable_shared_with_static_runtimes" | $SED "$delay_single_quote_subst"`'
+export_dynamic_flag_spec='`$ECHO "$export_dynamic_flag_spec" | $SED "$delay_single_quote_subst"`'
+whole_archive_flag_spec='`$ECHO "$whole_archive_flag_spec" | $SED "$delay_single_quote_subst"`'
+compiler_needs_object='`$ECHO "$compiler_needs_object" | $SED "$delay_single_quote_subst"`'
+old_archive_from_new_cmds='`$ECHO "$old_archive_from_new_cmds" | $SED "$delay_single_quote_subst"`'
+old_archive_from_expsyms_cmds='`$ECHO "$old_archive_from_expsyms_cmds" | $SED "$delay_single_quote_subst"`'
+archive_cmds='`$ECHO "$archive_cmds" | $SED "$delay_single_quote_subst"`'
+archive_expsym_cmds='`$ECHO "$archive_expsym_cmds" | $SED "$delay_single_quote_subst"`'
+module_cmds='`$ECHO "$module_cmds" | $SED "$delay_single_quote_subst"`'
+module_expsym_cmds='`$ECHO "$module_expsym_cmds" | $SED "$delay_single_quote_subst"`'
+with_gnu_ld='`$ECHO "$with_gnu_ld" | $SED "$delay_single_quote_subst"`'
+allow_undefined_flag='`$ECHO "$allow_undefined_flag" | $SED "$delay_single_quote_subst"`'
+no_undefined_flag='`$ECHO "$no_undefined_flag" | $SED "$delay_single_quote_subst"`'
+hardcode_libdir_flag_spec='`$ECHO "$hardcode_libdir_flag_spec" | $SED "$delay_single_quote_subst"`'
+hardcode_libdir_separator='`$ECHO "$hardcode_libdir_separator" | $SED "$delay_single_quote_subst"`'
+hardcode_direct='`$ECHO "$hardcode_direct" | $SED "$delay_single_quote_subst"`'
+hardcode_direct_absolute='`$ECHO "$hardcode_direct_absolute" | $SED "$delay_single_quote_subst"`'
+hardcode_minus_L='`$ECHO "$hardcode_minus_L" | $SED "$delay_single_quote_subst"`'
+hardcode_shlibpath_var='`$ECHO "$hardcode_shlibpath_var" | $SED "$delay_single_quote_subst"`'
+hardcode_automatic='`$ECHO "$hardcode_automatic" | $SED "$delay_single_quote_subst"`'
+inherit_rpath='`$ECHO "$inherit_rpath" | $SED "$delay_single_quote_subst"`'
+link_all_deplibs='`$ECHO "$link_all_deplibs" | $SED "$delay_single_quote_subst"`'
+always_export_symbols='`$ECHO "$always_export_symbols" | $SED "$delay_single_quote_subst"`'
+export_symbols_cmds='`$ECHO "$export_symbols_cmds" | $SED "$delay_single_quote_subst"`'
+exclude_expsyms='`$ECHO "$exclude_expsyms" | $SED "$delay_single_quote_subst"`'
+include_expsyms='`$ECHO "$include_expsyms" | $SED "$delay_single_quote_subst"`'
+prelink_cmds='`$ECHO "$prelink_cmds" | $SED "$delay_single_quote_subst"`'
+postlink_cmds='`$ECHO "$postlink_cmds" | $SED "$delay_single_quote_subst"`'
+file_list_spec='`$ECHO "$file_list_spec" | $SED "$delay_single_quote_subst"`'
+variables_saved_for_relink='`$ECHO "$variables_saved_for_relink" | $SED "$delay_single_quote_subst"`'
+need_lib_prefix='`$ECHO "$need_lib_prefix" | $SED "$delay_single_quote_subst"`'
+need_version='`$ECHO "$need_version" | $SED "$delay_single_quote_subst"`'
+version_type='`$ECHO "$version_type" | $SED "$delay_single_quote_subst"`'
+runpath_var='`$ECHO "$runpath_var" | $SED "$delay_single_quote_subst"`'
+shlibpath_var='`$ECHO "$shlibpath_var" | $SED "$delay_single_quote_subst"`'
+shlibpath_overrides_runpath='`$ECHO "$shlibpath_overrides_runpath" | $SED "$delay_single_quote_subst"`'
+libname_spec='`$ECHO "$libname_spec" | $SED "$delay_single_quote_subst"`'
+library_names_spec='`$ECHO "$library_names_spec" | $SED "$delay_single_quote_subst"`'
+soname_spec='`$ECHO "$soname_spec" | $SED "$delay_single_quote_subst"`'
+install_override_mode='`$ECHO "$install_override_mode" | $SED "$delay_single_quote_subst"`'
+postinstall_cmds='`$ECHO "$postinstall_cmds" | $SED "$delay_single_quote_subst"`'
+postuninstall_cmds='`$ECHO "$postuninstall_cmds" | $SED "$delay_single_quote_subst"`'
+finish_cmds='`$ECHO "$finish_cmds" | $SED "$delay_single_quote_subst"`'
+finish_eval='`$ECHO "$finish_eval" | $SED "$delay_single_quote_subst"`'
+hardcode_into_libs='`$ECHO "$hardcode_into_libs" | $SED "$delay_single_quote_subst"`'
+sys_lib_search_path_spec='`$ECHO "$sys_lib_search_path_spec" | $SED "$delay_single_quote_subst"`'
+sys_lib_dlsearch_path_spec='`$ECHO "$sys_lib_dlsearch_path_spec" | $SED "$delay_single_quote_subst"`'
+hardcode_action='`$ECHO "$hardcode_action" | $SED "$delay_single_quote_subst"`'
+enable_dlopen='`$ECHO "$enable_dlopen" | $SED "$delay_single_quote_subst"`'
+enable_dlopen_self='`$ECHO "$enable_dlopen_self" | $SED "$delay_single_quote_subst"`'
+enable_dlopen_self_static='`$ECHO "$enable_dlopen_self_static" | $SED "$delay_single_quote_subst"`'
+old_striplib='`$ECHO "$old_striplib" | $SED "$delay_single_quote_subst"`'
+striplib='`$ECHO "$striplib" | $SED "$delay_single_quote_subst"`'
+
+LTCC='$LTCC'
+LTCFLAGS='$LTCFLAGS'
+compiler='$compiler_DEFAULT'
+
+# A function that is used when there is no print builtin or printf.
+func_fallback_echo ()
+{
+  eval 'cat <<_LTECHO_EOF
+\$1
+_LTECHO_EOF'
+}
+
+# Quote evaled strings.
+for var in SHELL \
+ECHO \
+PATH_SEPARATOR \
+SED \
+GREP \
+EGREP \
+FGREP \
+LD \
+NM \
+LN_S \
+lt_SP2NL \
+lt_NL2SP \
+reload_flag \
+OBJDUMP \
+deplibs_check_method \
+file_magic_cmd \
+file_magic_glob \
+want_nocaseglob \
+DLLTOOL \
+sharedlib_from_linklib_cmd \
+AR \
+AR_FLAGS \
+archiver_list_spec \
+STRIP \
+RANLIB \
+CC \
+CFLAGS \
+compiler \
+lt_cv_sys_global_symbol_pipe \
+lt_cv_sys_global_symbol_to_cdecl \
+lt_cv_sys_global_symbol_to_c_name_address \
+lt_cv_sys_global_symbol_to_c_name_address_lib_prefix \
+nm_file_list_spec \
+lt_prog_compiler_no_builtin_flag \
+lt_prog_compiler_pic \
+lt_prog_compiler_wl \
+lt_prog_compiler_static \
+lt_cv_prog_compiler_c_o \
+need_locks \
+MANIFEST_TOOL \
+DSYMUTIL \
+NMEDIT \
+LIPO \
+OTOOL \
+OTOOL64 \
+shrext_cmds \
+export_dynamic_flag_spec \
+whole_archive_flag_spec \
+compiler_needs_object \
+with_gnu_ld \
+allow_undefined_flag \
+no_undefined_flag \
+hardcode_libdir_flag_spec \
+hardcode_libdir_separator \
+exclude_expsyms \
+include_expsyms \
+file_list_spec \
+variables_saved_for_relink \
+libname_spec \
+library_names_spec \
+soname_spec \
+install_override_mode \
+finish_eval \
+old_striplib \
+striplib; do
+    case \`eval \\\\\$ECHO \\\\""\\\\\$\$var"\\\\"\` in
+    *[\\\\\\\`\\"\\\$]*)
+      eval "lt_\$var=\\\\\\"\\\`\\\$ECHO \\"\\\$\$var\\" | \\\$SED \\"\\\$sed_quote_subst\\"\\\`\\\\\\""
+      ;;
+    *)
+      eval "lt_\$var=\\\\\\"\\\$\$var\\\\\\""
+      ;;
+    esac
+done
+
+# Double-quote double-evaled strings.
+for var in reload_cmds \
+old_postinstall_cmds \
+old_postuninstall_cmds \
+old_archive_cmds \
+extract_expsyms_cmds \
+old_archive_from_new_cmds \
+old_archive_from_expsyms_cmds \
+archive_cmds \
+archive_expsym_cmds \
+module_cmds \
+module_expsym_cmds \
+export_symbols_cmds \
+prelink_cmds \
+postlink_cmds \
+postinstall_cmds \
+postuninstall_cmds \
+finish_cmds \
+sys_lib_search_path_spec \
+sys_lib_dlsearch_path_spec; do
+    case \`eval \\\\\$ECHO \\\\""\\\\\$\$var"\\\\"\` in
+    *[\\\\\\\`\\"\\\$]*)
+      eval "lt_\$var=\\\\\\"\\\`\\\$ECHO \\"\\\$\$var\\" | \\\$SED -e \\"\\\$double_quote_subst\\" -e \\"\\\$sed_quote_subst\\" -e \\"\\\$delay_variable_subst\\"\\\`\\\\\\""
+      ;;
+    *)
+      eval "lt_\$var=\\\\\\"\\\$\$var\\\\\\""
+      ;;
+    esac
+done
+
+ac_aux_dir='$ac_aux_dir'
+xsi_shell='$xsi_shell'
+lt_shell_append='$lt_shell_append'
+
+# See if we are running on zsh, and set the options which allow our
+# commands through without removal of \ escapes INIT.
+if test -n "\${ZSH_VERSION+set}" ; then
+   setopt NO_GLOB_SUBST
+fi
+
+
+    PACKAGE='$PACKAGE'
+    VERSION='$VERSION'
+    TIMESTAMP='$TIMESTAMP'
+    RM='$RM'
+    ofile='$ofile'
+
+
+
+
+_ACEOF
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+
+# Handling of arguments.
+for ac_config_target in $ac_config_targets
+do
+  case $ac_config_target in
+    "src/config.h") CONFIG_HEADERS="$CONFIG_HEADERS src/config.h" ;;
+    "depfiles") CONFIG_COMMANDS="$CONFIG_COMMANDS depfiles" ;;
+    "libtool") CONFIG_COMMANDS="$CONFIG_COMMANDS libtool" ;;
+    "Makefile") CONFIG_FILES="$CONFIG_FILES Makefile" ;;
+    "src/Makefile") CONFIG_FILES="$CONFIG_FILES src/Makefile" ;;
+    "doc/Makefile") CONFIG_FILES="$CONFIG_FILES doc/Makefile" ;;
+    "tools/Makefile") CONFIG_FILES="$CONFIG_FILES tools/Makefile" ;;
+
+  *) as_fn_error $? "invalid argument: \`$ac_config_target'" "$LINENO" 5;;
+  esac
+done
+
+
+# If the user did not use the arguments to specify the items to instantiate,
+# then the envvar interface is used.  Set only those that are not.
+# We use the long form for the default assignment because of an extremely
+# bizarre bug on SunOS 4.1.3.
+if $ac_need_defaults; then
+  test "${CONFIG_FILES+set}" = set || CONFIG_FILES=$config_files
+  test "${CONFIG_HEADERS+set}" = set || CONFIG_HEADERS=$config_headers
+  test "${CONFIG_COMMANDS+set}" = set || CONFIG_COMMANDS=$config_commands
+fi
+
+# Have a temporary directory for convenience.  Make it in the build tree
+# simply because there is no reason against having it here, and in addition,
+# creating and moving files from /tmp can sometimes cause problems.
+# Hook for its removal unless debugging.
+# Note that there is a small window in which the directory will not be cleaned:
+# after its creation but before its name has been assigned to `$tmp'.
+$debug ||
+{
+  tmp= ac_tmp=
+  trap 'exit_status=$?
+  : "${ac_tmp:=$tmp}"
+  { test ! -d "$ac_tmp" || rm -fr "$ac_tmp"; } && exit $exit_status
+' 0
+  trap 'as_fn_exit 1' 1 2 13 15
+}
+# Create a (secure) tmp directory for tmp files.
+
+{
+  tmp=`(umask 077 && mktemp -d "./confXXXXXX") 2>/dev/null` &&
+  test -d "$tmp"
+}  ||
+{
+  tmp=./conf$$-$RANDOM
+  (umask 077 && mkdir "$tmp")
+} || as_fn_error $? "cannot create a temporary directory in ." "$LINENO" 5
+ac_tmp=$tmp
+
+# Set up the scripts for CONFIG_FILES section.
+# No need to generate them if there are no CONFIG_FILES.
+# This happens for instance with `./config.status config.h'.
+if test -n "$CONFIG_FILES"; then
+
+
+ac_cr=`echo X | tr X '\015'`
+# On cygwin, bash can eat \r inside `` if the user requested igncr.
+# But we know of no other shell where ac_cr would be empty at this
+# point, so we can use a bashism as a fallback.
+if test "x$ac_cr" = x; then
+  eval ac_cr=\$\'\\r\'
+fi
+ac_cs_awk_cr=`$AWK 'BEGIN { print "a\rb" }' </dev/null 2>/dev/null`
+if test "$ac_cs_awk_cr" = "a${ac_cr}b"; then
+  ac_cs_awk_cr='\\r'
+else
+  ac_cs_awk_cr=$ac_cr
+fi
+
+echo 'BEGIN {' >"$ac_tmp/subs1.awk" &&
+_ACEOF
+
+
+{
+  echo "cat >conf$$subs.awk <<_ACEOF" &&
+  echo "$ac_subst_vars" | sed 's/.*/&!$&$ac_delim/' &&
+  echo "_ACEOF"
+} >conf$$subs.sh ||
+  as_fn_error $? "could not make $CONFIG_STATUS" "$LINENO" 5
+ac_delim_num=`echo "$ac_subst_vars" | grep -c '^'`
+ac_delim='%!_!# '
+for ac_last_try in false false false false false :; do
+  . ./conf$$subs.sh ||
+    as_fn_error $? "could not make $CONFIG_STATUS" "$LINENO" 5
+
+  ac_delim_n=`sed -n "s/.*$ac_delim\$/X/p" conf$$subs.awk | grep -c X`
+  if test $ac_delim_n = $ac_delim_num; then
+    break
+  elif $ac_last_try; then
+    as_fn_error $? "could not make $CONFIG_STATUS" "$LINENO" 5
+  else
+    ac_delim="$ac_delim!$ac_delim _$ac_delim!! "
+  fi
+done
+rm -f conf$$subs.sh
+
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+cat >>"\$ac_tmp/subs1.awk" <<\\_ACAWK &&
+_ACEOF
+sed -n '
+h
+s/^/S["/; s/!.*/"]=/
+p
+g
+s/^[^!]*!//
+:repl
+t repl
+s/'"$ac_delim"'$//
+t delim
+:nl
+h
+s/\(.\{148\}\)..*/\1/
+t more1
+s/["\\]/\\&/g; s/^/"/; s/$/\\n"\\/
+p
+n
+b repl
+:more1
+s/["\\]/\\&/g; s/^/"/; s/$/"\\/
+p
+g
+s/.\{148\}//
+t nl
+:delim
+h
+s/\(.\{148\}\)..*/\1/
+t more2
+s/["\\]/\\&/g; s/^/"/; s/$/"/
+p
+b
+:more2
+s/["\\]/\\&/g; s/^/"/; s/$/"\\/
+p
+g
+s/.\{148\}//
+t delim
+' <conf$$subs.awk | sed '
+/^[^""]/{
+  N
+  s/\n//
+}
+' >>$CONFIG_STATUS || ac_write_fail=1
+rm -f conf$$subs.awk
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+_ACAWK
+cat >>"\$ac_tmp/subs1.awk" <<_ACAWK &&
+  for (key in S) S_is_set[key] = 1
+  FS = ""
+
+}
+{
+  line = $ 0
+  nfields = split(line, field, "@")
+  substed = 0
+  len = length(field[1])
+  for (i = 2; i < nfields; i++) {
+    key = field[i]
+    keylen = length(key)
+    if (S_is_set[key]) {
+      value = S[key]
+      line = substr(line, 1, len) "" value "" substr(line, len + keylen + 3)
+      len += length(value) + length(field[++i])
+      substed = 1
+    } else
+      len += 1 + keylen
+  }
+
+  print line
+}
+
+_ACAWK
+_ACEOF
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+if sed "s/$ac_cr//" < /dev/null > /dev/null 2>&1; then
+  sed "s/$ac_cr\$//; s/$ac_cr/$ac_cs_awk_cr/g"
+else
+  cat
+fi < "$ac_tmp/subs1.awk" > "$ac_tmp/subs.awk" \
+  || as_fn_error $? "could not setup config files machinery" "$LINENO" 5
+_ACEOF
+
+# VPATH may cause trouble with some makes, so we remove sole $(srcdir),
+# ${srcdir} and @srcdir@ entries from VPATH if srcdir is ".", strip leading and
+# trailing colons and then remove the whole line if VPATH becomes empty
+# (actually we leave an empty line to preserve line numbers).
+if test "x$srcdir" = x.; then
+  ac_vpsub='/^[	 ]*VPATH[	 ]*=[	 ]*/{
+h
+s///
+s/^/:/
+s/[	 ]*$/:/
+s/:\$(srcdir):/:/g
+s/:\${srcdir}:/:/g
+s/:@srcdir@:/:/g
+s/^:*//
+s/:*$//
+x
+s/\(=[	 ]*\).*/\1/
+G
+s/\n//
+s/^[^=]*=[	 ]*$//
+}'
+fi
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+fi # test -n "$CONFIG_FILES"
+
+# Set up the scripts for CONFIG_HEADERS section.
+# No need to generate them if there are no CONFIG_HEADERS.
+# This happens for instance with `./config.status Makefile'.
+if test -n "$CONFIG_HEADERS"; then
+cat >"$ac_tmp/defines.awk" <<\_ACAWK ||
+BEGIN {
+_ACEOF
+
+# Transform confdefs.h into an awk script `defines.awk', embedded as
+# here-document in config.status, that substitutes the proper values into
+# config.h.in to produce config.h.
+
+# Create a delimiter string that does not exist in confdefs.h, to ease
+# handling of long lines.
+ac_delim='%!_!# '
+for ac_last_try in false false :; do
+  ac_tt=`sed -n "/$ac_delim/p" confdefs.h`
+  if test -z "$ac_tt"; then
+    break
+  elif $ac_last_try; then
+    as_fn_error $? "could not make $CONFIG_HEADERS" "$LINENO" 5
+  else
+    ac_delim="$ac_delim!$ac_delim _$ac_delim!! "
+  fi
+done
+
+# For the awk script, D is an array of macro values keyed by name,
+# likewise P contains macro parameters if any.  Preserve backslash
+# newline sequences.
+
+ac_word_re=[_$as_cr_Letters][_$as_cr_alnum]*
+sed -n '
+s/.\{148\}/&'"$ac_delim"'/g
+t rset
+:rset
+s/^[	 ]*#[	 ]*define[	 ][	 ]*/ /
+t def
+d
+:def
+s/\\$//
+t bsnl
+s/["\\]/\\&/g
+s/^ \('"$ac_word_re"'\)\(([^()]*)\)[	 ]*\(.*\)/P["\1"]="\2"\
+D["\1"]=" \3"/p
+s/^ \('"$ac_word_re"'\)[	 ]*\(.*\)/D["\1"]=" \2"/p
+d
+:bsnl
+s/["\\]/\\&/g
+s/^ \('"$ac_word_re"'\)\(([^()]*)\)[	 ]*\(.*\)/P["\1"]="\2"\
+D["\1"]=" \3\\\\\\n"\\/p
+t cont
+s/^ \('"$ac_word_re"'\)[	 ]*\(.*\)/D["\1"]=" \2\\\\\\n"\\/p
+t cont
+d
+:cont
+n
+s/.\{148\}/&'"$ac_delim"'/g
+t clear
+:clear
+s/\\$//
+t bsnlc
+s/["\\]/\\&/g; s/^/"/; s/$/"/p
+d
+:bsnlc
+s/["\\]/\\&/g; s/^/"/; s/$/\\\\\\n"\\/p
+b cont
+' <confdefs.h | sed '
+s/'"$ac_delim"'/"\\\
+"/g' >>$CONFIG_STATUS || ac_write_fail=1
+
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+  for (key in D) D_is_set[key] = 1
+  FS = ""
+}
+/^[\t ]*#[\t ]*(define|undef)[\t ]+$ac_word_re([\t (]|\$)/ {
+  line = \$ 0
+  split(line, arg, " ")
+  if (arg[1] == "#") {
+    defundef = arg[2]
+    mac1 = arg[3]
+  } else {
+    defundef = substr(arg[1], 2)
+    mac1 = arg[2]
+  }
+  split(mac1, mac2, "(") #)
+  macro = mac2[1]
+  prefix = substr(line, 1, index(line, defundef) - 1)
+  if (D_is_set[macro]) {
+    # Preserve the white space surrounding the "#".
+    print prefix "define", macro P[macro] D[macro]
+    next
+  } else {
+    # Replace #undef with comments.  This is necessary, for example,
+    # in the case of _POSIX_SOURCE, which is predefined and required
+    # on some systems where configure will not decide to define it.
+    if (defundef == "undef") {
+      print "/*", prefix defundef, macro, "*/"
+      next
+    }
+  }
+}
+{ print }
+_ACAWK
+_ACEOF
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+  as_fn_error $? "could not setup config headers machinery" "$LINENO" 5
+fi # test -n "$CONFIG_HEADERS"
+
+
+eval set X "  :F $CONFIG_FILES  :H $CONFIG_HEADERS    :C $CONFIG_COMMANDS"
+shift
+for ac_tag
+do
+  case $ac_tag in
+  :[FHLC]) ac_mode=$ac_tag; continue;;
+  esac
+  case $ac_mode$ac_tag in
+  :[FHL]*:*);;
+  :L* | :C*:*) as_fn_error $? "invalid tag \`$ac_tag'" "$LINENO" 5;;
+  :[FH]-) ac_tag=-:-;;
+  :[FH]*) ac_tag=$ac_tag:$ac_tag.in;;
+  esac
+  ac_save_IFS=$IFS
+  IFS=:
+  set x $ac_tag
+  IFS=$ac_save_IFS
+  shift
+  ac_file=$1
+  shift
+
+  case $ac_mode in
+  :L) ac_source=$1;;
+  :[FH])
+    ac_file_inputs=
+    for ac_f
+    do
+      case $ac_f in
+      -) ac_f="$ac_tmp/stdin";;
+      *) # Look for the file first in the build tree, then in the source tree
+	 # (if the path is not absolute).  The absolute path cannot be DOS-style,
+	 # because $ac_f cannot contain `:'.
+	 test -f "$ac_f" ||
+	   case $ac_f in
+	   [\\/$]*) false;;
+	   *) test -f "$srcdir/$ac_f" && ac_f="$srcdir/$ac_f";;
+	   esac ||
+	   as_fn_error 1 "cannot find input file: \`$ac_f'" "$LINENO" 5;;
+      esac
+      case $ac_f in *\'*) ac_f=`$as_echo "$ac_f" | sed "s/'/'\\\\\\\\''/g"`;; esac
+      as_fn_append ac_file_inputs " '$ac_f'"
+    done
+
+    # Let's still pretend it is `configure' which instantiates (i.e., don't
+    # use $as_me), people would be surprised to read:
+    #    /* config.h.  Generated by config.status.  */
+    configure_input='Generated from '`
+	  $as_echo "$*" | sed 's|^[^:]*/||;s|:[^:]*/|, |g'
+	`' by configure.'
+    if test x"$ac_file" != x-; then
+      configure_input="$ac_file.  $configure_input"
+      { $as_echo "$as_me:${as_lineno-$LINENO}: creating $ac_file" >&5
+$as_echo "$as_me: creating $ac_file" >&6;}
+    fi
+    # Neutralize special characters interpreted by sed in replacement strings.
+    case $configure_input in #(
+    *\&* | *\|* | *\\* )
+       ac_sed_conf_input=`$as_echo "$configure_input" |
+       sed 's/[\\\\&|]/\\\\&/g'`;; #(
+    *) ac_sed_conf_input=$configure_input;;
+    esac
+
+    case $ac_tag in
+    *:-:* | *:-) cat >"$ac_tmp/stdin" \
+      || as_fn_error $? "could not create $ac_file" "$LINENO" 5 ;;
+    esac
+    ;;
+  esac
+
+  ac_dir=`$as_dirname -- "$ac_file" ||
+$as_expr X"$ac_file" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$ac_file" : 'X\(//\)[^/]' \| \
+	 X"$ac_file" : 'X\(//\)$' \| \
+	 X"$ac_file" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$ac_file" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+  as_dir="$ac_dir"; as_fn_mkdir_p
+  ac_builddir=.
+
+case "$ac_dir" in
+.) ac_dir_suffix= ac_top_builddir_sub=. ac_top_build_prefix= ;;
+*)
+  ac_dir_suffix=/`$as_echo "$ac_dir" | sed 's|^\.[\\/]||'`
+  # A ".." for each directory in $ac_dir_suffix.
+  ac_top_builddir_sub=`$as_echo "$ac_dir_suffix" | sed 's|/[^\\/]*|/..|g;s|/||'`
+  case $ac_top_builddir_sub in
+  "") ac_top_builddir_sub=. ac_top_build_prefix= ;;
+  *)  ac_top_build_prefix=$ac_top_builddir_sub/ ;;
+  esac ;;
+esac
+ac_abs_top_builddir=$ac_pwd
+ac_abs_builddir=$ac_pwd$ac_dir_suffix
+# for backward compatibility:
+ac_top_builddir=$ac_top_build_prefix
+
+case $srcdir in
+  .)  # We are building in place.
+    ac_srcdir=.
+    ac_top_srcdir=$ac_top_builddir_sub
+    ac_abs_top_srcdir=$ac_pwd ;;
+  [\\/]* | ?:[\\/]* )  # Absolute name.
+    ac_srcdir=$srcdir$ac_dir_suffix;
+    ac_top_srcdir=$srcdir
+    ac_abs_top_srcdir=$srcdir ;;
+  *) # Relative name.
+    ac_srcdir=$ac_top_build_prefix$srcdir$ac_dir_suffix
+    ac_top_srcdir=$ac_top_build_prefix$srcdir
+    ac_abs_top_srcdir=$ac_pwd/$srcdir ;;
+esac
+ac_abs_srcdir=$ac_abs_top_srcdir$ac_dir_suffix
+
+
+  case $ac_mode in
+  :F)
+  #
+  # CONFIG_FILE
+  #
+
+  case $INSTALL in
+  [\\/$]* | ?:[\\/]* ) ac_INSTALL=$INSTALL ;;
+  *) ac_INSTALL=$ac_top_build_prefix$INSTALL ;;
+  esac
+  ac_MKDIR_P=$MKDIR_P
+  case $MKDIR_P in
+  [\\/$]* | ?:[\\/]* ) ;;
+  */*) ac_MKDIR_P=$ac_top_build_prefix$MKDIR_P ;;
+  esac
+_ACEOF
+
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+# If the template does not know about datarootdir, expand it.
+# FIXME: This hack should be removed a few years after 2.60.
+ac_datarootdir_hack=; ac_datarootdir_seen=
+ac_sed_dataroot='
+/datarootdir/ {
+  p
+  q
+}
+/@datadir@/p
+/@docdir@/p
+/@infodir@/p
+/@localedir@/p
+/@mandir@/p'
+case `eval "sed -n \"\$ac_sed_dataroot\" $ac_file_inputs"` in
+*datarootdir*) ac_datarootdir_seen=yes;;
+*@datadir@*|*@docdir@*|*@infodir@*|*@localedir@*|*@mandir@*)
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file_inputs seems to ignore the --datarootdir setting" >&5
+$as_echo "$as_me: WARNING: $ac_file_inputs seems to ignore the --datarootdir setting" >&2;}
+_ACEOF
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+  ac_datarootdir_hack='
+  s&@datadir@&$datadir&g
+  s&@docdir@&$docdir&g
+  s&@infodir@&$infodir&g
+  s&@localedir@&$localedir&g
+  s&@mandir@&$mandir&g
+  s&\\\${datarootdir}&$datarootdir&g' ;;
+esac
+_ACEOF
+
+# Neutralize VPATH when `$srcdir' = `.'.
+# Shell code in configure.ac might set extrasub.
+# FIXME: do we really want to maintain this feature?
+cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
+ac_sed_extra="$ac_vpsub
+$extrasub
+_ACEOF
+cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
+:t
+/@[a-zA-Z_][a-zA-Z_0-9]*@/!b
+s|@configure_input@|$ac_sed_conf_input|;t t
+s&@top_builddir@&$ac_top_builddir_sub&;t t
+s&@top_build_prefix@&$ac_top_build_prefix&;t t
+s&@srcdir@&$ac_srcdir&;t t
+s&@abs_srcdir@&$ac_abs_srcdir&;t t
+s&@top_srcdir@&$ac_top_srcdir&;t t
+s&@abs_top_srcdir@&$ac_abs_top_srcdir&;t t
+s&@builddir@&$ac_builddir&;t t
+s&@abs_builddir@&$ac_abs_builddir&;t t
+s&@abs_top_builddir@&$ac_abs_top_builddir&;t t
+s&@INSTALL@&$ac_INSTALL&;t t
+s&@MKDIR_P@&$ac_MKDIR_P&;t t
+$ac_datarootdir_hack
+"
+eval sed \"\$ac_sed_extra\" "$ac_file_inputs" | $AWK -f "$ac_tmp/subs.awk" \
+  >$ac_tmp/out || as_fn_error $? "could not create $ac_file" "$LINENO" 5
+
+test -z "$ac_datarootdir_hack$ac_datarootdir_seen" &&
+  { ac_out=`sed -n '/\${datarootdir}/p' "$ac_tmp/out"`; test -n "$ac_out"; } &&
+  { ac_out=`sed -n '/^[	 ]*datarootdir[	 ]*:*=/p' \
+      "$ac_tmp/out"`; test -z "$ac_out"; } &&
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: $ac_file contains a reference to the variable \`datarootdir'
+which seems to be undefined.  Please make sure it is defined" >&5
+$as_echo "$as_me: WARNING: $ac_file contains a reference to the variable \`datarootdir'
+which seems to be undefined.  Please make sure it is defined" >&2;}
+
+  rm -f "$ac_tmp/stdin"
+  case $ac_file in
+  -) cat "$ac_tmp/out" && rm -f "$ac_tmp/out";;
+  *) rm -f "$ac_file" && mv "$ac_tmp/out" "$ac_file";;
+  esac \
+  || as_fn_error $? "could not create $ac_file" "$LINENO" 5
+ ;;
+  :H)
+  #
+  # CONFIG_HEADER
+  #
+  if test x"$ac_file" != x-; then
+    {
+      $as_echo "/* $configure_input  */" \
+      && eval '$AWK -f "$ac_tmp/defines.awk"' "$ac_file_inputs"
+    } >"$ac_tmp/config.h" \
+      || as_fn_error $? "could not create $ac_file" "$LINENO" 5
+    if diff "$ac_file" "$ac_tmp/config.h" >/dev/null 2>&1; then
+      { $as_echo "$as_me:${as_lineno-$LINENO}: $ac_file is unchanged" >&5
+$as_echo "$as_me: $ac_file is unchanged" >&6;}
+    else
+      rm -f "$ac_file"
+      mv "$ac_tmp/config.h" "$ac_file" \
+	|| as_fn_error $? "could not create $ac_file" "$LINENO" 5
+    fi
+  else
+    $as_echo "/* $configure_input  */" \
+      && eval '$AWK -f "$ac_tmp/defines.awk"' "$ac_file_inputs" \
+      || as_fn_error $? "could not create -" "$LINENO" 5
+  fi
+# Compute "$ac_file"'s index in $config_headers.
+_am_arg="$ac_file"
+_am_stamp_count=1
+for _am_header in $config_headers :; do
+  case $_am_header in
+    $_am_arg | $_am_arg:* )
+      break ;;
+    * )
+      _am_stamp_count=`expr $_am_stamp_count + 1` ;;
+  esac
+done
+echo "timestamp for $_am_arg" >`$as_dirname -- "$_am_arg" ||
+$as_expr X"$_am_arg" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$_am_arg" : 'X\(//\)[^/]' \| \
+	 X"$_am_arg" : 'X\(//\)$' \| \
+	 X"$_am_arg" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$_am_arg" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`/stamp-h$_am_stamp_count
+ ;;
+
+  :C)  { $as_echo "$as_me:${as_lineno-$LINENO}: executing $ac_file commands" >&5
+$as_echo "$as_me: executing $ac_file commands" >&6;}
+ ;;
+  esac
+
+
+  case $ac_file$ac_mode in
+    "depfiles":C) test x"$AMDEP_TRUE" != x"" || {
+  # Older Autoconf quotes --file arguments for eval, but not when files
+  # are listed without --file.  Let's play safe and only enable the eval
+  # if we detect the quoting.
+  case $CONFIG_FILES in
+  *\'*) eval set x "$CONFIG_FILES" ;;
+  *)   set x $CONFIG_FILES ;;
+  esac
+  shift
+  for mf
+  do
+    # Strip MF so we end up with the name of the file.
+    mf=`echo "$mf" | sed -e 's/:.*$//'`
+    # Check whether this is an Automake generated Makefile or not.
+    # We used to match only the files named 'Makefile.in', but
+    # some people rename them; so instead we look at the file content.
+    # Grep'ing the first line is not enough: some people post-process
+    # each Makefile.in and add a new line on top of each file to say so.
+    # Grep'ing the whole file is not good either: AIX grep has a line
+    # limit of 2048, but all sed's we know have understand at least 4000.
+    if sed -n 's,^#.*generated by automake.*,X,p' "$mf" | grep X >/dev/null 2>&1; then
+      dirpart=`$as_dirname -- "$mf" ||
+$as_expr X"$mf" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$mf" : 'X\(//\)[^/]' \| \
+	 X"$mf" : 'X\(//\)$' \| \
+	 X"$mf" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$mf" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+    else
+      continue
+    fi
+    # Extract the definition of DEPDIR, am__include, and am__quote
+    # from the Makefile without running 'make'.
+    DEPDIR=`sed -n 's/^DEPDIR = //p' < "$mf"`
+    test -z "$DEPDIR" && continue
+    am__include=`sed -n 's/^am__include = //p' < "$mf"`
+    test -z "$am__include" && continue
+    am__quote=`sed -n 's/^am__quote = //p' < "$mf"`
+    # Find all dependency output files, they are included files with
+    # $(DEPDIR) in their names.  We invoke sed twice because it is the
+    # simplest approach to changing $(DEPDIR) to its actual value in the
+    # expansion.
+    for file in `sed -n "
+      s/^$am__include $am__quote\(.*(DEPDIR).*\)$am__quote"'$/\1/p' <"$mf" | \
+	 sed -e 's/\$(DEPDIR)/'"$DEPDIR"'/g'`; do
+      # Make sure the directory exists.
+      test -f "$dirpart/$file" && continue
+      fdir=`$as_dirname -- "$file" ||
+$as_expr X"$file" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \
+	 X"$file" : 'X\(//\)[^/]' \| \
+	 X"$file" : 'X\(//\)$' \| \
+	 X"$file" : 'X\(/\)' \| . 2>/dev/null ||
+$as_echo X"$file" |
+    sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)[^/].*/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\/\)$/{
+	    s//\1/
+	    q
+	  }
+	  /^X\(\/\).*/{
+	    s//\1/
+	    q
+	  }
+	  s/.*/./; q'`
+      as_dir=$dirpart/$fdir; as_fn_mkdir_p
+      # echo "creating $dirpart/$file"
+      echo '# dummy' > "$dirpart/$file"
+    done
+  done
+}
+ ;;
+    "libtool":C)
+
+    # See if we are running on zsh, and set the options which allow our
+    # commands through without removal of \ escapes.
+    if test -n "${ZSH_VERSION+set}" ; then
+      setopt NO_GLOB_SUBST
+    fi
+
+    cfgfile="${ofile}T"
+    trap "$RM \"$cfgfile\"; exit 1" 1 2 15
+    $RM "$cfgfile"
+
+    cat <<_LT_EOF >> "$cfgfile"
+#! $SHELL
+
+# `$ECHO "$ofile" | sed 's%^.*/%%'` - Provide generalized library-building support services.
+# Generated automatically by $as_me ($PACKAGE$TIMESTAMP) $VERSION
+# Libtool was configured on host `(hostname || uname -n) 2>/dev/null | sed 1q`:
+# NOTE: Changes made to this file will be lost: look at ltmain.sh.
+#
+#   Copyright (C) 1996, 1997, 1998, 1999, 2000, 2001, 2003, 2004, 2005,
+#                 2006, 2007, 2008, 2009, 2010, 2011 Free Software
+#                 Foundation, Inc.
+#   Written by Gordon Matzigkeit, 1996
+#
+#   This file is part of GNU Libtool.
+#
+# GNU Libtool is free software; you can redistribute it and/or
+# modify it under the terms of the GNU General Public License as
+# published by the Free Software Foundation; either version 2 of
+# the License, or (at your option) any later version.
+#
+# As a special exception to the GNU General Public License,
+# if you distribute this file as part of a program or library that
+# is built using GNU Libtool, you may include this file under the
+# same distribution terms that you use for the rest of that program.
+#
+# GNU Libtool is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with GNU Libtool; see the file COPYING.  If not, a copy
+# can be downloaded from http://www.gnu.org/licenses/gpl.html, or
+# obtained by writing to the Free Software Foundation, Inc.,
+# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
+
+
+# The names of the tagged configurations supported by this script.
+available_tags=""
+
+# ### BEGIN LIBTOOL CONFIG
+
+# Which release of libtool.m4 was used?
+macro_version=$macro_version
+macro_revision=$macro_revision
+
+# Whether or not to build static libraries.
+build_old_libs=$enable_static
+
+# Whether or not to build shared libraries.
+build_libtool_libs=$enable_shared
+
+# What type of objects to build.
+pic_mode=$pic_mode
+
+# Whether or not to optimize for fast installation.
+fast_install=$enable_fast_install
+
+# Shell to use when invoking shell scripts.
+SHELL=$lt_SHELL
+
+# An echo program that protects backslashes.
+ECHO=$lt_ECHO
+
+# The PATH separator for the build system.
+PATH_SEPARATOR=$lt_PATH_SEPARATOR
+
+# The host system.
+host_alias=$host_alias
+host=$host
+host_os=$host_os
+
+# The build system.
+build_alias=$build_alias
+build=$build
+build_os=$build_os
+
+# A sed program that does not truncate output.
+SED=$lt_SED
+
+# Sed that helps us avoid accidentally triggering echo(1) options like -n.
+Xsed="\$SED -e 1s/^X//"
+
+# A grep program that handles long lines.
+GREP=$lt_GREP
+
+# An ERE matcher.
+EGREP=$lt_EGREP
+
+# A literal string matcher.
+FGREP=$lt_FGREP
+
+# A BSD- or MS-compatible name lister.
+NM=$lt_NM
+
+# Whether we need soft or hard links.
+LN_S=$lt_LN_S
+
+# What is the maximum length of a command?
+max_cmd_len=$max_cmd_len
+
+# Object file suffix (normally "o").
+objext=$ac_objext
+
+# Executable file suffix (normally "").
+exeext=$exeext
+
+# whether the shell understands "unset".
+lt_unset=$lt_unset
+
+# turn spaces into newlines.
+SP2NL=$lt_lt_SP2NL
+
+# turn newlines into spaces.
+NL2SP=$lt_lt_NL2SP
+
+# convert \$build file names to \$host format.
+to_host_file_cmd=$lt_cv_to_host_file_cmd
+
+# convert \$build files to toolchain format.
+to_tool_file_cmd=$lt_cv_to_tool_file_cmd
+
+# An object symbol dumper.
+OBJDUMP=$lt_OBJDUMP
+
+# Method to check whether dependent libraries are shared objects.
+deplibs_check_method=$lt_deplibs_check_method
+
+# Command to use when deplibs_check_method = "file_magic".
+file_magic_cmd=$lt_file_magic_cmd
+
+# How to find potential files when deplibs_check_method = "file_magic".
+file_magic_glob=$lt_file_magic_glob
+
+# Find potential files using nocaseglob when deplibs_check_method = "file_magic".
+want_nocaseglob=$lt_want_nocaseglob
+
+# DLL creation program.
+DLLTOOL=$lt_DLLTOOL
+
+# Command to associate shared and link libraries.
+sharedlib_from_linklib_cmd=$lt_sharedlib_from_linklib_cmd
+
+# The archiver.
+AR=$lt_AR
+
+# Flags to create an archive.
+AR_FLAGS=$lt_AR_FLAGS
+
+# How to feed a file listing to the archiver.
+archiver_list_spec=$lt_archiver_list_spec
+
+# A symbol stripping program.
+STRIP=$lt_STRIP
+
+# Commands used to install an old-style archive.
+RANLIB=$lt_RANLIB
+old_postinstall_cmds=$lt_old_postinstall_cmds
+old_postuninstall_cmds=$lt_old_postuninstall_cmds
+
+# Whether to use a lock for old archive extraction.
+lock_old_archive_extraction=$lock_old_archive_extraction
+
+# A C compiler.
+LTCC=$lt_CC
+
+# LTCC compiler flags.
+LTCFLAGS=$lt_CFLAGS
+
+# Take the output of nm and produce a listing of raw symbols and C names.
+global_symbol_pipe=$lt_lt_cv_sys_global_symbol_pipe
+
+# Transform the output of nm in a proper C declaration.
+global_symbol_to_cdecl=$lt_lt_cv_sys_global_symbol_to_cdecl
+
+# Transform the output of nm in a C name address pair.
+global_symbol_to_c_name_address=$lt_lt_cv_sys_global_symbol_to_c_name_address
+
+# Transform the output of nm in a C name address pair when lib prefix is needed.
+global_symbol_to_c_name_address_lib_prefix=$lt_lt_cv_sys_global_symbol_to_c_name_address_lib_prefix
+
+# Specify filename containing input files for \$NM.
+nm_file_list_spec=$lt_nm_file_list_spec
+
+# The root where to search for dependent libraries,and in which our libraries should be installed.
+lt_sysroot=$lt_sysroot
+
+# The name of the directory that contains temporary libtool files.
+objdir=$objdir
+
+# Used to examine libraries when file_magic_cmd begins with "file".
+MAGIC_CMD=$MAGIC_CMD
+
+# Must we lock files when doing compilation?
+need_locks=$lt_need_locks
+
+# Manifest tool.
+MANIFEST_TOOL=$lt_MANIFEST_TOOL
+
+# Tool to manipulate archived DWARF debug symbol files on Mac OS X.
+DSYMUTIL=$lt_DSYMUTIL
+
+# Tool to change global to local symbols on Mac OS X.
+NMEDIT=$lt_NMEDIT
+
+# Tool to manipulate fat objects and archives on Mac OS X.
+LIPO=$lt_LIPO
+
+# ldd/readelf like tool for Mach-O binaries on Mac OS X.
+OTOOL=$lt_OTOOL
+
+# ldd/readelf like tool for 64 bit Mach-O binaries on Mac OS X 10.4.
+OTOOL64=$lt_OTOOL64
+
+# Old archive suffix (normally "a").
+libext=$libext
+
+# Shared library suffix (normally ".so").
+shrext_cmds=$lt_shrext_cmds
+
+# The commands to extract the exported symbol list from a shared archive.
+extract_expsyms_cmds=$lt_extract_expsyms_cmds
+
+# Variables whose values should be saved in libtool wrapper scripts and
+# restored at link time.
+variables_saved_for_relink=$lt_variables_saved_for_relink
+
+# Do we need the "lib" prefix for modules?
+need_lib_prefix=$need_lib_prefix
+
+# Do we need a version for libraries?
+need_version=$need_version
+
+# Library versioning type.
+version_type=$version_type
+
+# Shared library runtime path variable.
+runpath_var=$runpath_var
+
+# Shared library path variable.
+shlibpath_var=$shlibpath_var
+
+# Is shlibpath searched before the hard-coded library search path?
+shlibpath_overrides_runpath=$shlibpath_overrides_runpath
+
+# Format of library name prefix.
+libname_spec=$lt_libname_spec
+
+# List of archive names.  First name is the real one, the rest are links.
+# The last name is the one that the linker finds with -lNAME
+library_names_spec=$lt_library_names_spec
+
+# The coded name of the library, if different from the real name.
+soname_spec=$lt_soname_spec
+
+# Permission mode override for installation of shared libraries.
+install_override_mode=$lt_install_override_mode
+
+# Command to use after installation of a shared archive.
+postinstall_cmds=$lt_postinstall_cmds
+
+# Command to use after uninstallation of a shared archive.
+postuninstall_cmds=$lt_postuninstall_cmds
+
+# Commands used to finish a libtool library installation in a directory.
+finish_cmds=$lt_finish_cmds
+
+# As "finish_cmds", except a single script fragment to be evaled but
+# not shown.
+finish_eval=$lt_finish_eval
+
+# Whether we should hardcode library paths into libraries.
+hardcode_into_libs=$hardcode_into_libs
+
+# Compile-time system search path for libraries.
+sys_lib_search_path_spec=$lt_sys_lib_search_path_spec
+
+# Run-time system search path for libraries.
+sys_lib_dlsearch_path_spec=$lt_sys_lib_dlsearch_path_spec
+
+# Whether dlopen is supported.
+dlopen_support=$enable_dlopen
+
+# Whether dlopen of programs is supported.
+dlopen_self=$enable_dlopen_self
+
+# Whether dlopen of statically linked programs is supported.
+dlopen_self_static=$enable_dlopen_self_static
+
+# Commands to strip libraries.
+old_striplib=$lt_old_striplib
+striplib=$lt_striplib
+
+
+# The linker used to build libraries.
+LD=$lt_LD
+
+# How to create reloadable object files.
+reload_flag=$lt_reload_flag
+reload_cmds=$lt_reload_cmds
+
+# Commands used to build an old-style archive.
+old_archive_cmds=$lt_old_archive_cmds
+
+# A language specific compiler.
+CC=$lt_compiler
+
+# Is the compiler the GNU compiler?
+with_gcc=$GCC
+
+# Compiler flag to turn off builtin functions.
+no_builtin_flag=$lt_lt_prog_compiler_no_builtin_flag
+
+# Additional compiler flags for building library objects.
+pic_flag=$lt_lt_prog_compiler_pic
+
+# How to pass a linker flag through the compiler.
+wl=$lt_lt_prog_compiler_wl
+
+# Compiler flag to prevent dynamic linking.
+link_static_flag=$lt_lt_prog_compiler_static
+
+# Does compiler simultaneously support -c and -o options?
+compiler_c_o=$lt_lt_cv_prog_compiler_c_o
+
+# Whether or not to add -lc for building shared libraries.
+build_libtool_need_lc=$archive_cmds_need_lc
+
+# Whether or not to disallow shared libs when runtime libs are static.
+allow_libtool_libs_with_static_runtimes=$enable_shared_with_static_runtimes
+
+# Compiler flag to allow reflexive dlopens.
+export_dynamic_flag_spec=$lt_export_dynamic_flag_spec
+
+# Compiler flag to generate shared objects directly from archives.
+whole_archive_flag_spec=$lt_whole_archive_flag_spec
+
+# Whether the compiler copes with passing no objects directly.
+compiler_needs_object=$lt_compiler_needs_object
+
+# Create an old-style archive from a shared archive.
+old_archive_from_new_cmds=$lt_old_archive_from_new_cmds
+
+# Create a temporary old-style archive to link instead of a shared archive.
+old_archive_from_expsyms_cmds=$lt_old_archive_from_expsyms_cmds
+
+# Commands used to build a shared archive.
+archive_cmds=$lt_archive_cmds
+archive_expsym_cmds=$lt_archive_expsym_cmds
+
+# Commands used to build a loadable module if different from building
+# a shared archive.
+module_cmds=$lt_module_cmds
+module_expsym_cmds=$lt_module_expsym_cmds
+
+# Whether we are building with GNU ld or not.
+with_gnu_ld=$lt_with_gnu_ld
+
+# Flag that allows shared libraries with undefined symbols to be built.
+allow_undefined_flag=$lt_allow_undefined_flag
+
+# Flag that enforces no undefined symbols.
+no_undefined_flag=$lt_no_undefined_flag
+
+# Flag to hardcode \$libdir into a binary during linking.
+# This must work even if \$libdir does not exist
+hardcode_libdir_flag_spec=$lt_hardcode_libdir_flag_spec
+
+# Whether we need a single "-rpath" flag with a separated argument.
+hardcode_libdir_separator=$lt_hardcode_libdir_separator
+
+# Set to "yes" if using DIR/libNAME\${shared_ext} during linking hardcodes
+# DIR into the resulting binary.
+hardcode_direct=$hardcode_direct
+
+# Set to "yes" if using DIR/libNAME\${shared_ext} during linking hardcodes
+# DIR into the resulting binary and the resulting library dependency is
+# "absolute",i.e impossible to change by setting \${shlibpath_var} if the
+# library is relocated.
+hardcode_direct_absolute=$hardcode_direct_absolute
+
+# Set to "yes" if using the -LDIR flag during linking hardcodes DIR
+# into the resulting binary.
+hardcode_minus_L=$hardcode_minus_L
+
+# Set to "yes" if using SHLIBPATH_VAR=DIR during linking hardcodes DIR
+# into the resulting binary.
+hardcode_shlibpath_var=$hardcode_shlibpath_var
+
+# Set to "yes" if building a shared library automatically hardcodes DIR
+# into the library and all subsequent libraries and executables linked
+# against it.
+hardcode_automatic=$hardcode_automatic
+
+# Set to yes if linker adds runtime paths of dependent libraries
+# to runtime path list.
+inherit_rpath=$inherit_rpath
+
+# Whether libtool must link a program against all its dependency libraries.
+link_all_deplibs=$link_all_deplibs
+
+# Set to "yes" if exported symbols are required.
+always_export_symbols=$always_export_symbols
+
+# The commands to list exported symbols.
+export_symbols_cmds=$lt_export_symbols_cmds
+
+# Symbols that should not be listed in the preloaded symbols.
+exclude_expsyms=$lt_exclude_expsyms
+
+# Symbols that must always be exported.
+include_expsyms=$lt_include_expsyms
+
+# Commands necessary for linking programs (against libraries) with templates.
+prelink_cmds=$lt_prelink_cmds
+
+# Commands necessary for finishing linking programs.
+postlink_cmds=$lt_postlink_cmds
+
+# Specify filename containing input files.
+file_list_spec=$lt_file_list_spec
+
+# How to hardcode a shared library path into an executable.
+hardcode_action=$hardcode_action
+
+# ### END LIBTOOL CONFIG
+
+_LT_EOF
+
+  case $host_os in
+  aix3*)
+    cat <<\_LT_EOF >> "$cfgfile"
+# AIX sometimes has problems with the GCC collect2 program.  For some
+# reason, if we set the COLLECT_NAMES environment variable, the problems
+# vanish in a puff of smoke.
+if test "X${COLLECT_NAMES+set}" != Xset; then
+  COLLECT_NAMES=
+  export COLLECT_NAMES
+fi
+_LT_EOF
+    ;;
+  esac
+
+
+ltmain="$ac_aux_dir/ltmain.sh"
+
+
+  # We use sed instead of cat because bash on DJGPP gets confused if
+  # if finds mixed CR/LF and LF-only lines.  Since sed operates in
+  # text mode, it properly converts lines to CR/LF.  This bash problem
+  # is reportedly fixed, but why not run on old versions too?
+  sed '$q' "$ltmain" >> "$cfgfile" \
+     || (rm -f "$cfgfile"; exit 1)
+
+  if test x"$xsi_shell" = xyes; then
+  sed -e '/^func_dirname ()$/,/^} # func_dirname /c\
+func_dirname ()\
+{\
+\    case ${1} in\
+\      */*) func_dirname_result="${1%/*}${2}" ;;\
+\      *  ) func_dirname_result="${3}" ;;\
+\    esac\
+} # Extended-shell func_dirname implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_basename ()$/,/^} # func_basename /c\
+func_basename ()\
+{\
+\    func_basename_result="${1##*/}"\
+} # Extended-shell func_basename implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_dirname_and_basename ()$/,/^} # func_dirname_and_basename /c\
+func_dirname_and_basename ()\
+{\
+\    case ${1} in\
+\      */*) func_dirname_result="${1%/*}${2}" ;;\
+\      *  ) func_dirname_result="${3}" ;;\
+\    esac\
+\    func_basename_result="${1##*/}"\
+} # Extended-shell func_dirname_and_basename implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_stripname ()$/,/^} # func_stripname /c\
+func_stripname ()\
+{\
+\    # pdksh 5.2.14 does not do ${X%$Y} correctly if both X and Y are\
+\    # positional parameters, so assign one to ordinary parameter first.\
+\    func_stripname_result=${3}\
+\    func_stripname_result=${func_stripname_result#"${1}"}\
+\    func_stripname_result=${func_stripname_result%"${2}"}\
+} # Extended-shell func_stripname implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_split_long_opt ()$/,/^} # func_split_long_opt /c\
+func_split_long_opt ()\
+{\
+\    func_split_long_opt_name=${1%%=*}\
+\    func_split_long_opt_arg=${1#*=}\
+} # Extended-shell func_split_long_opt implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_split_short_opt ()$/,/^} # func_split_short_opt /c\
+func_split_short_opt ()\
+{\
+\    func_split_short_opt_arg=${1#??}\
+\    func_split_short_opt_name=${1%"$func_split_short_opt_arg"}\
+} # Extended-shell func_split_short_opt implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_lo2o ()$/,/^} # func_lo2o /c\
+func_lo2o ()\
+{\
+\    case ${1} in\
+\      *.lo) func_lo2o_result=${1%.lo}.${objext} ;;\
+\      *)    func_lo2o_result=${1} ;;\
+\    esac\
+} # Extended-shell func_lo2o implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_xform ()$/,/^} # func_xform /c\
+func_xform ()\
+{\
+    func_xform_result=${1%.*}.lo\
+} # Extended-shell func_xform implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_arith ()$/,/^} # func_arith /c\
+func_arith ()\
+{\
+    func_arith_result=$(( $* ))\
+} # Extended-shell func_arith implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_len ()$/,/^} # func_len /c\
+func_len ()\
+{\
+    func_len_result=${#1}\
+} # Extended-shell func_len implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+fi
+
+if test x"$lt_shell_append" = xyes; then
+  sed -e '/^func_append ()$/,/^} # func_append /c\
+func_append ()\
+{\
+    eval "${1}+=\\${2}"\
+} # Extended-shell func_append implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  sed -e '/^func_append_quoted ()$/,/^} # func_append_quoted /c\
+func_append_quoted ()\
+{\
+\    func_quote_for_eval "${2}"\
+\    eval "${1}+=\\\\ \\$func_quote_for_eval_result"\
+} # Extended-shell func_append_quoted implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+
+
+  # Save a `func_append' function call where possible by direct use of '+='
+  sed -e 's%func_append \([a-zA-Z_]\{1,\}\) "%\1+="%g' $cfgfile > $cfgfile.tmp \
+    && mv -f "$cfgfile.tmp" "$cfgfile" \
+      || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+  test 0 -eq $? || _lt_function_replace_fail=:
+else
+  # Save a `func_append' function call even when '+=' is not available
+  sed -e 's%func_append \([a-zA-Z_]\{1,\}\) "%\1="$\1%g' $cfgfile > $cfgfile.tmp \
+    && mv -f "$cfgfile.tmp" "$cfgfile" \
+      || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+  test 0 -eq $? || _lt_function_replace_fail=:
+fi
+
+if test x"$_lt_function_replace_fail" = x":"; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: Unable to substitute extended shell functions in $ofile" >&5
+$as_echo "$as_me: WARNING: Unable to substitute extended shell functions in $ofile" >&2;}
+fi
+
+
+   mv -f "$cfgfile" "$ofile" ||
+    (rm -f "$ofile" && cp "$cfgfile" "$ofile" && rm -f "$cfgfile")
+  chmod +x "$ofile"
+
+ ;;
+
+  esac
+done # for ac_tag
+
+
+as_fn_exit 0
+_ACEOF
+ac_clean_files=$ac_clean_files_save
+
+test $ac_write_fail = 0 ||
+  as_fn_error $? "write failure creating $CONFIG_STATUS" "$LINENO" 5
+
+
+# configure is writing to config.log, and then calls config.status.
+# config.status does its own redirection, appending to config.log.
+# Unfortunately, on DOS this fails, as config.log is still kept open
+# by configure, so config.status won't be able to write to it; its
+# output is simply discarded.  So we exec the FD to /dev/null,
+# effectively closing config.log, so it can be properly (re)opened and
+# appended to by config.status.  When coming back to configure, we
+# need to make the FD available again.
+if test "$no_create" != yes; then
+  ac_cs_success=:
+  ac_config_status_args=
+  test "$silent" = yes &&
+    ac_config_status_args="$ac_config_status_args --quiet"
+  exec 5>/dev/null
+  $SHELL $CONFIG_STATUS $ac_config_status_args || ac_cs_success=false
+  exec 5>>config.log
+  # Use ||, not &&, to avoid exiting from the if with $? = 1, which
+  # would make configure fail if this is the last instruction.
+  $ac_cs_success || as_fn_exit 1
+fi
+if test -n "$ac_unrecognized_opts" && test "$enable_option_checking" != no; then
+  { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: unrecognized options: $ac_unrecognized_opts" >&5
+$as_echo "$as_me: WARNING: unrecognized options: $ac_unrecognized_opts" >&2;}
+fi
+
+
+{ $as_echo "$as_me:${as_lineno-$LINENO}: **************************************** success" >&5
+$as_echo "$as_me: **************************************** success" >&6;}
+# End of configure.ac
+# vim:ft=automake
diff --git a/configure.ac b/configure.ac
new file mode 100644
index 0000000..e3b7540
--- /dev/null
+++ b/configure.ac
@@ -0,0 +1,455 @@
+# Process this file with autoconf to produce a configure script.
+
+AC_INIT([stunnel],[5.22])
+AC_MSG_NOTICE([**************************************** initialization])
+AC_CONFIG_AUX_DIR(auto)
+AC_CONFIG_MACRO_DIR([m4])
+AC_CONFIG_HEADERS([src/config.h])
+AC_CONFIG_SRCDIR([src/stunnel.c])
+AM_INIT_AUTOMAKE
+AC_DEFINE([_GNU_SOURCE], [1], [Use GNU source])
+
+AM_CONDITIONAL([AUTHOR_TESTS], [test -d ".git"])
+AC_CANONICAL_HOST
+AC_SUBST([host])
+AC_DEFINE_UNQUOTED([HOST], ["$host"], [Host description])
+define([esc], [`echo ]$1[ | tr abcdefghijklmnopqrstuvwxyz.- ABCDEFGHIJKLMNOPQRSTUVWXYZ__ | tr -dc ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890_`])
+AC_DEFINE_UNQUOTED(esc(CPU_$host_cpu))
+AC_DEFINE_UNQUOTED(esc(VENDOR_$host_vendor))
+AC_DEFINE_UNQUOTED(esc(OS_$host_os))
+
+AC_PROG_CC
+AM_PROG_CC_C_O
+AC_PROG_INSTALL
+AC_PROG_MAKE_SET
+
+AC_MSG_NOTICE([**************************************** thread model])
+# thread detection should be done first, as it may change the CC variable
+
+AC_ARG_WITH(threads,
+[  --with-threads=model    select threading model (ucontext/pthread/fork)],
+[
+    case "$withval" in
+        ucontext)
+            AC_MSG_NOTICE([UCONTEXT mode selected])
+            AC_DEFINE([USE_UCONTEXT], [1], [Define to 1 to select UCONTEXT mode])
+            ;;
+        pthread)
+            AC_MSG_NOTICE([PTHREAD mode selected])
+            AX_PTHREAD()
+            LIBS="$PTHREAD_LIBS $LIBS"
+            CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+            CC="$PTHREAD_CC"
+            AC_DEFINE([USE_PTHREAD], [1], [Define to 1 to select PTHREAD mode])
+            ;;
+        fork)
+            AC_MSG_NOTICE([FORK mode selected])
+            AC_DEFINE([USE_FORK], [1], [Define to 1 to select FORK mode])
+            ;;
+        *)
+            AC_MSG_ERROR([Unknown thread model \"${withval}\"])
+            ;;
+    esac
+], [
+    # do not attempt to autodetect UCONTEXT threading
+    AX_PTHREAD([
+        AC_MSG_NOTICE([PTHREAD thread model detected])
+        LIBS="$PTHREAD_LIBS $LIBS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+        CC="$PTHREAD_CC"
+        AC_DEFINE([USE_PTHREAD], [1], [Define to 1 to select PTHREAD mode])
+    ], [
+        AC_MSG_NOTICE([FORK thread model detected])
+        AC_DEFINE([USE_FORK], [1], [Define to 1 to select FORK mode])
+    ])
+])
+
+AC_MSG_NOTICE([**************************************** compiler/linker flags])
+AX_APPEND_COMPILE_FLAGS([-Wall])
+AX_APPEND_COMPILE_FLAGS([-Wextra])
+AX_APPEND_COMPILE_FLAGS([-Wpedantic])
+AX_APPEND_COMPILE_FLAGS([-Wformat=2])
+AX_APPEND_COMPILE_FLAGS([-Wconversion])
+AX_APPEND_COMPILE_FLAGS([-Wno-long-long])
+AX_APPEND_COMPILE_FLAGS([-Wno-deprecated-declarations])
+AX_APPEND_COMPILE_FLAGS([-fstack-protector])
+AX_APPEND_COMPILE_FLAGS([-fPIE])
+AX_APPEND_COMPILE_FLAGS([-D_FORTIFY_SOURCE=2])
+AX_APPEND_LINK_FLAGS([-fPIE -pie])
+AX_APPEND_LINK_FLAGS([-Wl,-z,relro])
+AX_APPEND_LINK_FLAGS([-Wl,-z,now])
+AX_APPEND_LINK_FLAGS([-Wl,-z,noexecstack])
+
+AC_MSG_NOTICE([**************************************** libtool])
+LT_INIT([disable-static])
+AC_SUBST([LIBTOOL_DEPS])
+
+AC_MSG_NOTICE([**************************************** types])
+AC_TYPE_INT8_T
+AC_TYPE_INT16_T
+AC_TYPE_INT32_T
+AC_TYPE_INT64_T
+AC_TYPE_UINT8_T
+AC_TYPE_UINT16_T
+AC_TYPE_UINT32_T
+AC_TYPE_UINT64_T
+AC_TYPE_SIZE_T
+AC_TYPE_SSIZE_T
+AC_TYPE_UID_T
+AC_MSG_CHECKING([for socklen_t])
+AC_EGREP_HEADER(socklen_t, sys/socket.h,
+    AC_MSG_RESULT([yes]),
+    AC_MSG_RESULT([no (defined as int)])
+    AC_DEFINE([socklen_t], [int], [Type of socklen_t]))
+AC_CHECK_TYPES([struct sockaddr_un], [], [], [#include <sys/un.h>])
+AC_CHECK_TYPES([struct addrinfo], [], [], [#include <netdb.h>])
+
+AC_MSG_NOTICE([**************************************** PTY device files])
+if test "x$cross_compiling" = "xno"; then
+    AC_CHECK_FILE("/dev/ptmx", AC_DEFINE([HAVE_DEV_PTMX], [1],
+        [Define to 1 if you have '/dev/ptmx' device.]))
+    AC_CHECK_FILE("/dev/ptc", AC_DEFINE([HAVE_DEV_PTS_AND_PTC], [1],
+        [Define to 1 if you have '/dev/ptc' device.]))
+else
+    AC_MSG_WARN([cross-compilation: assuming /dev/ptmx and /dev/ptc are not available])
+fi
+
+AC_MSG_NOTICE([**************************************** entropy sources])
+
+if test "x$cross_compiling" = "xno"; then
+    AC_ARG_WITH(egd-socket,
+        [  --with-egd-socket=FILE  Entropy Gathering Daemon socket path],
+        [EGD_SOCKET="$withval"]
+    )
+    if test -n "$EGD_SOCKET"; then
+        AC_DEFINE_UNQUOTED([EGD_SOCKET], ["$EGD_SOCKET"],
+            [Entropy Gathering Daemon socket path])
+    fi
+
+    # Check for user-specified random device
+    AC_ARG_WITH(random,
+    [  --with-random=FILE      read randomness from file (default=/dev/urandom)],
+        [RANDOM_FILE="$withval"],
+        [
+            # Check for random device
+            AC_CHECK_FILE("/dev/urandom", RANDOM_FILE="/dev/urandom")
+        ]
+    )
+    if test -n "$RANDOM_FILE"; then
+        AC_SUBST([RANDOM_FILE])
+        AC_DEFINE_UNQUOTED([RANDOM_FILE], ["$RANDOM_FILE"], [Random file path])
+    fi
+else
+    AC_MSG_WARN([cross-compilation: assuming entropy sources are not available])
+fi
+
+AC_MSG_NOTICE([**************************************** default group])
+DEFAULT_GROUP=nobody
+if test "x$cross_compiling" = "xno"; then
+    grep '^nogroup:' /etc/group >/dev/null && DEFAULT_GROUP=nogroup
+else
+    AC_MSG_WARN([cross-compilation: assuming nogroup is not available])
+fi
+AC_MSG_CHECKING([for default group])
+AC_MSG_RESULT([$DEFAULT_GROUP])
+AC_SUBST([DEFAULT_GROUP])
+
+AC_MSG_NOTICE([**************************************** header files])
+# AC_HEADER_DIRENT
+# AC_HEADER_STDC
+# AC_HEADER_SYS_WAIT
+AC_CHECK_HEADERS([stdint.h inttypes.h malloc.h ucontext.h pthread.h poll.h tcpd.h stropts.h grp.h unistd.h util.h libutil.h pty.h])
+AC_CHECK_HEADERS([sys/types.h sys/select.h sys/poll.h sys/socket.h sys/un.h sys/ioctl.h sys/filio.h sys/resource.h sys/uio.h sys/syscall.h])
+AC_CHECK_HEADERS([linux/sched.h])
+AC_CHECK_MEMBERS([struct msghdr.msg_control],
+    [AC_DEFINE([HAVE_MSGHDR_MSG_CONTROL], [1],
+    [Define to 1 if you have 'msghdr.msg_control' structure.])], [], [
+AC_INCLUDES_DEFAULT
+#include <sys/socket.h>
+    ])
+AC_CHECK_HEADERS([linux/netfilter_ipv4.h], , , 
+    [
+#include <limits.h>
+#include <linux/types.h>
+#include <sys/socket.h>
+#include <netdb.h>
+    ])
+
+AC_MSG_NOTICE([**************************************** libraries])
+# Checks for standard libraries
+AC_SEARCH_LIBS([gethostbyname], [nsl])
+AC_SEARCH_LIBS([yp_get_default_domain], [nsl])
+AC_SEARCH_LIBS([socket], [socket])
+AC_SEARCH_LIBS([openpty], [util])
+# Checks for dynamic loader and zlib needed by OpenSSL
+AC_SEARCH_LIBS([dlopen], [dl])
+AC_SEARCH_LIBS([shl_load], [dld])
+AC_SEARCH_LIBS([inflateEnd], [z])
+
+# Add BeOS libraries
+if test "x$host_os" = "xbeos"; then
+    LIBS="$LIBS -lbe -lroot -lbind"
+fi
+
+AC_MSG_NOTICE([**************************************** library functions])
+# safe string operations
+AC_CHECK_FUNCS(snprintf vsnprintf)
+# pseudoterminal
+AC_CHECK_FUNCS(openpty _getpty)
+# Unix
+AC_CHECK_FUNCS(daemon waitpid wait4 setsid setgroups chroot)
+# limits
+AC_CHECK_FUNCS(sysconf getrlimit)
+# threads/reentrant functions
+AC_CHECK_FUNCS(pthread_sigmask localtime_r)
+# threads
+AC_CHECK_FUNCS(getcontext __makecontext_v2)
+# sockets
+AC_CHECK_FUNCS(poll gethostbyname2 endhostent getnameinfo)
+AC_MSG_CHECKING([for getaddrinfo])
+case "$host_os" in
+*androideabi*)
+    # http://stackoverflow.com/questions/7818246/segmentation-fault-in-getaddrinfo
+    AC_MSG_RESULT([no (buggy Android implementation)])
+    ;;
+*)
+    # Tru64 UNIX has getaddrinfo() but has it renamed in libc as
+    # something else so we must include <netdb.h> to get the
+    # redefinition.
+    AC_LINK_IFELSE(
+        [AC_LANG_PROGRAM(
+            [
+AC_INCLUDES_DEFAULT
+#include <sys/socket.h>
+#include <netdb.h>
+            ],
+            [
+getaddrinfo(NULL, NULL, NULL, NULL);
+            ],)],
+        [AC_MSG_RESULT([yes]); AC_DEFINE([HAVE_GETADDRINFO], [1], [Define to 1 if you have 'getaddrinfo' function.])],
+        [AC_MSG_RESULT([no])])
+    ;;
+esac
+# poll() is not recommended on Mac OS X <= 10.3 and broken on Mac OS X 10.4
+AC_MSG_CHECKING([for broken poll() implementation])
+case "$host_os" in
+darwin[0-8].*)
+    AC_MSG_RESULT([yes (poll() disabled)])
+    AC_DEFINE([BROKEN_POLL], [1], [Define to 1 if you have a broken 'poll' implementation.])
+    ;;
+*)
+    AC_MSG_RESULT([no])
+    ;;
+esac
+# GNU extensions
+AC_CHECK_FUNCS(pipe2 accept4)
+
+AC_MSG_NOTICE([**************************************** optional features])
+# Use IPv6?
+AC_MSG_CHECKING([whether to enable IPv6 support])
+AC_ARG_ENABLE(ipv6,
+[  --disable-ipv6          disable IPv6 support],
+    [
+        case "$enableval" in
+            yes) AC_MSG_RESULT([yes])
+                 AC_DEFINE([USE_IPv6], [1],
+                    [Define to 1 to enable IPv6 support])
+                 ;;
+            no)  AC_MSG_RESULT([no])
+                 ;;
+            *)   AC_MSG_RESULT([error])
+                 AC_MSG_ERROR([bad value \"${enableval}\"])
+                 ;;
+        esac
+    ], [
+        AC_MSG_RESULT([yes (default)])
+        AC_DEFINE([USE_IPv6], [1], [Define to 1 to enable IPv6 support])
+    ], [
+        AC_MSG_RESULT([no])
+    ]
+)
+
+# FIPS Mode
+AC_MSG_CHECKING([whether to enable FIPS support])
+AC_ARG_ENABLE(fips,
+[  --disable-fips          disable OpenSSL FIPS support],
+    [
+        case "$enableval" in
+            yes) AC_MSG_RESULT([no])
+                 use_fips="yes"
+                 AC_DEFINE([USE_FIPS], [1],
+                    [Define to 1 to enable OpenSSL FIPS support])
+                 ;;
+            no)  AC_MSG_RESULT([no])
+                 use_fips="no"
+                 ;;
+            *)   AC_MSG_RESULT([error])
+                 AC_MSG_ERROR([bad value \"${enableval}\"])
+                 ;;
+        esac
+    ],
+    [
+        use_fips="auto"
+        AC_MSG_RESULT([autodetecting])
+    ]
+)
+
+# Disable systemd socket activation support
+AC_MSG_CHECKING([whether to enable systemd socket activation support])
+AC_ARG_ENABLE(systemd,
+[  --disable-systemd       disable systemd socket activation support],
+    [
+        case "$enableval" in
+            yes) AC_MSG_RESULT([yes])
+                 AC_SEARCH_LIBS([sd_listen_fds], [systemd systemd-daemon])
+                 AC_DEFINE([USE_SYSTEMD], [1],
+                     [Define to 1 to enable systemd socket activation])
+                 ;;
+            no)  AC_MSG_RESULT([no])
+                 ;;
+            *)   AC_MSG_RESULT([error])
+                 AC_MSG_ERROR([Bad value \"${enableval}\"])
+                 ;;
+        esac
+    ],
+    [
+        AC_MSG_RESULT([autodetecting])
+        # the library name has changed to -lsystemd in systemd 209
+        AC_SEARCH_LIBS([sd_listen_fds], [systemd systemd-daemon],
+            [ AC_CHECK_HEADERS([systemd/sd-daemon.h], [
+                AC_DEFINE([USE_SYSTEMD], [1],
+                    [Define to 1 to enable systemd socket activation])
+                AC_MSG_NOTICE([systemd support enabled])
+            ], [
+                AC_MSG_NOTICE([systemd header not found])
+            ]) ], [
+                AC_MSG_NOTICE([systemd library not found])
+            ])
+    ]
+)
+
+# Disable use of libwrap (TCP wrappers)
+# it should be the last check!
+AC_MSG_CHECKING([whether to enable TCP wrappers support])
+AC_ARG_ENABLE(libwrap,
+[  --disable-libwrap       disable TCP wrappers support],
+    [
+        case "$enableval" in
+            yes) AC_MSG_RESULT([yes])
+                 AC_DEFINE([USE_LIBWRAP], [1],
+                     [Define to 1 to enable TCP wrappers support])
+                 LIBS="$LIBS -lwrap"
+                 ;;
+            no)  AC_MSG_RESULT([no])
+                 ;;
+            *)   AC_MSG_RESULT([error])
+                 AC_MSG_ERROR([Bad value \"${enableval}\"])
+                 ;;
+        esac
+    ],
+    [
+        AC_MSG_RESULT([autodetecting])
+        AC_MSG_CHECKING([for hosts_access in -lwrap])
+        valid_LIBS="$LIBS"
+        LIBS="$valid_LIBS -lwrap"
+        AC_LINK_IFELSE(
+            [
+                AC_LANG_PROGRAM(
+                    [int hosts_access(); int allow_severity, deny_severity;],
+                    [hosts_access()])
+            ], [
+                AC_MSG_RESULT([yes]);
+                AC_DEFINE([USE_LIBWRAP], [1],
+                    [Define to 1 to enable TCP wrappers support])
+                AC_MSG_NOTICE([libwrap support enabled])
+            ], [
+                AC_MSG_RESULT([no])
+                LIBS="$valid_LIBS"
+                AC_MSG_NOTICE([libwrap library not found])
+            ]
+        )
+    ]
+)
+
+AC_MSG_NOTICE([**************************************** SSL])
+
+AC_MSG_CHECKING([for compiler sysroot])
+if test "x$GCC" = "xyes"; then
+    sysroot=`$CC --print-sysroot 2>/dev/null`
+fi
+if test -z "$sysroot" -o "x$sysroot" = "x/"; then
+    sysroot=""
+    AC_MSG_RESULT([/])
+else
+    AC_MSG_RESULT([$sysroot])
+fi
+
+check_ssl_dir() { :
+    test -n "$1" -a -f "$1/include/openssl/ssl.h" && SSLDIR="$1"
+}
+
+find_ssl_dir() { :
+    stunnel_prefix="$prefix"
+    test "x$stunnel_prefix" = "xNONE" && stunnel_prefix=$ac_default_prefix
+    for main_dir in "$stunnel_prefix" "/usr/local" "/usr/lib" "/usr/pkg" "/opt/local" "/opt" "/usr" ""; do
+        for sub_dir in "/ssl" "/openssl" "/ossl" ""; do
+            check_ssl_dir "$sysroot$main_dir$sub_dir"
+            test -n "$SSLDIR" && return
+        done
+    done
+    if test -x "/usr/bin/xcrun"; then
+        sdk_path=`/usr/bin/xcrun --sdk macosx --show-sdk-path`
+        check_ssl_dir "$sdk_path/usr"
+    fi
+}
+
+SSLDIR=""
+AC_MSG_CHECKING([for SSL directory])
+AC_ARG_WITH(ssl,
+[  --with-ssl=DIR          location of installed SSL libraries/include files],
+    [check_ssl_dir "$withval"],
+    [find_ssl_dir]
+)
+if test -z "$SSLDIR"; then
+AC_MSG_RESULT([not found])
+AC_MSG_ERROR([
+Could not find your SSL library installation dir
+Use --with-ssl option to fix this problem
+]) 
+fi
+AC_MSG_RESULT([$SSLDIR])
+AC_SUBST([SSLDIR])
+AC_DEFINE_UNQUOTED([SSLDIR], ["$SSLDIR"], [SSL directory])
+
+valid_CPPFLAGS="$CPPFLAGS"; CPPFLAGS="$CPPFLAGS -I$SSLDIR/include"
+valid_LIBS="$LIBS"; LIBS="$LIBS -L$SSLDIR/lib64 -L$SSLDIR/lib -lssl -lcrypto"
+
+AC_CHECK_HEADER([$SSLDIR/include/openssl/engine.h],
+    [AC_DEFINE([HAVE_OSSL_ENGINE_H], [1],
+    [Define to 1 if you have <engine.h> header file.])],
+    [AC_MSG_WARN([OpenSSL engine header not found])])
+
+AC_CHECK_HEADER([$SSLDIR/include/openssl/ocsp.h],
+    [AC_DEFINE([HAVE_OSSL_OCSP_H], [1],
+    [Define to 1 if you have <ocsp.h> header file.])],
+    [AC_MSG_WARN([OpenSSL ocsp header not found])])
+
+if test "x$use_fips" = "xauto"; then
+    AC_CHECK_FUNCS(FIPS_mode_set, [
+        AC_DEFINE([USE_FIPS], [1], [Define to 1 to enable OpenSSL FIPS support])
+        AC_MSG_NOTICE([FIPS support enabled])
+    ], [
+        AC_MSG_NOTICE([FIPS support not found])
+    ])
+fi
+
+CPPFLAGS="$valid_CPPFLAGS"
+LIBS="$valid_LIBS"
+
+AC_MSG_NOTICE([**************************************** write the results])
+AC_CONFIG_FILES([Makefile src/Makefile doc/Makefile tools/Makefile])
+AC_OUTPUT
+
+AC_MSG_NOTICE([**************************************** success])
+# End of configure.ac
+# vim:ft=automake
diff --git a/doc/Makefile.am b/doc/Makefile.am
new file mode 100644
index 0000000..0040fba
--- /dev/null
+++ b/doc/Makefile.am
@@ -0,0 +1,34 @@
+## Process this file with automake to produce Makefile.in
+
+EXTRA_DIST = stunnel.pod.in stunnel.8.in stunnel.html.in en
+EXTRA_DIST += stunnel.pl.pod.in stunnel.pl.8.in stunnel.pl.html.in pl
+
+man_MANS = stunnel.8 stunnel.pl.8
+
+docdir = $(datadir)/doc/stunnel
+doc_DATA = stunnel.html stunnel.pl.html
+
+CLEANFILES = $(man_MANS) $(doc_DATA)
+
+SUFFIXES = .pod.in .8.in .html.in
+
+.pod.in.8.in:
+	pod2man -u -n stunnel -s 8 -r $(VERSION) \
+		-c "stunnel TLS Proxy" -d `date +%Y.%m.%d` $< $@
+
+.pod.in.html.in:
+	pod2html --index --backlink --header \
+		--title "stunnel TLS Proxy" --infile=$< --outfile=$@
+	rm -f pod2htmd.tmp pod2htmi.tmp
+
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g'
+
+$(man_MANS) $(doc_DATA): Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.8: $(srcdir)/stunnel.8.in
+stunnel.html: $(srcdir)/stunnel.html.in
+stunnel.pl.8: $(srcdir)/stunnel.pl.8.in
+stunnel.pl.html: $(srcdir)/stunnel.pl.html.in
diff --git a/doc/Makefile.in b/doc/Makefile.in
new file mode 100644
index 0000000..16a94fd
--- /dev/null
+++ b/doc/Makefile.in
@@ -0,0 +1,567 @@
+# Makefile.in generated by automake 1.14.1 from Makefile.am.
+# @configure_input@
+
+# Copyright (C) 1994-2013 Free Software Foundation, Inc.
+
+# This Makefile.in is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+@SET_MAKE@
+
+VPATH = @srcdir@
+am__is_gnu_make = test -n '$(MAKEFILE_LIST)' && test -n '$(MAKELEVEL)'
+am__make_running_with_option = \
+  case $${target_option-} in \
+      ?) ;; \
+      *) echo "am__make_running_with_option: internal error: invalid" \
+              "target option '$${target_option-}' specified" >&2; \
+         exit 1;; \
+  esac; \
+  has_opt=no; \
+  sane_makeflags=$$MAKEFLAGS; \
+  if $(am__is_gnu_make); then \
+    sane_makeflags=$$MFLAGS; \
+  else \
+    case $$MAKEFLAGS in \
+      *\\[\ \	]*) \
+        bs=\\; \
+        sane_makeflags=`printf '%s\n' "$$MAKEFLAGS" \
+          | sed "s/$$bs$$bs[$$bs $$bs	]*//g"`;; \
+    esac; \
+  fi; \
+  skip_next=no; \
+  strip_trailopt () \
+  { \
+    flg=`printf '%s\n' "$$flg" | sed "s/$$1.*$$//"`; \
+  }; \
+  for flg in $$sane_makeflags; do \
+    test $$skip_next = yes && { skip_next=no; continue; }; \
+    case $$flg in \
+      *=*|--*) continue;; \
+        -*I) strip_trailopt 'I'; skip_next=yes;; \
+      -*I?*) strip_trailopt 'I';; \
+        -*O) strip_trailopt 'O'; skip_next=yes;; \
+      -*O?*) strip_trailopt 'O';; \
+        -*l) strip_trailopt 'l'; skip_next=yes;; \
+      -*l?*) strip_trailopt 'l';; \
+      -[dEDm]) skip_next=yes;; \
+      -[JT]) skip_next=yes;; \
+    esac; \
+    case $$flg in \
+      *$$target_option*) has_opt=yes; break;; \
+    esac; \
+  done; \
+  test $$has_opt = yes
+am__make_dryrun = (target_option=n; $(am__make_running_with_option))
+am__make_keepgoing = (target_option=k; $(am__make_running_with_option))
+pkgdatadir = $(datadir)/@PACKAGE@
+pkgincludedir = $(includedir)/@PACKAGE@
+pkglibdir = $(libdir)/@PACKAGE@
+pkglibexecdir = $(libexecdir)/@PACKAGE@
+am__cd = CDPATH="$${ZSH_VERSION+.}$(PATH_SEPARATOR)" && cd
+install_sh_DATA = $(install_sh) -c -m 644
+install_sh_PROGRAM = $(install_sh) -c
+install_sh_SCRIPT = $(install_sh) -c
+INSTALL_HEADER = $(INSTALL_DATA)
+transform = $(program_transform_name)
+NORMAL_INSTALL = :
+PRE_INSTALL = :
+POST_INSTALL = :
+NORMAL_UNINSTALL = :
+PRE_UNINSTALL = :
+POST_UNINSTALL = :
+build_triplet = @build@
+host_triplet = @host@
+subdir = doc
+DIST_COMMON = $(srcdir)/Makefile.in $(srcdir)/Makefile.am
+ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
+am__aclocal_m4_deps = $(top_srcdir)/m4/ax_append_compile_flags.m4 \
+	$(top_srcdir)/m4/ax_append_flag.m4 \
+	$(top_srcdir)/m4/ax_append_link_flags.m4 \
+	$(top_srcdir)/m4/ax_check_compile_flag.m4 \
+	$(top_srcdir)/m4/ax_check_link_flag.m4 \
+	$(top_srcdir)/m4/ax_pthread.m4 \
+	$(top_srcdir)/m4/ax_require_defined.m4 \
+	$(top_srcdir)/m4/libtool.m4 $(top_srcdir)/m4/ltoptions.m4 \
+	$(top_srcdir)/m4/ltsugar.m4 $(top_srcdir)/m4/ltversion.m4 \
+	$(top_srcdir)/m4/lt~obsolete.m4 $(top_srcdir)/configure.ac
+am__configure_deps = $(am__aclocal_m4_deps) $(CONFIGURE_DEPENDENCIES) \
+	$(ACLOCAL_M4)
+mkinstalldirs = $(install_sh) -d
+CONFIG_HEADER = $(top_builddir)/src/config.h
+CONFIG_CLEAN_FILES =
+CONFIG_CLEAN_VPATH_FILES =
+AM_V_P = $(am__v_P_@AM_V@)
+am__v_P_ = $(am__v_P_@AM_DEFAULT_V@)
+am__v_P_0 = false
+am__v_P_1 = :
+AM_V_GEN = $(am__v_GEN_@AM_V@)
+am__v_GEN_ = $(am__v_GEN_@AM_DEFAULT_V@)
+am__v_GEN_0 = @echo "  GEN     " $@;
+am__v_GEN_1 = 
+AM_V_at = $(am__v_at_@AM_V@)
+am__v_at_ = $(am__v_at_@AM_DEFAULT_V@)
+am__v_at_0 = @
+am__v_at_1 = 
+SOURCES =
+DIST_SOURCES =
+am__can_run_installinfo = \
+  case $$AM_UPDATE_INFO_DIR in \
+    n|no|NO) false;; \
+    *) (install-info --version) >/dev/null 2>&1;; \
+  esac
+am__vpath_adj_setup = srcdirstrip=`echo "$(srcdir)" | sed 's|.|.|g'`;
+am__vpath_adj = case $$p in \
+    $(srcdir)/*) f=`echo "$$p" | sed "s|^$$srcdirstrip/||"`;; \
+    *) f=$$p;; \
+  esac;
+am__strip_dir = f=`echo $$p | sed -e 's|^.*/||'`;
+am__install_max = 40
+am__nobase_strip_setup = \
+  srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*|]/\\\\&/g'`
+am__nobase_strip = \
+  for p in $$list; do echo "$$p"; done | sed -e "s|$$srcdirstrip/||"
+am__nobase_list = $(am__nobase_strip_setup); \
+  for p in $$list; do echo "$$p $$p"; done | \
+  sed "s| $$srcdirstrip/| |;"' / .*\//!s/ .*/ ./; s,\( .*\)/[^/]*$$,\1,' | \
+  $(AWK) 'BEGIN { files["."] = "" } { files[$$2] = files[$$2] " " $$1; \
+    if (++n[$$2] == $(am__install_max)) \
+      { print $$2, files[$$2]; n[$$2] = 0; files[$$2] = "" } } \
+    END { for (dir in files) print dir, files[dir] }'
+am__base_list = \
+  sed '$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;s/\n/ /g' | \
+  sed '$$!N;$$!N;$$!N;$$!N;s/\n/ /g'
+am__uninstall_files_from_dir = { \
+  test -z "$$files" \
+    || { test ! -d "$$dir" && test ! -f "$$dir" && test ! -r "$$dir"; } \
+    || { echo " ( cd '$$dir' && rm -f" $$files ")"; \
+         $(am__cd) "$$dir" && rm -f $$files; }; \
+  }
+man8dir = $(mandir)/man8
+am__installdirs = "$(DESTDIR)$(man8dir)" "$(DESTDIR)$(docdir)"
+NROFF = nroff
+MANS = $(man_MANS)
+DATA = $(doc_DATA)
+am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) $(LISP)
+DISTFILES = $(DIST_COMMON) $(DIST_SOURCES) $(TEXINFOS) $(EXTRA_DIST)
+ACLOCAL = @ACLOCAL@
+AMTAR = @AMTAR@
+AM_DEFAULT_VERBOSITY = @AM_DEFAULT_VERBOSITY@
+AR = @AR@
+AUTOCONF = @AUTOCONF@
+AUTOHEADER = @AUTOHEADER@
+AUTOMAKE = @AUTOMAKE@
+AWK = @AWK@
+CC = @CC@
+CCDEPMODE = @CCDEPMODE@
+CFLAGS = @CFLAGS@
+CPP = @CPP@
+CPPFLAGS = @CPPFLAGS@
+CYGPATH_W = @CYGPATH_W@
+DEFAULT_GROUP = @DEFAULT_GROUP@
+DEFS = @DEFS@
+DEPDIR = @DEPDIR@
+DLLTOOL = @DLLTOOL@
+DSYMUTIL = @DSYMUTIL@
+DUMPBIN = @DUMPBIN@
+ECHO_C = @ECHO_C@
+ECHO_N = @ECHO_N@
+ECHO_T = @ECHO_T@
+EGREP = @EGREP@
+EXEEXT = @EXEEXT@
+FGREP = @FGREP@
+GREP = @GREP@
+INSTALL = @INSTALL@
+INSTALL_DATA = @INSTALL_DATA@
+INSTALL_PROGRAM = @INSTALL_PROGRAM@
+INSTALL_SCRIPT = @INSTALL_SCRIPT@
+INSTALL_STRIP_PROGRAM = @INSTALL_STRIP_PROGRAM@
+LD = @LD@
+LDFLAGS = @LDFLAGS@
+LIBOBJS = @LIBOBJS@
+LIBS = @LIBS@
+LIBTOOL = @LIBTOOL@
+LIBTOOL_DEPS = @LIBTOOL_DEPS@
+LIPO = @LIPO@
+LN_S = @LN_S@
+LTLIBOBJS = @LTLIBOBJS@
+MAKEINFO = @MAKEINFO@
+MANIFEST_TOOL = @MANIFEST_TOOL@
+MKDIR_P = @MKDIR_P@
+NM = @NM@
+NMEDIT = @NMEDIT@
+OBJDUMP = @OBJDUMP@
+OBJEXT = @OBJEXT@
+OTOOL = @OTOOL@
+OTOOL64 = @OTOOL64@
+PACKAGE = @PACKAGE@
+PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
+PACKAGE_NAME = @PACKAGE_NAME@
+PACKAGE_STRING = @PACKAGE_STRING@
+PACKAGE_TARNAME = @PACKAGE_TARNAME@
+PACKAGE_URL = @PACKAGE_URL@
+PACKAGE_VERSION = @PACKAGE_VERSION@
+PATH_SEPARATOR = @PATH_SEPARATOR@
+PTHREAD_CC = @PTHREAD_CC@
+PTHREAD_CFLAGS = @PTHREAD_CFLAGS@
+PTHREAD_LIBS = @PTHREAD_LIBS@
+RANDOM_FILE = @RANDOM_FILE@
+RANLIB = @RANLIB@
+SED = @SED@
+SET_MAKE = @SET_MAKE@
+SHELL = @SHELL@
+SSLDIR = @SSLDIR@
+STRIP = @STRIP@
+VERSION = @VERSION@
+abs_builddir = @abs_builddir@
+abs_srcdir = @abs_srcdir@
+abs_top_builddir = @abs_top_builddir@
+abs_top_srcdir = @abs_top_srcdir@
+ac_ct_AR = @ac_ct_AR@
+ac_ct_CC = @ac_ct_CC@
+ac_ct_DUMPBIN = @ac_ct_DUMPBIN@
+am__include = @am__include@
+am__leading_dot = @am__leading_dot@
+am__quote = @am__quote@
+am__tar = @am__tar@
+am__untar = @am__untar@
+ax_pthread_config = @ax_pthread_config@
+bindir = @bindir@
+build = @build@
+build_alias = @build_alias@
+build_cpu = @build_cpu@
+build_os = @build_os@
+build_vendor = @build_vendor@
+builddir = @builddir@
+datadir = @datadir@
+datarootdir = @datarootdir@
+docdir = $(datadir)/doc/stunnel
+dvidir = @dvidir@
+exec_prefix = @exec_prefix@
+host = @host@
+host_alias = @host_alias@
+host_cpu = @host_cpu@
+host_os = @host_os@
+host_vendor = @host_vendor@
+htmldir = @htmldir@
+includedir = @includedir@
+infodir = @infodir@
+install_sh = @install_sh@
+libdir = @libdir@
+libexecdir = @libexecdir@
+localedir = @localedir@
+localstatedir = @localstatedir@
+mandir = @mandir@
+mkdir_p = @mkdir_p@
+oldincludedir = @oldincludedir@
+pdfdir = @pdfdir@
+prefix = @prefix@
+program_transform_name = @program_transform_name@
+psdir = @psdir@
+sbindir = @sbindir@
+sharedstatedir = @sharedstatedir@
+srcdir = @srcdir@
+sysconfdir = @sysconfdir@
+target_alias = @target_alias@
+top_build_prefix = @top_build_prefix@
+top_builddir = @top_builddir@
+top_srcdir = @top_srcdir@
+EXTRA_DIST = stunnel.pod.in stunnel.8.in stunnel.html.in en \
+	stunnel.pl.pod.in stunnel.pl.8.in stunnel.pl.html.in pl
+man_MANS = stunnel.8 stunnel.pl.8
+doc_DATA = stunnel.html stunnel.pl.html
+CLEANFILES = $(man_MANS) $(doc_DATA)
+SUFFIXES = .pod.in .8.in .html.in
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g'
+
+all: all-am
+
+.SUFFIXES:
+.SUFFIXES: .pod.in .8.in .html.in
+$(srcdir)/Makefile.in:  $(srcdir)/Makefile.am  $(am__configure_deps)
+	@for dep in $?; do \
+	  case '$(am__configure_deps)' in \
+	    *$$dep*) \
+	      ( cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh ) \
+	        && { if test -f $@; then exit 0; else break; fi; }; \
+	      exit 1;; \
+	  esac; \
+	done; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu doc/Makefile'; \
+	$(am__cd) $(top_srcdir) && \
+	  $(AUTOMAKE) --gnu doc/Makefile
+.PRECIOUS: Makefile
+Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
+	@case '$?' in \
+	  *config.status*) \
+	    cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh;; \
+	  *) \
+	    echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe)'; \
+	    cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe);; \
+	esac;
+
+$(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+
+$(top_srcdir)/configure:  $(am__configure_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(ACLOCAL_M4):  $(am__aclocal_m4_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(am__aclocal_m4_deps):
+
+mostlyclean-libtool:
+	-rm -f *.lo
+
+clean-libtool:
+	-rm -rf .libs _libs
+install-man8: $(man_MANS)
+	@$(NORMAL_INSTALL)
+	@list1=''; \
+	list2='$(man_MANS)'; \
+	test -n "$(man8dir)" \
+	  && test -n "`echo $$list1$$list2`" \
+	  || exit 0; \
+	echo " $(MKDIR_P) '$(DESTDIR)$(man8dir)'"; \
+	$(MKDIR_P) "$(DESTDIR)$(man8dir)" || exit 1; \
+	{ for i in $$list1; do echo "$$i"; done;  \
+	if test -n "$$list2"; then \
+	  for i in $$list2; do echo "$$i"; done \
+	    | sed -n '/\.8[a-z]*$$/p'; \
+	fi; \
+	} | while read p; do \
+	  if test -f $$p; then d=; else d="$(srcdir)/"; fi; \
+	  echo "$$d$$p"; echo "$$p"; \
+	done | \
+	sed -e 'n;s,.*/,,;p;h;s,.*\.,,;s,^[^8][0-9a-z]*$$,8,;x' \
+	      -e 's,\.[0-9a-z]*$$,,;$(transform);G;s,\n,.,' | \
+	sed 'N;N;s,\n, ,g' | { \
+	list=; while read file base inst; do \
+	  if test "$$base" = "$$inst"; then list="$$list $$file"; else \
+	    echo " $(INSTALL_DATA) '$$file' '$(DESTDIR)$(man8dir)/$$inst'"; \
+	    $(INSTALL_DATA) "$$file" "$(DESTDIR)$(man8dir)/$$inst" || exit $$?; \
+	  fi; \
+	done; \
+	for i in $$list; do echo "$$i"; done | $(am__base_list) | \
+	while read files; do \
+	  test -z "$$files" || { \
+	    echo " $(INSTALL_DATA) $$files '$(DESTDIR)$(man8dir)'"; \
+	    $(INSTALL_DATA) $$files "$(DESTDIR)$(man8dir)" || exit $$?; }; \
+	done; }
+
+uninstall-man8:
+	@$(NORMAL_UNINSTALL)
+	@list=''; test -n "$(man8dir)" || exit 0; \
+	files=`{ for i in $$list; do echo "$$i"; done; \
+	l2='$(man_MANS)'; for i in $$l2; do echo "$$i"; done | \
+	  sed -n '/\.8[a-z]*$$/p'; \
+	} | sed -e 's,.*/,,;h;s,.*\.,,;s,^[^8][0-9a-z]*$$,8,;x' \
+	      -e 's,\.[0-9a-z]*$$,,;$(transform);G;s,\n,.,'`; \
+	dir='$(DESTDIR)$(man8dir)'; $(am__uninstall_files_from_dir)
+install-docDATA: $(doc_DATA)
+	@$(NORMAL_INSTALL)
+	@list='$(doc_DATA)'; test -n "$(docdir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(docdir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(docdir)" || exit 1; \
+	fi; \
+	for p in $$list; do \
+	  if test -f "$$p"; then d=; else d="$(srcdir)/"; fi; \
+	  echo "$$d$$p"; \
+	done | $(am__base_list) | \
+	while read files; do \
+	  echo " $(INSTALL_DATA) $$files '$(DESTDIR)$(docdir)'"; \
+	  $(INSTALL_DATA) $$files "$(DESTDIR)$(docdir)" || exit $$?; \
+	done
+
+uninstall-docDATA:
+	@$(NORMAL_UNINSTALL)
+	@list='$(doc_DATA)'; test -n "$(docdir)" || list=; \
+	files=`for p in $$list; do echo $$p; done | sed -e 's|^.*/||'`; \
+	dir='$(DESTDIR)$(docdir)'; $(am__uninstall_files_from_dir)
+tags TAGS:
+
+ctags CTAGS:
+
+cscope cscopelist:
+
+
+distdir: $(DISTFILES)
+	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	list='$(DISTFILES)'; \
+	  dist_files=`for file in $$list; do echo $$file; done | \
+	  sed -e "s|^$$srcdirstrip/||;t" \
+	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
+	case $$dist_files in \
+	  */*) $(MKDIR_P) `echo "$$dist_files" | \
+			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sort -u` ;; \
+	esac; \
+	for file in $$dist_files; do \
+	  if test -f $$file || test -d $$file; then d=.; else d=$(srcdir); fi; \
+	  if test -d $$d/$$file; then \
+	    dir=`echo "/$$file" | sed -e 's,/[^/]*$$,,'`; \
+	    if test -d "$(distdir)/$$file"; then \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    if test -d $(srcdir)/$$file && test $$d != $(srcdir); then \
+	      cp -fpR $(srcdir)/$$file "$(distdir)$$dir" || exit 1; \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    cp -fpR $$d/$$file "$(distdir)$$dir" || exit 1; \
+	  else \
+	    test -f "$(distdir)/$$file" \
+	    || cp -p $$d/$$file "$(distdir)/$$file" \
+	    || exit 1; \
+	  fi; \
+	done
+check-am: all-am
+check: check-am
+all-am: Makefile $(MANS) $(DATA)
+installdirs:
+	for dir in "$(DESTDIR)$(man8dir)" "$(DESTDIR)$(docdir)"; do \
+	  test -z "$$dir" || $(MKDIR_P) "$$dir"; \
+	done
+install: install-am
+install-exec: install-exec-am
+install-data: install-data-am
+uninstall: uninstall-am
+
+install-am: all-am
+	@$(MAKE) $(AM_MAKEFLAGS) install-exec-am install-data-am
+
+installcheck: installcheck-am
+install-strip:
+	if test -z '$(STRIP)'; then \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	      install; \
+	else \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	    "INSTALL_PROGRAM_ENV=STRIPPROG='$(STRIP)'" install; \
+	fi
+mostlyclean-generic:
+
+clean-generic:
+	-test -z "$(CLEANFILES)" || rm -f $(CLEANFILES)
+
+distclean-generic:
+	-test -z "$(CONFIG_CLEAN_FILES)" || rm -f $(CONFIG_CLEAN_FILES)
+	-test . = "$(srcdir)" || test -z "$(CONFIG_CLEAN_VPATH_FILES)" || rm -f $(CONFIG_CLEAN_VPATH_FILES)
+
+maintainer-clean-generic:
+	@echo "This command is intended for maintainers to use"
+	@echo "it deletes files that may require special tools to rebuild."
+clean: clean-am
+
+clean-am: clean-generic clean-libtool mostlyclean-am
+
+distclean: distclean-am
+	-rm -f Makefile
+distclean-am: clean-am distclean-generic
+
+dvi: dvi-am
+
+dvi-am:
+
+html: html-am
+
+html-am:
+
+info: info-am
+
+info-am:
+
+install-data-am: install-docDATA install-man
+
+install-dvi: install-dvi-am
+
+install-dvi-am:
+
+install-exec-am:
+
+install-html: install-html-am
+
+install-html-am:
+
+install-info: install-info-am
+
+install-info-am:
+
+install-man: install-man8
+
+install-pdf: install-pdf-am
+
+install-pdf-am:
+
+install-ps: install-ps-am
+
+install-ps-am:
+
+installcheck-am:
+
+maintainer-clean: maintainer-clean-am
+	-rm -f Makefile
+maintainer-clean-am: distclean-am maintainer-clean-generic
+
+mostlyclean: mostlyclean-am
+
+mostlyclean-am: mostlyclean-generic mostlyclean-libtool
+
+pdf: pdf-am
+
+pdf-am:
+
+ps: ps-am
+
+ps-am:
+
+uninstall-am: uninstall-docDATA uninstall-man
+
+uninstall-man: uninstall-man8
+
+.MAKE: install-am install-strip
+
+.PHONY: all all-am check check-am clean clean-generic clean-libtool \
+	cscopelist-am ctags-am distclean distclean-generic \
+	distclean-libtool distdir dvi dvi-am html html-am info info-am \
+	install install-am install-data install-data-am \
+	install-docDATA install-dvi install-dvi-am install-exec \
+	install-exec-am install-html install-html-am install-info \
+	install-info-am install-man install-man8 install-pdf \
+	install-pdf-am install-ps install-ps-am install-strip \
+	installcheck installcheck-am installdirs maintainer-clean \
+	maintainer-clean-generic mostlyclean mostlyclean-generic \
+	mostlyclean-libtool pdf pdf-am ps ps-am tags-am uninstall \
+	uninstall-am uninstall-docDATA uninstall-man uninstall-man8
+
+
+.pod.in.8.in:
+	pod2man -u -n stunnel -s 8 -r $(VERSION) \
+		-c "stunnel TLS Proxy" -d `date +%Y.%m.%d` $< $@
+
+.pod.in.html.in:
+	pod2html --index --backlink --header \
+		--title "stunnel TLS Proxy" --infile=$< --outfile=$@
+	rm -f pod2htmd.tmp pod2htmi.tmp
+
+$(man_MANS) $(doc_DATA): Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.8: $(srcdir)/stunnel.8.in
+stunnel.html: $(srcdir)/stunnel.html.in
+stunnel.pl.8: $(srcdir)/stunnel.pl.8.in
+stunnel.pl.html: $(srcdir)/stunnel.pl.html.in
+
+# Tell versions [3.59,3.63) of GNU make to not export all variables.
+# Otherwise a system limit (for SysV at least) may be exceeded.
+.NOEXPORT:
diff --git a/doc/en/VNC_StunnelHOWTO.html b/doc/en/VNC_StunnelHOWTO.html
new file mode 100644
index 0000000..7116551
--- /dev/null
+++ b/doc/en/VNC_StunnelHOWTO.html
@@ -0,0 +1,190 @@
+<!-- saved from url=(0022)http://internet.e-mail -->

+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">

+<HTML>

+<HEAD>

+	<META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=iso-8859-1">

+	<TITLE></TITLE>

+	<META NAME="GENERATOR" CONTENT="StarOffice/5.2 (Win32)">

+	<META NAME="CREATED" CONTENT="20010220;7501784">

+	<META NAME="CHANGED" CONTENT="16010101;0">

+	<STYLE>

+	<!--

+		@page { margin: 2cm }

+	-->

+	</STYLE>

+</HEAD>

+<BODY>

+<P ALIGN=CENTER STYLE="margin-bottom: 0cm"><FONT SIZE=4 STYLE="font-size: 16pt"><U><B>VNC

+over STUNNEL with a Linux server and Windows 2000 client HOWTO</B></U></FONT></P>

+<P ALIGN=CENTER STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">19 February 2001</P>

+<P STYLE="margin-bottom: 0cm">ver 1.0</P>

+<P STYLE="margin-bottom: 0cm">by Craig Furter and Arno van der Walt</P>

+<P STYLE="margin-bottom: 0cm">contact us at <A HREF="mailto:cfurter@vexen.co.za">cfurter@vexen.co.za</A>

+and <A HREF="mailto:arnovdw@mycomax.com">arnovdw@mycomax.com</A></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">We assume that you have already

+downloaded VNCServer and VNCViewer.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">First of all there is a step by step

+HOWTO and then we'll look at the theory behind all this.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">Download and install OpenSSL,

+	SSLeay, and Stunnel on the Linux/Unix box. Download the modules.</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">a)

+[root@anthrax$]gunzip openssl-x.xx.tar.gz (repeat for all 3 the

+modules)</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">b)

+[root@anthrax$]tar &#150; xvf openssl-x.xx.tar (repeat for all 3 the

+modules)</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">Copy the following to Notepad and

+	save the file as VNCRegEdit.REG on the Windows 2000 box</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">--cut here and copy

+to VNCRegEdit.REG then double click the file to

+import--<BR>REGEDIT4<BR><BR>[HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3]<BR>AllowLoopback=dword:00000001<BR><BR>[HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\Default]<BR>AllowLoopback=dword:00000001<BR>--stop

+here--<BR><BR>

+</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">Install Stunnel on the Windows

+	2000 machine by copying the following files to your \WINNT\SYSTEM32\

+	directory</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">a)libeay32.dll</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">b)libssl.dll</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">c)stunnel.pem</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">On the Linux box execute the

+	following command as root and let it run in its own terminal.</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">./stunnel -d 5900

+-r 5901</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">Execute vncserver (it should run

+	as display:1 when you execute the ps aux |grep vnc command)</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">Now on the Windows 2000 machine

+	execute the following command and let it run in its own terminal.</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">stunnel -d 5900 -r

+unix.ip.address:5900 -c</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">.</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">And on the Windows 2000 machine

+	open VNCviewer and connect to localhost specifying no display</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">ie. 10.10.1.53 in

+the window</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">For each additional display repeat

+	steps 4 &#150; 6 and increment the specified ports with 2  ie. The

+	Linux command will look as follows:</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm"> ./stunnel -d 5902

+-r 5903 

+</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">and the Windows

+2000 command as follows: 

+</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">stunnel -d 5902 -r

+unix.ip.address:5902</P>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">and remember to

+start another vncserver on the Linux box for each VNC display</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<OL>

+	<LI><P STYLE="margin-bottom: 0cm">The display number on the

+	vncviewer must also be incremented with two ie:</P>

+</OL>

+<P STYLE="margin-left: 0.5cm; margin-bottom: 0cm">10.10.1.53:2 etc.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><FONT SIZE=4><U>The THEORY</U></FONT></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><U>Tunneling:</U></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">What this means is that software

+(daemon)  runs on the client and server machine. In this case, the

+Windows 2000 machine is the client and the server is the *NIX

+machine. Stunnel will then run as client on Windows 2000 and server

+mode on the UNIX box.<BR><BR>eg:<BR>Windows:<BR>stunnel -d 5900 -r

+unix.ip.address:5900 -c<BR><BR>UNIX<BR>stunnel -d 5900 -r 5901<BR><BR>This

+means that connecting to VNC display 0 in the localhost will transfer

+all the calls to the *NIX machine on display 1. So the VNC server on

+the *NIX machine must be running on display 1. Not display 0. If you

+run stunnel before VNC, VNC will automatically move to display 1

+noticing that port 5900 (&quot;display&quot; 0) is already in

+use).<BR><BR>What happens now is that when you connect to port 5900

+on the Windows machine via an &quot;unsecured&quot; connection, a

+secure &quot;tunnel&quot; is opened from Windows 2000 to the *NIX

+machine on port 5900. The *NIX machine then opens a &quot;unsecured&quot;

+connection to itself on port 5901. We now have a secure tunnel

+available.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><U>A bit about VNC and displays</U></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">The -d is the listening IPaddress:port

+and the -r is the remote IPaddress:port. VNC uses port 5900 for

+display 0. That means that display 1 will be 5901. If you want VNC

+server to listen for a connection on port 80 then the display number

+will be 80 - 5900 = -5820. If you want VNC server to<BR>listen on

+port 14000 then the display number is 14000 - 5900 = 8100.<BR><BR>So

+all you have to do is run stunnel on the UNIX machine and VNC on the

+desired &quot;display&quot; number.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><U>VNC on the Windows 2000 machine</U></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">To connect from the client machine you

+need to enter the client machine's IP address and the &quot;display&quot;

+(from the port conversion). But VNC will think that you are trying to

+connect to the local machine and does not allow this. To override

+this add the following to your registry.<BR><BR>--cut here and copy to

+anything.reg. then double click the file to

+import--<BR>REGEDIT4<BR><BR>[HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3]<BR>AllowLoopback=dword:00000001<BR><BR>[HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3\Default]<BR>AllowLoopback=dword:00000001<BR>--stop

+here--<BR><BR>Now VNC will not complain. So you need to always run

+stunnel in client mode on the Windows machine and then connect with

+VNCViewer to the localhost on the correct &quot;display&quot;. By the

+way, *NIX doesn't complain about this. There is no setting needed if

+*NIX to *NIX.</P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm"><U>VNC's Java client</U></P>

+<P STYLE="margin-bottom: 0cm"><BR>

+</P>

+<P STYLE="margin-bottom: 0cm">Unfortunately this will not work well

+with the built-in web version. If you did not known about it, try

+http'ing into a machine running VNC server on it, to port 58XX (where

+XX is the display number), and the Java client will be loaded.<BR><BR>

+</P>

+</BODY>

+</HTML>

diff --git a/doc/pl/faq.stunnel-2.html b/doc/pl/faq.stunnel-2.html
new file mode 100644
index 0000000..275f400
--- /dev/null
+++ b/doc/pl/faq.stunnel-2.html
@@ -0,0 +1,143 @@
+<HTML>
+<HEAD>
+   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-2">
+   <TITLE>Gdy pojawiaj± siê k³opoty</TITLE>
+</HEAD>
+<BODY TEXT="#000000" BGCOLOR="#FFFFFF" LINK="#0000EF" VLINK="#51188E" ALINK="#FF0000">
+<B>Q: </B>Próbuje kompilowaæ stunnel jednak dostaje
+nastêpuj±ce komunikaty:
+<BR>stunnel.c:69: ssl.h: No such file or directory
+<BR>stunnel.c:71: bio.h: No such file or directory
+<BR>stunnel.c:72: pem.h: No such file or directory
+<BR>make: *** [stunnel.o] Error 1
+
+<P><B>A:</B> S± dwie prawdopodobne przyczyny: nie masz zainstalowanego
+w systemie pakietu SSLeay lub pakiet nie znajduje sie w miejscu domy¶lnym
+czyli<B> /usr/local/ssl. </B>Nale¿y zainstalowaæ SSLeay lub te¿ poprawiæ
+Makefile tak by ¶cie¿ka by³a prawid³owa.
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B>&nbsp; Próbuje uruchomiæ stunnel jako wrapper dla httpd. Po
+wydaniu komendy: <B>stunnel 443 @localhost:80</B> demon siê nie uruchamia
+a w syslogu pojawia siê komunikat "<B>stunnel[2481]: getpeername: Socket
+operation on non-socket (88)"</B><B></B>
+
+<P><B>A</B>: Jest to b³±d charakterystyczny dla Linuxa. Nale¿y w pliku
+stunnel.c zmieniæ liniê<B> #define INET_SOCKET_PAIR 1</B> na
+<BR><B>#define INET_SOCKET_PAIR 0</B> i zrekompilowaæ program ponownie.
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B> Stunnel nadal siê nie uruchamia a w syslogu pojawia siê komunikat
+"<B>stunnel[2525]: /usr/local/ssl/certs/localhost:80.pem: No such file
+or directory (2)</B>"<B></B>
+
+<P><B>A:</B> Nie posiadasz odpowiedniego certyfikatu dla demona. Stunnel
+w celu poprawnego dzia³ania <B>MUSI</B> posiadaæ certyfikat. W celu wygenerowania
+odpowiedniego certyfikatu nale¿y wydaæ komende: <B>/usr/local/ssl/bin/ssleay
+req -new -x509 -nodes -out server.pem -days 365 -keyout server.pem</B>&nbsp;
+b±d¼ te¿ u¿yæ <B>Makefile</B> do³±czonego do programu stunnel i przy pomocy
+komendy <B>make cert </B>stworzyæ certyfikat. Tak utworzony certyfikat (server.pem)
+nale¿y umie¶ciæ w katalogu <B>/usr/local/ssl/certs</B> i utworzyæ doñ odpowiednie
+linki lub zmieæ nazwê certyfikatu na wymagan± przez stunnel.
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B> Wygenerowa³em odpowiedni certyfikat przy pomocy skryptu CA.sh,
+a stunnel <B>przy starcie prosi o podanie has³a</B>. Jak mo¿na przekazaæ
+has³o zabezpieczaj±ce certyfikat do programu ?<B></B>
+
+<P><B>A:</B> W chwili obecnej jest to niemo¿liwe. Certyfikaty którymi pos³uguje
+sie stunnel nie mog± byæ zabezpieczane has³em. Przy tworzeniu certyfikatu
+nale¿y u¿yæ opcji -nodes (lub utworzyæ certyfikat przy pomocy makefile
+odstarczonego z programem).
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B> Po uruchomieniu programu stunnel w syslogu pojawia siê komunikat:
+"<B>stunnel[2805]: WARNING: Wrong permissions on /usr/local/ssl/certs/localhost:80.pem</B>".
+Co jest nie tak ?<B></B>
+
+<P><B>A:</B> To tylko ostrze¿enie ! Certyfikat nie powien daæ siê odczytaæ
+przez innych u¿ytkowników systemu. Prawid³owe prawa dostêpu powinny byæ
+nastêpuj±ce: <B>-rw------&nbsp;&nbsp; 1 root&nbsp;&nbsp;&nbsp;&nbsp; root&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+1370 Nov 8 1997&nbsp; server.pem </B>(je¶li uruchamiaj±cym stunnel jest
+root).
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B> Probowa³em zrobiæ tunelowanie po³±czenia do demona <B>pop3</B>.
+Pomimo zrobienia prawid³owego wpisu do inetd.conf
+<BR>"spop3&nbsp; stream&nbsp; tcp&nbsp; nowait&nbsp; root&nbsp; /usr/sbin/stunnel&nbsp;
+qpopper -s" stunnel nie dzia³a a w syslogu pojawia siê komunikat:
+<BR><B>inetd[2949]: spop3/tcp: unknown service.</B><B></B>
+
+<P><B>A: </B>Nie zrobi³e¶ dodatkowych wpisów do pliku <B>/etc/services.</B>
+Zgodnie z rfc???? prawid³owymi portami na których dzia³aj± demony pos³uguj±ce
+siê SSL s±:
+<TABLE>
+<TR>
+<TD>https</TD>
+
+<TD>443/tcp</TD>
+
+<TD># HTTP over SSL&nbsp;</TD>
+</TR>
+
+<TR>
+<TD>ssmtp</TD>
+
+<TD>465/tcp</TD>
+
+<TD># SMTP over SSL&nbsp;</TD>
+</TR>
+
+<TR>
+<TD>snews</TD>
+
+<TD>563/tcp</TD>
+
+<TD># NNTP over SSL&nbsp;</TD>
+</TR>
+
+<TR>
+<TD>ssl-ldap</TD>
+
+<TD>636/tcp</TD>
+
+<TD># LDAP over SSL&nbsp;</TD>
+</TR>
+
+<TR>
+<TD>simap</TD>
+
+<TD>993/tcp</TD>
+
+<TD># IMAP over SSL&nbsp;</TD>
+</TR>
+
+<TR>
+<TD>spop3</TD>
+
+<TD>995/tcp</TD>
+
+<TD># POP-3 over SSL&nbsp;</TD>
+</TR>
+</TABLE>
+Je¶li nie chesz robiæ poprawek zamiast nazwy serwisu u¿yj numeru portu
+na którym on dzia³a.
+<BR>
+<HR WIDTH="100%">
+<BR><B>Q:</B> Dobrze, zrobi³em wymagany wpis lecz w dalszym ciagu stunnel
+nie dzia³a, natomiast w syslogu pojawia sie wpis:
+<BR>&nbsp;<B>stunnel[3015]: execvp: No such file or directory (2). </B>Co
+jeszcze jest nie tak ?<B></B>
+
+<P><B>A:</B>&nbsp; Prawdopodone s± dwie przyczyny: pierwsza w twoim systemie
+nie ma demona dla ktorego zrobi³e¶ wpis w inetd.conf,
+<BR>(spop3&nbsp; stream&nbsp; tcp&nbsp; nowait&nbsp; root&nbsp; /usr/sbin/stunnel&nbsp;
+qpopper -s) lub te¿ dany program jest w systemie, jednak ¶cie¿ka dostêpu
+do niego nie jest wymieniona w zmiennej systemowej <B>$PATH</B>. Nale¿y
+wiêc poprawiæ zapis w inetd.conf uzupe³niaj±c o pe³na ¶cie¿ke dostêpu do
+demona np.&nbsp; <B>spop3&nbsp; stream&nbsp; tcp&nbsp; nowait&nbsp; root&nbsp;
+/usr/sbin/stunnel&nbsp; /usr/sbin/qpopper -s</B>
+<BR>&nbsp;
+<BR>&nbsp;
+</BODY>
+</HTML>
diff --git a/doc/pl/tworzenie_certyfikatow.html b/doc/pl/tworzenie_certyfikatow.html
new file mode 100644
index 0000000..60ebf04
--- /dev/null
+++ b/doc/pl/tworzenie_certyfikatow.html
@@ -0,0 +1,744 @@
+<HTML>
+<HEAD>
+   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-2">
+   <META NAME="Author" CONTENT="Adam Hernik">
+   <TITLE>Wszystko co powiniene¶ wiedzieæ o tworzeniu certyfikatów ale nie chce Ci siê poszukaæ w dokumentacji</TITLE>
+</HEAD>
+<BODY TEXT="#000000" BGCOLOR="#CCCCCC" LINK="#0000EF" VLINK="#51188E" ALINK="#FF0000">
+
+<CENTER>
+<H1>
+<FONT SIZE=+2>Wszystko co powiniene¶ wiedzieæ o tworzeniu certyfikatów
+ale nie chce Ci siê</FONT></H1></CENTER>
+
+<CENTER>
+<H1>
+<FONT SIZE=+2>poszukaæ w dokumentacji.</FONT></H1></CENTER>
+&nbsp;
+
+<P><B><FONT SIZE=+1>Co powinno znajdowaæ siê na Twoim dysku zamin zostaniesz
+"Certificate Authorities".</FONT></B>
+
+<P>Podstawowym oprogramowaniem jest oczywi¶cie <A HREF="http://www.openssl.org">openssl</A>.
+W tym miejscu nale¿y zachowaæ czujno¶æ
+<BR>bo openssl <B>MUSI</B> byæ co najmniej w wersji 0.9.2b dziêki czemu
+ominie Ciê czê¶æ karko³omnych
+<BR>operacji przy pomocy <A HREF="http://www.drh-consultancy.demon.co.uk">pcks12</A>
+ktory tak¿e musisz posiadaæ w swoich zasobach dyskowych.
+<BR>Je¶li masz ju¿ zainstalowane powy¿sze oprogramowanie mo¿esz zacz±æ
+tworzyæ certyfikaty.
+
+<P><B><FONT SIZE=+1>Konfiguracja openssl.</FONT></B>
+
+<P>Zak³adam ze openssl jest zainstalowany standardowo czyli w <B>/usr/local/ssl</B>.
+Pierwszym krokiem jest
+<BR>przejrzenie i "dokonfigurowanie" <B>/usr/local/ssl/lib/openssl.cnf</B>.
+Mój domowy konfig wygl±da nastêpuj±co
+<BR>(kolorem czerwonym zaznaczylem opcje które raczej powiniene¶ zmieniæ)
+:
+<BR><FONT SIZE=-2><A HREF="#koniec openssl.cnf">je¶li nie chce Ci siê tego
+czytaæ to skocz na koniec konfiga</A></FONT>
+
+<P><I>#</I>
+<BR><I># OpenSSL example configuration file.</I>
+<BR><I># This is mostly being used for generation of certificate requests.</I>
+<BR><I>#</I>
+<BR><I>&nbsp;</I>
+<BR><I>RANDFILE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= $ENV::HOME/.rnd</I>
+<BR><I>oid_file&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= $ENV::HOME/.oid</I>
+<BR><I>oid_section&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= new_oids</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ new_oids ]</I>
+<BR><I>&nbsp;</I>
+<BR><I># We can add new OIDs in here for use by 'ca' and 'req'.</I>
+<BR><I># Add a simple OID like this:</I>
+<BR><I># testoid1=1.2.3.4</I>
+<BR><I># Or use config file substitution like this:</I>
+<BR><I># testoid2=${testoid1}.5.6</I>
+<BR><I>&nbsp;</I>
+<BR><I>####################################################################</I>
+<BR><I>[ ca ]</I>
+<BR><I>default_ca&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = CA_default&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# The default ca section</I>
+<BR><I>&nbsp;</I>
+<BR><I>####################################################################</I>
+<BR><I>[ CA_default ]</I>
+<BR><I>&nbsp;</I>
+<BR><I>dir&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= ./demoCA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where everything is kept</I>
+<BR><I>certs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= $dir/certs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where the issued certs are kept</I>
+<BR><I>crl_dir&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/crl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where the issued crl are kept</I>
+<BR><I>database&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/index.txt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# database index file.</I>
+<BR><I>new_certs_dir&nbsp;&nbsp; = $dir/newcerts&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# default place for new certs.</I>
+<BR><I>&nbsp;</I>
+<BR><I>certificate&nbsp;&nbsp;&nbsp;&nbsp; = $dir/cacert.pem&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# The CA certificate</I>
+<BR><I>serial&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/serial&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# The current serial number</I>
+<BR><I>crl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= $dir/crl.pem&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #
+The current CRL</I>
+<BR><I>private_key&nbsp;&nbsp;&nbsp;&nbsp; = $dir/private/cakey.pem# The
+private key</I>
+<BR><I>RANDFILE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/private/.rand&nbsp;&nbsp;&nbsp;
+# private random number file</I>
+<BR><I>&nbsp;</I>
+<BR><I>x509_extensions = usr_cert&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# The extensions to add to the cert</I>
+<BR><I>crl_extensions&nbsp; = crl_ext&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Extensions to add to CRL</I>
+<BR><I>default_days&nbsp;&nbsp;&nbsp; = 365&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# how long to certify for</I>
+<BR><I>default_crl_days= 30&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# how long before next CRL</I>
+<BR><I>default_md&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = md5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# which md to use.</I>
+<BR><I>preserve&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# keep passed DN ordering</I>
+<BR><I>&nbsp;</I>
+<BR><I># A few difference way of specifying how similar the request should
+look</I>
+<BR><I># For type CA, the listed attributes must be the same, and the optional</I>
+<BR><I># and supplied fields are just that :-)</I>
+<BR><I>policy&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = policy_match</I>
+<BR><I># For the CA policy</I>
+<BR><I>[ policy_match ]</I>
+<BR><I>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= match</I>
+<BR><I>stateOrProvinceName&nbsp;&nbsp;&nbsp;&nbsp; = match</I>
+<BR><I>organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = match</I>
+<BR><I>organizationalUnitName&nbsp; = optional</I>
+<BR><I>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= supplied</I>
+<BR><I>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= optional</I>
+<BR><I>&nbsp;</I>
+<BR><I># For the 'anything' policy</I>
+<BR><I># At this point in time, you must list all acceptable 'object'</I>
+<BR><I># types.</I>
+<BR><I>[ policy_anything ]</I>
+<BR><I>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= optional</I>
+<BR><I>stateOrProvinceName&nbsp;&nbsp;&nbsp;&nbsp; = optional</I>
+<BR><I>localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= optional</I>
+<BR><I>organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = optional</I>
+<BR><I>organizationalUnitName&nbsp; = optional</I>
+<BR><I>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= supplied</I>
+<BR><I>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= optional</I>
+<BR><I>&nbsp;</I>
+<BR><I>####################################################################</I>
+<BR><A NAME="req"></A><I>[ req ]</I>
+<BR><I>default_bits&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= <FONT COLOR="#FF0000">1024</FONT></I>
+<BR><I>default_keyfile&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= privkey.pem</I>
+<BR><I>distinguished_name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = req_distinguished_name</I>
+<BR><I>attributes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= req_attributes</I>
+<BR><I>x509_extensions = v3_ca # The extensions to add to the self signed
+cert</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ req_distinguished_name ]</I>
+<BR><I>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Country Name (2 letter code)</I>
+<BR><I>countryName_default&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= <FONT COLOR="#FF0000">PL</FONT></I>
+<BR><I>countryName_min&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= 2</I>
+<BR><I>countryName_max&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= 2</I>
+<BR><I>&nbsp;</I>
+<BR><I>stateOrProvinceName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= State i Prowincja</I>
+<BR><I>stateOrProvinceName_default&nbsp;&nbsp;&nbsp;&nbsp; = <FONT COLOR="#FF0000">State-Prowincja
+domyslna</FONT></I>
+<BR><I>localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Locality Name (eg, city)</I>
+<BR><I>localityName_default&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= <FONT COLOR="#FF0000">Lodz</FONT></I>
+<BR><I>&nbsp;</I>
+<BR><I>0.organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Organization Name (eg, company)</I>
+<BR><I>0.organizationName_default&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = <FONT COLOR="#FF0000">Nawza
+Organizacji</FONT></I>
+<BR><I>&nbsp;</I>
+<BR><I># we can do this but it is not needed normally :-)</I>
+<BR><I>#1.organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Second Organization Name (eg, company)</I>
+<BR><I>#1.organizationName_default&nbsp;&nbsp;&nbsp;&nbsp; = World Wide
+Web Pty Ltd</I>
+<BR><I>organizationalUnitName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Organizational Unit Name (eg, section)</I>
+<BR><I>organizationalUnitName_default&nbsp; = <FONT COLOR="#FF0000">Unit
+name domyslny</FONT></I>
+<BR><I>&nbsp;</I>
+<BR><I>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Common Name (eg, YOUR name)</I>
+<BR><I>commonName_max&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= 64</I>
+<BR><I>&nbsp;</I>
+<BR><I>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= Email Address</I>
+<BR><I>emailAddress_max&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= 40</I>
+<BR><I>&nbsp;</I>
+<BR><I># SET-ex3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= SET extension number 3</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ req_attributes ]</I>
+<BR><I>challengePassword&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= A challenge password</I>
+<BR><I>challengePassword_min&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = 4</I>
+<BR><I>challengePassword_max&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = 20</I>
+<BR><I>&nbsp;</I>
+<BR><I>unstructuredName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= An optional company name</I>
+<BR><I>&nbsp;</I>
+<BR><A NAME="usr_cert"></A><I>[ usr_cert ]</I>
+<BR><I>&nbsp;</I>
+<BR><I># These extensions are added when 'ca' signs a request.</I>
+<BR><I>&nbsp;</I>
+<BR><I># This goes against PKIX guidelines but some CAs do it and some
+software</I>
+<BR><I># requires this to avoid interpreting an end user certificate as
+a CA.</I>
+<BR><I>&nbsp;</I>
+<BR><I>basicConstraints=CA:FALSE</I>
+<BR><I>&nbsp;</I>
+<BR><I># Here are some examples of the usage of nsCertType. If it is omitted</I>
+<BR><I># the certificate can be used for anything *except* object signing.</I>
+<BR><I>&nbsp;</I>
+<BR><A NAME="server"></A><I># This is OK for an SSL server.</I>
+<BR><I><FONT COLOR="#006600">#nsCertType&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= server</FONT></I>
+<BR><I>&nbsp;</I>
+<BR><I># For an object signing certificate this would be used.</I>
+<BR><I>#nsCertType = objsign</I>
+<BR><I>&nbsp;</I>
+<BR><A NAME="klient"></A><I># For normal client use this is typical</I>
+<BR><I><FONT COLOR="#006600">nsCertType = client, email</FONT></I>
+<BR><I>&nbsp;</I>
+<BR><I># This is typical also</I>
+<BR><I>&nbsp;</I>
+<BR><I>keyUsage = nonRepudiation, digitalSignature, keyEncipherment</I>
+<BR><I>&nbsp;</I>
+<BR><I>nsComment&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= "<FONT COLOR="#FF0000">OpenSSL Generated Certificate</FONT>"</I>
+<BR><I>&nbsp;</I>
+<BR><I># PKIX recommendations</I>
+<BR><I>subjectKeyIdentifier=hash</I>
+<BR><I>authorityKeyIdentifier=keyid,issuer:always</I>
+<BR><I># Import the email address.</I>
+<BR><I>&nbsp;</I>
+<BR><I>subjectAltName=email:copy</I>
+<BR><I>&nbsp;</I>
+<BR><I># Copy subject details</I>
+<BR><I>&nbsp;</I>
+<BR><I>issuerAltName=issuer:copy</I>
+<BR><I>&nbsp;</I>
+<BR><I>#nsCaRevocationUrl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= http://www.domain.dom/ca-crl.pem</I>
+<BR><I>#nsBaseUrl</I>
+<BR><I>#nsRevocationUrl</I>
+<BR><I>#nsRenewalUrl</I>
+<BR><I>#nsCaPolicyUrl</I>
+<BR><I>#nsSslServerName</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ v3_ca]</I>
+<BR><I>&nbsp;</I>
+<BR><I># Extensions for a typical CA</I>
+<BR><I>&nbsp;</I>
+<BR><I># It's a CA certificate</I>
+<BR><I>basicConstraints = CA:true</I>
+<BR><I>&nbsp;</I>
+<BR><I># PKIX recommendation.</I>
+<BR><I>&nbsp;</I>
+<BR><I>subjectKeyIdentifier=hash</I>
+<BR><I>&nbsp;</I>
+<BR><I>authorityKeyIdentifier=keyid:always,issuer:always</I>
+<BR><I>&nbsp;</I>
+<BR><I># This is what PKIX recommends but some broken software chokes on
+critical</I>
+<BR><I># extensions.</I>
+<BR><I>#basicConstraints = critical,CA:true</I>
+<BR><I>&nbsp;</I>
+<BR><I># Key usage: again this should really be critical.</I>
+<BR><I>keyUsage = cRLSign, keyCertSign</I>
+<BR><I>&nbsp;</I>
+<BR><I># Some might want this also</I>
+<BR><I>nsCertType = sslCA, emailCA, objCA</I>
+<BR><I>&nbsp;</I>
+<BR><I># Include email address in subject alt name: another PKIX recommendation</I>
+<BR><I>subjectAltName=email:copy</I>
+<BR><I># Copy issuer details</I>
+<BR><I>issuerAltName=issuer:copy</I>
+<BR><I>&nbsp;</I>
+<BR><I># RAW DER hex encoding of an extension: beware experts only!</I>
+<BR><I># 1.2.3.5=RAW:02:03</I>
+<BR><I># You can even override a supported extension:</I>
+<BR><I># basicConstraints= critical, RAW:30:03:01:01:FF</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ crl_ext ]</I>
+<BR><I>&nbsp;</I>
+<BR><I># CRL extensions.</I>
+<BR><I># Only issuerAltName and authorityKeyIdentifier make any sense in
+a CRL.</I>
+
+<P><I>issuerAltName=issuer:copy</I>
+<BR><I>authorityKeyIdentifier=keyid:always,issuer:always</I>
+<BR>################################################################################
+<BR>########## koniec pliku openssl.cnf
+
+<P><A NAME="koniec openssl.cnf"></A>Jak widaæ zmiany s± praktycznie kosmetyczne.&nbsp;
+Nale¿y zwrócic jedynie uwagê na opcjê <A HREF="#req">default_bits</A> w
+sekcji req.
+<BR>W momencie generowania certyfikatu CA powinna mieæ ona warto¶æ 1024
+lub wiêcej, natomiast w trakcie tworzenia
+<BR>certyfikatów klienckich winno mieæ siê na uwadze wredn± cechê produktów
+M$ dostêpnych poza granicami USA.
+<BR>Nie s± one w stanie zaimportowaæ kluczy maj±cych wiêcej ni¿ 512 bitów.
+W takim przypadku default_bits nale¿y
+<BR>zmniejszyæ do tej warto¶ci. Je¶li chodzi o Netscapa konieczno¶æ taka
+nie wystêpuje, nawet gdy nie jest on
+<BR>patchowany przy pomocy <A HREF="http://www.fortify.net/">Fortify</A>.
+Jednak¿e klucz nie powinien byæ wiêkszy ni¿ 1024 bity.
+
+<P><B><FONT SIZE=+1>Generowanie certyfikatu CA</FONT></B>
+
+<P>Pierwszy± czynno¶ci± jak± nale¿y wykonaæ jest wygenerowanie certyfikatu
+CA czyli czego¶ czym bêd±
+<BR>podpiswane certyfikaty udostêpniane klientom. Uruchom rxvt lub co¶
+innego i wykonaj polecenie:
+
+<P><I>adas:~# <B>cd /usr/local/ssl/bin</B></I>
+<BR><I>adas:/usr/local/ssl/bin# <B>./CA.pl -newca</B></I>
+
+<P><I>CA certificate filename (or enter to create)</I>
+
+<P><I>Making CA certificate ...</I>
+<BR><I>Using configuration from /usr/local/ssl/lib/openssl.cnf</I>
+<BR><I>Generating a 1024 bit RSA private key</I>
+<BR><I>..+++++</I>
+<BR><I>....+++++</I>
+<BR><I>writing new private key to './demoCA/private/cakey.pem'</I>
+<BR><A NAME="pem_pass"></A><I><FONT COLOR="#009900">Enter PEM pass phrase:</FONT></I>
+<BR><I><FONT COLOR="#009900">Verifying password - Enter PEM pass phrase:</FONT></I>
+<BR><I>-----</I>
+<BR><I>You are about to be asked to enter information that will be incorporated</I>
+<BR><I>into your certificate request.</I>
+<BR><I>What you are about to enter is what is called a Distinguished Name
+or a DN.</I>
+<BR><I>There are quite a few fields but you can leave some blank</I>
+<BR><I>For some fields there will be a default value,</I>
+<BR><I>If you enter '.', the field will be left blank.</I>
+<BR><I>-----</I>
+<BR><I>Country Name (2 letter code) [PL]:</I>
+<BR><I>State i Prowincja [Kraina Bezrobotnych Szwaczek]:</I>
+<BR><I>Locality Name (eg, city) [Lodz]:</I>
+<BR><I>Organization Name (eg, company) [Instytut Badan Czarow i Magii]:</I>
+<BR><I>Organizational Unit Name (eg, section) [Komorka d/s Egzorcyzmow
+i Opentan]:</I>
+<BR><I>Common Name (eg, YOUR name) []:Adam Hernik</I>
+<BR><I>Email Address []:adas@infocentrum.com</I>
+
+<P><I>adas:/usr/local/ssl/bin#</I>
+
+<P>Skrypt CA.pl uruchomiony poraz pierwszy tworzy w /usr/local/ssl/bin
+katalog o nazwie demoCA w którym znajduje siê
+<BR>wygenerowany przed chwil± certyfikat publiczny <B>cacert.pem</B> (do³±czany
+pó¿niej do certyfikatów klienckich) oraz tajny
+<BR>zabezpieczony <A HREF="#pem_pass">has³em</A> klucz <B>cakey.pem</B>
+którym bêdziesz podpisywa³ certyfikaty wydawane u¿ytkownikom. Klucz i has³o
+<BR>oczywi¶cie nale¿y dobrze chroniæ i najlepiej jest gdy znajduje siê
+na serwerze tylko w momencie generowania certyfikatu.
+<BR>Ponowne uruchomienie CA.pl z parametrem -newca niszczy to co pracowicie
+stworzy³e¶ i generuje nowy klucz i certyfikat.
+<BR>&nbsp;
+
+<P><B><FONT SIZE=+1>Tworzenie certyfikatu dla stunnela i innych serwerów</FONT></B>
+<BR>&nbsp;
+
+<P>Zanim siê do tego zabierzesz powiniene¶ lekko zmodyfikowac skrypt <B>CA.pl</B>
+oraz plik konfiguracyjny <B>openssl.cnf</B>.
+<BR>Skopiuj je odpowiednio do plików <B>/usr/local/ssl/bin/CAserv.pl</B>
+i <B>/usr/local/ssl/lib/openssl_serv.cnf</B>.<B></B>
+<BR>Generowane certyfikaty domy¶lnie zabezpieczone s± has³em, w takim przypadku
+w momencie startu stunnela zawsze
+<BR>bêdziesz pytany o haslo zabezpieczaj±ce, co skutecznie uniemo¿liwi
+automatyczne uruchamianie programu w czasie
+<BR>bootowania&nbsp; serwera, czy te¿ przy próbie wystartowania go przez
+inetd. Nale¿y poprawiæ <B>linie 40</B> i <B>41</B> skryptu
+<BR><B>CAserv.pl</B> z
+
+<P><FONT COLOR="#006600">linia 40:</FONT>
+<BR><B>$REQ="openssl req <I>$SSLEAY_CONFIG</I>";</B>
+<BR>na
+<BR><B>$REQ="openssl req <FONT COLOR="#FF0000">-nodes -config /usr/local/ssl/lib/openssl_serv.cnf</FONT>";</B>
+
+<P><FONT COLOR="#006600">linia 41:</FONT>
+<BR><B>$CA="openssl ca <I>$SSLEAY_CONFIG</I>";</B>
+<BR>na
+<BR><B>$CA="openssl ca <FONT COLOR="#FF0000">-config /usr/local/ssl/lib/openssl_serv.cnf</FONT>";</B>
+<BR>&nbsp;
+
+<P>Natomiast w pliku <B>/usr/local/ssl/lib/openssl_serv.cnf </B>nalezy&nbsp;
+w sekcji <A HREF="#usr_cert">usr_cert</A> "zahashowaæ" linijkê
+<BR><A HREF="#klient">nsCertType = client, email</A>&nbsp; oraz "odhashowaæ"
+linijkê <A HREF="#server">nsCertType&nbsp;&nbsp; = server</A> . Je¶li tego
+nie zrobisz klient nie bêdzie
+<BR>poprawnie rozpoznawa³ typu certyfikatu. A teraz kolej na wygenerowanie
+"requestu" posy³anego zazwyczaj do CA.
+<BR>Bêd±c w katalogu /usr/local/ssl/bin wykonaj:
+
+<P><I>adas:/usr/local/ssl/bin# .<B>/CAserv.pl -newreq</B></I>
+<BR><I>Using configuration from /usr/local/ssl/lib/openssl_serv.cnf</I>
+<BR><I>Generating a 1024 bit RSA private key</I>
+<BR><I>..............................+++++</I>
+<BR><I>.........+++++</I>
+<BR><I>writing new private key to 'newreq.pem'</I>
+<BR><I>-----</I>
+<BR><I>You are about to be asked to enter information that will be incorporated</I>
+<BR><I>into your certificate request.</I>
+<BR><I>What you are about to enter is what is called a Distinguished Name
+or a DN.</I>
+<BR><I>There are quite a few fields but you can leave some blank</I>
+<BR><I>For some fields there will be a default value,</I>
+<BR><I>If you enter '.', the field will be left blank.</I>
+<BR><I>-----</I>
+<BR><I>Country Name (2 letter code) [PL]:</I>
+<BR><I>State i Prowincja [Kraina Bezrobotnych Szwaczek]:Kraina latajacych
+scyzorykow</I>
+<BR><I>Locality Name (eg, city) [Lodz]:Sielpia</I>
+<BR><I>Organization Name (eg, company) [Instytut Badan Czarow i Magii]:Bar
+Sloneczko</I>
+<BR><I>Organizational Unit Name (eg, section) [Komorka d/s Egzorcyzmow
+i Opentan]:Kuflownia</I>
+<BR><I><FONT COLOR="#FF0000">Common Name (eg, YOUR name) []:adas.pl</FONT></I>
+<BR><I>Email Address []:adas@adas.pl</I>
+
+<P><I>Please enter the following 'extra' attributes</I>
+<BR><I>to be sent with your certificate request</I>
+<BR><I>A challenge password []:</I>
+<BR><I>An optional company name []:</I>
+<BR><I>Request (and private key) is in newreq.pem</I>
+<BR><I>adas:/usr/local/ssl/bin#</I>
+
+<P>Polem o którym warto wspomnieæ jest "Common Name" (zaznaczone na czerwono).
+W trakcie generowania requestu
+<BR>nale¿y w tym miejscu wpisaæ <B>FQDN serwera</B> na którym bêdzie on
+u¿ywany. W przeciwnym wypadku w chwili
+<BR>po³±czenia klient bêdzie twierdzi³, ¿e certyfikat jakim przedstawia
+siê serwer nie nale¿y do niego. Unikniemy w ten
+<BR>sposób niepotrzebnego klikania. Kolejn± czynno¶ci± jest podpisanie
+wygenerowanego requestu. W katalogu
+<BR>/usr/local/ssl/bin wykonaj polecenie:
+
+<P><I>adas:/usr/local/ssl/bin# .<B>/CAserv.pl -sign</B></I>
+<BR><I>Using configuration from /usr/local/ssl/lib/openssl.cnf</I>
+<BR><I><FONT COLOR="#009900">Enter PEM pass phrase:</FONT></I>
+<BR><I>Check that the request matches the signature</I>
+<BR><I>Signature ok</I>
+<BR><I>The Subjects Distinguished Name is as follows</I>
+<BR><I>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+:PRINTABLE:'PL'</I>
+<BR><I>stateOrProvinceName&nbsp;&nbsp; :PRINTABLE:'Kraina latajacych scyzorykow'</I>
+<BR><I>localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+:PRINTABLE:'Sielpia'</I>
+<BR><I>organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :PRINTABLE:'Bar Sloneczko'</I>
+<BR><I>organizationalUnitName:PRINTABLE:'Kuflownia'</I>
+<BR><I>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+:PRINTABLE:'adas.pl'</I>
+<BR><I>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+:IA5STRING:'adas@adas.pl'</I>
+<BR><I>Certificate is to be certified until Mar 26 21:06:13 2000 GMT (365
+days)</I>
+<BR><I>Sign the certificate? [y/n]:y</I>
+<BR>&nbsp;
+
+<P><I>1 out of 1 certificate requests certified, commit? [y/n]y</I>
+<BR><I>Write out database with 1 new entries</I>
+<BR><I>Data Base Updated</I>
+<BR><I>Signed certificate is in newcert.pem</I>
+<BR><I>adas:/usr/local/ssl/bin#</I>
+
+<P>W trakcie podpisywania bêdziesz pytany o has³o zabezpieczaj±ce klucz
+prywatny CA (zaznaczone na zielono).
+<BR>Po tej operacji powiniene¶ w katalogu /usr/local/ssl/bin otrzymaæ 2
+pliki: <B>newcert.pem</B> oraz <B>newreq.pem</B>.
+<BR>Zanim zaczniesz ich u¿ywaæ musisz wykonaæ jeszcze jedn± operacje, a
+mianowicie z³orzyæ wszystko do kupy.
+<BR>Wykonujesz: <B>cat newcert.pem newreq.pem > httpds.pem</B> a nastêpnie
+poddajesz tak powsta³y certyfikat edycji.
+<BR>Nale¿y z pliku httpds.pem nale¿y usun±æ wszystkie niepotrzebne informacje
+tak by pozosta³ jedynie certyfikat oraz
+<BR>klucz prywatny. Po tej operacji plik httpds.pem powinien wygl±daæ mniej
+wiêcej tak:
+
+<P><I>issuer :/C=PL/ST=Kraina Bezrobotnych Szwaczek/L=Lodz/O=Instytut Badan
+Czarow i Magii/OU=Komorka d/s Egzorcyzmow i opentan/CN=Adam Hernik/Email=adas@infocentrum.com</I>
+<BR><I>subject:/C=PL/ST=Kraina latajacych scyzorykow/L=Sielpia/O=Bar Sloneczko/OU=Kuflownia/CN=adas.pl/</I>
+<BR><I>Email=adas@adas.pl</I>
+<BR><I>-----BEGIN CERTIFICATE-----</I>
+<BR><I>&nbsp;Tu s± magiczne dane</I>
+<BR><I>-----END CERTIFICATE-----</I>
+
+<P><I>-----BEGIN RSA PRIVATE KEY-----</I>
+<BR><I>&nbsp; I tu te¿ s± magiczne dane</I>
+<BR><I>-----END RSA PRIVATE KEY-----</I>
+
+<P>Spreparowany w ten sposób plik umieszczamy w katalogu /usr/local/ssl/certs
+i zajmujemy siê generowaniem dwu
+<BR>certyfikatów klienckich.
+<BR>&nbsp;
+
+<P><B><FONT SIZE=+1>Generowanie i importowanie certyfikatów klienckich
+do Netscape Communikatora.</FONT></B>
+<BR>&nbsp;
+<BR>Generalnie s± dwie metody tworzenia i importowania certyfikatów klienckich
+do Netscapa
+<BR><B>Sposób pierwszy:</B>
+<BR>Przy pomocy komendy <B>CA.pl -newreq</B> wygeneruj request a nastêpnie
+przy pomocy <B>CA.pl -sign</B> podpisz go.
+<BR>Pytanie o <I>challenge password</I> zignoruj. Kolejn± czynno¶ci± jest
+scalenie i podczyszczenie certyfikatu.
+<BR>W przypadku certyfikatu klienta wa¿ne jest podanie <B>prawid³owego
+adresu email</B> <B>!</B> Bez tego nie bêdzie mo¿na
+<BR>podpisywaæ i szyfrowaæ listów.&nbsp; Stwórz dwa certyfikaty. Bêd± one
+potrzebne do wyja¶nienia dzia³ania opcji -v 3
+<BR>programu stunnel. Zak³adam ¿e pierwszy certyfikat nale¿y do Jana Kowalskiego
+jan@ibczim.pl zachowany w
+<BR>pliku jan.pem a drugi do Genowefy Pigwy pigwa@scyzoryki.pl znajduj±cym
+siê w pliku pigwa.pem.&nbsp; Przed
+<BR>zaimportowaniem plików do Netscpea nale¿y przekonwertowaæ je z formatu
+PEM do PCKS12. Wykonuje siê to
+<BR>przy pomocy wspomnianego na pocz±tku programu <B>pcks12</B>. Aby przekonwertowaæ
+certyfikat Jan Kowalskiego,
+<BR>w katalogu w ktorym znajduje siê plik jan.pem wykonaj:
+<BR>&nbsp;
+
+<P><B>pkcs12 -export -name "Jan Kowalski jan@ibczim.pl" -in jan.pem -out
+jan.p12 -certfile /usr/local/ssl/bin/demoCA/cacert.pem</B>
+
+<P>(<FONT COLOR="#990000">jest to jedna linia !!!</FONT>)
+<BR>w wyniku czego powstanie plik jan.p12 który mo¿na zaimportowaæ do Netscapea.
+Bardzo wa¿n± opcj± jest
+<BR><B><I>-certfile /usr/local/ssl/bin/demoCA/cacert.pem</I></B>. Bez niej
+nie bêdzie mo¿na w prawid³owy sposób podpisywaæ listów.
+<BR>Prze³±cznik -certfile powoduje do³±czenie publicznego certyfikatu CA
+do certyfikatu klienta dziêki czemu Netscape
+<BR>jest wstanie "wyekstrachowaæ" certyfikat CA i dodaæ go do wewnêtrznej
+bazy CA. Wykonaj powy¿sz± operacjê tak¿e
+<BR>dla pigwy. Samo zaimportowanie certyfikatu jest bardzo proste wykonuje
+siê to klikaj±c w Netscape na
+
+<P><B>Security-> Yours -> Import a Certificate</B>
+
+<P>Po zaimportowaniu nale¿y w <B>Security -> Signers</B> zaznaczyæ nasz
+CA certyfikat a nastêpnie klikn±æ na przycisku Edit
+<BR>oraz "zaczekowaæ" opcje:
+
+<P><I>Accept this Certificate Authority for Certifying network sites</I>
+<BR><I>Accept this Certificate Authority for Certifying e-mail users</I>
+
+<P>Od tej pory nasz certyfikat bêdzie traktowany na równi z innymi, komercyjnymi.
+
+<P><B>Sposób drugi:</B>
+<BR>Polega on na wygenerowaniu i imporcie certyfikatu poprzez strone www.
+Wraz z stunnelem dostarczane s±
+<BR>przk³adowe strony (dwie) i skrypty (dwa).&nbsp; Skrypty nale¿y raczej
+traktowaæ jako wzorzec i ka¿dy powinien napisaæ
+<BR>swoje, bardziej bezpieczne. Pierwszym krokiem jest import certyfikatu
+CA. U¿ywa siê do tego strony <B>importCA.html</B>
+<BR>oraz skryptu <B>importCA.sh</B>. Sam skrypt wygl±da tak:
+
+<P><I>#!/bin/bash</I>
+
+<P><I>echo "Content-type: application/x-x509-ca-cert"</I>
+<BR><I>echo</I>
+<BR><I>cat <FONT COLOR="#CC0000">/var/lib/httpds/cgi-bin/<B>cacert.pem</B></FONT></I>
+
+<P>cacert.pem jest to oczywi¶cie certyfikat publiczny CA znajduj±cy siê
+w katalogu /usr/local/ssl/bin/demoCA
+<BR>który nale¿y przekopiowaæ do katalogu cgi-bin serwera httpd oraz nadaæ
+mu odpowiednie prawa dostêpu.
+<BR>Po zaimportowaniu certyfikatu CA nale¿y w Security->Signers zaznaczyæ
+do jakich celów bêdziemy uznawli
+<BR>go za wiarygodny. Do generowania certyfikatu klienta wykorzystamy pozosta³±
+strone i skrypt. Zanim do tego dojdzie
+<BR>nale¿y "dokonfigurowaæ" skrypt i stworzyæ potrzebne katalogi.&nbsp;
+W /tmp (lub w innym miejscu) nalezy stworzyæ
+<BR>katalog ssl a nastêpnie przekopiowaæ do niego katalog <B>/usr/local/bin/demoCA</B>
+oraz plik <B>openssl.cnf</B>.
+<BR>Jako ¿e skrypty domy¶lnie uruchamiane s± z prawami u¿ytkownika nobody
+nale¿y uczyniæ go&nbsp; wla¶cicielem
+<BR>katalogu /tmp/ssl i ca³ej jego zawarto¶ci. Kolejn± czynno¶ci± jest
+wygenerowanie pliku <B>.rnd</B>. W Linuxie robimy to
+<BR>tak:
+<BR><B>cat /dev/random > /tmp/ssl/.rnd</B>
+<BR>czekamy chwilkê tak by plik .rnd mia³ wielko¶æ oko³o 1024 B po czym
+w³a¶cicielem pliku robimy u¿ytkownika nobody.
+<BR>Teraz trzeba przekonfigurowaæ plik /tmp/ssl/openssl.cnf
+
+<P><I>#</I>
+<BR><I># OpenSSL example configuration file.</I>
+<BR><I># This is mostly being used for generation of certificate requests.</I>
+<BR><I>#</I>
+<BR><I>&nbsp;</I>
+<BR><I><FONT COLOR="#FF0000">RANDFILE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= /tmp/ssl/.rnd</FONT></I>
+<BR><I>#oid_file&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= /tmp/ssl/.oid</I>
+<BR><I>oid_section&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= new_oids</I>
+<BR><I>&nbsp;</I>
+<BR><I>[ new_oids ]</I>
+<BR><I>&nbsp;</I>
+<BR><I># We can add new OIDs in here for use by 'ca' and 'req'.</I>
+<BR><I># Add a simple OID like this:</I>
+<BR><I># testoid1=1.2.3.4</I>
+<BR><I># Or use config file substitution like this:</I>
+<BR><I># testoid2=${testoid1}.5.6</I><I></I>
+
+<P><I>####################################################################</I>
+<BR><I>[ ca ]</I>
+<BR><I>default_ca&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = CA_default&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# The default ca section</I><I></I>
+
+<P><I>####################################################################</I>
+<BR><I>[ CA_default ]</I>
+<BR><I>&nbsp;</I>
+<BR><I><FONT COLOR="#FF0000">dir&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= /tmp/ssl/demoCA&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where everything is kept</FONT></I>
+<BR><I>certs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+= $dir/certs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where the issued certs are kept</I>
+<BR><I>crl_dir&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/crl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# Where the issued crl are kept</I>
+<BR><I>database&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; = $dir/index.txt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# database index file.</I>
+<BR><I>new_certs_dir&nbsp;&nbsp; = $dir/newcerts&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
+# default place for new certs.</I>
+<BR>&nbsp;
+<BR>Nale¿y zmieniæ opcje zaznaczone na czerwono. Ostatni± czynno¶ci± jest
+sprawdzenie i ewentualne poprawienie
+<BR>strony ca.html i skryptu ca.pl. W pliku ca.html nalezy wpisaæ poprawn±
+nazwê serwera na którym znajduje siê
+<BR>skrypt ca.pl czyli linijkê <B>&lt;FORM ACTION="<FONT COLOR="#FF0000">http://localhost/cgi-bin/ca.pl</FONT>"
+METHOD=POST></B>. W ca.pl
+<BR>nale¿y skontrolowaæ poprawno¶æ podanych ¶cie¿ek oraz wpisaæ has³o jakim
+zabezpieczony jest klucz prywatny CA
+<BR>(zmienna $certpass zaznaczona na czerwono).
+<BR>&nbsp;
+
+<P><I>#!/usr/bin/perl</I>
+<BR><I>#ca.pl</I><I></I>
+
+<P><I>$config&nbsp;&nbsp; = "/tmp/ssl/openssl.cnf";</I>
+<BR><I>$capath&nbsp;&nbsp; = "/usr/local/ssl/bin/openssl ca";</I>
+<BR><I><FONT COLOR="#FF0000">$certpass = "tu_jest_haslo";</FONT></I>
+<BR><I>$tempca&nbsp;&nbsp; = "/tmp/ssl/cli".rand 10000;</I>
+<BR><I>$tempout&nbsp; = "/tmp/ssl/certtmp".rand 10000;</I>
+<BR><I>$caout&nbsp;&nbsp;&nbsp; = "/tmp/ssl/certwynik.txt";</I>
+<BR><I>$CAcert&nbsp;&nbsp; = "/tmp/ssl/demoCA/cacert.pem";</I>
+<BR><I>...</I>
+<BR>&nbsp;
+
+<P>Po umieszczeniu tak przygotowanych stron i skryptów na serwerze bêdzie
+mo¿na generowaæ certyfikaty dla klientów.
+
+<P><B>Wady i zalety obydwu sposobów generowania i instalowania certyfikatów.</B>
+
+<P><A NAME="usuwanie"></A>Jak wynika z powy¿szego opisu bezpieczniejszym
+i polecanym przeze mnie jest sposób pierwszy. Jego powa¿n± wad±
+<BR>jest&nbsp; fakt ¿e cz³owiek generuj±cy certyfikaty znajduje siê w posiadaniu
+klucza prywatnego osoby wystêpuj±cej o
+<BR>certyfikat.&nbsp; <FONT COLOR="#FF0000">Oczywi¶cie uczciwy CA powinien
+skasowaæ go, zaraz po utworzeniu</FONT>. W takim wypadku metoda pierwsza
+<BR>spe³nia&nbsp; wszelkie wymogi. Sposób drugi prócz samych wad ma jedn±
+acz ogromn± zaletê. Mianowicie klucz prywatny
+<BR>klienta&nbsp; nigdy nie opuszcza jego komputera. Do wad mo¿na zaliczyæ
+fakt ¿e has³o zabezpieczaj±ce klucz prywatny CA
+<BR>znajduje siê na serwerze i to w dodatku w ¿aden sposób nie chronione.&nbsp;
+Kolejn± wad± jest generowanie kompletnych
+<BR>certyfikatów przez strone www, co mo¿e groziæ wykradzeniem klucza prywatnego.
+Rozwi±zaniem mo¿e byæ sk³adowanie
+<BR>requestów w bazie danych a nastpnie rêczna ich obróbka przez administratora.
+Reasumuj±c, sposób drugi nale¿y
+<BR>potraktowaæ jako demonstracje metody któr± mo¿na przeæwiczyæ przed
+napisaniem porz±dnych skryptów.
+<BR>&nbsp;<B><FONT SIZE=+1></FONT></B>
+
+<P><B><FONT SIZE=+1>Tajemniczy prze³±cznik -v 3 w stunnelu</FONT></B>
+
+<P>Stunnel posiada trzy tryby weryfikacji klienta.
+<BR>Pierwszy opcja <B><FONT SIZE=+1>-v 1</FONT></B> oznacza ¿e nale¿y spróbowaæ
+zweryfikowaæ osobê nawi±zuj±c± po³±czenie czyli uzyskaæ jej
+<BR>ceryfikat. Je¶li operacja ta siê nie powiedzie, mimo wszystko dostêp
+do serwera bêdzie zapewniony.
+<BR>Prze³±cznik <B><FONT SIZE=+1>-v 2</FONT></B> nakazuje stunnelowi zweryfikowaæ
+klienta. Je¶li u¿ytkownik nie posiada certyfikatu lub certyfikat
+<BR>jest niewa¿ny, niew³a¶ciwy czy te¿ nie posiadamy certyfikatu CA którym
+podpisany jest certyfikat klienta
+<BR><FONT SIZE=-2>(straszny jest ten jêzyk polski)</FONT> nawi±zanie po³±czenia
+z serwerem bêdzie niemo¿liwe. I wreszcie opcja <B><FONT SIZE=+1>-v 3</FONT></B>
+nakazuj±ca
+<BR>stunnelowi zweryfikowaæ klienta a tak¿e poszukaæ jego certyfikatu w
+naszej lokalnej bazie.
+<BR>Dzieki opcji -v 3 mo¿emy stworzyæ bardzo selektywny dostêp do us³ug
+oferowanych przez serwer, unikaj±c generowania du¿ych ilo¶ci certyfikatów.
+<FONT COLOR="#FF0000">Uwaga ogólna: do poprawnej weryfikacji klienta KONIECZNE
+jest posiadanie certyfikatu CA którym podpisany&nbsp; jest sprawdzany certyfikat</FONT>.
+Bez tego stunnel nie jest wstanie przeprowadziæ poprawnej autoryzacji klienta.
+Próba taka koñczy siê b³êdami "<B>VERIFY ERROR: self signed certificate
+for .....</B>" oraz "<B>SSL_accept: error:140890B1:SSL routines:</B> <B>SSL3_GET_CLIENT_CERTIFICATE:no
+certificate returned</B>". A teraz przyk³ad praktyczny: chcemy aby do https
+bêd±cym na <B>porcie 444</B> mia³y dostêp wszystkie osoby maj±ce certyfikaty
+natomiast
+<BR>do do https na <B>porcie 445</B> dostêp mia³ tylko Jan Kowalski. Pierwsz±
+czynno¶ci± jak± nale¿y wykonaæ jest skopiowanie
+<BR>certyfikatu CA do katalogu <B>/usr/local/ssl/certs</B> (default cert
+area), nastêpnie w tym katalogu nale¿y utworzyæ
+<BR>podkatalog o&nbsp; nazwie <B>mytrusted</B>, poczym skopiowaæ do niego
+certyfikat klienta czyli jan.pem. <A HREF="#usuwanie"><B>Uwaga</B>: z pliku
+jan.pem</A>
+<BR><A HREF="#usuwanie"><B>MUSISZ</B> usun±æ klucz prywatny</A> !!! Czyli&nbsp;
+to co siê znajduje miêdzy
+
+<P>-----BEGIN RSA PRIVATE KEY-----
+<BR>.......
+<BR>-----END RSA PRIVATE KEY-----
+
+<P>³±cznie z powy¿szymi liniami. Nastêpnie w katalogach <B>/usr/local/ssl/certs</B>
+i <B>/usr/local/ssl/certs/mytrusted</B> nale¿y
+<BR>wykonaæ polecenie
+<BR><B>/usr/local/ssl/bin/c_rehash ./</B>
+<BR>Teraz kolej na uruchomienie stunnela:
+<BR><B>stunnel -d 444 -r 80 -v 2</B>
+<BR>oraz
+<BR><B>stunnel -d 445 -r 80 -v 3</B>
+<BR>Netscapem nale¿y po³±czyæ sie z https://localhost:444/ a po pytaniu
+o certyfikat przedstawiæ certyfikat nale¿±cy
+<BR>do pigwy. Dostêp do serwera bêdzie zapewniony. Czynno¶c tê nale¿y powtórzyæ
+przedstawiaj±c siê za drugim razem
+<BR>certyfikatem Jana Kowalskiego. Po³±czenie tak¿e bêdzie zrealizowane.&nbsp;
+W przypadku https://localhost:445/ wej¶cie
+<BR>na serwer bêdzie zapewnione tylko po wylegitymowaniu siê certyfikatem
+Jana Kowalskiego. Po kazdej zmianie w
+<BR>katalogu /usr/local/ssl/certs/mytrusted nale¿y wykonaæ komendê c_rehash
+./ i zrestartowaæ stunnela.
+<BR>&nbsp;
+</BODY>
+</HTML>
diff --git a/doc/stunnel.8.in b/doc/stunnel.8.in
new file mode 100644
index 0000000..5a1de12
--- /dev/null
+++ b/doc/stunnel.8.in
@@ -0,0 +1,1253 @@
+.\" Automatically generated by Pod::Man 2.28 (Pod::Simple 3.28)
+.\"
+.\" Standard preamble:
+.\" ========================================================================
+.de Sp \" Vertical space (when we can't use .PP)
+.if t .sp .5v
+.if n .sp
+..
+.de Vb \" Begin verbatim text
+.ft CW
+.nf
+.ne \\$1
+..
+.de Ve \" End verbatim text
+.ft R
+.fi
+..
+.\" Set up some character translations and predefined strings.  \*(-- will
+.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
+.\" double quote, and \*(R" will give a right double quote.  \*(C+ will
+.\" give a nicer C++.  Capital omega is used to do unbreakable dashes and
+.\" therefore won't be available.  \*(C` and \*(C' expand to `' in nroff,
+.\" nothing in troff, for use with C<>.
+.tr \(*W-
+.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
+.ie n \{\
+.    ds -- \(*W-
+.    ds PI pi
+.    if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
+.    if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\"  diablo 12 pitch
+.    ds L" ""
+.    ds R" ""
+.    ds C` ""
+.    ds C' ""
+'br\}
+.el\{\
+.    ds -- \|\(em\|
+.    ds PI \(*p
+.    ds L" ``
+.    ds R" ''
+.    ds C`
+.    ds C'
+'br\}
+.\"
+.\" Escape single quotes in literal strings from groff's Unicode transform.
+.ie \n(.g .ds Aq \(aq
+.el       .ds Aq '
+.\"
+.\" If the F register is turned on, we'll generate index entries on stderr for
+.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
+.\" entries marked with X<> in POD.  Of course, you'll have to process the
+.\" output yourself in some meaningful fashion.
+.\"
+.\" Avoid warning from groff about undefined register 'F'.
+.de IX
+..
+.nr rF 0
+.if \n(.g .if rF .nr rF 1
+.if (\n(rF:(\n(.g==0)) \{
+.    if \nF \{
+.        de IX
+.        tm Index:\\$1\t\\n%\t"\\$2"
+..
+.        if !\nF==2 \{
+.            nr % 0
+.            nr F 2
+.        \}
+.    \}
+.\}
+.rr rF
+.\" ========================================================================
+.\"
+.IX Title "stunnel 8"
+.TH stunnel 8 "2015.07.27" "5.22" "stunnel TLS Proxy"
+.\" For nroff, turn off justification.  Always turn off hyphenation; it makes
+.\" way too many mistakes in technical documents.
+.if n .ad l
+.nh
+.SH "NAME"
+stunnel \- TLS offloading and load\-balancing proxy
+.SH "SYNOPSIS"
+.IX Header "SYNOPSIS"
+.IP "\fBUnix:\fR" 4
+.IX Item "Unix:"
+\&\fBstunnel\fR [\s-1FILE\s0] | \-fd N | \-help | \-version | \-sockets | \-options
+.IP "\fB\s-1WIN32:\s0\fR" 4
+.IX Item "WIN32:"
+\&\fBstunnel\fR [ [ \-install | \-uninstall | \-start | \-stop |
+    \-reload | \-reopen | \-exit ] [\-quiet] [\s-1FILE\s0] ] |
+    \-help | \-version | \-sockets | \-options
+.SH "DESCRIPTION"
+.IX Header "DESCRIPTION"
+The \fBstunnel\fR program is designed to work as \fI\s-1SSL\s0\fR encryption wrapper 
+between remote clients and local (\fIinetd\fR\-startable) or remote
+servers. The concept is that having non-SSL aware daemons running on
+your system you can easily set them up to communicate with clients over
+secure \s-1SSL\s0 channels.
+.PP
+\&\fBstunnel\fR can be used to add \s-1SSL\s0 functionality to commonly used \fIInetd\fR
+daemons like \s-1POP\-2, POP\-3,\s0 and \s-1IMAP\s0 servers, to standalone daemons like
+\&\s-1NNTP, SMTP\s0 and \s-1HTTP,\s0 and in tunneling \s-1PPP\s0 over network sockets without
+changes to the source code.
+.PP
+This product includes cryptographic software written by
+Eric Young (eay@cryptsoft.com)
+.SH "OPTIONS"
+.IX Header "OPTIONS"
+.IP "\fB\s-1FILE\s0\fR" 4
+.IX Item "FILE"
+Use specified configuration file
+.IP "\fB\-fd N\fR (Unix only)" 4
+.IX Item "-fd N (Unix only)"
+Read the config file from specified file descriptor
+.IP "\fB\-help\fR" 4
+.IX Item "-help"
+Print \fBstunnel\fR help menu
+.IP "\fB\-version\fR" 4
+.IX Item "-version"
+Print \fBstunnel\fR version and compile time defaults
+.IP "\fB\-sockets\fR" 4
+.IX Item "-sockets"
+Print default socket options
+.IP "\fB\-options\fR" 4
+.IX Item "-options"
+Print supported \s-1SSL\s0 options
+.IP "\fB\-install\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-install (Windows NT and later only)"
+Install \s-1NT\s0 Service
+.IP "\fB\-uninstall\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-uninstall (Windows NT and later only)"
+Uninstall \s-1NT\s0 Service
+.IP "\fB\-start\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-start (Windows NT and later only)"
+Start \s-1NT\s0 Service
+.IP "\fB\-stop\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-stop (Windows NT and later only)"
+Stop \s-1NT\s0 Service
+.IP "\fB\-reload\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-reload (Windows NT and later only)"
+Reload the configuration file of the running \s-1NT\s0 Service
+.IP "\fB\-reopen\fR (Windows \s-1NT\s0 and later only)" 4
+.IX Item "-reopen (Windows NT and later only)"
+Reopen the log file of the running \s-1NT\s0 Service
+.IP "\fB\-exit\fR (Win32 only)" 4
+.IX Item "-exit (Win32 only)"
+Exit an already started stunnel
+.IP "\fB\-quiet\fR (Win32 only)" 4
+.IX Item "-quiet (Win32 only)"
+Don't display any message boxes
+.SH "CONFIGURATION FILE"
+.IX Header "CONFIGURATION FILE"
+Each line of the configuration file can be either:
+.IP "\(bu" 4
+An empty line (ignored).
+.IP "\(bu" 4
+A comment starting with ';' (ignored).
+.IP "\(bu" 4
+An 'option_name = option_value' pair.
+.IP "\(bu" 4
+\&'[service_name]' indicating a start of a service definition.
+.PP
+An address parameter of an option may be either:
+.IP "\(bu" 4
+A port number.
+.IP "\(bu" 4
+A colon-separated pair of \s-1IP\s0 address (either IPv4, IPv6, or domain name) and port number.
+.IP "\(bu" 4
+A Unix socket path (Unix only).
+.SS "\s-1GLOBAL OPTIONS\s0"
+.IX Subsection "GLOBAL OPTIONS"
+.IP "\fBchroot\fR = \s-1DIRECTORY \s0(Unix only)" 4
+.IX Item "chroot = DIRECTORY (Unix only)"
+directory to chroot \fBstunnel\fR process
+.Sp
+\&\fBchroot\fR keeps \fBstunnel\fR in a chrooted jail.  \fICApath\fR, \fICRLpath\fR, \fIpid\fR
+and \fIexec\fR are located inside the jail and the patches have to be relative
+to the directory specified with \fBchroot\fR.
+.Sp
+Several functions of the operating system also need their files to be located within the chroot jail, e.g.:
+.RS 4
+.IP "\(bu" 4
+Delayed resolver typically needs /etc/nsswitch.conf and /etc/resolv.conf.
+.IP "\(bu" 4
+Local time in log files needs /etc/timezone.
+.IP "\(bu" 4
+Some other functions may need devices, e.g. /dev/zero or /dev/null.
+.RE
+.RS 4
+.RE
+.IP "\fBcompression\fR = deflate | zlib" 4
+.IX Item "compression = deflate | zlib"
+select data compression algorithm
+.Sp
+default: no compression
+.Sp
+deflate is the standard compression method as described in \s-1RFC 1951.\s0
+.Sp
+zlib compression of \fBOpenSSL 0.9.8\fR or above is not backward compatible with
+\&\fBOpenSSL 0.9.7\fR.
+.IP "\fBdebug\fR = [\s-1FACILITY.\s0]LEVEL" 4
+.IX Item "debug = [FACILITY.]LEVEL"
+debugging level
+.Sp
+Level is one of the syslog level names or numbers
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6), or debug (7).  All logs for the specified level and
+all levels numerically less than it will be shown.  Use \fIdebug = debug\fR or
+\&\fIdebug = 7\fR for greatest debugging output.  The default is notice (5).
+.Sp
+The syslog facility 'daemon' will be used unless a facility name is supplied.
+(Facilities are not supported on Win32.)
+.Sp
+Case is ignored for both facilities and levels.
+.IP "\fB\s-1EGD\s0\fR = \s-1EGD_PATH \s0(Unix only)" 4
+.IX Item "EGD = EGD_PATH (Unix only)"
+path to Entropy Gathering Daemon socket
+.Sp
+Entropy Gathering Daemon socket to use to feed the \fBOpenSSL\fR random number
+generator.  (Available only if compiled with \fBOpenSSL 0.9.5a\fR or higher)
+.IP "\fBengine\fR = auto | \s-1ENGINE_ID\s0" 4
+.IX Item "engine = auto | ENGINE_ID"
+select hardware engine
+.Sp
+default: software-only cryptography
+.Sp
+Here is an example of advanced engine configuration to read the private key from an
+OpenSC engine
+.Sp
+.Vb 7
+\&    engine=dynamic
+\&    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+\&    engineCtrl=ID:pkcs11
+\&    engineCtrl=LIST_ADD:1
+\&    engineCtrl=LOAD
+\&    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc\-pkcs11.so
+\&    engineCtrl=INIT
+\&
+\&    [service]
+\&    engineNum=1
+\&    key=id_45
+.Ve
+.IP "\fBengineCtrl\fR = COMMAND[:PARAMETER]" 4
+.IX Item "engineCtrl = COMMAND[:PARAMETER]"
+control hardware engine
+.Sp
+Special commands \*(L"\s-1LOAD\*(R"\s0 and \*(L"\s-1INIT\*(R"\s0 can be used to load and initialize the
+engine cryptogaphic module.
+.IP "\fBengineDefault\fR = \s-1TASK_LIST\s0" 4
+.IX Item "engineDefault = TASK_LIST"
+set OpenSSL tasks delegated to the current engine
+.Sp
+The parameter specifies a comma-separated list of task to be delegated to the
+current engine.
+.Sp
+The following tasks may be available, if supported by the engine: \s-1ALL, RSA,
+DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.\s0
+.IP "\fBfips\fR = yes | no" 4
+.IX Item "fips = yes | no"
+Enable or disable \s-1FIPS 140\-2\s0 mode.
+.Sp
+This option allows you to disable entering \s-1FIPS\s0 mode if \fBstunnel\fR was compiled
+with \s-1FIPS 140\-2\s0 support.
+.Sp
+default: no (since version 5.00)
+.IP "\fBforeground\fR = yes | no (Unix only)" 4
+.IX Item "foreground = yes | no (Unix only)"
+foreground mode
+.Sp
+Stay in foreground (don't fork) and log to stderr
+instead of via syslog (unless \fIoutput\fR is specified).
+.Sp
+default: background in daemon mode
+.IP "\fBiconActive\fR = \s-1ICON_FILE \s0(\s-1GUI\s0 only)" 4
+.IX Item "iconActive = ICON_FILE (GUI only)"
+\&\s-1GUI\s0 icon to be displayed when there are established connections
+.Sp
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+.IP "\fBiconError\fR = \s-1ICON_FILE \s0(\s-1GUI\s0 only)" 4
+.IX Item "iconError = ICON_FILE (GUI only)"
+\&\s-1GUI\s0 icon to be displayed when no valid configuration is loaded
+.Sp
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+.IP "\fBiconIdle\fR = \s-1ICON_FILE \s0(\s-1GUI\s0 only)" 4
+.IX Item "iconIdle = ICON_FILE (GUI only)"
+\&\s-1GUI\s0 icon to be displayed when there are no established connections
+.Sp
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+.IP "\fBlog\fR = append | overwrite" 4
+.IX Item "log = append | overwrite"
+log file handling
+.Sp
+This option allows you to choose whether the log file (specified with the \fIoutput\fR
+option) is appended or overwritten when opened or re-opened.
+.Sp
+default: append
+.IP "\fBoutput\fR = \s-1FILE\s0" 4
+.IX Item "output = FILE"
+append log messages to a file
+.Sp
+/dev/stdout device can be used to send log messages to the standard
+output (for example to log them with daemontools splogger).
+.IP "\fBpid\fR = \s-1FILE \s0(Unix only)" 4
+.IX Item "pid = FILE (Unix only)"
+pid file location
+.Sp
+If the argument is empty, then no pid file will be created.
+.Sp
+\&\fIpid\fR path is relative to the \fIchroot\fR directory if specified.
+.IP "\fBRNDbytes\fR = \s-1BYTES\s0" 4
+.IX Item "RNDbytes = BYTES"
+bytes to read from random seed files
+.Sp
+Number of bytes of data read from random seed files.  With \s-1SSL\s0 versions less
+than \fB0.9.5a\fR, also determines how many bytes of data are considered
+sufficient to seed the \s-1PRNG. \s0 More recent \fBOpenSSL\fR versions have a builtin
+function to determine when sufficient randomness is available.
+.IP "\fBRNDfile\fR = \s-1FILE\s0" 4
+.IX Item "RNDfile = FILE"
+path to file with random seed data
+.Sp
+The \s-1SSL\s0 library will use data from this file first to seed the random
+number generator.
+.IP "\fBRNDoverwrite\fR = yes | no" 4
+.IX Item "RNDoverwrite = yes | no"
+overwrite the random seed files with new random data
+.Sp
+default: yes
+.IP "\fBservice\fR = \s-1SERVICE \s0(Unix only)" 4
+.IX Item "service = SERVICE (Unix only)"
+stunnel service name
+.Sp
+The specified service name is used for syslog and as the \fIinetd\fR mode service
+name for \s-1TCP\s0 Wrappers.  While this option can technically be specified in the
+service sections, it is only useful in global options.
+.Sp
+default: stunnel
+.IP "\fBsetgid\fR = \s-1GROUP \s0(Unix only)" 4
+.IX Item "setgid = GROUP (Unix only)"
+\&\fIsetgid()\fR to the specified group in daemon mode and clear all other groups
+.IP "\fBsetuid\fR = \s-1USER \s0(Unix only)" 4
+.IX Item "setuid = USER (Unix only)"
+\&\fIsetuid()\fR to the specified user in daemon mode
+.IP "\fBsocket\fR = a|l|r:OPTION=VALUE[:VALUE]" 4
+.IX Item "socket = a|l|r:OPTION=VALUE[:VALUE]"
+Set an option on the accept/local/remote socket
+.Sp
+The values for the linger option are l_onof:l_linger.
+The values for the time are tv_sec:tv_usec.
+.Sp
+Examples:
+.Sp
+.Vb 9
+\&    socket = l:SO_LINGER=1:60
+\&        set one minute timeout for closing local socket
+\&    socket = r:SO_OOBINLINE=yes
+\&        place out\-of\-band data directly into the
+\&        receive data stream for remote sockets
+\&    socket = a:SO_REUSEADDR=no
+\&        disable address reuse (enabled by default)
+\&    socket = a:SO_BINDTODEVICE=lo
+\&        only accept connections on loopback interface
+.Ve
+.IP "\fBsyslog\fR = yes | no (Unix only)" 4
+.IX Item "syslog = yes | no (Unix only)"
+enable logging via syslog
+.Sp
+default: yes
+.IP "\fBtaskbar\fR = yes | no (\s-1WIN32\s0 only)" 4
+.IX Item "taskbar = yes | no (WIN32 only)"
+enable the taskbar icon
+.Sp
+default: yes
+.SS "SERVICE-LEVEL \s-1OPTIONS\s0"
+.IX Subsection "SERVICE-LEVEL OPTIONS"
+Each configuration section begins with a service name in square brackets.
+The service name is used for libwrap (\s-1TCP\s0 Wrappers) access control and lets
+you distinguish \fBstunnel\fR services in your log files.
+.PP
+Note that if you wish to run \fBstunnel\fR in \fIinetd\fR mode (where it
+is provided a network socket by a server such as \fIinetd\fR, \fIxinetd\fR,
+or \fItcpserver\fR) then you should read the section entitled \fI\s-1INETD MODE\s0\fR
+below.
+.IP "\fBaccept\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "accept = [HOST:]PORT"
+accept connections on specified address
+.Sp
+If no host specified, defaults to all IPv4 addresses for the local host.
+.Sp
+To listen on all IPv6 addresses use:
+.Sp
+.Vb 1
+\&    accept = :::PORT
+.Ve
+.IP "\fBCApath\fR = \s-1DIRECTORY\s0" 4
+.IX Item "CApath = DIRECTORY"
+Certificate Authority directory
+.Sp
+This is the directory in which \fBstunnel\fR will look for certificates when using
+the \fIverify\fR option.  Note that the certificates in this directory should be named
+\&\s-1XXXXXXXX.0\s0 where \s-1XXXXXXXX\s0 is the hash value of the \s-1DER\s0 encoded subject of the
+cert.
+.Sp
+The hash algorithm has been changed in \fBOpenSSL 1.0.0\fR.  It is required to
+c_rehash the directory on upgrade from \fBOpenSSL 0.x.x\fR to \fBOpenSSL 1.x.x\fR.
+.Sp
+\&\fICApath\fR path is relative to the \fIchroot\fR directory if specified.
+.IP "\fBCAfile\fR = \s-1CERT_FILE\s0" 4
+.IX Item "CAfile = CERT_FILE"
+Certificate Authority file
+.Sp
+This file contains multiple \s-1CA\s0 certificates, used with the \fIverify\fR option.
+.IP "\fBcert\fR = \s-1PEM_FILE\s0" 4
+.IX Item "cert = PEM_FILE"
+certificate chain \s-1PEM\s0 file name
+.Sp
+The certificates must be in \s-1PEM\s0 format, and must be from the
+actual server/client certificate to the self-signed root \s-1CA\s0 certificate.
+.Sp
+A certificate is required in server mode, and optional in client mode.
+.IP "\fBcheckEmail\fR = \s-1EMAIL\s0" 4
+.IX Item "checkEmail = EMAIL"
+email address of the peer certificate subject
+.Sp
+Multiple \fIcheckEmail\fR options are allowed in a single service section.
+Certificates are accepted if no \fIcheckEmail\fR option was specified, or the
+email address of the peer certificate matches any of the email addresses
+specified with \fIcheckEmail\fR.
+.IP "\fBcheckHost\fR = \s-1HOST\s0" 4
+.IX Item "checkHost = HOST"
+host of the peer certificate subject
+.Sp
+Multiple \fIcheckHost\fR options are allowed in a single service section.
+Certificates are accepted if no \fIcheckHost\fR option was specified, or the host
+name of the peer certificate matches any of the hosts specified with
+\&\fIcheckHost\fR.
+.IP "\fBcheckIP\fR = \s-1IP\s0" 4
+.IX Item "checkIP = IP"
+\&\s-1IP\s0 address of the peer certificate subject
+.Sp
+Multiple \fIcheckIP\fR options are allowed in a single service section.
+Certificates are accepted if no \fIcheckIP\fR option was specified, or the \s-1IP\s0
+address of the peer certificate matches any of the \s-1IP\s0 addresses specified with
+\&\fIcheckIP\fR.
+.IP "\fBciphers\fR = \s-1CIPHER_LIST\s0" 4
+.IX Item "ciphers = CIPHER_LIST"
+Select permitted \s-1SSL\s0 ciphers
+.Sp
+A colon-delimited list of the ciphers to allow in the \s-1SSL\s0 connection,
+for example \s-1DES\-CBC3\-SHA:IDEA\-CBC\-MD5.\s0
+.IP "\fBclient\fR = yes | no" 4
+.IX Item "client = yes | no"
+client mode (remote service uses \s-1SSL\s0)
+.Sp
+default: no (server mode)
+.IP "\fBconnect\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "connect = [HOST:]PORT"
+connect to a remote address
+.Sp
+If no host is specified, the host defaults to localhost.
+.Sp
+Multiple \fIconnect\fR options are allowed in a single service section.
+.Sp
+If host resolves to multiple addresses and/or if multiple \fIconnect\fR
+options are specified, then the remote address is chosen using a
+round-robin algorithm.
+.IP "\fBCRLpath\fR = \s-1DIRECTORY\s0" 4
+.IX Item "CRLpath = DIRECTORY"
+Certificate Revocation Lists directory
+.Sp
+This is the directory in which \fBstunnel\fR will look for CRLs when
+using the \fIverify\fR option. Note that the CRLs in this directory should
+be named \s-1XXXXXXXX\s0.r0 where \s-1XXXXXXXX\s0 is the hash value of the \s-1CRL.\s0
+.Sp
+The hash algorithm has been changed in \fBOpenSSL 1.0.0\fR.  It is required to
+c_rehash the directory on upgrade from \fBOpenSSL 0.x.x\fR to \fBOpenSSL 1.x.x\fR.
+.Sp
+\&\fICRLpath\fR path is relative to the \fIchroot\fR directory if specified.
+.IP "\fBCRLfile\fR = \s-1CERT_FILE\s0" 4
+.IX Item "CRLfile = CERT_FILE"
+Certificate Revocation Lists file
+.Sp
+This file contains multiple CRLs, used with the \fIverify\fR option.
+.IP "\fBcurve\fR = \s-1NID\s0" 4
+.IX Item "curve = NID"
+specify \s-1ECDH\s0 curve name
+.Sp
+To get a list of supported curves use:
+.Sp
+.Vb 1
+\&    openssl ecparam \-list_curves
+.Ve
+.Sp
+default: prime256v1
+.IP "\fBlogId\fR = \s-1TYPE\s0" 4
+.IX Item "logId = TYPE"
+connection identifier type
+.Sp
+This identifier allows you to distinguish log entries generated for each of the
+connections.
+.Sp
+Currently supported types:
+.RS 4
+.IP "\fIsequential\fR" 4
+.IX Item "sequential"
+The numeric sequential identifier is only unique within a single instance of
+\&\fBstunnel\fR, but very compact.  It is most useful for manual log analysis.
+.IP "\fIunique\fR" 4
+.IX Item "unique"
+This alphanumeric identifier is globally unique, but longer than the sequential
+number.  It is most useful for automated log analysis.
+.IP "\fIthread\fR" 4
+.IX Item "thread"
+The operating system thread identifier is neither unique (even within a single
+instance of \fBstunnel\fR) nor short.  It is most useful for debugging software
+or configuration issues.
+.RE
+.RS 4
+.Sp
+default: sequential
+.RE
+.IP "\fBdebug\fR = \s-1LEVEL\s0" 4
+.IX Item "debug = LEVEL"
+debugging level
+.Sp
+Level is a one of the syslog level names or numbers
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6), or debug (7).  All logs for the specified level and
+all levels numerically less than it will be shown.  Use \fIdebug = debug\fR or
+\&\fIdebug = 7\fR for greatest debugging output.  The default is notice (5).
+.IP "\fBdelay\fR = yes | no" 4
+.IX Item "delay = yes | no"
+delay \s-1DNS\s0 lookup for the \fIconnect\fR option
+.Sp
+This option is useful for dynamic \s-1DNS,\s0 or when \s-1DNS\s0 is not available during
+\&\fBstunnel\fR startup (road warrior \s-1VPN,\s0 dial-up configurations).
+.Sp
+Delayed resolver mode is automatically engaged when stunnel fails to resolve on
+startup any of the \fIconnect\fR targets for a service.
+.Sp
+Delayed resolver inflicts \fIfailover = prio\fR.
+.Sp
+default: no
+.IP "\fBengineId\fR = \s-1ENGINE_ID\s0" 4
+.IX Item "engineId = ENGINE_ID"
+select engine \s-1ID\s0 for the service
+.IP "\fBengineNum\fR = \s-1ENGINE_NUMBER\s0" 4
+.IX Item "engineNum = ENGINE_NUMBER"
+select engine number for the service
+.Sp
+The engines are numbered starting from 1.
+.IP "\fBexec\fR = \s-1EXECUTABLE_PATH\s0" 4
+.IX Item "exec = EXECUTABLE_PATH"
+execute a local inetd-type program
+.Sp
+\&\fIexec\fR path is relative to the \fIchroot\fR directory if specified.
+.Sp
+The following environmental variables are set on Unix platforms:
+\&\s-1REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.\s0
+.ie n .IP "\fBexecArgs\fR = $0 $1 $2 ..." 4
+.el .IP "\fBexecArgs\fR = \f(CW$0\fR \f(CW$1\fR \f(CW$2\fR ..." 4
+.IX Item "execArgs = $0 $1 $2 ..."
+arguments for \fIexec\fR including the program name ($0)
+.Sp
+Quoting is currently not supported.
+Arguments are separated with an arbitrary amount of whitespace.
+.IP "\fBfailover\fR = rr | prio" 4
+.IX Item "failover = rr | prio"
+Failover strategy for multiple \*(L"connect\*(R" targets.
+.Sp
+.Vb 2
+\&    rr (round robin) \- fair load distribution
+\&    prio (priority) \- use the order specified in config file
+.Ve
+.Sp
+default: rr
+.IP "\fBident\fR = \s-1USERNAME\s0" 4
+.IX Item "ident = USERNAME"
+use \s-1IDENT \s0(\s-1RFC 1413\s0) username checking
+.IP "\fBinclude\fR = \s-1DIRECTORY\s0" 4
+.IX Item "include = DIRECTORY"
+include all configuration file parts located in \s-1DIRECTORY\s0
+.Sp
+The files are included in the ascending alphabetical order of their names.
+.IP "\fBkey\fR = \s-1KEY_FILE\s0" 4
+.IX Item "key = KEY_FILE"
+private key for the certificate specified with \fIcert\fR option
+.Sp
+A private key is needed to authenticate the certificate owner.
+Since this file should be kept secret it should only be readable
+by its owner.  On Unix systems you can use the following command:
+.Sp
+.Vb 1
+\&    chmod 600 keyfile
+.Ve
+.Sp
+default: the value of the \fIcert\fR option
+.IP "\fBlibwrap\fR = yes | no" 4
+.IX Item "libwrap = yes | no"
+Enable or disable the use of /etc/hosts.allow and /etc/hosts.deny.
+.Sp
+default: no (since version 5.00)
+.IP "\fBlocal\fR = \s-1HOST\s0" 4
+.IX Item "local = HOST"
+By default, the \s-1IP\s0 address of the outgoing interface is used as the source for remote connections.
+Use this option to bind a static local \s-1IP\s0 address instead.
+.IP "\fBsni\fR = \s-1SERVICE:SERVER_PATTERN \s0(server mode)" 4
+.IX Item "sni = SERVICE:SERVER_PATTERN (server mode)"
+Use the service as a slave service (a name-based virtual server) for Server
+Name Indication \s-1TLS\s0 extension (\s-1RFC 3546\s0).
+.Sp
+\&\fIservice_name\fR specifies the master service that accepts client connections
+with the \fIaccept\fR option.  \fIserver_name_pattern\fR specifies the host name to be
+redirected.  The pattern may start with the '*' character, e.g. '*.example.com'.
+Multiple slave services are normally specified for a single master service.
+The \fIsni\fR option can also be specified more than once within a single slave
+service.
+.Sp
+This service, as well as the master service, may not be configured in client
+mode.
+.Sp
+The \fIconnect\fR option of the slave service is ignored when the \fIprotocol\fR option is
+specified, as \fIprotocol\fR connects to the remote host before \s-1TLS\s0 handshake.
+.Sp
+Libwrap checks (Unix only) are performed twice: with the master service name after
+\&\s-1TCP\s0 connection is accepted, and with the slave service name during the \s-1TLS\s0 handshake.
+.Sp
+The \fIsni\fR option is only available when compiled with \fBOpenSSL 1.0.0\fR and later.
+.IP "\fBsni\fR = \s-1SERVER \s0(client mode)" 4
+.IX Item "sni = SERVER (client mode)"
+Use the parameter as the value of \s-1TLS\s0 Server Name Indication (\s-1RFC 3546\s0)
+extension.
+.Sp
+The \fIsni\fR option is only available when compiled with \fBOpenSSL 1.0.0\fR and later.
+.IP "\fB\s-1OCSP\s0\fR = \s-1URL\s0" 4
+.IX Item "OCSP = URL"
+select \s-1OCSP\s0 server for certificate verification
+.IP "\fBOCSPaia\fR = yes | no" 4
+.IX Item "OCSPaia = yes | no"
+validate certificates with their \s-1AIA OCSP\s0 responders
+.Sp
+This option enables \fIstunnel\fR to validate certificates with the list of
+\&\s-1OCSP\s0 responder URLs retrieved from their \s-1AIA \s0(Authority Information Access)
+extension.
+.IP "\fBOCSPflag\fR = \s-1OCSP_FLAG\s0" 4
+.IX Item "OCSPflag = OCSP_FLAG"
+specify \s-1OCSP\s0 server flag
+.Sp
+Several \fIOCSPflag\fR can be used to specify multiple flags.
+.Sp
+currently supported flags: \s-1NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY,
+NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME\s0
+.IP "\fBoptions\fR = \s-1SSL_OPTIONS\s0" 4
+.IX Item "options = SSL_OPTIONS"
+\&\fBOpenSSL\fR library options
+.Sp
+The parameter is the \fBOpenSSL\fR option name as described in the
+\&\fI\fISSL_CTX_set_options\fI\|(3ssl)\fR manual, but without \fI\s-1SSL_OP_\s0\fR prefix.
+\&\fIstunnel \-options\fR lists the options found to be allowed in the
+current combination of \fIstunnel\fR and the \fIOpenSSL\fR library used
+to build it.
+.Sp
+Several \fIoptions\fR can be used to specify multiple options.
+An option name can be prepended with a dash (\*(L"\-\*(R") to disable the option.
+.Sp
+For example, for compatibility with the erroneous Eudora \s-1SSL\s0
+implementation, the following option can be used:
+.Sp
+.Vb 1
+\&    options = DONT_INSERT_EMPTY_FRAGMENTS
+.Ve
+.Sp
+default:
+.Sp
+.Vb 2
+\&    options = NO_SSLv2
+\&    options = NO_SSLv3
+.Ve
+.IP "\fBprotocol\fR = \s-1PROTO\s0" 4
+.IX Item "protocol = PROTO"
+application protocol to negotiate \s-1SSL\s0
+.Sp
+This option enables initial, protocol-specific negotiation of the \s-1SSL/TLS\s0
+encryption.
+The \fIprotocol\fR option should not be used with \s-1SSL\s0 encryption on a separate port.
+.Sp
+Currently supported protocols:
+.RS 4
+.IP "\fIcifs\fR" 4
+.IX Item "cifs"
+Proprietary (undocummented) extension of \s-1CIFS\s0 protocol implemented in Samba.
+Support for this extension was dropped in Samba 3.0.0.
+.IP "\fIconnect\fR" 4
+.IX Item "connect"
+Based on \s-1RFC 2817 \- \s0\fIUpgrading to \s-1TLS\s0 Within \s-1HTTP/1.1\s0\fR, section 5.2 \- \fIRequesting a Tunnel with \s-1CONNECT\s0\fR
+.Sp
+This protocol is only supported in client mode.
+.IP "\fIimap\fR" 4
+.IX Item "imap"
+Based on \s-1RFC 2595 \- \s0\fIUsing \s-1TLS\s0 with \s-1IMAP, POP3\s0 and \s-1ACAP\s0\fR
+.IP "\fInntp\fR" 4
+.IX Item "nntp"
+Based on \s-1RFC 4642 \- \s0\fIUsing Transport Layer Security (\s-1TLS\s0) with Network News Transfer Protocol (\s-1NNTP\s0)\fR
+.Sp
+This protocol is only supported in client mode.
+.IP "\fIpgsql\fR" 4
+.IX Item "pgsql"
+Based on
+\&\fIhttp://www.postgresql.org/docs/8.3/static/protocol\-flow.html#AEN73982\fR
+.IP "\fIpop3\fR" 4
+.IX Item "pop3"
+Based on \s-1RFC 2449 \- \s0\fI\s-1POP3\s0 Extension Mechanism\fR
+.IP "\fIproxy\fR" 4
+.IX Item "proxy"
+Haproxy client \s-1IP\s0 address
+\&\fIhttp://haproxy.1wt.eu/download/1.5/doc/proxy\-protocol.txt\fR
+.IP "\fIsmtp\fR" 4
+.IX Item "smtp"
+Based on \s-1RFC 2487 \- \s0\fI\s-1SMTP\s0 Service Extension for Secure \s-1SMTP\s0 over \s-1TLS\s0\fR
+.IP "\fIsocks\fR" 4
+.IX Item "socks"
+\&\s-1SOCKS\s0 versions 4, 4a, and 5 are supported.  The \s-1SOCKS\s0 protocol itself
+is encapsulated within \s-1SSL/TLS\s0 encryption layer to protect the final
+destination address.
+.Sp
+\&\fIhttp://www.openssh.com/txt/socks4.protocol\fR
+.Sp
+\&\fIhttp://www.openssh.com/txt/socks4a.protocol\fR
+.Sp
+The \s-1BIND\s0 command of the \s-1SOCKS\s0 protocol is not supported.
+The \s-1USERID\s0 parameter is ignored.
+.Sp
+See Examples section for sample configuration files for \s-1VPN\s0 based on \s-1SOCKS\s0
+encryption.
+.RE
+.RS 4
+.RE
+.IP "\fBprotocolAuthentication\fR = basic | ntlm" 4
+.IX Item "protocolAuthentication = basic | ntlm"
+authentication type for protocol negotiations
+.Sp
+Currently the authentication type only applies to the 'connect' protocol.
+.Sp
+default: basic
+.IP "\fBprotocolHost\fR = \s-1HOST:PORT\s0" 4
+.IX Item "protocolHost = HOST:PORT"
+destination address for protocol negotiations
+.Sp
+\&\fIprotocolHost\fR specifies the final \s-1SSL\s0 server to be connected to by the proxy,
+and not the proxy server directly connected by \fBstunnel\fR.
+The proxy server should be specified with the 'connect' option.
+.Sp
+Currently the protocol destination address only applies to 'connect' protocol.
+.IP "\fBprotocolPassword\fR = \s-1PASSWORD\s0" 4
+.IX Item "protocolPassword = PASSWORD"
+password for protocol negotiations
+.IP "\fBprotocolUsername\fR = \s-1USERNAME\s0" 4
+.IX Item "protocolUsername = USERNAME"
+username for protocol negotiations
+.IP "\fBPSKidentity\fR = \s-1IDENTITY\s0" 4
+.IX Item "PSKidentity = IDENTITY"
+\&\s-1PSK\s0 identity for the \s-1PSK\s0 client
+.Sp
+\&\fIPSKidentity\fR can be used on \fBstunnel\fR clients to select the \s-1PSK\s0 identity
+used for authentication.  This option is ignored in server sections.
+.Sp
+default: the first identity specified in the \fIPSKsecrets\fR file.
+.IP "\fBPSKsecrets\fR = \s-1FILE\s0" 4
+.IX Item "PSKsecrets = FILE"
+file with \s-1PSK\s0 identities and corresponding keys
+.Sp
+Each line of the file in the following format:
+.Sp
+.Vb 1
+\&    IDENTITY:KEY
+.Ve
+.Sp
+The key is required to be at least 20 characters long.
+The file should not be world-readable nor world-writable.
+.IP "\fBpty\fR = yes | no (Unix only)" 4
+.IX Item "pty = yes | no (Unix only)"
+allocate a pseudoterminal for 'exec' option
+.IP "\fBredirect\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "redirect = [HOST:]PORT"
+redirect \s-1SSL\s0 client connections on certificate-based authentication failures
+.Sp
+This option only works in server mode.
+Some protocol negotiations are also incompatible with the \fIredirect\fR option.
+.IP "\fBrenegotiation\fR = yes | no" 4
+.IX Item "renegotiation = yes | no"
+support \s-1SSL\s0 renegotiation
+.Sp
+Applications of the \s-1SSL\s0 renegotiation include some authentication scenarios,
+or re-keying long lasting connections.
+.Sp
+On the other hand this feature can facilitate a trivial CPU-exhaustion
+DoS attack:
+.Sp
+\&\fIhttp://vincent.bernat.im/en/blog/2011\-ssl\-dos\-mitigation.html\fR
+.Sp
+Please note that disabling \s-1SSL\s0 renegotiation does not fully mitigate
+this issue.
+.Sp
+default: yes (if supported by \fBOpenSSL\fR)
+.IP "\fBreset\fR = yes | no" 4
+.IX Item "reset = yes | no"
+attempt to use the \s-1TCP RST\s0 flag to indicate an error
+.Sp
+This option is not supported on some platforms.
+.Sp
+default: yes
+.IP "\fBretry\fR = yes | no" 4
+.IX Item "retry = yes | no"
+reconnect a connect+exec section after it's disconnected
+.Sp
+default: no
+.IP "\fBsessionCacheSize\fR = \s-1NUM_ENTRIES\s0" 4
+.IX Item "sessionCacheSize = NUM_ENTRIES"
+session cache size
+.Sp
+\&\fIsessionCacheSize\fR specifies the maximum number of the internal session cache
+entries.
+.Sp
+The value of 0 can be used for unlimited size.  It is not recommended
+for production use due to the risk of a memory exhaustion DoS attack.
+.IP "\fBsessionCacheTimeout\fR = \s-1TIMEOUT\s0" 4
+.IX Item "sessionCacheTimeout = TIMEOUT"
+session cache timeout
+.Sp
+This is the number of seconds to keep cached \s-1SSL\s0 sessions.
+.IP "\fBsessiond\fR = \s-1HOST:PORT\s0" 4
+.IX Item "sessiond = HOST:PORT"
+address of sessiond \s-1SSL\s0 cache server
+.IP "\fBsslVersion\fR = \s-1SSL_VERSION\s0" 4
+.IX Item "sslVersion = SSL_VERSION"
+select the \s-1SSL\s0 protocol version
+.Sp
+Supported values: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2
+.Sp
+Availability of specific protocols depends on the linked OpenSSL library.
+Older versions of OpenSSL do not support TLSv1.1 and TLSv1.2.
+Newer versions of OpenSSL do not support SSLv2.
+.Sp
+Obsolete SSLv2 and SSLv3 are currently disabled by default.
+See the \fBoptions\fR option documentation for details.
+.IP "\fBstack\fR = \s-1BYTES \s0(except for \s-1FORK\s0 model)" 4
+.IX Item "stack = BYTES (except for FORK model)"
+thread stack size
+.IP "\fBTIMEOUTbusy\fR = \s-1SECONDS\s0" 4
+.IX Item "TIMEOUTbusy = SECONDS"
+time to wait for expected data
+.IP "\fBTIMEOUTclose\fR = \s-1SECONDS\s0" 4
+.IX Item "TIMEOUTclose = SECONDS"
+time to wait for close_notify (set to 0 for buggy \s-1MSIE\s0)
+.IP "\fBTIMEOUTconnect\fR = \s-1SECONDS\s0" 4
+.IX Item "TIMEOUTconnect = SECONDS"
+time to wait to connect to a remote host
+.IP "\fBTIMEOUTidle\fR = \s-1SECONDS\s0" 4
+.IX Item "TIMEOUTidle = SECONDS"
+time to keep an idle connection
+.IP "\fBtransparent\fR = none | source | destination | both (Unix only)" 4
+.IX Item "transparent = none | source | destination | both (Unix only)"
+enable transparent proxy support on selected platforms
+.Sp
+Supported values:
+.RS 4
+.IP "\fInone\fR" 4
+.IX Item "none"
+Disable transparent proxy support.  This is the default.
+.IP "\fIsource\fR" 4
+.IX Item "source"
+Re-write the address to appear as if a wrapped daemon is connecting
+from the \s-1SSL\s0 client machine instead of the machine running \fBstunnel\fR.
+.Sp
+This option is currently available in:
+.RS 4
+.IP "Remote mode (\fIconnect\fR option) on \fILinux >=2.6.28\fR" 4
+.IX Item "Remote mode (connect option) on Linux >=2.6.28"
+This configuration requires \fBstunnel\fR to be executed as root and without
+the \fIsetuid\fR option.
+.Sp
+This configuration requires the following setup for iptables and routing
+(possibly in /etc/rc.local or equivalent file):
+.Sp
+.Vb 7
+\&    iptables \-t mangle \-N DIVERT
+\&    iptables \-t mangle \-A PREROUTING \-p tcp \-m socket \-j DIVERT
+\&    iptables \-t mangle \-A DIVERT \-j MARK \-\-set\-mark 1
+\&    iptables \-t mangle \-A DIVERT \-j ACCEPT
+\&    ip rule add fwmark 1 lookup 100
+\&    ip route add local 0.0.0.0/0 dev lo table 100
+\&    echo 0 >/proc/sys/net/ipv4/conf/lo/rp_filter
+.Ve
+.Sp
+\&\fBstunnel\fR must also to be executed as root and without the \fIsetuid\fR option.
+.IP "Remote mode (\fIconnect\fR option) on \fILinux 2.2.x\fR" 4
+.IX Item "Remote mode (connect option) on Linux 2.2.x"
+This configuration requires the kernel to be compiled with the \fItransparent proxy\fR
+option.
+Connected service must be installed on a separate host.
+Routing towards the clients has to go through the \fBstunnel\fR box.
+.Sp
+\&\fBstunnel\fR must also to be executed as root and without the \fIsetuid\fR option.
+.IP "Remote mode (\fIconnect\fR option) on \fIFreeBSD >=8.0\fR" 4
+.IX Item "Remote mode (connect option) on FreeBSD >=8.0"
+This configuration requires additional firewall and routing setup.
+\&\fBstunnel\fR must also to be executed as root and without the \fIsetuid\fR option.
+.IP "Local mode (\fIexec\fR option)" 4
+.IX Item "Local mode (exec option)"
+This configuration works by pre-loading the \fIlibstunnel.so\fR shared library.
+_RLD_LIST environment variable is used on Tru64, and \s-1LD_PRELOAD\s0 variable on
+other platforms.
+.RE
+.RS 4
+.RE
+.IP "\fIdestination\fR" 4
+.IX Item "destination"
+The original destination is used instead of the \fIconnect\fR option.
+.Sp
+A service section for transparent destination may look like this:
+.Sp
+.Vb 4
+\&    [transparent]
+\&    client=yes
+\&    accept=<stunnel_port>
+\&    transparent=destination
+.Ve
+.Sp
+This configuration requires iptables setup to work,
+possibly in /etc/rc.local or equivalent file.
+.Sp
+For a connect target installed on the same host:
+.Sp
+.Vb 3
+\&    /sbin/iptables \-t nat \-I OUTPUT \-p tcp \-\-dport <redirected_port> \e
+\&        \-m ! \-\-uid\-owner <stunnel_user_id> \e
+\&        \-j DNAT \-\-to\-destination <local_ip>:<stunnel_port>
+.Ve
+.Sp
+For a connect target installed on a remote host:
+.Sp
+.Vb 3
+\&    /sbin/iptables \-I INPUT \-i eth0 \-p tcp \-\-dport <stunnel_port> \-j ACCEPT
+\&    /sbin/iptables \-t nat \-I PREROUTING \-p tcp \-\-dport <redirected_port> \e
+\&        \-i eth0 \-j DNAT \-\-to\-destination <local_ip>:<stunnel_port>
+.Ve
+.Sp
+The transparent destination option is currently only supported on Linux.
+.IP "\fIboth\fR" 4
+.IX Item "both"
+Use both \fIsource\fR and \fIdestination\fR transparent proxy.
+.RE
+.RS 4
+.Sp
+Two legacy options are also supported for backward compatibility:
+.IP "\fIyes\fR" 4
+.IX Item "yes"
+This option has been renamed to \fIsource\fR.
+.IP "\fIno\fR" 4
+.IX Item "no"
+This option has been renamed to \fInone\fR.
+.RE
+.RS 4
+.RE
+.IP "\fBverify\fR = \s-1LEVEL\s0" 4
+.IX Item "verify = LEVEL"
+verify the peer certificate
+.RS 4
+.IP "level 0" 4
+.IX Item "level 0"
+Request and ignore the peer certificate.
+.IP "level 1" 4
+.IX Item "level 1"
+Verify the peer certificate if present.
+.IP "level 2" 4
+.IX Item "level 2"
+Verify the peer certificate.
+.IP "level 3" 4
+.IX Item "level 3"
+Verify the peer with locally installed certificate.
+.IP "level 4" 4
+.IX Item "level 4"
+Ignore the \s-1CA\s0 chain and only verify the peer certificate.
+.IP "default" 4
+.IX Item "default"
+No verify.
+.RE
+.RS 4
+.Sp
+It is important to understand that this option was solely designed for access
+control and not for authorization.  Specifically for level 2 every non-revoked
+certificate is accepted regardless of its Common Name.  For this reason a
+dedicated \s-1CA\s0 should be used with level 2, and not a generic \s-1CA\s0 commonly used
+for webservers.  Level 3 is preferred for point-to-point connections.
+.RE
+.SH "RETURN VALUE"
+.IX Header "RETURN VALUE"
+\&\fBstunnel\fR returns zero on success, non-zero on error.
+.SH "SIGNALS"
+.IX Header "SIGNALS"
+The following signals can be used to control \fBstunnel\fR in Unix environment:
+.IP "\s-1SIGHUP\s0" 4
+.IX Item "SIGHUP"
+Force a reload of the configuration file.
+.Sp
+Some global options will not be reloaded:
+.RS 4
+.IP "\(bu" 4
+chroot
+.IP "\(bu" 4
+foreground
+.IP "\(bu" 4
+pid
+.IP "\(bu" 4
+setgid
+.IP "\(bu" 4
+setuid
+.RE
+.RS 4
+.Sp
+The use of the 'setuid' option will also prevent \fBstunnel\fR from binding to privileged
+(<1024) ports during configuration reloading.
+.Sp
+When the 'chroot' option is used, \fBstunnel\fR will look for all its files (including
+the configuration file, certificates, the log file and the pid file) within the chroot
+jail.
+.RE
+.IP "\s-1SIGUSR1\s0" 4
+.IX Item "SIGUSR1"
+Close and reopen the \fBstunnel\fR log file.
+This function can be used for log rotation.
+.IP "\s-1SIGTERM, SIGQUIT, SIGINT\s0" 4
+.IX Item "SIGTERM, SIGQUIT, SIGINT"
+Shut \fBstunnel\fR down.
+.PP
+The result of sending any other signals to the server is undefined.
+.SH "EXAMPLES"
+.IX Header "EXAMPLES"
+In order to provide \s-1SSL\s0 encapsulation to your local \fIimapd\fR service, use:
+.PP
+.Vb 4
+\&    [imapd]
+\&    accept = 993
+\&    exec = /usr/sbin/imapd
+\&    execArgs = imapd
+.Ve
+.PP
+or in remote mode:
+.PP
+.Vb 3
+\&    [imapd]
+\&    accept = 993
+\&    connect = 143
+.Ve
+.PP
+In order to let your local e\-mail client connect to an SSL-enabled \fIimapd\fR
+service on another server, configure the e\-mail client to connect to localhost
+on port 119 and use:
+.PP
+.Vb 4
+\&    [imap]
+\&    client = yes
+\&    accept = 143
+\&    connect = servername:993
+.Ve
+.PP
+If you want to provide tunneling to your \fIpppd\fR daemon on port 2020,
+use something like:
+.PP
+.Vb 5
+\&    [vpn]
+\&    accept = 2020
+\&    exec = /usr/sbin/pppd
+\&    execArgs = pppd local
+\&    pty = yes
+.Ve
+.PP
+If you want to use \fBstunnel\fR in \fIinetd\fR mode to launch your imapd
+process, you'd use this \fIstunnel.conf\fR.
+Note there must be no \fI[service_name]\fR section.
+.PP
+.Vb 2
+\&    exec = /usr/sbin/imapd
+\&    execArgs = imapd
+.Ve
+.PP
+To setup \s-1SOCKS VPN\s0 configure the following client service:
+.PP
+.Vb 6
+\&    [socks_client]
+\&    client = yes
+\&    accept = 127.0.0.1:1080
+\&    connect = vpn_server:9080
+\&    verify = 4
+\&    CAfile = stunnel.pem
+.Ve
+.PP
+The corresponding configuration on the vpn_server host:
+.PP
+.Vb 5
+\&    [socks_server]
+\&    protocol = socks
+\&    accept = 9080
+\&    cert = stunnel.pem
+\&    key = stunnel.key
+.Ve
+.PP
+Now test your configuration on the client machine with:
+.PP
+.Vb 1
+\&    curl \-\-socks4a localhost http://www.example.com/
+.Ve
+.SH "NOTES"
+.IX Header "NOTES"
+.SS "\s-1RESTRICTIONS\s0"
+.IX Subsection "RESTRICTIONS"
+\&\fBstunnel\fR cannot be used for the \s-1FTP\s0 daemon because of the nature
+of the \s-1FTP\s0 protocol which utilizes multiple ports for data transfers.
+There are available SSL-enabled versions of \s-1FTP\s0 and telnet daemons, however.
+.SS "\s-1INETD MODE\s0"
+.IX Subsection "INETD MODE"
+The most common use of \fBstunnel\fR is to listen on a network
+port and establish communication with either a new port
+via the connect option, or a new program via the \fIexec\fR option.
+However there is a special case when you wish to have
+some other program accept incoming connections and
+launch \fBstunnel\fR, for example with \fIinetd\fR, \fIxinetd\fR,
+or \fItcpserver\fR.
+.PP
+For example, if you have the following line in \fIinetd.conf\fR:
+.PP
+.Vb 1
+\&    imaps stream tcp nowait root @bindir@/stunnel stunnel @sysconfdir@/stunnel/imaps.conf
+.Ve
+.PP
+In these cases, the \fIinetd\fR\-style program is responsible
+for binding a network socket (\fIimaps\fR above) and handing
+it to \fBstunnel\fR when a connection is received.
+Thus you do not want \fBstunnel\fR to have any \fIaccept\fR option.
+All the \fIService Level Options\fR should be placed in the
+global options section, and no \fI[service_name]\fR section
+will be present.  See the \fI\s-1EXAMPLES\s0\fR section for example
+configurations.
+.SS "\s-1CERTIFICATES\s0"
+.IX Subsection "CERTIFICATES"
+Each SSL-enabled daemon needs to present a valid X.509 certificate
+to the peer. It also needs a private key to decrypt the incoming
+data. The easiest way to obtain a certificate and a key is to 
+generate them with the free \fBOpenSSL\fR package. You can find more
+information on certificates generation on pages listed below.
+.PP
+The order of contents of the \fI.pem\fR file is important.  It should contain the
+unencrypted private key first, then a signed certificate (not certificate
+request).  There should also be empty lines after the certificate and the private key.
+Any plaintext certificate information appended on the top of generated certificate
+should be discarded. So the file should look like this:
+.PP
+.Vb 8
+\&    \-\-\-\-\-BEGIN RSA PRIVATE KEY\-\-\-\-\-
+\&    [encoded key]
+\&    \-\-\-\-\-END RSA PRIVATE KEY\-\-\-\-\-
+\&    [empty line]
+\&    \-\-\-\-\-BEGIN CERTIFICATE\-\-\-\-\-
+\&    [encoded certificate]
+\&    \-\-\-\-\-END CERTIFICATE\-\-\-\-\-
+\&    [empty line]
+.Ve
+.SS "\s-1RANDOMNESS\s0"
+.IX Subsection "RANDOMNESS"
+\&\fBstunnel\fR needs to seed the \s-1PRNG \s0(pseudo-random number generator) in
+order for \s-1SSL\s0 to use good randomness.  The following sources are loaded
+in order until sufficient random data has been gathered:
+.IP "\(bu" 4
+The file specified with the \fIRNDfile\fR flag.
+.IP "\(bu" 4
+The file specified by the \s-1RANDFILE\s0 environment variable, if set.
+.IP "\(bu" 4
+The file .rnd in your home directory, if \s-1RANDFILE\s0 not set.
+.IP "\(bu" 4
+The file specified with '\-\-with\-random' at compile time.
+.IP "\(bu" 4
+The contents of the screen if running on Windows.
+.IP "\(bu" 4
+The egd socket specified with the \fI\s-1EGD\s0\fR flag.
+.IP "\(bu" 4
+The egd socket specified with '\-\-with\-egd\-sock' at compile time.
+.IP "\(bu" 4
+The /dev/urandom device.
+.PP
+With recent (\fBOpenSSL 0.9.5a\fR or later) version of \s-1SSL\s0 it will stop loading
+random data automatically when sufficient entropy has been gathered.  With
+previous versions it will continue to gather from all the above sources since
+no \s-1SSL\s0 function exists to tell when enough data is available.
+.PP
+Note that on Windows machines that do not have console user interaction
+(mouse movements, creating windows, etc.) the screen contents are not
+variable enough to be sufficient, and you should provide a random file
+for use with the \fIRNDfile\fR flag.
+.PP
+Note that the file specified with the \fIRNDfile\fR flag should contain
+random data \*(-- that means it should contain different information
+each time \fBstunnel\fR is run.  This is handled automatically
+unless the \fIRNDoverwrite\fR flag is used.  If you wish to update this file
+manually, the \fIopenssl rand\fR command in recent versions of \fBOpenSSL\fR,
+would be useful.
+.PP
+Important note: If /dev/urandom is available, \fBOpenSSL\fR often seeds the \s-1PRNG\s0
+with it while checking the random state.  On systems with /dev/urandom
+\&\fBOpenSSL\fR is likely to use it even though it is listed at the very bottom of
+the list above.  This is the behaviour of \fBOpenSSL\fR and not \fBstunnel\fR.
+.SS "\s-1DH PARAMETERS\s0"
+.IX Subsection "DH PARAMETERS"
+\&\fBstunnel\fR 4.40 and later contains hardcoded 2048\-bit \s-1DH\s0 parameters.  Starting
+with \fBstunnel\fR 5.18, these hardcoded \s-1DH\s0 parameters are replaced every 24 hours
+with autogenerated temporary \s-1DH\s0 parameters.  \s-1DH\s0 parameter generation may take
+several minutes.
+.PP
+Alternatively, it is possible to specify static \s-1DH\s0 parameters in the
+certificate file, which disables generating temporary \s-1DH\s0 parameters:
+.PP
+.Vb 1
+\&    openssl dhparam 2048 >> stunnel.pem
+.Ve
+.SH "FILES"
+.IX Header "FILES"
+.ie n .IP "\fI\fI@sysconfdir\fI@/stunnel/stunnel.conf\fR" 4
+.el .IP "\fI\f(CI@sysconfdir\fI@/stunnel/stunnel.conf\fR" 4
+.IX Item "@sysconfdir@/stunnel/stunnel.conf"
+\&\fBstunnel\fR configuration file
+.SH "BUGS"
+.IX Header "BUGS"
+The \fIexecArgs\fR option and the Win32 command line do not support quoting.
+.SH "SEE ALSO"
+.IX Header "SEE ALSO"
+.IP "\fItcpd\fR\|(8)" 4
+.IX Item "tcpd"
+access control facility for internet services
+.IP "\fIinetd\fR\|(8)" 4
+.IX Item "inetd"
+internet 'super\-server'
+.IP "\fIhttp://www.stunnel.org/\fR" 4
+.IX Item "http://www.stunnel.org/"
+\&\fBstunnel\fR homepage
+.IP "\fIhttp://www.openssl.org/\fR" 4
+.IX Item "http://www.openssl.org/"
+\&\fBOpenSSL\fR project website
+.SH "AUTHOR"
+.IX Header "AUTHOR"
+.IP "Michał Trojnara" 4
+.IX Item "Michał Trojnara"
+<\fIMichal.Trojnara@mirt.net\fR>
diff --git a/doc/stunnel.html.in b/doc/stunnel.html.in
new file mode 100644
index 0000000..fb9add5
--- /dev/null
+++ b/doc/stunnel.html.in
@@ -0,0 +1,1477 @@
+<?xml version="1.0" ?>
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
+<html xmlns="http://www.w3.org/1999/xhtml">
+<head>
+<title>stunnel TLS Proxy</title>
+<meta http-equiv="content-type" content="text/html; charset=utf-8" />
+<link rev="made" href="mailto:root@localhost" />
+</head>
+
+<body id="_podtop_">
+<table border="0" width="100%" cellspacing="0" cellpadding="3">
+<tr><td class="_podblock_" style="background-color: #cccccc; color: #000" valign="middle">
+<big><strong><span class="_podblock_">&nbsp;stunnel TLS Proxy</span></strong></big>
+</td></tr>
+</table>
+
+
+
+<ul id="index">
+  <li><a href="#NAME">NAME</a></li>
+  <li><a href="#SYNOPSIS">SYNOPSIS</a></li>
+  <li><a href="#DESCRIPTION">DESCRIPTION</a></li>
+  <li><a href="#OPTIONS">OPTIONS</a></li>
+  <li><a href="#CONFIGURATION-FILE">CONFIGURATION FILE</a>
+    <ul>
+      <li><a href="#GLOBAL-OPTIONS">GLOBAL OPTIONS</a></li>
+      <li><a href="#SERVICE-LEVEL-OPTIONS">SERVICE-LEVEL OPTIONS</a></li>
+    </ul>
+  </li>
+  <li><a href="#RETURN-VALUE">RETURN VALUE</a></li>
+  <li><a href="#SIGNALS">SIGNALS</a></li>
+  <li><a href="#EXAMPLES">EXAMPLES</a></li>
+  <li><a href="#NOTES">NOTES</a>
+    <ul>
+      <li><a href="#RESTRICTIONS">RESTRICTIONS</a></li>
+      <li><a href="#INETD-MODE">INETD MODE</a></li>
+      <li><a href="#CERTIFICATES">CERTIFICATES</a></li>
+      <li><a href="#RANDOMNESS">RANDOMNESS</a></li>
+      <li><a href="#DH-PARAMETERS">DH PARAMETERS</a></li>
+    </ul>
+  </li>
+  <li><a href="#FILES">FILES</a></li>
+  <li><a href="#BUGS">BUGS</a></li>
+  <li><a href="#SEE-ALSO">SEE ALSO</a></li>
+  <li><a href="#AUTHOR">AUTHOR</a></li>
+</ul>
+
+<a href="#_podtop_"><h1 id="NAME">NAME</h1></a>
+
+<p>stunnel - TLS offloading and load-balancing proxy</p>
+
+<a href="#_podtop_"><h1 id="SYNOPSIS">SYNOPSIS</h1></a>
+
+<dl>
+
+<dt id="Unix"><b>Unix:</b></dt>
+<dd>
+
+<p><b>stunnel</b> [<span style="white-space: nowrap;">FILE</span>] | <span style="white-space: nowrap;">-fd N</span> | <span style="white-space: nowrap;">-help</span> | <span style="white-space: nowrap;">-version</span> | <span style="white-space: nowrap;">-sockets</span> | <span style="white-space: nowrap;">-options</span></p>
+
+</dd>
+<dt id="WIN32"><b>WIN32:</b></dt>
+<dd>
+
+<p><b>stunnel</b> [ [ <span style="white-space: nowrap;">-install</span> | <span style="white-space: nowrap;">-uninstall</span> | <span style="white-space: nowrap;">-start</span> | <span style="white-space: nowrap;">-stop</span> | <span style="white-space: nowrap;">-reload</span> | <span style="white-space: nowrap;">-reopen</span> | <span style="white-space: nowrap;">-exit</span> ] [<span style="white-space: nowrap;">-quiet</span>] [<span style="white-space: nowrap;">FILE</span>] ] | <span style="white-space: nowrap;">-help</span> | <span style="white-space: nowrap;">-version</span> | <span style="white-space: nowrap;">-sockets</span> | <span style="white-space: nowrap;">-options</span></p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="DESCRIPTION">DESCRIPTION</h1></a>
+
+<p>The <b>stunnel</b> program is designed to work as <i>SSL</i> encryption wrapper between remote clients and local (<i>inetd</i>-startable) or remote servers. The concept is that having non-SSL aware daemons running on your system you can easily set them up to communicate with clients over secure SSL channels.</p>
+
+<p><b>stunnel</b> can be used to add SSL functionality to commonly used <i>Inetd</i> daemons like POP-2, POP-3, and IMAP servers, to standalone daemons like NNTP, SMTP and HTTP, and in tunneling PPP over network sockets without changes to the source code.</p>
+
+<p>This product includes cryptographic software written by Eric Young (eay@cryptsoft.com)</p>
+
+<a href="#_podtop_"><h1 id="OPTIONS">OPTIONS</h1></a>
+
+<dl>
+
+<dt id="FILE"><b>FILE</b></dt>
+<dd>
+
+<p>Use specified configuration file</p>
+
+</dd>
+<dt id="fd-N-Unix-only"><b>-fd N</b> (Unix only)</dt>
+<dd>
+
+<p>Read the config file from specified file descriptor</p>
+
+</dd>
+<dt id="help"><b>-help</b></dt>
+<dd>
+
+<p>Print <b>stunnel</b> help menu</p>
+
+</dd>
+<dt id="version"><b>-version</b></dt>
+<dd>
+
+<p>Print <b>stunnel</b> version and compile time defaults</p>
+
+</dd>
+<dt id="sockets"><b>-sockets</b></dt>
+<dd>
+
+<p>Print default socket options</p>
+
+</dd>
+<dt id="options"><b>-options</b></dt>
+<dd>
+
+<p>Print supported SSL options</p>
+
+</dd>
+<dt id="install-Windows-NT-and-later-only"><b>-install</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Install NT Service</p>
+
+</dd>
+<dt id="uninstall-Windows-NT-and-later-only"><b>-uninstall</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Uninstall NT Service</p>
+
+</dd>
+<dt id="start-Windows-NT-and-later-only"><b>-start</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Start NT Service</p>
+
+</dd>
+<dt id="stop-Windows-NT-and-later-only"><b>-stop</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Stop NT Service</p>
+
+</dd>
+<dt id="reload-Windows-NT-and-later-only"><b>-reload</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Reload the configuration file of the running NT Service</p>
+
+</dd>
+<dt id="reopen-Windows-NT-and-later-only"><b>-reopen</b> (Windows NT and later only)</dt>
+<dd>
+
+<p>Reopen the log file of the running NT Service</p>
+
+</dd>
+<dt id="exit-Win32-only"><b>-exit</b> (Win32 only)</dt>
+<dd>
+
+<p>Exit an already started stunnel</p>
+
+</dd>
+<dt id="quiet-Win32-only"><b>-quiet</b> (Win32 only)</dt>
+<dd>
+
+<p>Don&#39;t display any message boxes</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="CONFIGURATION-FILE">CONFIGURATION FILE</h1></a>
+
+<p>Each line of the configuration file can be either:</p>
+
+<ul>
+
+<li><p>An empty line (ignored).</p>
+
+</li>
+<li><p>A comment starting with &#39;;&#39; (ignored).</p>
+
+</li>
+<li><p>An &#39;option_name = option_value&#39; pair.</p>
+
+</li>
+<li><p>&#39;[service_name]&#39; indicating a start of a service definition.</p>
+
+</li>
+</ul>
+
+<p>An address parameter of an option may be either:</p>
+
+<ul>
+
+<li><p>A port number.</p>
+
+</li>
+<li><p>A colon-separated pair of IP address (either IPv4, IPv6, or domain name) and port number.</p>
+
+</li>
+<li><p>A Unix socket path (Unix only).</p>
+
+</li>
+</ul>
+
+<h2 id="GLOBAL-OPTIONS">GLOBAL OPTIONS</h2>
+
+<dl>
+
+<dt id="chroot-DIRECTORY-Unix-only"><b>chroot</b> = DIRECTORY (Unix only)</dt>
+<dd>
+
+<p>directory to chroot <b>stunnel</b> process</p>
+
+<p><b>chroot</b> keeps <b>stunnel</b> in a chrooted jail. <i>CApath</i>, <i>CRLpath</i>, <i>pid</i> and <i>exec</i> are located inside the jail and the patches have to be relative to the directory specified with <b>chroot</b>.</p>
+
+<p>Several functions of the operating system also need their files to be located within the chroot jail, e.g.:</p>
+
+<ul>
+
+<li><p>Delayed resolver typically needs /etc/nsswitch.conf and /etc/resolv.conf.</p>
+
+</li>
+<li><p>Local time in log files needs /etc/timezone.</p>
+
+</li>
+<li><p>Some other functions may need devices, e.g. /dev/zero or /dev/null.</p>
+
+</li>
+</ul>
+
+</dd>
+<dt id="compression-deflate-zlib"><b>compression</b> = deflate | zlib</dt>
+<dd>
+
+<p>select data compression algorithm</p>
+
+<p>default: no compression</p>
+
+<p>deflate is the standard compression method as described in RFC 1951.</p>
+
+<p>zlib compression of <b>OpenSSL 0.9.8</b> or above is not backward compatible with <b>OpenSSL 0.9.7</b>.</p>
+
+</dd>
+<dt id="debug-FACILITY.-LEVEL"><b>debug</b> = [FACILITY.]LEVEL</dt>
+<dd>
+
+<p>debugging level</p>
+
+<p>Level is one of the syslog level names or numbers emerg (0), alert (1), crit (2), err (3), warning (4), notice (5), info (6), or debug (7). All logs for the specified level and all levels numerically less than it will be shown. Use <i>debug = debug</i> or <i>debug = 7</i> for greatest debugging output. The default is notice (5).</p>
+
+<p>The syslog facility &#39;daemon&#39; will be used unless a facility name is supplied. (Facilities are not supported on Win32.)</p>
+
+<p>Case is ignored for both facilities and levels.</p>
+
+</dd>
+<dt id="EGD-EGD_PATH-Unix-only"><b>EGD</b> = EGD_PATH (Unix only)</dt>
+<dd>
+
+<p>path to Entropy Gathering Daemon socket</p>
+
+<p>Entropy Gathering Daemon socket to use to feed the <b>OpenSSL</b> random number generator. (Available only if compiled with <b>OpenSSL 0.9.5a</b> or higher)</p>
+
+</dd>
+<dt id="engine-auto-ENGINE_ID"><b>engine</b> = auto | ENGINE_ID</dt>
+<dd>
+
+<p>select hardware engine</p>
+
+<p>default: software-only cryptography</p>
+
+<p>Here is an example of advanced engine configuration to read the private key from an OpenSC engine</p>
+
+<pre><code>    engine=dynamic
+    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+    engineCtrl=ID:pkcs11
+    engineCtrl=LIST_ADD:1
+    engineCtrl=LOAD
+    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc-pkcs11.so
+    engineCtrl=INIT
+
+    [service]
+    engineNum=1
+    key=id_45</code></pre>
+
+</dd>
+<dt id="engineCtrl-COMMAND-:PARAMETER"><b>engineCtrl</b> = COMMAND[:PARAMETER]</dt>
+<dd>
+
+<p>control hardware engine</p>
+
+<p>Special commands &quot;LOAD&quot; and &quot;INIT&quot; can be used to load and initialize the engine cryptogaphic module.</p>
+
+</dd>
+<dt id="engineDefault-TASK_LIST"><b>engineDefault</b> = TASK_LIST</dt>
+<dd>
+
+<p>set OpenSSL tasks delegated to the current engine</p>
+
+<p>The parameter specifies a comma-separated list of task to be delegated to the current engine.</p>
+
+<p>The following tasks may be available, if supported by the engine: ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.</p>
+
+</dd>
+<dt id="fips-yes-no"><b>fips</b> = yes | no</dt>
+<dd>
+
+<p>Enable or disable FIPS 140-2 mode.</p>
+
+<p>This option allows you to disable entering FIPS mode if <b>stunnel</b> was compiled with FIPS 140-2 support.</p>
+
+<p>default: no (since version 5.00)</p>
+
+</dd>
+<dt id="foreground-yes-no-Unix-only"><b>foreground</b> = yes | no (Unix only)</dt>
+<dd>
+
+<p>foreground mode</p>
+
+<p>Stay in foreground (don&#39;t fork) and log to stderr instead of via syslog (unless <i>output</i> is specified).</p>
+
+<p>default: background in daemon mode</p>
+
+</dd>
+<dt id="iconActive-ICON_FILE-GUI-only"><b>iconActive</b> = ICON_FILE (GUI only)</dt>
+<dd>
+
+<p>GUI icon to be displayed when there are established connections</p>
+
+<p>On Windows platform the parameter should be an .ico file containing a 16x16 pixel image.</p>
+
+</dd>
+<dt id="iconError-ICON_FILE-GUI-only"><b>iconError</b> = ICON_FILE (GUI only)</dt>
+<dd>
+
+<p>GUI icon to be displayed when no valid configuration is loaded</p>
+
+<p>On Windows platform the parameter should be an .ico file containing a 16x16 pixel image.</p>
+
+</dd>
+<dt id="iconIdle-ICON_FILE-GUI-only"><b>iconIdle</b> = ICON_FILE (GUI only)</dt>
+<dd>
+
+<p>GUI icon to be displayed when there are no established connections</p>
+
+<p>On Windows platform the parameter should be an .ico file containing a 16x16 pixel image.</p>
+
+</dd>
+<dt id="log-append-overwrite"><b>log</b> = append | overwrite</dt>
+<dd>
+
+<p>log file handling</p>
+
+<p>This option allows you to choose whether the log file (specified with the <i>output</i> option) is appended or overwritten when opened or re-opened.</p>
+
+<p>default: append</p>
+
+</dd>
+<dt id="output-FILE"><b>output</b> = FILE</dt>
+<dd>
+
+<p>append log messages to a file</p>
+
+<p>/dev/stdout device can be used to send log messages to the standard output (for example to log them with daemontools splogger).</p>
+
+</dd>
+<dt id="pid-FILE-Unix-only"><b>pid</b> = FILE (Unix only)</dt>
+<dd>
+
+<p>pid file location</p>
+
+<p>If the argument is empty, then no pid file will be created.</p>
+
+<p><i>pid</i> path is relative to the <i>chroot</i> directory if specified.</p>
+
+</dd>
+<dt id="RNDbytes-BYTES"><b>RNDbytes</b> = BYTES</dt>
+<dd>
+
+<p>bytes to read from random seed files</p>
+
+<p>Number of bytes of data read from random seed files. With SSL versions less than <b>0.9.5a</b>, also determines how many bytes of data are considered sufficient to seed the PRNG. More recent <b>OpenSSL</b> versions have a builtin function to determine when sufficient randomness is available.</p>
+
+</dd>
+<dt id="RNDfile-FILE"><b>RNDfile</b> = FILE</dt>
+<dd>
+
+<p>path to file with random seed data</p>
+
+<p>The SSL library will use data from this file first to seed the random number generator.</p>
+
+</dd>
+<dt id="RNDoverwrite-yes-no"><b>RNDoverwrite</b> = yes | no</dt>
+<dd>
+
+<p>overwrite the random seed files with new random data</p>
+
+<p>default: yes</p>
+
+</dd>
+<dt id="service-SERVICE-Unix-only"><b>service</b> = SERVICE (Unix only)</dt>
+<dd>
+
+<p>stunnel service name</p>
+
+<p>The specified service name is used for syslog and as the <i>inetd</i> mode service name for TCP Wrappers. While this option can technically be specified in the service sections, it is only useful in global options.</p>
+
+<p>default: stunnel</p>
+
+</dd>
+<dt id="setgid-GROUP-Unix-only"><b>setgid</b> = GROUP (Unix only)</dt>
+<dd>
+
+<p>setgid() to the specified group in daemon mode and clear all other groups</p>
+
+</dd>
+<dt id="setuid-USER-Unix-only"><b>setuid</b> = USER (Unix only)</dt>
+<dd>
+
+<p>setuid() to the specified user in daemon mode</p>
+
+</dd>
+<dt id="socket-a-l-r:OPTION-VALUE-:VALUE"><b>socket</b> = a|l|r:OPTION=VALUE[:VALUE]</dt>
+<dd>
+
+<p>Set an option on the accept/local/remote socket</p>
+
+<p>The values for the linger option are l_onof:l_linger. The values for the time are tv_sec:tv_usec.</p>
+
+<p>Examples:</p>
+
+<pre><code>    socket = l:SO_LINGER=1:60
+        set one minute timeout for closing local socket
+    socket = r:SO_OOBINLINE=yes
+        place out-of-band data directly into the
+        receive data stream for remote sockets
+    socket = a:SO_REUSEADDR=no
+        disable address reuse (enabled by default)
+    socket = a:SO_BINDTODEVICE=lo
+        only accept connections on loopback interface</code></pre>
+
+</dd>
+<dt id="syslog-yes-no-Unix-only"><b>syslog</b> = yes | no (Unix only)</dt>
+<dd>
+
+<p>enable logging via syslog</p>
+
+<p>default: yes</p>
+
+</dd>
+<dt id="taskbar-yes-no-WIN32-only"><b>taskbar</b> = yes | no (WIN32 only)</dt>
+<dd>
+
+<p>enable the taskbar icon</p>
+
+<p>default: yes</p>
+
+</dd>
+</dl>
+
+<h2 id="SERVICE-LEVEL-OPTIONS">SERVICE-LEVEL OPTIONS</h2>
+
+<p>Each configuration section begins with a service name in square brackets. The service name is used for libwrap (TCP Wrappers) access control and lets you distinguish <b>stunnel</b> services in your log files.</p>
+
+<p>Note that if you wish to run <b>stunnel</b> in <i>inetd</i> mode (where it is provided a network socket by a server such as <i>inetd</i>, <i>xinetd</i>, or <i>tcpserver</i>) then you should read the section entitled <i>INETD MODE</i> below.</p>
+
+<dl>
+
+<dt id="accept-HOST:-PORT"><b>accept</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>accept connections on specified address</p>
+
+<p>If no host specified, defaults to all IPv4 addresses for the local host.</p>
+
+<p>To listen on all IPv6 addresses use:</p>
+
+<pre><code>    accept = :::PORT</code></pre>
+
+</dd>
+<dt id="CApath-DIRECTORY"><b>CApath</b> = DIRECTORY</dt>
+<dd>
+
+<p>Certificate Authority directory</p>
+
+<p>This is the directory in which <b>stunnel</b> will look for certificates when using the <i>verify</i> option. Note that the certificates in this directory should be named XXXXXXXX.0 where XXXXXXXX is the hash value of the DER encoded subject of the cert.</p>
+
+<p>The hash algorithm has been changed in <b>OpenSSL 1.0.0</b>. It is required to c_rehash the directory on upgrade from <b>OpenSSL 0.x.x</b> to <b>OpenSSL 1.x.x</b>.</p>
+
+<p><i>CApath</i> path is relative to the <i>chroot</i> directory if specified.</p>
+
+</dd>
+<dt id="CAfile-CERT_FILE"><b>CAfile</b> = CERT_FILE</dt>
+<dd>
+
+<p>Certificate Authority file</p>
+
+<p>This file contains multiple CA certificates, used with the <i>verify</i> option.</p>
+
+</dd>
+<dt id="cert-PEM_FILE"><b>cert</b> = PEM_FILE</dt>
+<dd>
+
+<p>certificate chain PEM file name</p>
+
+<p>The certificates must be in PEM format, and must be from the actual server/client certificate to the self-signed root CA certificate.</p>
+
+<p>A certificate is required in server mode, and optional in client mode.</p>
+
+</dd>
+<dt id="checkEmail-EMAIL"><b>checkEmail</b> = EMAIL</dt>
+<dd>
+
+<p>email address of the peer certificate subject</p>
+
+<p>Multiple <i>checkEmail</i> options are allowed in a single service section. Certificates are accepted if no <i>checkEmail</i> option was specified, or the email address of the peer certificate matches any of the email addresses specified with <i>checkEmail</i>.</p>
+
+</dd>
+<dt id="checkHost-HOST"><b>checkHost</b> = HOST</dt>
+<dd>
+
+<p>host of the peer certificate subject</p>
+
+<p>Multiple <i>checkHost</i> options are allowed in a single service section. Certificates are accepted if no <i>checkHost</i> option was specified, or the host name of the peer certificate matches any of the hosts specified with <i>checkHost</i>.</p>
+
+</dd>
+<dt id="checkIP-IP"><b>checkIP</b> = IP</dt>
+<dd>
+
+<p>IP address of the peer certificate subject</p>
+
+<p>Multiple <i>checkIP</i> options are allowed in a single service section. Certificates are accepted if no <i>checkIP</i> option was specified, or the IP address of the peer certificate matches any of the IP addresses specified with <i>checkIP</i>.</p>
+
+</dd>
+<dt id="ciphers-CIPHER_LIST"><b>ciphers</b> = CIPHER_LIST</dt>
+<dd>
+
+<p>Select permitted SSL ciphers</p>
+
+<p>A colon-delimited list of the ciphers to allow in the SSL connection, for example DES-CBC3-SHA:IDEA-CBC-MD5.</p>
+
+</dd>
+<dt id="client-yes-no"><b>client</b> = yes | no</dt>
+<dd>
+
+<p>client mode (remote service uses SSL)</p>
+
+<p>default: no (server mode)</p>
+
+</dd>
+<dt id="connect-HOST:-PORT"><b>connect</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>connect to a remote address</p>
+
+<p>If no host is specified, the host defaults to localhost.</p>
+
+<p>Multiple <i>connect</i> options are allowed in a single service section.</p>
+
+<p>If host resolves to multiple addresses and/or if multiple <i>connect</i> options are specified, then the remote address is chosen using a round-robin algorithm.</p>
+
+</dd>
+<dt id="CRLpath-DIRECTORY"><b>CRLpath</b> = DIRECTORY</dt>
+<dd>
+
+<p>Certificate Revocation Lists directory</p>
+
+<p>This is the directory in which <b>stunnel</b> will look for CRLs when using the <i>verify</i> option. Note that the CRLs in this directory should be named XXXXXXXX.r0 where XXXXXXXX is the hash value of the CRL.</p>
+
+<p>The hash algorithm has been changed in <b>OpenSSL 1.0.0</b>. It is required to c_rehash the directory on upgrade from <b>OpenSSL 0.x.x</b> to <b>OpenSSL 1.x.x</b>.</p>
+
+<p><i>CRLpath</i> path is relative to the <i>chroot</i> directory if specified.</p>
+
+</dd>
+<dt id="CRLfile-CERT_FILE"><b>CRLfile</b> = CERT_FILE</dt>
+<dd>
+
+<p>Certificate Revocation Lists file</p>
+
+<p>This file contains multiple CRLs, used with the <i>verify</i> option.</p>
+
+</dd>
+<dt id="curve-NID"><b>curve</b> = NID</dt>
+<dd>
+
+<p>specify ECDH curve name</p>
+
+<p>To get a list of supported curves use:</p>
+
+<pre><code>    openssl ecparam -list_curves</code></pre>
+
+<p>default: prime256v1</p>
+
+</dd>
+<dt id="logId-TYPE"><b>logId</b> = TYPE</dt>
+<dd>
+
+<p>connection identifier type</p>
+
+<p>This identifier allows you to distinguish log entries generated for each of the connections.</p>
+
+<p>Currently supported types:</p>
+
+<dl>
+
+<dt id="sequential"><i>sequential</i></dt>
+<dd>
+
+<p>The numeric sequential identifier is only unique within a single instance of <b>stunnel</b>, but very compact. It is most useful for manual log analysis.</p>
+
+</dd>
+<dt id="unique"><i>unique</i></dt>
+<dd>
+
+<p>This alphanumeric identifier is globally unique, but longer than the sequential number. It is most useful for automated log analysis.</p>
+
+</dd>
+<dt id="thread"><i>thread</i></dt>
+<dd>
+
+<p>The operating system thread identifier is neither unique (even within a single instance of <b>stunnel</b>) nor short. It is most useful for debugging software or configuration issues.</p>
+
+</dd>
+</dl>
+
+<p>default: sequential</p>
+
+</dd>
+<dt id="debug-LEVEL"><b>debug</b> = LEVEL</dt>
+<dd>
+
+<p>debugging level</p>
+
+<p>Level is a one of the syslog level names or numbers emerg (0), alert (1), crit (2), err (3), warning (4), notice (5), info (6), or debug (7). All logs for the specified level and all levels numerically less than it will be shown. Use <i>debug = debug</i> or <i>debug = 7</i> for greatest debugging output. The default is notice (5).</p>
+
+</dd>
+<dt id="delay-yes-no"><b>delay</b> = yes | no</dt>
+<dd>
+
+<p>delay DNS lookup for the <i>connect</i> option</p>
+
+<p>This option is useful for dynamic DNS, or when DNS is not available during <b>stunnel</b> startup (road warrior VPN, dial-up configurations).</p>
+
+<p>Delayed resolver mode is automatically engaged when stunnel fails to resolve on startup any of the <i>connect</i> targets for a service.</p>
+
+<p>Delayed resolver inflicts <i>failover = prio</i>.</p>
+
+<p>default: no</p>
+
+</dd>
+<dt id="engineId-ENGINE_ID"><b>engineId</b> = ENGINE_ID</dt>
+<dd>
+
+<p>select engine ID for the service</p>
+
+</dd>
+<dt id="engineNum-ENGINE_NUMBER"><b>engineNum</b> = ENGINE_NUMBER</dt>
+<dd>
+
+<p>select engine number for the service</p>
+
+<p>The engines are numbered starting from 1.</p>
+
+</dd>
+<dt id="exec-EXECUTABLE_PATH"><b>exec</b> = EXECUTABLE_PATH</dt>
+<dd>
+
+<p>execute a local inetd-type program</p>
+
+<p><i>exec</i> path is relative to the <i>chroot</i> directory if specified.</p>
+
+<p>The following environmental variables are set on Unix platforms: REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.</p>
+
+</dd>
+<dt id="execArgs-0-1-2"><b>execArgs</b> = $0 $1 $2 ...</dt>
+<dd>
+
+<p>arguments for <i>exec</i> including the program name ($0)</p>
+
+<p>Quoting is currently not supported. Arguments are separated with an arbitrary amount of whitespace.</p>
+
+</dd>
+<dt id="failover-rr-prio"><b>failover</b> = rr | prio</dt>
+<dd>
+
+<p>Failover strategy for multiple &quot;connect&quot; targets.</p>
+
+<pre><code>    rr (round robin) - fair load distribution
+    prio (priority) - use the order specified in config file</code></pre>
+
+<p>default: rr</p>
+
+</dd>
+<dt id="ident-USERNAME"><b>ident</b> = USERNAME</dt>
+<dd>
+
+<p>use IDENT (RFC 1413) username checking</p>
+
+</dd>
+<dt id="include-DIRECTORY"><b>include</b> = DIRECTORY</dt>
+<dd>
+
+<p>include all configuration file parts located in DIRECTORY</p>
+
+<p>The files are included in the ascending alphabetical order of their names.</p>
+
+</dd>
+<dt id="key-KEY_FILE"><b>key</b> = KEY_FILE</dt>
+<dd>
+
+<p>private key for the certificate specified with <i>cert</i> option</p>
+
+<p>A private key is needed to authenticate the certificate owner. Since this file should be kept secret it should only be readable by its owner. On Unix systems you can use the following command:</p>
+
+<pre><code>    chmod 600 keyfile</code></pre>
+
+<p>default: the value of the <i>cert</i> option</p>
+
+</dd>
+<dt id="libwrap-yes-no"><b>libwrap</b> = yes | no</dt>
+<dd>
+
+<p>Enable or disable the use of /etc/hosts.allow and /etc/hosts.deny.</p>
+
+<p>default: no (since version 5.00)</p>
+
+</dd>
+<dt id="local-HOST"><b>local</b> = HOST</dt>
+<dd>
+
+<p>By default, the IP address of the outgoing interface is used as the source for remote connections. Use this option to bind a static local IP address instead.</p>
+
+</dd>
+<dt id="sni-SERVICE:SERVER_PATTERN-server-mode"><b>sni</b> = SERVICE:SERVER_PATTERN (server mode)</dt>
+<dd>
+
+<p>Use the service as a slave service (a name-based virtual server) for Server Name Indication TLS extension (RFC 3546).</p>
+
+<p><i>service_name</i> specifies the master service that accepts client connections with the <i>accept</i> option. <i>server_name_pattern</i> specifies the host name to be redirected. The pattern may start with the &#39;*&#39; character, e.g. &#39;*.example.com&#39;. Multiple slave services are normally specified for a single master service. The <i>sni</i> option can also be specified more than once within a single slave service.</p>
+
+<p>This service, as well as the master service, may not be configured in client mode.</p>
+
+<p>The <i>connect</i> option of the slave service is ignored when the <i>protocol</i> option is specified, as <i>protocol</i> connects to the remote host before TLS handshake.</p>
+
+<p>Libwrap checks (Unix only) are performed twice: with the master service name after TCP connection is accepted, and with the slave service name during the TLS handshake.</p>
+
+<p>The <i>sni</i> option is only available when compiled with <b>OpenSSL 1.0.0</b> and later.</p>
+
+</dd>
+<dt id="sni-SERVER-client-mode"><b>sni</b> = SERVER (client mode)</dt>
+<dd>
+
+<p>Use the parameter as the value of TLS Server Name Indication (RFC 3546) extension.</p>
+
+<p>The <i>sni</i> option is only available when compiled with <b>OpenSSL 1.0.0</b> and later.</p>
+
+</dd>
+<dt id="OCSP-URL"><b>OCSP</b> = URL</dt>
+<dd>
+
+<p>select OCSP server for certificate verification</p>
+
+</dd>
+<dt id="OCSPaia-yes-no"><b>OCSPaia</b> = yes | no</dt>
+<dd>
+
+<p>validate certificates with their AIA OCSP responders</p>
+
+<p>This option enables <i>stunnel</i> to validate certificates with the list of OCSP responder URLs retrieved from their AIA (Authority Information Access) extension.</p>
+
+</dd>
+<dt id="OCSPflag-OCSP_FLAG"><b>OCSPflag</b> = OCSP_FLAG</dt>
+<dd>
+
+<p>specify OCSP server flag</p>
+
+<p>Several <i>OCSPflag</i> can be used to specify multiple flags.</p>
+
+<p>currently supported flags: NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY, NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME</p>
+
+</dd>
+<dt id="options-SSL_OPTIONS"><b>options</b> = SSL_OPTIONS</dt>
+<dd>
+
+<p><b>OpenSSL</b> library options</p>
+
+<p>The parameter is the <b>OpenSSL</b> option name as described in the <i>SSL_CTX_set_options(3ssl)</i> manual, but without <i>SSL_OP_</i> prefix. <i>stunnel -options</i> lists the options found to be allowed in the current combination of <i>stunnel</i> and the <i>OpenSSL</i> library used to build it.</p>
+
+<p>Several <i>options</i> can be used to specify multiple options. An option name can be prepended with a dash (&quot;-&quot;) to disable the option.</p>
+
+<p>For example, for compatibility with the erroneous Eudora SSL implementation, the following option can be used:</p>
+
+<pre><code>    options = DONT_INSERT_EMPTY_FRAGMENTS</code></pre>
+
+<p>default:</p>
+
+<pre><code>    options = NO_SSLv2
+    options = NO_SSLv3</code></pre>
+
+</dd>
+<dt id="protocol-PROTO"><b>protocol</b> = PROTO</dt>
+<dd>
+
+<p>application protocol to negotiate SSL</p>
+
+<p>This option enables initial, protocol-specific negotiation of the SSL/TLS encryption. The <i>protocol</i> option should not be used with SSL encryption on a separate port.</p>
+
+<p>Currently supported protocols:</p>
+
+<dl>
+
+<dt id="cifs"><i>cifs</i></dt>
+<dd>
+
+<p>Proprietary (undocummented) extension of CIFS protocol implemented in Samba. Support for this extension was dropped in Samba 3.0.0.</p>
+
+</dd>
+<dt id="connect"><i>connect</i></dt>
+<dd>
+
+<p>Based on RFC 2817 - <i>Upgrading to TLS Within HTTP/1.1</i>, section 5.2 - <i>Requesting a Tunnel with CONNECT</i></p>
+
+<p>This protocol is only supported in client mode.</p>
+
+</dd>
+<dt id="imap"><i>imap</i></dt>
+<dd>
+
+<p>Based on RFC 2595 - <i>Using TLS with IMAP, POP3 and ACAP</i></p>
+
+</dd>
+<dt id="nntp"><i>nntp</i></dt>
+<dd>
+
+<p>Based on RFC 4642 - <i>Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)</i></p>
+
+<p>This protocol is only supported in client mode.</p>
+
+</dd>
+<dt id="pgsql"><i>pgsql</i></dt>
+<dd>
+
+<p>Based on <i>http://www.postgresql.org/docs/8.3/static/protocol-flow.html#AEN73982</i></p>
+
+</dd>
+<dt id="pop3"><i>pop3</i></dt>
+<dd>
+
+<p>Based on RFC 2449 - <i>POP3 Extension Mechanism</i></p>
+
+</dd>
+<dt id="proxy"><i>proxy</i></dt>
+<dd>
+
+<p>Haproxy client IP address <i>http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt</i></p>
+
+</dd>
+<dt id="smtp"><i>smtp</i></dt>
+<dd>
+
+<p>Based on RFC 2487 - <i>SMTP Service Extension for Secure SMTP over TLS</i></p>
+
+</dd>
+<dt id="socks"><i>socks</i></dt>
+<dd>
+
+<p>SOCKS versions 4, 4a, and 5 are supported. The SOCKS protocol itself is encapsulated within SSL/TLS encryption layer to protect the final destination address.</p>
+
+<p><i>http://www.openssh.com/txt/socks4.protocol</i></p>
+
+<p><i>http://www.openssh.com/txt/socks4a.protocol</i></p>
+
+<p>The BIND command of the SOCKS protocol is not supported. The USERID parameter is ignored.</p>
+
+<p>See Examples section for sample configuration files for VPN based on SOCKS encryption.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="protocolAuthentication-basic-ntlm"><b>protocolAuthentication</b> = basic | ntlm</dt>
+<dd>
+
+<p>authentication type for protocol negotiations</p>
+
+<p>Currently the authentication type only applies to the &#39;connect&#39; protocol.</p>
+
+<p>default: basic</p>
+
+</dd>
+<dt id="protocolHost-HOST:PORT"><b>protocolHost</b> = HOST:PORT</dt>
+<dd>
+
+<p>destination address for protocol negotiations</p>
+
+<p><i>protocolHost</i> specifies the final SSL server to be connected to by the proxy, and not the proxy server directly connected by <b>stunnel</b>. The proxy server should be specified with the &#39;connect&#39; option.</p>
+
+<p>Currently the protocol destination address only applies to &#39;connect&#39; protocol.</p>
+
+</dd>
+<dt id="protocolPassword-PASSWORD"><b>protocolPassword</b> = PASSWORD</dt>
+<dd>
+
+<p>password for protocol negotiations</p>
+
+</dd>
+<dt id="protocolUsername-USERNAME"><b>protocolUsername</b> = USERNAME</dt>
+<dd>
+
+<p>username for protocol negotiations</p>
+
+</dd>
+<dt id="PSKidentity-IDENTITY"><b>PSKidentity</b> = IDENTITY</dt>
+<dd>
+
+<p>PSK identity for the PSK client</p>
+
+<p><i>PSKidentity</i> can be used on <b>stunnel</b> clients to select the PSK identity used for authentication. This option is ignored in server sections.</p>
+
+<p>default: the first identity specified in the <i>PSKsecrets</i> file.</p>
+
+</dd>
+<dt id="PSKsecrets-FILE"><b>PSKsecrets</b> = FILE</dt>
+<dd>
+
+<p>file with PSK identities and corresponding keys</p>
+
+<p>Each line of the file in the following format:</p>
+
+<pre><code>    IDENTITY:KEY</code></pre>
+
+<p>The key is required to be at least 20 characters long. The file should not be world-readable nor world-writable.</p>
+
+</dd>
+<dt id="pty-yes-no-Unix-only"><b>pty</b> = yes | no (Unix only)</dt>
+<dd>
+
+<p>allocate a pseudoterminal for &#39;exec&#39; option</p>
+
+</dd>
+<dt id="redirect-HOST:-PORT"><b>redirect</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>redirect SSL client connections on certificate-based authentication failures</p>
+
+<p>This option only works in server mode. Some protocol negotiations are also incompatible with the <i>redirect</i> option.</p>
+
+</dd>
+<dt id="renegotiation-yes-no"><b>renegotiation</b> = yes | no</dt>
+<dd>
+
+<p>support SSL renegotiation</p>
+
+<p>Applications of the SSL renegotiation include some authentication scenarios, or re-keying long lasting connections.</p>
+
+<p>On the other hand this feature can facilitate a trivial CPU-exhaustion DoS attack:</p>
+
+<p><i>http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html</i></p>
+
+<p>Please note that disabling SSL renegotiation does not fully mitigate this issue.</p>
+
+<p>default: yes (if supported by <b>OpenSSL</b>)</p>
+
+</dd>
+<dt id="reset-yes-no"><b>reset</b> = yes | no</dt>
+<dd>
+
+<p>attempt to use the TCP RST flag to indicate an error</p>
+
+<p>This option is not supported on some platforms.</p>
+
+<p>default: yes</p>
+
+</dd>
+<dt id="retry-yes-no"><b>retry</b> = yes | no</dt>
+<dd>
+
+<p>reconnect a connect+exec section after it&#39;s disconnected</p>
+
+<p>default: no</p>
+
+</dd>
+<dt id="sessionCacheSize-NUM_ENTRIES"><b>sessionCacheSize</b> = NUM_ENTRIES</dt>
+<dd>
+
+<p>session cache size</p>
+
+<p><i>sessionCacheSize</i> specifies the maximum number of the internal session cache entries.</p>
+
+<p>The value of 0 can be used for unlimited size. It is not recommended for production use due to the risk of a memory exhaustion DoS attack.</p>
+
+</dd>
+<dt id="sessionCacheTimeout-TIMEOUT"><b>sessionCacheTimeout</b> = TIMEOUT</dt>
+<dd>
+
+<p>session cache timeout</p>
+
+<p>This is the number of seconds to keep cached SSL sessions.</p>
+
+</dd>
+<dt id="sessiond-HOST:PORT"><b>sessiond</b> = HOST:PORT</dt>
+<dd>
+
+<p>address of sessiond SSL cache server</p>
+
+</dd>
+<dt id="sslVersion-SSL_VERSION"><b>sslVersion</b> = SSL_VERSION</dt>
+<dd>
+
+<p>select the SSL protocol version</p>
+
+<p>Supported values: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2</p>
+
+<p>Availability of specific protocols depends on the linked OpenSSL library. Older versions of OpenSSL do not support TLSv1.1 and TLSv1.2. Newer versions of OpenSSL do not support SSLv2.</p>
+
+<p>Obsolete SSLv2 and SSLv3 are currently disabled by default. See the <b>options</b> option documentation for details.</p>
+
+</dd>
+<dt id="stack-BYTES-except-for-FORK-model"><b>stack</b> = BYTES (except for FORK model)</dt>
+<dd>
+
+<p>thread stack size</p>
+
+</dd>
+<dt id="TIMEOUTbusy-SECONDS"><b>TIMEOUTbusy</b> = SECONDS</dt>
+<dd>
+
+<p>time to wait for expected data</p>
+
+</dd>
+<dt id="TIMEOUTclose-SECONDS"><b>TIMEOUTclose</b> = SECONDS</dt>
+<dd>
+
+<p>time to wait for close_notify (set to 0 for buggy MSIE)</p>
+
+</dd>
+<dt id="TIMEOUTconnect-SECONDS"><b>TIMEOUTconnect</b> = SECONDS</dt>
+<dd>
+
+<p>time to wait to connect to a remote host</p>
+
+</dd>
+<dt id="TIMEOUTidle-SECONDS"><b>TIMEOUTidle</b> = SECONDS</dt>
+<dd>
+
+<p>time to keep an idle connection</p>
+
+</dd>
+<dt id="transparent-none-source-destination-both-Unix-only"><b>transparent</b> = none | source | destination | both (Unix only)</dt>
+<dd>
+
+<p>enable transparent proxy support on selected platforms</p>
+
+<p>Supported values:</p>
+
+<dl>
+
+<dt id="none"><i>none</i></dt>
+<dd>
+
+<p>Disable transparent proxy support. This is the default.</p>
+
+</dd>
+<dt id="source"><i>source</i></dt>
+<dd>
+
+<p>Re-write the address to appear as if a wrapped daemon is connecting from the SSL client machine instead of the machine running <b>stunnel</b>.</p>
+
+<p>This option is currently available in:</p>
+
+<dl>
+
+<dt id="Remote-mode-connect-option-on-Linux-2.6.28">Remote mode (<i>connect</i> option) on <i>Linux &gt;=2.6.28</i></dt>
+<dd>
+
+<p>This configuration requires <b>stunnel</b> to be executed as root and without the <i>setuid</i> option.</p>
+
+<p>This configuration requires the following setup for iptables and routing (possibly in /etc/rc.local or equivalent file):</p>
+
+<pre><code>    iptables -t mangle -N DIVERT
+    iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT
+    iptables -t mangle -A DIVERT -j MARK --set-mark 1
+    iptables -t mangle -A DIVERT -j ACCEPT
+    ip rule add fwmark 1 lookup 100
+    ip route add local 0.0.0.0/0 dev lo table 100
+    echo 0 &gt;/proc/sys/net/ipv4/conf/lo/rp_filter</code></pre>
+
+<p><b>stunnel</b> must also to be executed as root and without the <i>setuid</i> option.</p>
+
+</dd>
+<dt id="Remote-mode-connect-option-on-Linux-2.2.x">Remote mode (<i>connect</i> option) on <i>Linux 2.2.x</i></dt>
+<dd>
+
+<p>This configuration requires the kernel to be compiled with the <i>transparent proxy</i> option. Connected service must be installed on a separate host. Routing towards the clients has to go through the <b>stunnel</b> box.</p>
+
+<p><b>stunnel</b> must also to be executed as root and without the <i>setuid</i> option.</p>
+
+</dd>
+<dt id="Remote-mode-connect-option-on-FreeBSD-8.0">Remote mode (<i>connect</i> option) on <i>FreeBSD &gt;=8.0</i></dt>
+<dd>
+
+<p>This configuration requires additional firewall and routing setup. <b>stunnel</b> must also to be executed as root and without the <i>setuid</i> option.</p>
+
+</dd>
+<dt id="Local-mode-exec-option">Local mode (<i>exec</i> option)</dt>
+<dd>
+
+<p>This configuration works by pre-loading the <i>libstunnel.so</i> shared library. _RLD_LIST environment variable is used on Tru64, and LD_PRELOAD variable on other platforms.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="destination"><i>destination</i></dt>
+<dd>
+
+<p>The original destination is used instead of the <i>connect</i> option.</p>
+
+<p>A service section for transparent destination may look like this:</p>
+
+<pre><code>    [transparent]
+    client=yes
+    accept=&lt;stunnel_port&gt;
+    transparent=destination</code></pre>
+
+<p>This configuration requires iptables setup to work, possibly in /etc/rc.local or equivalent file.</p>
+
+<p>For a connect target installed on the same host:</p>
+
+<pre><code>    /sbin/iptables -t nat -I OUTPUT -p tcp --dport &lt;redirected_port&gt; \
+        -m ! --uid-owner &lt;stunnel_user_id&gt; \
+        -j DNAT --to-destination &lt;local_ip&gt;:&lt;stunnel_port&gt;</code></pre>
+
+<p>For a connect target installed on a remote host:</p>
+
+<pre><code>    /sbin/iptables -I INPUT -i eth0 -p tcp --dport &lt;stunnel_port&gt; -j ACCEPT
+    /sbin/iptables -t nat -I PREROUTING -p tcp --dport &lt;redirected_port&gt; \
+        -i eth0 -j DNAT --to-destination &lt;local_ip&gt;:&lt;stunnel_port&gt;</code></pre>
+
+<p>The transparent destination option is currently only supported on Linux.</p>
+
+</dd>
+<dt id="both"><i>both</i></dt>
+<dd>
+
+<p>Use both <i>source</i> and <i>destination</i> transparent proxy.</p>
+
+</dd>
+</dl>
+
+<p>Two legacy options are also supported for backward compatibility:</p>
+
+<dl>
+
+<dt id="yes"><i>yes</i></dt>
+<dd>
+
+<p>This option has been renamed to <i>source</i>.</p>
+
+</dd>
+<dt id="no"><i>no</i></dt>
+<dd>
+
+<p>This option has been renamed to <i>none</i>.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="verify-LEVEL"><b>verify</b> = LEVEL</dt>
+<dd>
+
+<p>verify the peer certificate</p>
+
+<dl>
+
+<dt id="level-0">level 0</dt>
+<dd>
+
+<p>Request and ignore the peer certificate.</p>
+
+</dd>
+<dt id="level-1">level 1</dt>
+<dd>
+
+<p>Verify the peer certificate if present.</p>
+
+</dd>
+<dt id="level-2">level 2</dt>
+<dd>
+
+<p>Verify the peer certificate.</p>
+
+</dd>
+<dt id="level-3">level 3</dt>
+<dd>
+
+<p>Verify the peer with locally installed certificate.</p>
+
+</dd>
+<dt id="level-4">level 4</dt>
+<dd>
+
+<p>Ignore the CA chain and only verify the peer certificate.</p>
+
+</dd>
+<dt id="default">default</dt>
+<dd>
+
+<p>No verify.</p>
+
+</dd>
+</dl>
+
+<p>It is important to understand that this option was solely designed for access control and not for authorization. Specifically for level 2 every non-revoked certificate is accepted regardless of its Common Name. For this reason a dedicated CA should be used with level 2, and not a generic CA commonly used for webservers. Level 3 is preferred for point-to-point connections.</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="RETURN-VALUE">RETURN VALUE</h1></a>
+
+<p><b>stunnel</b> returns zero on success, non-zero on error.</p>
+
+<a href="#_podtop_"><h1 id="SIGNALS">SIGNALS</h1></a>
+
+<p>The following signals can be used to control <b>stunnel</b> in Unix environment:</p>
+
+<dl>
+
+<dt id="SIGHUP">SIGHUP</dt>
+<dd>
+
+<p>Force a reload of the configuration file.</p>
+
+<p>Some global options will not be reloaded:</p>
+
+<ul>
+
+<li><p>chroot</p>
+
+</li>
+<li><p>foreground</p>
+
+</li>
+<li><p>pid</p>
+
+</li>
+<li><p>setgid</p>
+
+</li>
+<li><p>setuid</p>
+
+</li>
+</ul>
+
+<p>The use of the &#39;setuid&#39; option will also prevent <b>stunnel</b> from binding to privileged (&lt;1024) ports during configuration reloading.</p>
+
+<p>When the &#39;chroot&#39; option is used, <b>stunnel</b> will look for all its files (including the configuration file, certificates, the log file and the pid file) within the chroot jail.</p>
+
+</dd>
+<dt id="SIGUSR1">SIGUSR1</dt>
+<dd>
+
+<p>Close and reopen the <b>stunnel</b> log file. This function can be used for log rotation.</p>
+
+</dd>
+<dt id="SIGTERM-SIGQUIT-SIGINT">SIGTERM, SIGQUIT, SIGINT</dt>
+<dd>
+
+<p>Shut <b>stunnel</b> down.</p>
+
+</dd>
+</dl>
+
+<p>The result of sending any other signals to the server is undefined.</p>
+
+<a href="#_podtop_"><h1 id="EXAMPLES">EXAMPLES</h1></a>
+
+<p>In order to provide SSL encapsulation to your local <i>imapd</i> service, use:</p>
+
+<pre><code>    [imapd]
+    accept = 993
+    exec = /usr/sbin/imapd
+    execArgs = imapd</code></pre>
+
+<p>or in remote mode:</p>
+
+<pre><code>    [imapd]
+    accept = 993
+    connect = 143</code></pre>
+
+<p>In order to let your local e-mail client connect to an SSL-enabled <i>imapd</i> service on another server, configure the e-mail client to connect to localhost on port 119 and use:</p>
+
+<pre><code>    [imap]
+    client = yes
+    accept = 143
+    connect = servername:993</code></pre>
+
+<p>If you want to provide tunneling to your <i>pppd</i> daemon on port 2020, use something like:</p>
+
+<pre><code>    [vpn]
+    accept = 2020
+    exec = /usr/sbin/pppd
+    execArgs = pppd local
+    pty = yes</code></pre>
+
+<p>If you want to use <b>stunnel</b> in <i>inetd</i> mode to launch your imapd process, you&#39;d use this <i>stunnel.conf</i>. Note there must be no <i>[service_name]</i> section.</p>
+
+<pre><code>    exec = /usr/sbin/imapd
+    execArgs = imapd</code></pre>
+
+<p>To setup SOCKS VPN configure the following client service:</p>
+
+<pre><code>    [socks_client]
+    client = yes
+    accept = 127.0.0.1:1080
+    connect = vpn_server:9080
+    verify = 4
+    CAfile = stunnel.pem</code></pre>
+
+<p>The corresponding configuration on the vpn_server host:</p>
+
+<pre><code>    [socks_server]
+    protocol = socks
+    accept = 9080
+    cert = stunnel.pem
+    key = stunnel.key</code></pre>
+
+<p>Now test your configuration on the client machine with:</p>
+
+<pre><code>    curl --socks4a localhost http://www.example.com/</code></pre>
+
+<a href="#_podtop_"><h1 id="NOTES">NOTES</h1></a>
+
+<h2 id="RESTRICTIONS">RESTRICTIONS</h2>
+
+<p><b>stunnel</b> cannot be used for the FTP daemon because of the nature of the FTP protocol which utilizes multiple ports for data transfers. There are available SSL-enabled versions of FTP and telnet daemons, however.</p>
+
+<h2 id="INETD-MODE">INETD MODE</h2>
+
+<p>The most common use of <b>stunnel</b> is to listen on a network port and establish communication with either a new port via the connect option, or a new program via the <i>exec</i> option. However there is a special case when you wish to have some other program accept incoming connections and launch <b>stunnel</b>, for example with <i>inetd</i>, <i>xinetd</i>, or <i>tcpserver</i>.</p>
+
+<p>For example, if you have the following line in <i>inetd.conf</i>:</p>
+
+<pre><code>    imaps stream tcp nowait root @bindir@/stunnel stunnel @sysconfdir@/stunnel/imaps.conf</code></pre>
+
+<p>In these cases, the <i>inetd</i>-style program is responsible for binding a network socket (<i>imaps</i> above) and handing it to <b>stunnel</b> when a connection is received. Thus you do not want <b>stunnel</b> to have any <i>accept</i> option. All the <i>Service Level Options</i> should be placed in the global options section, and no <i>[service_name]</i> section will be present. See the <i>EXAMPLES</i> section for example configurations.</p>
+
+<h2 id="CERTIFICATES">CERTIFICATES</h2>
+
+<p>Each SSL-enabled daemon needs to present a valid X.509 certificate to the peer. It also needs a private key to decrypt the incoming data. The easiest way to obtain a certificate and a key is to generate them with the free <b>OpenSSL</b> package. You can find more information on certificates generation on pages listed below.</p>
+
+<p>The order of contents of the <i>.pem</i> file is important. It should contain the unencrypted private key first, then a signed certificate (not certificate request). There should also be empty lines after the certificate and the private key. Any plaintext certificate information appended on the top of generated certificate should be discarded. So the file should look like this:</p>
+
+<pre><code>    -----BEGIN RSA PRIVATE KEY-----
+    [encoded key]
+    -----END RSA PRIVATE KEY-----
+    [empty line]
+    -----BEGIN CERTIFICATE-----
+    [encoded certificate]
+    -----END CERTIFICATE-----
+    [empty line]</code></pre>
+
+<h2 id="RANDOMNESS">RANDOMNESS</h2>
+
+<p><b>stunnel</b> needs to seed the PRNG (pseudo-random number generator) in order for SSL to use good randomness. The following sources are loaded in order until sufficient random data has been gathered:</p>
+
+<ul>
+
+<li><p>The file specified with the <i>RNDfile</i> flag.</p>
+
+</li>
+<li><p>The file specified by the RANDFILE environment variable, if set.</p>
+
+</li>
+<li><p>The file .rnd in your home directory, if RANDFILE not set.</p>
+
+</li>
+<li><p>The file specified with &#39;--with-random&#39; at compile time.</p>
+
+</li>
+<li><p>The contents of the screen if running on Windows.</p>
+
+</li>
+<li><p>The egd socket specified with the <i>EGD</i> flag.</p>
+
+</li>
+<li><p>The egd socket specified with &#39;--with-egd-sock&#39; at compile time.</p>
+
+</li>
+<li><p>The /dev/urandom device.</p>
+
+</li>
+</ul>
+
+<p>With recent (<b>OpenSSL 0.9.5a</b> or later) version of SSL it will stop loading random data automatically when sufficient entropy has been gathered. With previous versions it will continue to gather from all the above sources since no SSL function exists to tell when enough data is available.</p>
+
+<p>Note that on Windows machines that do not have console user interaction (mouse movements, creating windows, etc.) the screen contents are not variable enough to be sufficient, and you should provide a random file for use with the <i>RNDfile</i> flag.</p>
+
+<p>Note that the file specified with the <i>RNDfile</i> flag should contain random data -- that means it should contain different information each time <b>stunnel</b> is run. This is handled automatically unless the <i>RNDoverwrite</i> flag is used. If you wish to update this file manually, the <i>openssl rand</i> command in recent versions of <b>OpenSSL</b>, would be useful.</p>
+
+<p>Important note: If /dev/urandom is available, <b>OpenSSL</b> often seeds the PRNG with it while checking the random state. On systems with /dev/urandom <b>OpenSSL</b> is likely to use it even though it is listed at the very bottom of the list above. This is the behaviour of <b>OpenSSL</b> and not <b>stunnel</b>.</p>
+
+<h2 id="DH-PARAMETERS">DH PARAMETERS</h2>
+
+<p><b>stunnel</b> 4.40 and later contains hardcoded 2048-bit DH parameters. Starting with <b>stunnel</b> 5.18, these hardcoded DH parameters are replaced every 24 hours with autogenerated temporary DH parameters. DH parameter generation may take several minutes.</p>
+
+<p>Alternatively, it is possible to specify static DH parameters in the certificate file, which disables generating temporary DH parameters:</p>
+
+<pre><code>    openssl dhparam 2048 &gt;&gt; stunnel.pem</code></pre>
+
+<a href="#_podtop_"><h1 id="FILES">FILES</h1></a>
+
+<dl>
+
+<dt id="sysconfdir-stunnel-stunnel.conf"><i>@sysconfdir@/stunnel/stunnel.conf</i></dt>
+<dd>
+
+<p><b>stunnel</b> configuration file</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="BUGS">BUGS</h1></a>
+
+<p>The <i>execArgs</i> option and the Win32 command line do not support quoting.</p>
+
+<a href="#_podtop_"><h1 id="SEE-ALSO">SEE ALSO</h1></a>
+
+<dl>
+
+<dt id="tcpd-8"><a href="http://man.he.net/man8/tcpd">tcpd(8)</a></dt>
+<dd>
+
+<p>access control facility for internet services</p>
+
+</dd>
+<dt id="inetd-8"><a href="http://man.he.net/man8/inetd">inetd(8)</a></dt>
+<dd>
+
+<p>internet &#39;super-server&#39;</p>
+
+</dd>
+<dt id="http:-www.stunnel.org"><i>http://www.stunnel.org/</i></dt>
+<dd>
+
+<p><b>stunnel</b> homepage</p>
+
+</dd>
+<dt id="http:-www.openssl.org"><i>http://www.openssl.org/</i></dt>
+<dd>
+
+<p><b>OpenSSL</b> project website</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="AUTHOR">AUTHOR</h1></a>
+
+<dl>
+
+<dt id="Micha-Trojnara">Micha&#x142; Trojnara</dt>
+<dd>
+
+<p>&lt;<i>Michal.Trojnara@mirt.net</i>&gt;</p>
+
+</dd>
+</dl>
+
+<table border="0" width="100%" cellspacing="0" cellpadding="3">
+<tr><td class="_podblock_" style="background-color: #cccccc; color: #000" valign="middle">
+<big><strong><span class="_podblock_">&nbsp;stunnel TLS Proxy</span></strong></big>
+</td></tr>
+</table>
+
+</body>
+
+</html>
+
+
diff --git a/doc/stunnel.pl.8.in b/doc/stunnel.pl.8.in
new file mode 100644
index 0000000..23271c2
--- /dev/null
+++ b/doc/stunnel.pl.8.in
@@ -0,0 +1,1283 @@
+.\" Automatically generated by Pod::Man 2.28 (Pod::Simple 3.28)
+.\"
+.\" Standard preamble:
+.\" ========================================================================
+.de Sp \" Vertical space (when we can't use .PP)
+.if t .sp .5v
+.if n .sp
+..
+.de Vb \" Begin verbatim text
+.ft CW
+.nf
+.ne \\$1
+..
+.de Ve \" End verbatim text
+.ft R
+.fi
+..
+.\" Set up some character translations and predefined strings.  \*(-- will
+.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
+.\" double quote, and \*(R" will give a right double quote.  \*(C+ will
+.\" give a nicer C++.  Capital omega is used to do unbreakable dashes and
+.\" therefore won't be available.  \*(C` and \*(C' expand to `' in nroff,
+.\" nothing in troff, for use with C<>.
+.tr \(*W-
+.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
+.ie n \{\
+.    ds -- \(*W-
+.    ds PI pi
+.    if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
+.    if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\"  diablo 12 pitch
+.    ds L" ""
+.    ds R" ""
+.    ds C` ""
+.    ds C' ""
+'br\}
+.el\{\
+.    ds -- \|\(em\|
+.    ds PI \(*p
+.    ds L" ``
+.    ds R" ''
+.    ds C`
+.    ds C'
+'br\}
+.\"
+.\" Escape single quotes in literal strings from groff's Unicode transform.
+.ie \n(.g .ds Aq \(aq
+.el       .ds Aq '
+.\"
+.\" If the F register is turned on, we'll generate index entries on stderr for
+.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
+.\" entries marked with X<> in POD.  Of course, you'll have to process the
+.\" output yourself in some meaningful fashion.
+.\"
+.\" Avoid warning from groff about undefined register 'F'.
+.de IX
+..
+.nr rF 0
+.if \n(.g .if rF .nr rF 1
+.if (\n(rF:(\n(.g==0)) \{
+.    if \nF \{
+.        de IX
+.        tm Index:\\$1\t\\n%\t"\\$2"
+..
+.        if !\nF==2 \{
+.            nr % 0
+.            nr F 2
+.        \}
+.    \}
+.\}
+.rr rF
+.\" ========================================================================
+.\"
+.IX Title "stunnel 8"
+.TH stunnel 8 "2015.07.27" "5.22" "stunnel TLS Proxy"
+.\" For nroff, turn off justification.  Always turn off hyphenation; it makes
+.\" way too many mistakes in technical documents.
+.if n .ad l
+.nh
+.SH "NAZWA"
+.IX Header "NAZWA"
+stunnel \- uniwersalny tunel protokołu \s-1SSL\s0
+.SH "SKŁADNIA"
+.IX Header "SKŁADNIA"
+.IP "\fBUnix:\fR" 4
+.IX Item "Unix:"
+\&\fBstunnel\fR [\s-1PLIK\s0] | \-fd N | \-help | \-version | \-sockets | \-options
+.IP "\fB\s-1WIN32:\s0\fR" 4
+.IX Item "WIN32:"
+\&\fBstunnel\fR [ [ \-install | \-uninstall | \-start | \-stop |
+    \-reload | \-reopen | \-exit ] [\-quiet] [\s-1PLIK\s0] ] |
+    \-help | \-version | \-sockets | \-options
+.SH "OPIS"
+.IX Header "OPIS"
+Program \fBstunnel\fR został zaprojektowany do opakowywania w protokół \fI\s-1SSL\s0\fR
+połączeń pomiędzy zdalnymi klientami a lokalnymi lub zdalnymi serwerami.
+Przez serwer lokalny rozumiana jest aplikacja przeznaczona do uruchamiania
+przy pomocy \fIinetd\fR.
+Stunnel pozwala na proste zestawienie komunikacji serwerów nie posiadających
+funkcjonalności \fI\s-1SSL\s0\fR poprzez bezpieczne kanały \fI\s-1SSL\s0\fR.
+.PP
+\&\fBstunnel\fR pozwala dodać funkcjonalność \fI\s-1SSL\s0\fR do powszechnie stosowanych
+demonów \fIinetd\fR, np. \fIpop3\fR lub \fIimap\fR, do samodzielnych demonów,
+np. \fInntp\fR, \fIsmtp\fR lub \fIhttp\fR, a nawet tunelować ppp poprzez gniazda sieciowe
+bez zmian w kodzie źródłowym.
+.SH "OPCJE"
+.IX Header "OPCJE"
+.IP "\fB\s-1PLIK\s0\fR" 4
+.IX Item "PLIK"
+użyj podanego pliku konfiguracyjnego
+.IP "\fB\-fd N\fR (tylko Unix)" 4
+.IX Item "-fd N (tylko Unix)"
+wczytaj konfigurację z podanego deskryptora pliku
+.IP "\fB\-help\fR" 4
+.IX Item "-help"
+drukuj listę wspieranych opcji
+.IP "\fB\-version\fR" 4
+.IX Item "-version"
+drukuj wersję programu i domyślne wartości parametrów
+.IP "\fB\-sockets\fR" 4
+.IX Item "-sockets"
+drukuj domyślne opcje gniazd
+.IP "\fB\-options\fR" 4
+.IX Item "-options"
+drukuj wspierane opcje \s-1SSL\s0
+.IP "\fB\-install\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-install (tylko Windows NT lub nowszy)"
+instaluj serwis \s-1NT\s0
+.IP "\fB\-uninstall\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-uninstall (tylko Windows NT lub nowszy)"
+odinstaluj serwis \s-1NT\s0
+.IP "\fB\-start\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-start (tylko Windows NT lub nowszy)"
+uruchom serwis \s-1NT\s0
+.IP "\fB\-stop\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-stop (tylko Windows NT lub nowszy)"
+zatrzymaj serwis \s-1NT\s0
+.IP "\fB\-reload\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-reload (tylko Windows NT lub nowszy)"
+przeładuj plik konfiguracyjny uruchomionego serwisu \s-1NT\s0
+.IP "\fB\-reopen\fR (tylko Windows \s-1NT\s0 lub nowszy)" 4
+.IX Item "-reopen (tylko Windows NT lub nowszy)"
+otwórz ponownie log uruchomionego serwisu \s-1NT\s0
+.IP "\fB\-exit\fR (tylko Win32)" 4
+.IX Item "-exit (tylko Win32)"
+zatrzymaj uruchomiony program
+.IP "\fB\-quiet\fR (tylko Win32)" 4
+.IX Item "-quiet (tylko Win32)"
+nie wyświetlaj okienek z komunikatami
+.SH "PLIK KONFIGURACYJNY"
+.IX Header "PLIK KONFIGURACYJNY"
+Linia w pliku konfiguracyjnym może być:
+.IP "\(bu" 4
+pusta (ignorowana)
+.IP "\(bu" 4
+komentarzem rozpoczynającym się znakiem ';' (ignorowana)
+.IP "\(bu" 4
+parą 'nazwa_opcji = wartość_opcji'
+.IP "\(bu" 4
+tekstem '[nazwa_usługi]' wskazującym początek definicji usługi
+.PP
+Parametr adres może być:
+.IP "\(bu" 4
+numerem portu
+.IP "\(bu" 4
+oddzieloną średnikiem parą adresu (IPv4, IPv6, lub nazwą domenową) i numeru portu
+.IP "\(bu" 4
+ścieżką do gniazda Unix (tylko Unix)
+.SS "\s-1OPCJE GLOBALNE\s0"
+.IX Subsection "OPCJE GLOBALNE"
+.IP "\fBchroot\fR = \s-1KATALOG \s0(tylko Unix)" 4
+.IX Item "chroot = KATALOG (tylko Unix)"
+katalog roboczego korzenia systemu plików
+.Sp
+Opcja określa katalog, w którym uwięziony zostanie proces programu
+\&\fBstunnel\fR tuż po jego inicjalizacji, a przed rozpoczęciem odbierania
+połączeń.  Ścieżki podane w opcjach \fICApath\fR, \fICRLpath\fR, \fIpid\fR
+oraz \fIexec\fR muszą być umieszczone wewnątrz katalogu podanego w opcji
+\&\fIchroot\fR i określone względem tego katalogu.
+.Sp
+Niektóre funkcje systemu operacyjnego mogą wymagać dodatkowych plików umieszczonych w katalogu podanego w parametrze chroot:
+.RS 4
+.IP "\(bu" 4
+opóźnione rozwinięcie adresów \s-1DNS\s0 typowo wymaga /etc/nsswitch.conf i /etc/resolv.conf
+.IP "\(bu" 4
+lokalizacja strefy czasowej w logach wymaga pliku /etc/timezone
+.IP "\(bu" 4
+niektóre inne pliki mogą potrzebować plików urządzeń, np. /dev/zero lub /dev/null
+.RE
+.RS 4
+.RE
+.IP "\fBcompression\fR = deflate | zlib" 4
+.IX Item "compression = deflate | zlib"
+wybór algorytmu kompresji przesyłanych danych
+.Sp
+domyślnie: bez kompresji
+.Sp
+Algorytm deflate jest standardową metodą kompresji zgodnie z \s-1RFC 1951.\s0
+.Sp
+Kompresja zlib zaimplementowana w \fBOpenSSL 0.9.8\fR i nowszych nie jest
+kompatybilna implementacją \fBOpenSSL 0.9.7\fR.
+.IP "\fBdebug\fR = [\s-1PODSYSTEM\s0].POZIOM" 4
+.IX Item "debug = [PODSYSTEM].POZIOM"
+szczegółowość logowania
+.Sp
+Poziom logowania można określić przy pomocy jednej z nazw lub liczb:
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6) lub debug (7).
+Zapisywane są komunikaty o poziomie niższym (numerycznie) lub równym podanemu.
+Do uzyskania najwyższego poziomu szczegółowości można użyć opcji
+\&\fIdebug = debug\fR lub \fIdebug = 7\fR.  Domyślnym poziomem jest notice (5).
+.Sp
+O ile nie wyspecyfikowano podsystemu użyty będzie domyślny: daemon.
+Podsystemy nie są wspierane przez platformę Win32.
+.Sp
+Wielkość liter jest ignorowana zarówno dla poziomu jak podsystemu.
+.IP "\fB\s-1EGD\s0\fR = ŚCIEŻKA_DO_EGD (tylko Unix)" 4
+.IX Item "EGD = ŚCIEŻKA_DO_EGD (tylko Unix)"
+ścieżka do gniazda programu Entropy Gathering Daemon
+.Sp
+Opcja pozwala określić ścieżkę do gniazda programu Entropy Gathering Daemon
+używanego do zainicjalizowania generatora ciągów pseudolosowych biblioteki
+\&\fBOpenSSL\fR.  Opcja jest dostępna z biblioteką \fBOpenSSL 0.9.5a\fR lub nowszą.
+.IP "\fBengine\fR = auto | IDENTYFIKATOR_URZĄDZENIA" 4
+.IX Item "engine = auto | IDENTYFIKATOR_URZĄDZENIA"
+wybór sprzętowego urządzenia kryptograficznego
+.Sp
+domyślnie: bez wykorzystania urządzeń kryptograficznych
+.Sp
+Przykładowa konfiguracja umożliwiająca odczytanie klucza prywatnego z
+urządzenia zgodnego z OpenSC:
+.Sp
+.Vb 7
+\&    engine=dynamic
+\&    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+\&    engineCtrl=ID:pkcs11
+\&    engineCtrl=LIST_ADD:1
+\&    engineCtrl=LOAD
+\&    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc\-pkcs11.so
+\&    engineCtrl=INIT
+\&
+\&    [service]
+\&    engineNum=1
+\&    key=id_45
+.Ve
+.IP "\fBengineCtrl\fR = KOMENDA[:PARAMETR]" 4
+.IX Item "engineCtrl = KOMENDA[:PARAMETR]"
+konfiguracja urządzenia kryptograficznego
+.Sp
+Specjalne komendy \*(L"\s-1LOAD\*(R"\s0 i \*(L"\s-1INIT\*(R"\s0 pozwalają na załadowanie i inicjalizację
+modułu kryptograficznego urządzenia.
+.IP "\fBengineDefault\fR = LISTA_ZADAŃ" 4
+.IX Item "engineDefault = LISTA_ZADAŃ"
+lista zadań OpenSSL oddelegowanych do bieżącego urządzenia
+.Sp
+Parametrem jest lista oddzielonych przecinkami zadań OpenSSL, które mają
+zostać oddelegowane do bieżącego urządzenia kryptograficznego.
+.Sp
+W zależności od konkretnego urządzenia dostępne mogą być następujące zadania:
+\&\s-1ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO,
+PKEY_ASN1.\s0
+.IP "\fBfips\fR = yes | no" 4
+.IX Item "fips = yes | no"
+tryb \s-1FIPS 140\-2\s0
+.Sp
+Opcja pozwala wyłączyć wejście w tryb \s-1FIPS,\s0 jeśli \fBstunnel\fR został
+skompilowany ze wsparciem dla \s-1FIPS 140\-2.\s0
+.Sp
+domyślnie: no (od wersji 5.00)
+.IP "\fBforeground\fR = yes | no (tylko Unix)" 4
+.IX Item "foreground = yes | no (tylko Unix)"
+tryb pierwszoplanowy
+.Sp
+Użycie tej opcji powoduje, że \fBstunnel\fR nie przechodzi w tło logując
+swoje komunikaty na konsolę zamiast przez \fIsyslog\fR (o ile nie użyto
+opcji \fIoutput\fR).
+.IP "\fBiconActive\fR = PLIK_Z_IKONKĄ (tylko \s-1GUI\s0)" 4
+.IX Item "iconActive = PLIK_Z_IKONKĄ (tylko GUI)"
+ikonka wyświetlana przy obecności aktywnych połączeń do usługi
+.Sp
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+.IP "\fBiconError\fR = PLIK_Z_IKONKĄ (tylko \s-1GUI\s0)" 4
+.IX Item "iconError = PLIK_Z_IKONKĄ (tylko GUI)"
+ikonka wyświetlana, jeżeli nie został załadowany poprawny plik konfiguracyjny
+.Sp
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+.IP "\fBiconIdle\fR = PLIK_Z_IKONKĄ (tylko \s-1GUI\s0)" 4
+.IX Item "iconIdle = PLIK_Z_IKONKĄ (tylko GUI)"
+ikonka wyświetlana przy braku aktywnych połączeń do usługi
+.Sp
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+.IP "\fBlog\fR = append | overwrite" 4
+.IX Item "log = append | overwrite"
+log file handling
+.Sp
+This option allows to choose whether the log file (specified with the \fIoutput\fR
+option) is appended or overwritten when opened or re-opened.
+.Sp
+domyślnie: append
+.IP "\fBoutput\fR = \s-1PLIK\s0" 4
+.IX Item "output = PLIK"
+plik, do którego dopisane zostaną logi
+.Sp
+Użycie tej opcji powoduje dopisanie logów do podanego pliku.
+.Sp
+Do kierowaniakomunikatów na standardowe wyjście (na przykład po to, żeby
+zalogować je programem splogger z pakietu daemontools) można podać jako
+parametr urządzenie /dev/stdout.
+.IP "\fBpid\fR = \s-1PLIK \s0(tylko Unix)" 4
+.IX Item "pid = PLIK (tylko Unix)"
+położenie pliku z numerem procesu
+.Sp
+Jeżeli argument jest pusty plik nie zostanie stworzony.
+.Sp
+Jeżeli zdefiniowano katalog \fIchroot\fR, to ścieżka do \fIpid\fR jest określona
+względem tego katalogu.
+.IP "\fBRNDbytes\fR = LICZBA_BAJTÓW" 4
+.IX Item "RNDbytes = LICZBA_BAJTÓW"
+liczba bajtów do zainicjowania generatora pseudolosowego
+.Sp
+W wersjach biblioteki \fBOpenSSL\fR starszych niż \fB0.9.5a\fR opcja ta określa
+również liczbę bajtów wystarczających do zainicjowania \s-1PRNG.\s0
+Nowsze wersje biblioteki mają wbudowaną funkcję określającą, czy
+dostarczona ilość losowości jest wystarczająca do zainicjowania generatora.
+.IP "\fBRNDfile\fR = \s-1PLIK\s0" 4
+.IX Item "RNDfile = PLIK"
+ścieżka do pliku zawierającego losowe dane
+.Sp
+Biblioteka \fBOpenSSL\fR użyje danych z tego pliku do zainicjowania
+generatora pseudolosowego.
+.IP "\fBRNDoverwrite\fR = yes | no" 4
+.IX Item "RNDoverwrite = yes | no"
+nadpisz plik nowymi wartościami pseudolosowymi
+.Sp
+domyślnie: yes (nadpisz)
+.IP "\fBservice\fR = \s-1SERWIS \s0(tylko Unix)" 4
+.IX Item "service = SERWIS (tylko Unix)"
+nazwa usługi
+.Sp
+Podana nazwa usługi będzie używana jako nazwa usługi dla inicjalizacji sysloga,
+oraz dla biblioteki \s-1TCP\s0 Wrapper w trybie \fIinetd\fR.  Chociaż technicznie można
+użyć tej opcji w trybie w sekcji usług, to jest ona użyteczna jedynie w opcjach
+globalnych.
+.Sp
+domyślnie: stunnel
+.IP "\fBsetgid\fR = \s-1IDENTYFIKATOR_GRUPY \s0(tylko Unix)" 4
+.IX Item "setgid = IDENTYFIKATOR_GRUPY (tylko Unix)"
+grupa z której prawami pracował będzie \fBstunnel\fR
+.IP "\fBsetuid\fR = IDENTYFIKATOR_UŻYTKOWNIKA (tylko Unix)" 4
+.IX Item "setuid = IDENTYFIKATOR_UŻYTKOWNIKA (tylko Unix)"
+użytkownik, z którego prawami pracował będzie \fBstunnel\fR
+.IP "\fBsocket\fR = a|l|r:OPCJA=WARTOŚĆ[:WARTOŚĆ]" 4
+.IX Item "socket = a|l|r:OPCJA=WARTOŚĆ[:WARTOŚĆ]"
+ustaw opcję na akceptującym/lokalnym/zdalnym gnieździe
+.Sp
+Dla opcji linger wartości mają postać l_onof:l_linger.
+Dla opcji time wartości mają postać tv_sec:tv_usec.
+.Sp
+Przykłady:
+.Sp
+.Vb 10
+\&    socket = l:SO_LINGER=1:60
+\&        ustaw jednominutowe przeterminowanie
+\&        przy zamykaniu lokalnego gniazda
+\&    socket = r:SO_OOBINLINE=yes
+\&        umieść dane pozapasmowe (out\-of\-band)
+\&        bezpośrednio w strumieniu danych
+\&        wejściowych dla zdalnych gniazd
+\&    socket = a:SO_REUSEADDR=no
+\&        zablokuj ponowne używanie portu
+\&        (domyślnie włączone)
+\&    socket = a:SO_BINDTODEVICE=lo
+\&        przyjmuj połączenia wyłącznie na
+\&        interfejsie zwrotnym (ang. loopback)
+.Ve
+.IP "\fBsyslog\fR = yes | no (tylko Unix)" 4
+.IX Item "syslog = yes | no (tylko Unix)"
+włącz logowanie poprzez mechanizm syslog
+.Sp
+domyślnie: yes (włącz)
+.IP "\fBtaskbar\fR = yes | no (tylko \s-1WIN32\s0)" 4
+.IX Item "taskbar = yes | no (tylko WIN32)"
+włącz ikonkę w prawym dolnym rogu ekranu
+.Sp
+domyślnie: yes (włącz)
+.SS "\s-1OPCJE\s0 USŁUG"
+.IX Subsection "OPCJE USŁUG"
+Każda sekcja konfiguracji usługi zaczyna się jej nazwą ujętą w nawias
+kwadratowy.  Nazwa usługi używana jest do kontroli dostępu przez
+bibliotekę libwrap (\s-1TCP\s0 wrappers) oraz pozwala rozróżnić poszczególne
+usługi w logach.
+.PP
+Jeżeli \fBstunnel\fR ma zostać użyty w trybie \fIinetd\fR, gdzie za odebranie
+połączenia odpowiada osobny program (zwykle \fIinetd\fR, \fIxinetd\fR
+lub \fItcpserver\fR), należy przeczytać sekcję \fI\s-1TRYB INETD\s0\fR poniżej.
+.IP "\fBaccept\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "accept = [HOST:]PORT"
+nasłuchuje na połączenia na podanym adresie i porcie
+.Sp
+Jeżeli nie został podany adres, \fBstunnel\fR domyślnie nasłuchuje
+na wszystkich adresach IPv4 lokalnych interfejsów.
+.Sp
+Aby nasłuchiwać na wszystkich adresach IPv6 należy użyć:
+.Sp
+.Vb 1
+\&    accept = :::port
+.Ve
+.IP "\fBCApath\fR = \s-1KATALOG_CA\s0" 4
+.IX Item "CApath = KATALOG_CA"
+katalog Centrum Certyfikacji
+.Sp
+Opcja określa katalog, w którym \fBstunnel\fR będzie szukał certyfikatów,
+jeżeli użyta została opcja \fIverify\fR.  Pliki z certyfikatami muszą
+posiadać specjalne nazwy \s-1XXXXXXXX.0,\s0 gdzie \s-1XXXXXXXX\s0 jest skrótem
+kryptograficznym reprezentacji \s-1DER\s0 nazwy podmiotu certyfikatu.
+.Sp
+Funkcja skrótu została zmieniona w \fBOpenSSL 1.0.0\fR.
+Należy wykonać c_rehash przy zmianie \fBOpenSSL 0.x.x\fR na \fB1.x.x\fR.
+.Sp
+Jeżeli zdefiniowano katalog \fIchroot\fR, to ścieżka do \fICApath\fR jest określona
+względem tego katalogu.
+.IP "\fBCAfile\fR = \s-1PLIK_CA\s0" 4
+.IX Item "CAfile = PLIK_CA"
+plik Centrum Certyfikacji
+.Sp
+Opcja pozwala określić położenie pliku zawierającego certyfikaty używane
+przez opcję \fIverify\fR.
+.IP "\fBcert\fR = \s-1PLIK_PEM\s0" 4
+.IX Item "cert = PLIK_PEM"
+plik z łańcuchem certyfikatów
+.Sp
+Opcja określa położenie pliku zawierającego certyfikaty używane przez
+program \fBstunnel\fR do uwierzytelnienia się przed drugą stroną połączenia.
+Certyfikat jest konieczny, aby używać programu w trybie serwera.
+W trybie klienta certyfikat jest opcjonalny.
+.IP "\fBcheckEmail\fR = \s-1EMAIL\s0" 4
+.IX Item "checkEmail = EMAIL"
+adres email przedstawionego certyfikatu
+.Sp
+Pojedyncza sekcja może zawierać wiele wystąpień opcji \fBcheckEmail\fR.
+Certyfikaty są akceptowane, jeżeli sekcja nie zawiera opcji \fBcheckEmail\fR,
+albo adres email przedstawionego certyfikatu pasuje do jednego z adresów
+email określonych przy pomocy \fBcheckEmail\fR.
+.IP "\fBcheckHost\fR = \s-1NAZWA_SERWERA\s0" 4
+.IX Item "checkHost = NAZWA_SERWERA"
+nazwa serwera przedstawionego certyfikatu
+.Sp
+Pojedyncza sekcja może zawierać wiele wystąpień opcji \fBcheckHost\fR.
+Certyfikaty są akceptowane, jeżeli sekcja nie zawiera opcji \fBcheckHost\fR, albo
+nazwa serwera przedstawionego certyfikatu pasuje do jednego nazw określonych
+przy pomocy \fBcheckHost\fR.
+.IP "\fBcheckIP\fR = \s-1IP\s0" 4
+.IX Item "checkIP = IP"
+adres \s-1IP\s0 przedstawionego certyfikatu
+.Sp
+Pojedyncza sekcja może zawierać wiele wystąpień opcji \fBcheckIP\fR.  Certyfikaty
+są akceptowane, jeżeli sekcja nie zawiera opcji \fBcheckIP\fR, albo adres \s-1IP\s0
+przedstawionego certyfikatu pasuje do jednego z adresów \s-1IP\s0 określonych przy
+pomocy \fBcheckIP\fR.
+.IP "\fBciphers\fR = LISTA_SZYFRÓW" 4
+.IX Item "ciphers = LISTA_SZYFRÓW"
+lista dozwolonych szyfrów \s-1SSL\s0
+.Sp
+Parametrem tej opcji jest lista szyfrów, które będą użyte przy
+otwieraniu nowych połączeń \s-1SSL,\s0 np.:  \s-1DES\-CBC3\-SHA:IDEA\-CBC\-MD5\s0
+.IP "\fBclient\fR = yes | no" 4
+.IX Item "client = yes | no"
+tryb kliencki (zdalna usługa używa \s-1SSL\s0)
+.Sp
+domyślnie: no (tryb serwerowy)
+.IP "\fBconnect\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "connect = [HOST:]PORT"
+połącz się ze zdalnym serwerem na podany port
+.Sp
+Jeżeli nie został podany adres, \fBstunnel\fR domyślnie łączy się
+z lokalnym serwerem.
+.Sp
+Komenda może byc użyta wielokrotnie w pojedynczej sekcji
+celem zapewnienia wysokiej niezawodności lub rozłożenia
+ruchu pomiędzy wiele serwerów.
+.IP "\fBCRLpath\fR = \s-1KATALOG_CRL\s0" 4
+.IX Item "CRLpath = KATALOG_CRL"
+katalog List Odwołanych Certyfikatów (\s-1CRL\s0)
+.Sp
+Opcja określa katalog, w którym \fBstunnel\fR będzie szukał list \s-1CRL,\s0
+jeżeli użyta została opcja \fIverify\fR.  Pliki z listami \s-1CRL\s0 muszą
+posiadać specjalne nazwy \s-1XXXXXXXX\s0.r0, gdzie \s-1XXXXXXXX\s0 jest skrótem
+listy \s-1CRL.\s0
+.Sp
+Funkcja skrótu została zmieniona \fBOpenSSL 1.0.0\fR.
+Należy wykonać c_rehash przy zmianie \fBOpenSSL 0.x.x\fR na \fB1.x.x\fR.
+.Sp
+Jeżeli zdefiniowano katalog \fIchroot\fR, to ścieżka do \fICRLpath\fR jest określona
+względem tego katalogu.
+.IP "\fBCRLfile\fR = \s-1PLIK_CRL\s0" 4
+.IX Item "CRLfile = PLIK_CRL"
+plik List Odwołanych Certyfikatów (\s-1CRL\s0)
+.Sp
+Opcja pozwala określić położenie pliku zawierającego listy \s-1CRL\s0 używane
+przez opcję \fIverify\fR.
+.IP "\fBcurve\fR = \s-1NID\s0" 4
+.IX Item "curve = NID"
+krzywa dla \s-1ECDH\s0
+.Sp
+Listę dostępnych krzywych można uzyskać poleceniem:
+.Sp
+.Vb 1
+\&    openssl ecparam \-list_curves
+.Ve
+.Sp
+domyślnie: prime256v1
+.IP "\fBlogId\fR = \s-1TYP\s0" 4
+.IX Item "logId = TYP"
+typ identyfikatora połączenia klienta
+.Sp
+Identyfikator ten pozwala rozróżnić wpisy w logu wygenerowane dla
+poszczególnych połączeń.
+.Sp
+Aktualnie wspierane typy:
+.RS 4
+.IP "\fIsequential\fR" 4
+.IX Item "sequential"
+Kolejny numer połączenia jest unikalny jedynie w obrębie pojedynczej instancji
+programu \fBstunnel\fR, ale bardzo krótki.  Jest on szczególnie użytczny przy
+ręcznej analizie logów.
+.IP "\fIunique\fR" 4
+.IX Item "unique"
+Ten rodzaj identyfikatora jest globalnie unikalny, ale znacznie dłuższy, niż
+kolejny numer połączenia.  Jest on szczególnie użyteczny przy zautomatyzowanej
+analizie logów.
+.IP "\fIthread\fR" 4
+.IX Item "thread"
+Identyfikator wątku systemu operacyjnego nie jest ani unikalny (nawet w obrębie
+pojedynczej instancji programu \fBstunnel\fR), ani krótki.  Jest on szczególnie
+użyteczny przy diagnozowaniu problemów z oprogramowaniem lub konfiguracją.
+.RE
+.RS 4
+.Sp
+domyślnie: sequential
+.RE
+.IP "\fBdebug\fR = \s-1POZIOM\s0" 4
+.IX Item "debug = POZIOM"
+szczegółowość logowania
+.Sp
+Poziom logowania można określić przy pomocy jednej z nazw lub liczb:
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6) lub debug (7).
+Zapisywane są komunikaty o poziomie niższym (numerycznie) lub równym podanemu.
+Do uzyskania najwyższego poziomu szczegółowości można użyć opcji
+\&\fIdebug = debug\fR lub \fIdebug = 7\fR.  Domyślnym poziomem jest notice (5).
+.IP "\fBdelay\fR = yes | no" 4
+.IX Item "delay = yes | no"
+opóźnij rozwinięcie adresu \s-1DNS\s0 podanego w opcji \fIconnect\fR
+.Sp
+Opcja jest przydatna przy dynamicznym \s-1DNS,\s0 albo gdy usługa \s-1DNS\s0 nie jest
+dostępna przy starcie programu \fBstunnel\fR (klient \s-1VPN,\s0 połączenie wdzwaniane).
+.Sp
+Opóźnione rozwijanie adresu \s-1DNS\s0 jest włączane automatycznie, jeżeli nie
+powiedzie się rozwinięcie któregokolwiek z adresów \fIconnect\fR dla danej
+usługi.
+.Sp
+Opóźnione rozwijanie adresu automatycznie aktywuje \fIfailover = prio\fR.
+.Sp
+default: no
+.IP "\fBengineId\fR = NUMER_URZĄDZENIA" 4
+.IX Item "engineId = NUMER_URZĄDZENIA"
+wybierz urządzenie dla usługi
+.IP "\fBengineNum\fR = NUMER_URZĄDZENIA" 4
+.IX Item "engineNum = NUMER_URZĄDZENIA"
+wybierz urządzenie dla usługi
+.Sp
+Urządzenia są numerowane od 1 w górę.
+.IP "\fBexec\fR = ŚCIEŻKA_DO_PROGRAMU" 4
+.IX Item "exec = ŚCIEŻKA_DO_PROGRAMU"
+wykonaj lokalny program przystosowany do pracy z superdemonem inetd
+.Sp
+Jeżeli zdefiniowano katalog \fIchroot\fR, to ścieżka do \fIexec\fR jest określona
+względem tego katalogu.
+.Sp
+Na platformach Unix ustawiane są następujące zmienne środowiskowe:
+\&\s-1REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.\s0
+.ie n .IP "\fBexecArgs\fR = $0 $1 $2 ..." 4
+.el .IP "\fBexecArgs\fR = \f(CW$0\fR \f(CW$1\fR \f(CW$2\fR ..." 4
+.IX Item "execArgs = $0 $1 $2 ..."
+argumenty do opcji \fIexec\fR włącznie z nazwą programu ($0)
+.Sp
+Cytowanie nie jest wspierane w obecnej wersji programu.
+Argumenty są rozdzielone dowolną liczbą białych znaków.
+.IP "\fBfailover\fR = rr | prio" 4
+.IX Item "failover = rr | prio"
+Strategia wybierania serwerów wyspecyfikowanych parametrami \*(L"connect\*(R".
+.Sp
+.Vb 2
+\&    rr (round robin) \- sprawiedliwe rozłożenie obciążenia
+\&    prio (priority) \- użyj kolejności opcji w pliku konfiguracyjnym
+.Ve
+.Sp
+domyślnie: rr
+.IP "\fBident\fR = NAZWA_UŻYTKOWNIKA" 4
+.IX Item "ident = NAZWA_UŻYTKOWNIKA"
+weryfikuj nazwę zdalnego użytkownika korzystając z protokołu \s-1IDENT \s0(\s-1RFC 1413\s0)
+.IP "\fBinclude\fR = \s-1KATALOG\s0" 4
+.IX Item "include = KATALOG"
+wczytaj fragmenty plików konfiguracyjnych z podanego katalogu
+.Sp
+Pliki są wczytywane w rosnącej kolejności alfabetycznej ich nazw.
+.IP "\fBkey\fR = \s-1PLIK_KLUCZA\s0" 4
+.IX Item "key = PLIK_KLUCZA"
+klucz prywatny do certyfikatu podanego w opcji \fIcert\fR
+.Sp
+Klucz prywatny jest potrzebny do uwierzytelnienia właściciela certyfikatu.
+Ponieważ powinien on być zachowany w tajemnicy, prawa do jego odczytu
+powinien mieć wyłącznie właściciel pliku.  W systemie Unix można to osiągnąć
+komendą:
+.Sp
+.Vb 1
+\&    chmod 600 keyfile
+.Ve
+.Sp
+domyślnie: wartość opcji \fIcert\fR
+.IP "\fBlibwrap\fR = yes | no" 4
+.IX Item "libwrap = yes | no"
+włącz lub wyłącz korzystanie z /etc/hosts.allow i /etc/hosts.deny.
+.Sp
+domyślnie: no (od wersji 5.00)
+.IP "\fBlocal\fR = \s-1HOST\s0" 4
+.IX Item "local = HOST"
+\&\s-1IP\s0 źródła do nawiązywania zdalnych połączeń
+.Sp
+Domyślnie używane jest \s-1IP\s0 najbardziej zewnętrznego interfejsu w stronę
+serwera, do którego nawiązywane jest połączenie.
+.IP "\fBsni\fR = USŁUGA:WZORZEC_NAZWY_SERWERA (tryb serwera)" 4
+.IX Item "sni = USŁUGA:WZORZEC_NAZWY_SERWERA (tryb serwera)"
+Użyj usługi jako podrzędnej (virtualnego serwera) dla rozszerzenia \s-1TLS\s0 Server
+Name Indication (\s-1RFC 3546\s0).
+.Sp
+\&\fInazwa_usługi\fR wskazuje usługę nadrzędną, która odbiera połączenia od klientów
+przy pomocy opcji \fIaccept\fR.  \fIwzorzec_nazwy_serwera\fR wskazuje nazwę serwera
+wirtualnego.  Wzorzec może zaczynać się znakiem '*', np. '*.example.com".
+Z pojedyńczą usługą nadrzędną powiązane jest zwykle wiele usług podrzędnych.
+Opcja \fIsni\fR może być rownież użyta wielokrotnie w ramach jednej usługi
+podrzędnej.
+.Sp
+Zarówno usługa nadrzędna jak i podrzędna nie może być skonfigurowana w trybie
+klienckim.
+.Sp
+Opcja \fIconnect\fR usługi podrzędnej jest ignorowana w połączeniu z opcją
+\&\fIprotocol\fR, gdyż połączenie do zdalnego serwera jest w tym wypadku nawiązywane
+przed negocjacją \s-1TLS.\s0
+.Sp
+Uwierzytelnienie przy pomocy biblioteki libwrap jest realizowane dwukrotnie:
+najpierw dla usługi nadrzędnej po odebraniu połączenia \s-1TCP,\s0 a następnie dla
+usługi podrzędnej podczas negocjacji \s-1TLS.\s0
+.Sp
+Opcja \fIsni\fR jest dostępna począwszy od \fBOpenSSL 1.0.0\fR.
+.IP "\fBsni\fR = \s-1HOST \s0(tryb klienta)" 4
+.IX Item "sni = HOST (tryb klienta)"
+Użyj parametru jako wartości rozszerzenia \s-1TLS\s0 Server Name Indication
+(\s-1RFC 3546\s0).
+.Sp
+Opcja \fIsni\fR jest dostępna począwszy od \fBOpenSSL 1.0.0\fR.
+.IP "\fB\s-1OCSP\s0\fR = \s-1URL\s0" 4
+.IX Item "OCSP = URL"
+serwer \s-1OCSP\s0 do weryfikacji certyfikatów
+.IP "\fBOCSPaia\fR = yes | no" 4
+.IX Item "OCSPaia = yes | no"
+weryfikuj certyfikaty przy użyciu respondertów \s-1AIA\s0
+.Sp
+Opcja \fIOCSPaia\fR pozwala na weryfikowanie certyfikatów przy pomocy listy URLi
+serwerów \s-1OCSP\s0 przesłanych w rozszerzeniach \s-1AIA \s0(Authority Information Access).
+.IP "\fBOCSPflag\fR = \s-1FLAGA_OCSP\s0" 4
+.IX Item "OCSPflag = FLAGA_OCSP"
+flaga serwera \s-1OCSP\s0
+.Sp
+aktualnie wspierane flagi: \s-1NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY,
+NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME\s0
+.Sp
+Aby wyspecyfikować kilka flag należy użyć \fIOCSPflag\fR wielokrotnie.
+.IP "\fBoptions\fR = \s-1OPCJE_SSL\s0" 4
+.IX Item "options = OPCJE_SSL"
+opcje biblioteki \fBOpenSSL\fR
+.Sp
+Parametrem jest nazwa opcji zgodnie z opisem w \fI\fISSL_CTX_set_options\fI\|(3ssl)\fR,
+ale bez przedrostka \fI\s-1SSL_OP_\s0\fR.
+\&\fIstunnel \-options\fR wyświetla opcje dozwolone w aktualnej kombinacji
+programu \fIstunnel\fR i biblioteki \fIOpenSSL\fR.
+.Sp
+Aby wyspecyfikować kilka opcji należy użyć \fIoptions\fR wielokrotnie.
+Nazwa opcji może być poprzedzona myślnikiem (\*(L"\-\*(R") celem wyłączenia opcji.
+.Sp
+Na przykład, dla zachowania kompatybilności z błędami implementacji \s-1SSL\s0
+w programie Eudora, można użyć opcji:
+.Sp
+.Vb 1
+\&    options = DONT_INSERT_EMPTY_FRAGMENTS
+.Ve
+.Sp
+domyślnie:
+.Sp
+.Vb 2
+\&    options = NO_SSLv2
+\&    options = NO_SSLv3
+.Ve
+.IP "\fBprotocol\fR = PROTOKÓŁ" 4
+.IX Item "protocol = PROTOKÓŁ"
+negocjuj \s-1SSL\s0 podanym protokołem aplikacyjnym
+.Sp
+Opcja ta włącza wstępną negocjację szyfrowania \s-1SSL\s0 dla wybranego protokołu
+aplikacyjnego.
+Opcji \fIprotocol\fR nie należy używać z szyfrowaniem \s-1SSL\s0 na osobnym porcie.
+.Sp
+Aktualnie wspierane protokoły:
+.RS 4
+.IP "\fIcifs\fR" 4
+.IX Item "cifs"
+Unieudokumentowane rozszerzenie protokołu \s-1CIFS\s0 wspierane przez serwer Samba.
+Wsparcie dla tego rozrzeczenia zostało zarzucone w wersji 3.0.0 serwera Samba.
+.IP "\fIconnect\fR" 4
+.IX Item "connect"
+Negocjacja \s-1RFC 2817 \- \s0\fIUpgrading to \s-1TLS\s0 Within \s-1HTTP/1.1\s0\fR, rozdział 5.2 \- \fIRequesting a Tunnel with \s-1CONNECT\s0\fR
+.Sp
+Ten protokół jest wspierany wyłącznie w trybie klienckim.
+.IP "\fIimap\fR" 4
+.IX Item "imap"
+Negocjacja \s-1RFC 2595 \- \s0\fIUsing \s-1TLS\s0 with \s-1IMAP, POP3\s0 and \s-1ACAP\s0\fR
+.IP "\fInntp\fR" 4
+.IX Item "nntp"
+Negocjacja \s-1RFC 4642 \- \s0\fIUsing Transport Layer Security (\s-1TLS\s0) with Network News Transfer Protocol (\s-1NNTP\s0)\fR
+.Sp
+Ten protokół jest wspierany wyłącznie w trybie klienckim.
+.IP "\fIpgsql\fR" 4
+.IX Item "pgsql"
+Negocjacja http://www.postgresql.org/docs/8.3/static/protocol\-flow.html#AEN73982
+.IP "\fIpop3\fR" 4
+.IX Item "pop3"
+Negocjacja \s-1RFC 2449 \- \s0\fI\s-1POP3\s0 Extension Mechanism\fR
+.IP "\fIproxy\fR" 4
+.IX Item "proxy"
+Przekazywanie adresu \s-1IP\s0 haproxy http://haproxy.1wt.eu/download/1.5/doc/proxy\-protocol.txt
+.IP "\fIsmtp\fR" 4
+.IX Item "smtp"
+Negocjacja \s-1RFC 2487 \- \s0\fI\s-1SMTP\s0 Service Extension for Secure \s-1SMTP\s0 over \s-1TLS\s0\fR
+.IP "\fIsocks\fR" 4
+.IX Item "socks"
+Wspierany jest protokół \s-1SOCKS\s0 w wersjach 4, 4a i 5.
+Protokół \s-1SOCKS\s0 enkapsulowany jest w protokole \s-1SSL/TLS,\s0 więc adres serwera
+docelowego nie jest widoczny dla napastnika przechwytującego ruch sieciowy.
+.Sp
+\&\fIhttp://www.openssh.com/txt/socks4.protocol\fR
+.Sp
+\&\fIhttp://www.openssh.com/txt/socks4a.protocol\fR
+.Sp
+Nie jest wspierana komenda \s-1BIND\s0 protokołu \s-1SOCKS.\s0
+Przesłana wartość parametru \s-1USERID\s0 jest ignorowana.
+.Sp
+Sekcja PRZYKŁADY zawiera przykładowe pliki konfiguracyjne VPNa zbudowanego
+w oparciu o szyfrowany protokół \s-1SOCKS.\s0
+.RE
+.RS 4
+.RE
+.IP "\fBprotocolAuthentication\fR = basic | ntlm" 4
+.IX Item "protocolAuthentication = basic | ntlm"
+rodzaj uwierzytelnienia do negocjacji protokołu
+.Sp
+Obecnie typ uwierzytelnienia ma zastosowanie wyłącznie w protokole 'connect'.
+.Sp
+domyślnie: basic
+.IP "\fBprotocolHost\fR = \s-1HOST:PORT\s0" 4
+.IX Item "protocolHost = HOST:PORT"
+adres docelowy do negocjacji protokołu
+.Sp
+\&\fIprotocolHost\fR określa docelowy serwer \s-1SSL,\s0 do którego połączyć ma się proxy.
+Nie jest to adres serwera proxy, do którego połączenie zestawia \fBstunnel\fR.
+Adres serwera proxy powinien być określony przy pomocy opcji 'connect'.
+.Sp
+W obecnej wersji adres docelowy protokołu ma zastosowanie wyłącznie w protokole
+\&'connect'.
+.IP "\fBprotocolPassword\fR = HASŁO" 4
+.IX Item "protocolPassword = HASŁO"
+hasło do negocjacji protokołu
+.IP "\fBprotocolUsername\fR = UŻYTKOWNIK" 4
+.IX Item "protocolUsername = UŻYTKOWNIK"
+nazwa użytkownika do negocjacji protokołu
+.IP "\fBPSKidentity\fR = TOŻSAMOŚĆ" 4
+.IX Item "PSKidentity = TOŻSAMOŚĆ"
+tożsamość klienta \s-1PSK\s0
+.Sp
+\&\fIPSKidentity\fR może zostać użyte w sekcjach klienckich do wybrania
+tożsamości użytej do uwierzytelnienia \s-1PSK.\s0
+Opcja jest ignorowana w sekcjach serwerowych.
+.Sp
+domyślnie: pierwsza tożsamość zdefiniowana w pliku \fIPSKsecrets\fR
+.IP "\fBPSKsecrets\fR = \s-1PLIK\s0" 4
+.IX Item "PSKsecrets = PLIK"
+plik z tożsamościami i kluczami \s-1PSK\s0
+.Sp
+Każda linia pliku jest w następującym formacie:
+.Sp
+.Vb 1
+\&    TOŻSAMOŚĆ:KLUCZ
+.Ve
+.Sp
+Klucz musi być mieć przynajmniej 20 znaków.
+Należy ograniczyć dostęp do czytania lub pisania do tego pliku.
+.IP "\fBpty\fR = yes | no (tylko Unix)" 4
+.IX Item "pty = yes | no (tylko Unix)"
+alokuj pseudoterminal dla programu uruchamianego w opcji 'exec'
+.IP "\fBredirect\fR = [\s-1HOST:\s0]PORT" 4
+.IX Item "redirect = [HOST:]PORT"
+przekieruj klienta, któremu nie udało się poprawnie uwierzytelnić przy pomocy certyfikatu
+.Sp
+Opcja działa wyłącznie w trybie serwera.
+Część negocjacji protokołów jest niekompatybilna z opcją \fIredirect\fR.
+.IP "\fBrenegotiation\fR = yes | no" 4
+.IX Item "renegotiation = yes | no"
+pozwalaj na renegocjację \s-1SSL\s0
+.Sp
+Wśród zastosowań renegocjacji \s-1SSL\s0 są niektóre scenariusze uwierzytelnienia,
+oraz renegocjacja kluczy dla długotrwałych połączeń.
+.Sp
+Z drugiej strony własność na może ułatwić trywialny atak DoS poprzez
+wygenerowanie obciążenia procesora:
+.Sp
+http://vincent.bernat.im/en/blog/2011\-ssl\-dos\-mitigation.html
+.Sp
+Warto zauważyć, że zablokowanie renegocjacji \s-1SSL\s0 nie zebezpiecza w pełni
+przed opisanym problemem.
+.Sp
+domyślnie: yes (o ile wspierane przez \fBOpenSSL\fR)
+.IP "\fBreset\fR = yes | no" 4
+.IX Item "reset = yes | no"
+sygnalizuj wystąpienie błędu przy pomocy flagi \s-1TCP RST\s0
+.Sp
+Opcja nie jest wspierana na niektórych platformach.
+.Sp
+domyślnie: yes
+.IP "\fBretry\fR = yes | no" 4
+.IX Item "retry = yes | no"
+połącz ponownie sekcję connect+exec po rozłączeniu
+.Sp
+domyślnie: no
+.IP "\fBsessionCacheSize\fR = \s-1LICZBA_POZYCJI_CACHE\s0" 4
+.IX Item "sessionCacheSize = LICZBA_POZYCJI_CACHE"
+rozmiar pamięci podręcznej sesji \s-1SSL\s0
+.Sp
+Parametr określa maksymalną liczbę pozycji wewnętrznej pamięci podręcznej
+sesji.
+.Sp
+Wartość 0 oznacza brak ograniczenia rozmiaru.  Nie jest to zalecane dla
+systemów produkcyjnych z uwagi na ryzyko ataku DoS przez wyczerpanie pamięci
+\&\s-1RAM.\s0
+.IP "\fBsessionCacheTimeout\fR = \s-1LICZBA_SEKUND\s0" 4
+.IX Item "sessionCacheTimeout = LICZBA_SEKUND"
+przeterminowanie pamięci podręcznej sesji \s-1SSL\s0
+.Sp
+Parametr określa czas w sekundach, po którym sesja \s-1SSL\s0 zostanie usunięta z
+pamięci podręcznej.
+.IP "\fBsessiond\fR = \s-1HOST:PORT\s0" 4
+.IX Item "sessiond = HOST:PORT"
+adres sessiond \- servera cache sesji \s-1SSL\s0
+.IP "\fBsslVersion\fR = \s-1WERSJA_SSL\s0" 4
+.IX Item "sslVersion = WERSJA_SSL"
+wersja protokołu \s-1SSL\s0
+.Sp
+Wspierane opcje: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2
+.Sp
+Dostępność konkretnych protokołów zależy od użytej wersji OpenSSL.
+Starsze wersje OpenSSL nie wspierają TLSv1.1 i TLSv1.2.
+Nowsze wersje OpenSSL nie wspierają SSLv2.
+.Sp
+Przestarzałe protokoły SSLv2 i SSLv3 są domyślnie wyłączone.
+Szczegółowe informacje dostępne są w opisie opcji \fBoptions\fR.
+.IP "\fBstack\fR = LICZBA_BAJTÓW (z wyjątkiem modelu \s-1FORK\s0)" 4
+.IX Item "stack = LICZBA_BAJTÓW (z wyjątkiem modelu FORK)"
+rozmiar stosu procesora wątku
+.IP "\fBTIMEOUTbusy\fR = \s-1LICZBA_SEKUND\s0" 4
+.IX Item "TIMEOUTbusy = LICZBA_SEKUND"
+czas oczekiwania na spodziewane dane
+.IP "\fBTIMEOUTclose\fR = \s-1LICZBA_SEKUND\s0" 4
+.IX Item "TIMEOUTclose = LICZBA_SEKUND"
+czas oczekiwania na close_notify (ustaw na 0, jeżeli klientem jest \s-1MSIE\s0)
+.IP "\fBTIMEOUTconnect\fR = \s-1LICZBA_SEKUND\s0" 4
+.IX Item "TIMEOUTconnect = LICZBA_SEKUND"
+czas oczekiwania na nawiązanie połączenia
+.IP "\fBTIMEOUTidle\fR = \s-1LICZBA_SEKUND\s0" 4
+.IX Item "TIMEOUTidle = LICZBA_SEKUND"
+maksymalny czas utrzymywania bezczynnego połączenia
+.IP "\fBtransparent\fR = none | source | destination | both (tylko Unix)" 4
+.IX Item "transparent = none | source | destination | both (tylko Unix)"
+tryb przezroczystego proxy na wspieranych platformach
+.Sp
+Wspierane opcje:
+.RS 4
+.IP "\fBnone\fR" 4
+.IX Item "none"
+Zablokuj wsparcie dla przezroczystago proxy.  Jest to wartość domyślna.
+.IP "\fBsource\fR" 4
+.IX Item "source"
+Przepisz adres, aby nawiązywane połączenie wydawało się pochodzić
+bezpośrednio od klienta, a nie od programu \fBstunnel\fR.
+.Sp
+Opcja jest aktualnie obsługiwana w:
+.RS 4
+.IP "Trybie zdalnym (opcja \fIconnect\fR) w systemie \fILinux >=2.6.28\fR" 4
+.IX Item "Trybie zdalnym (opcja connect) w systemie Linux >=2.6.28"
+Konfiguracja wymaga następujących ustawień iptables oraz routingu
+(na przykład w pliku /etc/rc.local lub analogicznym):
+.Sp
+.Vb 7
+\&    iptables \-t mangle \-N DIVERT
+\&    iptables \-t mangle \-A PREROUTING \-p tcp \-m socket \-j DIVERT
+\&    iptables \-t mangle \-A DIVERT \-j MARK \-\-set\-mark 1
+\&    iptables \-t mangle \-A DIVERT \-j ACCEPT
+\&    ip rule add fwmark 1 lookup 100
+\&    ip route add local 0.0.0.0/0 dev lo table 100
+\&    echo 0 >/proc/sys/net/ipv4/conf/lo/rp_filter
+.Ve
+.Sp
+Konfiguracja ta wymaga, aby \fBstunnel\fR był wykonywany jako root i bez opcji \fIsetuid\fR.
+.IP "Trybie zdalnym (opcja \fIconnect\fR) w systemie \fILinux 2.2.x\fR" 4
+.IX Item "Trybie zdalnym (opcja connect) w systemie Linux 2.2.x"
+Konfiguracja ta wymaga skompilowania jądra z opcją \fItransparent proxy\fR.
+Docelowa usługa musi być umieszczona na osobnej maszynie, do której routing
+kierowany jest poprzez serwer \fBstunnela\fR.
+.Sp
+Dodatkowo \fBstunnel\fR powinien być wykonywany jako root i bez opcji \fIsetuid\fR.
+.IP "Trybie zdalnym (opcja \fIconnect\fR) w systemie \fIFreeBSD >=8.0\fR" 4
+.IX Item "Trybie zdalnym (opcja connect) w systemie FreeBSD >=8.0"
+Konfiguracja ta wymaga skonfigurowania firewalla i routingu.
+\&\fBstunnel\fR musi być wykonywany jako root i bez opcji \fIsetuid\fR.
+.IP "Trybie lokalnym (opcja \fIexec\fR)" 4
+.IX Item "Trybie lokalnym (opcja exec)"
+Konfiguracja ta jest realizowana przy pomocy biblioteki \fIlibstunnel.so\fR.
+Do załadowania biblioteki wykorzystywana jest zmienna środowiskowa _RLD_LIST na
+platformie Tru64 lub \s-1LD_PRELOAD\s0 na innych platformach.
+.RE
+.RS 4
+.RE
+.IP "\fIdestination\fR" 4
+.IX Item "destination"
+Oryginalny adres docelowy jest używany zamiast opcji \fIconnect\fR.
+.Sp
+Przykładowana konfiguracja przezroczystego adresu docelowego:
+.Sp
+.Vb 4
+\&    [transparent]
+\&    client=yes
+\&    accept=<port_stunnela>
+\&    transparent=destination
+.Ve
+.Sp
+Konfiguracja wymaga ustawień iptables, na przykład w pliku
+/etc/rc.local lub analogicznym.
+.Sp
+W przypadku docelowej usługi umieszczonej na tej samej maszynie:
+.Sp
+.Vb 3
+\&    /sbin/iptables \-t nat \-I OUTPUT \-p tcp \-\-dport <port_przekierowany> \e
+\&        \-m ! \-\-uid\-owner <identyfikator_użytkownika_stunnela> \e
+\&        \-j DNAT \-\-to\-destination <lokalne_ip>:<lokalny_port>
+.Ve
+.Sp
+W przypadku docelowej usługi umieszczonej na zdalnej maszynie:
+.Sp
+.Vb 3
+\&    /sbin/iptables \-I INPUT \-i eth0 \-p tcp \-\-dport <port_stunnela> \-j ACCEPT
+\&    /sbin/iptables \-t nat \-I PREROUTING \-p tcp \-\-dport <port_przekierowany> \e
+\&        \-i eth0 \-j DNAT \-\-to\-destination <lokalne_ip>:<port_stunnela>
+.Ve
+.Sp
+Przezroczysty adres docelowy jest aktualnie wspierany wyłącznie w systemie Linux.
+.IP "\fIboth\fR" 4
+.IX Item "both"
+Użyj przezroczystego proxy zarówno dla adresu źródłowego jak i docelowego.
+.RE
+.RS 4
+.Sp
+Dla zapewnienia kompatybilności z wcześniejszymim wersjami wspierane są dwie
+dodatkowe opcje:
+.IP "\fIyes\fR" 4
+.IX Item "yes"
+Opcja została przemianowana na \fIsource\fR.
+.IP "\fIno\fR" 4
+.IX Item "no"
+Opcja została przemianowana na \fInone\fR.
+.RE
+.RS 4
+.RE
+.IP "\fBverify\fR = \s-1POZIOM\s0" 4
+.IX Item "verify = POZIOM"
+weryfikuj certyfikat drugiej strony połączenia
+.RS 4
+.IP "\fIpoziom 0\fR" 4
+.IX Item "poziom 0"
+zarządaj certyfikatu i zignoruj go
+.IP "\fIpoziom 1\fR" 4
+.IX Item "poziom 1"
+weryfikuj, jeżeli został przedstawiony
+.IP "\fIpoziom 2\fR" 4
+.IX Item "poziom 2"
+weryfikuj z zainstalowanym certyfikatem Centrum Certyfikacji
+.IP "\fIpoziom 3\fR" 4
+.IX Item "poziom 3"
+weryfikuj z lokalnie zainstalowanym certyfikatem drugiej strony
+.IP "\fIpoziom 4\fR" 4
+.IX Item "poziom 4"
+weryfikuj z certyfikatem drugiej strony ignorując łańcuch \s-1CA\s0
+.IP "\fIdomyślnie\fR" 4
+.IX Item "domyślnie"
+nie weryfikuj
+.RE
+.RS 4
+.RE
+.SH "ZWRACANA WARTOŚĆ"
+.IX Header "ZWRACANA WARTOŚĆ"
+\&\fBstunnel\fR zwraca zero w przypadku sukcesu, lub wartość niezerową
+w przypadku błędu.
+.SH "SIGNAŁY"
+.IX Header "SIGNAŁY"
+Następujące sygnały mogą być użyte do sterowania programem w systemie Unix:
+.IP "\s-1SIGHUP\s0" 4
+.IX Item "SIGHUP"
+Załaduj ponownie plik konfiguracyjny.
+.Sp
+Niektóre globalne opcje nie będą przeładowane:
+.RS 4
+.IP "\(bu" 4
+chroot
+.IP "\(bu" 4
+foreground
+.IP "\(bu" 4
+pid
+.IP "\(bu" 4
+setgid
+.IP "\(bu" 4
+setuid
+.RE
+.RS 4
+.Sp
+Jeżeli wykorzystywana jest opcja 'setuid' \fBstunnel\fR nie będzie mógł załadować
+ponownie konfiguracji wykorzystującej uprzywilejowane (<1024) porty.
+.Sp
+Jeżeli wykorzystywana jest opcja 'chroot' \fBstunnel\fR będzie szukał wszystkich
+potrzebnych plików (łącznie z plikiem konfiguracyjnym, certyfikatami, logiem i
+plikiem pid) wewnątrz katalogu wskazanego przez 'chroot'.
+.RE
+.IP "\s-1SIGUSR1\s0" 4
+.IX Item "SIGUSR1"
+Zamknij i otwórz ponownie log.
+Funkcja ta może zostać użyta w skrypcie rotującym log programu \fBstunnel\fR.
+.IP "\s-1SIGTERM, SIGQUIT, SIGINT\s0" 4
+.IX Item "SIGTERM, SIGQUIT, SIGINT"
+Zakończ działanie programu.
+.PP
+Skutek wysłania innych sygnałów jest niezdefiniowany.
+.SH "PRZYKŁADY"
+.IX Header "PRZYKŁADY"
+Szyfrowanie połączeń do lokalnego serwera \fIimapd\fR można użyć:
+.PP
+.Vb 4
+\&    [imapd]
+\&    accept = 993
+\&    exec = /usr/sbin/imapd
+\&    execArgs = imapd
+.Ve
+.PP
+albo w trybie zdalnym:
+.PP
+.Vb 3
+\&    [imapd]
+\&    accept = 993
+\&    connect = 143
+.Ve
+.PP
+Aby umożliwić lokalnemu klientowi poczty elektronicznej korzystanie z serwera
+\&\fIimapd\fR przez \s-1SSL\s0 należy skonfigurować pobieranie poczty z adresu localhost i
+portu 119, oraz użyć następującej konfiguracji:
+.PP
+.Vb 4
+\&    [imap]
+\&    client = yes
+\&    accept = 143
+\&    connect = serwer:993
+.Ve
+.PP
+W połączeniu z programem \fIpppd\fR \fBstunnel\fR pozwala zestawić prosty \s-1VPN.\s0
+Po stronie serwera nasłuchującego na porcie 2020 jego konfiguracja
+może wyglądać następująco:
+.PP
+.Vb 5
+\&    [vpn]
+\&    accept = 2020
+\&    exec = /usr/sbin/pppd
+\&    execArgs = pppd local
+\&    pty = yes
+.Ve
+.PP
+Poniższy plik konfiguracyjny może być wykorzystany do uruchomienia
+programu \fBstunnel\fR w trybie \fIinetd\fR.  Warto zauważyć, że w pliku
+konfiguracyjnym nie ma sekcji \fI[nazwa_usługi]\fR.
+.PP
+.Vb 2
+\&    exec = /usr/sbin/imapd
+\&    execArgs = imapd
+.Ve
+.PP
+Aby skonfigurować \s-1VPN\s0 można użyć następującej konfiguracji klienta:
+.PP
+.Vb 6
+\&    [socks_client]
+\&    client = yes
+\&    accept = 127.0.0.1:1080
+\&    connect = vpn_server:9080
+\&    verify = 4
+\&    CAfile = stunnel.pem
+.Ve
+.PP
+Odpowiadająca jej konfiguracja serwera vpn_server:
+.PP
+.Vb 5
+\&    [socks_server]
+\&    protocol = socks
+\&    accept = 9080
+\&    cert = stunnel.pem
+\&    key = stunnel.key
+.Ve
+.PP
+Do przetestowania konfiguracji można wydać na maszynie klienckiej komendę:
+.PP
+.Vb 1
+\&    curl \-\-socks4a localhost http://www.example.com/
+.Ve
+.SH "NOTKI"
+.IX Header "NOTKI"
+.SS "\s-1OGRANICZENIA\s0"
+.IX Subsection "OGRANICZENIA"
+\&\fBstunnel\fR nie może być używany do szyfrowania protokołu \fI\s-1FTP\s0\fR,
+ponieważ do przesyłania poszczególnych plików używa on dodatkowych
+połączeń otwieranych na portach o dynamicznie przydzielanych numerach.
+Istnieją jednak specjalne wersje klientów i serwerów \s-1FTP\s0 pozwalające
+na szyfrowanie przesyłanych danych przy pomocy protokołu \fI\s-1SSL\s0\fR.
+.SS "\s-1TRYB INETD \s0(tylko Unix)"
+.IX Subsection "TRYB INETD (tylko Unix)"
+W większości zastosowań \fBstunnel\fR samodzielnie nasłuchuje na porcie
+podanym w pliku konfiguracyjnym i tworzy połączenie z innym portem
+podanym w opcji \fIconnect\fR lub nowym programem podanym w opcji \fIexec\fR.
+Niektórzy wolą jednak wykorzystywać oddzielny program, który odbiera
+połączenia, po czym uruchamia program \fBstunnel\fR.  Przykładami takich
+programów są inetd, xinetd i tcpserver.
+.PP
+Przykładowa linia pliku /etc/inetd.conf może wyglądać tak:
+.PP
+.Vb 2
+\&    imaps stream tcp nowait root @bindir@/stunnel
+\&        stunnel @sysconfdir@/stunnel/imaps.conf
+.Ve
+.PP
+Ponieważ w takich przypadkach połączenie na zdefiniowanym porcie
+(tutaj \fIimaps\fR) nawiązuje osobny program (tutaj \fIinetd\fR), \fBstunnel\fR
+nie może używać opcji \fIaccept\fR.  W pliku konfiguracyjnym nie może
+być również zdefiniowana żadna usługa (\fI[nazwa_usługi]\fR), ponieważ
+konfiguracja taka pozwala na nawiązanie tylko jednego połączenia.
+Wszystkie \fI\s-1OPCJE\s0 USŁUG\fR powinny być umieszczone razem z opcjami
+globalnymi.  Przykład takiej konfiguracji znajduje się w sekcji
+\&\fIPRZYKŁADY\fR.
+.SS "\s-1CERTYFIKATY\s0"
+.IX Subsection "CERTYFIKATY"
+Protokół \s-1SSL\s0 wymaga, aby każdy serwer przedstawiał się nawiązującemu
+połączenie klientowi prawidłowym certyfikatem X.509.
+Potwierdzenie tożsamości serwera polega na wykazaniu, że posiada on
+odpowiadający certyfikatowi klucz prywatny.
+Najprostszą metodą uzyskania certyfikatu jest wygenerowanie go przy pomocy
+wolnego pakietu \fBOpenSSL\fR.  Więcej informacji na temat generowania
+certyfikatów można znaleźć na umieszczonych poniżej stronach.
+.PP
+Istotną kwestią jest kolejność zawartości pliku \fI.pem\fR.
+W pierwszej kolejności powinien on zawierać klucz prywatny,
+a dopiero za nim podpisany certyfikat (nie żądanie certyfikatu).
+Po certyfikacie i kluczu prywatnym powinny znajdować się puste linie.
+Jeżeli przed certyfikatem znajdują się dodatkowe informacje tekstowe,
+to powinny one zostać usunięte.  Otrzymany plik powinien mieć
+następującą postać:
+.PP
+.Vb 8
+\&    \-\-\-\-\-BEGIN RSA PRIVATE KEY\-\-\-\-\-
+\&    [zakodowany klucz]
+\&    \-\-\-\-\-END RSA PRIVATE KEY\-\-\-\-\-
+\&    [pusta linia]
+\&    \-\-\-\-\-BEGIN CERTIFICATE\-\-\-\-\-
+\&    [zakodowany certyfikat]
+\&    \-\-\-\-\-END CERTIFICATE\-\-\-\-\-
+\&    [pusta linia]
+.Ve
+.SS "LOSOWOŚĆ"
+.IX Subsection "LOSOWOŚĆ"
+\&\fBstunnel\fR potrzebuje zainicjować \s-1PRNG \s0(generator liczb pseudolosowych),
+gdyż protokół \s-1SSL\s0 wymaga do bezpieczeństwa kryptograficznego źródła
+dobrej losowości.  Następujące źródła są kolejno odczytywane aż do
+uzyskania  wystarczającej ilości entropii:
+.IP "\(bu" 4
+Zawartość pliku podanego w opcji \fIRNDfile\fR.
+.IP "\(bu" 4
+Zawartość pliku o nazwie określonej przez zmienną środowiskową
+\&\s-1RANDFILE,\s0 o ile jest ona ustawiona.
+.IP "\(bu" 4
+Plik .rnd umieszczony w katalogu domowym użytkownika,
+jeżeli zmienna \s-1RANDFILE\s0 nie jest ustawiona.
+.IP "\(bu" 4
+Plik podany w opcji '\-\-with\-random' w czasie konfiguracji programu.
+.IP "\(bu" 4
+Zawartość ekranu w systemie Windows.
+.IP "\(bu" 4
+Gniazdo egd, jeżeli użyta została opcja \fI\s-1EGD\s0\fR.
+.IP "\(bu" 4
+Gniazdo egd podane w opcji '\-\-with\-egd\-socket' w czasie konfiguracji
+programu.
+.IP "\(bu" 4
+Urządzenie /dev/urandom.
+.PP
+Współczesne (\fB0.9.5a\fR lub nowsze) wersje biblioteki \fBOpenSSL\fR automatycznie
+zaprzestają ładowania kolejnych danych w momencie uzyskania wystarczającej
+ilości entropii.  Wcześniejsze wersje biblioteki wykorzystają wszystkie
+powyższe źródła, gdyż nie istnieje tam funkcja pozwalająca określić, czy
+uzyskano już wystarczająco dużo danych.
+.PP
+Warto zwrócić uwagę, że na maszynach z systemem Windows, na których
+konsoli nie pracuje użytkownik, zawartość ekranu nie jest wystarczająco
+zmienna, aby zainicjować \s-1PRNG.  W\s0 takim przypadku do zainicjowania
+generatora należy użyć opcji \fIRNDfile\fR.
+.PP
+Plik \fIRNDfile\fR powinien zawierać dane losowe \*(-- również w tym sensie,
+że powinny być one inne przy każdym uruchomieniu programu \fBstunnel\fR.
+O ile nie użyta została opcja \fIRNDoverwrite\fR jest to robione
+automatycznie.  Do ręcznego uzyskania takiego pliku użyteczna
+może być komenda \fIopenssl rand\fR dostarczana ze współczesnymi
+wersjami pakietu \fBOpenSSL\fR.
+.PP
+Jeszcze jedna istotna informacja \*(-- jeżeli dostępne jest urządzenie
+\&\fI/dev/urandom\fR biblioteka \fBOpenSSL\fR ma zwyczaj zasilania nim \s-1PRNG\s0 w trakcie
+sprawdzania stanu generatora.  W systemach z \fI/dev/urandom\fR urządzenie
+to będzie najprawdopodobniej użyte, pomimo że znajduje się na samym końcu
+powyższej listy.  Jest to właściwość biblioteki \fBOpenSSL\fR, a nie programu
+\&\fBstunnel\fR.
+.SS "\s-1PARAMETRY DH\s0"
+.IX Subsection "PARAMETRY DH"
+Począwszy od wersji 4.40 \fBstunnel\fR zawiera w kodzie programu 2048\-bitowe
+parametry \s-1DH. \s0 Od wersji 5.18 te początkowe wartości parametrów \s-1DH\s0 są
+wymieniane na autogenerowane parametry tymczasowe.
+Wygenerowanie parametrów \s-1DH\s0 może zająć nawet wiele minut.
+.PP
+Alternatywnie parametry \s-1DH\s0 można umieścić w pliku razem z certyfikatem,
+co wyłącza generowanie parametrów tymczasowych:
+.PP
+.Vb 1
+\&    openssl dhparam 2048 >> stunnel.pem
+.Ve
+.SH "PLIKI"
+.IX Header "PLIKI"
+.ie n .IP "\fI\fI@sysconfdir\fI@/stunnel/stunnel.conf\fR" 4
+.el .IP "\fI\f(CI@sysconfdir\fI@/stunnel/stunnel.conf\fR" 4
+.IX Item "@sysconfdir@/stunnel/stunnel.conf"
+plik konfiguracyjny programu
+.SH "BŁĘDY"
+.IX Header "BŁĘDY"
+Opcja \fIexecArgs\fR oraz linia komend Win32 nie obsługuje cytowania.
+.SH "ZOBACZ RÓWNIEŻ"
+.IX Header "ZOBACZ RÓWNIEŻ"
+.IP "\fItcpd\fR\|(8)" 4
+.IX Item "tcpd"
+biblioteka kontroli dostępu do usług internetowych
+.IP "\fIinetd\fR\|(8)" 4
+.IX Item "inetd"
+\&'super\-serwer' internetowy
+.IP "\fIhttp://www.stunnel.org/\fR" 4
+.IX Item "http://www.stunnel.org/"
+strona domowa programu \fBstunnel\fR
+.IP "\fIhttp://www.openssl.org/\fR" 4
+.IX Item "http://www.openssl.org/"
+strona projektu \fBOpenSSL\fR
+.SH "AUTOR"
+.IX Header "AUTOR"
+.IP "Michał Trojnara" 4
+.IX Item "Michał Trojnara"
+<\fIMichal.Trojnara@mirt.net\fR>
diff --git a/doc/stunnel.pl.html.in b/doc/stunnel.pl.html.in
new file mode 100644
index 0000000..3f85b6d
--- /dev/null
+++ b/doc/stunnel.pl.html.in
@@ -0,0 +1,1474 @@
+<?xml version="1.0" ?>
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
+<html xmlns="http://www.w3.org/1999/xhtml">
+<head>
+<title>stunnel TLS Proxy</title>
+<meta http-equiv="content-type" content="text/html; charset=utf-8" />
+<link rev="made" href="mailto:root@localhost" />
+</head>
+
+<body id="_podtop_">
+<table border="0" width="100%" cellspacing="0" cellpadding="3">
+<tr><td class="_podblock_" style="background-color: #cccccc; color: #000" valign="middle">
+<big><strong><span class="_podblock_">&nbsp;stunnel TLS Proxy</span></strong></big>
+</td></tr>
+</table>
+
+
+
+<ul id="index">
+  <li><a href="#NAZWA">NAZWA</a></li>
+  <li><a href="#SKADNIA">SK&#x141;ADNIA</a></li>
+  <li><a href="#OPIS">OPIS</a></li>
+  <li><a href="#OPCJE">OPCJE</a></li>
+  <li><a href="#PLIK-KONFIGURACYJNY">PLIK KONFIGURACYJNY</a>
+    <ul>
+      <li><a href="#OPCJE-GLOBALNE">OPCJE GLOBALNE</a></li>
+      <li><a href="#OPCJE-USUG">OPCJE US&#x141;UG</a></li>
+    </ul>
+  </li>
+  <li><a href="#ZWRACANA-WARTO">ZWRACANA WARTO&#x15A;&#x106;</a></li>
+  <li><a href="#SIGNAY">SIGNA&#x141;Y</a></li>
+  <li><a href="#PRZYKADY">PRZYK&#x141;ADY</a></li>
+  <li><a href="#NOTKI">NOTKI</a>
+    <ul>
+      <li><a href="#OGRANICZENIA">OGRANICZENIA</a></li>
+      <li><a href="#TRYB-INETD-tylko-Unix">TRYB INETD (tylko Unix)</a></li>
+      <li><a href="#CERTYFIKATY">CERTYFIKATY</a></li>
+      <li><a href="#LOSOWO">LOSOWO&#x15A;&#x106;</a></li>
+      <li><a href="#PARAMETRY-DH">PARAMETRY DH</a></li>
+    </ul>
+  </li>
+  <li><a href="#PLIKI">PLIKI</a></li>
+  <li><a href="#BDY">B&#x141;&#x118;DY</a></li>
+  <li><a href="#ZOBACZ-RWNIE">ZOBACZ R&Oacute;WNIE&#x17B;</a></li>
+  <li><a href="#AUTOR">AUTOR</a></li>
+</ul>
+
+<a href="#_podtop_"><h1 id="NAZWA">NAZWA</h1></a>
+
+<p>stunnel - uniwersalny tunel protoko&#x142;u SSL</p>
+
+<a href="#_podtop_"><h1 id="SKADNIA">SK&#x141;ADNIA</h1></a>
+
+<dl>
+
+<dt id="Unix"><b>Unix:</b></dt>
+<dd>
+
+<p><b>stunnel</b> [<span style="white-space: nowrap;">PLIK</span>] | <span style="white-space: nowrap;">-fd N</span> | <span style="white-space: nowrap;">-help</span> | <span style="white-space: nowrap;">-version</span> | <span style="white-space: nowrap;">-sockets</span> | <span style="white-space: nowrap;">-options</span></p>
+
+</dd>
+<dt id="WIN32"><b>WIN32:</b></dt>
+<dd>
+
+<p><b>stunnel</b> [ [ <span style="white-space: nowrap;">-install</span> | <span style="white-space: nowrap;">-uninstall</span> | <span style="white-space: nowrap;">-start</span> | <span style="white-space: nowrap;">-stop</span> | <span style="white-space: nowrap;">-reload</span> | <span style="white-space: nowrap;">-reopen</span> | <span style="white-space: nowrap;">-exit</span> ] [<span style="white-space: nowrap;">-quiet</span>] [<span style="white-space: nowrap;">PLIK</span>] ] | <span style="white-space: nowrap;">-help</span> | <span style="white-space: nowrap;">-version</span> | <span style="white-space: nowrap;">-sockets</span> | <span style="white-space: nowrap;">-options</span></p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="OPIS">OPIS</h1></a>
+
+<p>Program <b>stunnel</b> zosta&#x142; zaprojektowany do opakowywania w protok&oacute;&#x142; <i>SSL</i> po&#x142;&#x105;cze&#x144; pomi&#x119;dzy zdalnymi klientami a lokalnymi lub zdalnymi serwerami. Przez serwer lokalny rozumiana jest aplikacja przeznaczona do uruchamiania przy pomocy <i>inetd</i>. Stunnel pozwala na proste zestawienie komunikacji serwer&oacute;w nie posiadaj&#x105;cych funkcjonalno&#x15B;ci <i>SSL</i> poprzez bezpieczne kana&#x142;y <i>SSL</i>.</p>
+
+<p><b>stunnel</b> pozwala doda&#x107; funkcjonalno&#x15B;&#x107; <i>SSL</i> do powszechnie stosowanych demon&oacute;w <i>inetd</i>, np. <i>pop3</i> lub <i>imap</i>, do samodzielnych demon&oacute;w, np. <i>nntp</i>, <i>smtp</i> lub <i>http</i>, a nawet tunelowa&#x107; ppp poprzez gniazda sieciowe bez zmian w kodzie &#x17A;r&oacute;d&#x142;owym.</p>
+
+<a href="#_podtop_"><h1 id="OPCJE">OPCJE</h1></a>
+
+<dl>
+
+<dt id="PLIK"><b>PLIK</b></dt>
+<dd>
+
+<p>u&#x17C;yj podanego pliku konfiguracyjnego</p>
+
+</dd>
+<dt id="fd-N-tylko-Unix"><b>-fd N</b> (tylko Unix)</dt>
+<dd>
+
+<p>wczytaj konfiguracj&#x119; z podanego deskryptora pliku</p>
+
+</dd>
+<dt id="help"><b>-help</b></dt>
+<dd>
+
+<p>drukuj list&#x119; wspieranych opcji</p>
+
+</dd>
+<dt id="version"><b>-version</b></dt>
+<dd>
+
+<p>drukuj wersj&#x119; programu i domy&#x15B;lne warto&#x15B;ci parametr&oacute;w</p>
+
+</dd>
+<dt id="sockets"><b>-sockets</b></dt>
+<dd>
+
+<p>drukuj domy&#x15B;lne opcje gniazd</p>
+
+</dd>
+<dt id="options"><b>-options</b></dt>
+<dd>
+
+<p>drukuj wspierane opcje SSL</p>
+
+</dd>
+<dt id="install-tylko-Windows-NT-lub-nowszy"><b>-install</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>instaluj serwis NT</p>
+
+</dd>
+<dt id="uninstall-tylko-Windows-NT-lub-nowszy"><b>-uninstall</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>odinstaluj serwis NT</p>
+
+</dd>
+<dt id="start-tylko-Windows-NT-lub-nowszy"><b>-start</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>uruchom serwis NT</p>
+
+</dd>
+<dt id="stop-tylko-Windows-NT-lub-nowszy"><b>-stop</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>zatrzymaj serwis NT</p>
+
+</dd>
+<dt id="reload-tylko-Windows-NT-lub-nowszy"><b>-reload</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>prze&#x142;aduj plik konfiguracyjny uruchomionego serwisu NT</p>
+
+</dd>
+<dt id="reopen-tylko-Windows-NT-lub-nowszy"><b>-reopen</b> (tylko Windows NT lub nowszy)</dt>
+<dd>
+
+<p>otw&oacute;rz ponownie log uruchomionego serwisu NT</p>
+
+</dd>
+<dt id="exit-tylko-Win32"><b>-exit</b> (tylko Win32)</dt>
+<dd>
+
+<p>zatrzymaj uruchomiony program</p>
+
+</dd>
+<dt id="quiet-tylko-Win32"><b>-quiet</b> (tylko Win32)</dt>
+<dd>
+
+<p>nie wy&#x15B;wietlaj okienek z komunikatami</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="PLIK-KONFIGURACYJNY">PLIK KONFIGURACYJNY</h1></a>
+
+<p>Linia w pliku konfiguracyjnym mo&#x17C;e by&#x107;:</p>
+
+<ul>
+
+<li><p>pusta (ignorowana)</p>
+
+</li>
+<li><p>komentarzem rozpoczynaj&#x105;cym si&#x119; znakiem &#39;;&#39; (ignorowana)</p>
+
+</li>
+<li><p>par&#x105; &#39;nazwa_opcji = warto&#x15B;&#x107;_opcji&#39;</p>
+
+</li>
+<li><p>tekstem &#39;[nazwa_us&#x142;ugi]&#39; wskazuj&#x105;cym pocz&#x105;tek definicji us&#x142;ugi</p>
+
+</li>
+</ul>
+
+<p>Parametr adres mo&#x17C;e by&#x107;:</p>
+
+<ul>
+
+<li><p>numerem portu</p>
+
+</li>
+<li><p>oddzielon&#x105; &#x15B;rednikiem par&#x105; adresu (IPv4, IPv6, lub nazw&#x105; domenow&#x105;) i numeru portu</p>
+
+</li>
+<li><p>&#x15B;cie&#x17C;k&#x105; do gniazda Unix (tylko Unix)</p>
+
+</li>
+</ul>
+
+<h2 id="OPCJE-GLOBALNE">OPCJE GLOBALNE</h2>
+
+<dl>
+
+<dt id="chroot-KATALOG-tylko-Unix"><b>chroot</b> = KATALOG (tylko Unix)</dt>
+<dd>
+
+<p>katalog roboczego korzenia systemu plik&oacute;w</p>
+
+<p>Opcja okre&#x15B;la katalog, w kt&oacute;rym uwi&#x119;ziony zostanie proces programu <b>stunnel</b> tu&#x17C; po jego inicjalizacji, a przed rozpocz&#x119;ciem odbierania po&#x142;&#x105;cze&#x144;. &#x15A;cie&#x17C;ki podane w opcjach <i>CApath</i>, <i>CRLpath</i>, <i>pid</i> oraz <i>exec</i> musz&#x105; by&#x107; umieszczone wewn&#x105;trz katalogu podanego w opcji <i>chroot</i> i okre&#x15B;lone wzgl&#x119;dem tego katalogu.</p>
+
+<p>Niekt&oacute;re funkcje systemu operacyjnego mog&#x105; wymaga&#x107; dodatkowych plik&oacute;w umieszczonych w katalogu podanego w parametrze chroot:</p>
+
+<ul>
+
+<li><p>op&oacute;&#x17A;nione rozwini&#x119;cie adres&oacute;w DNS typowo wymaga /etc/nsswitch.conf i /etc/resolv.conf</p>
+
+</li>
+<li><p>lokalizacja strefy czasowej w logach wymaga pliku /etc/timezone</p>
+
+</li>
+<li><p>niekt&oacute;re inne pliki mog&#x105; potrzebowa&#x107; plik&oacute;w urz&#x105;dze&#x144;, np. /dev/zero lub /dev/null</p>
+
+</li>
+</ul>
+
+</dd>
+<dt id="compression-deflate-zlib"><b>compression</b> = deflate | zlib</dt>
+<dd>
+
+<p>wyb&oacute;r algorytmu kompresji przesy&#x142;anych danych</p>
+
+<p>domy&#x15B;lnie: bez kompresji</p>
+
+<p>Algorytm deflate jest standardow&#x105; metod&#x105; kompresji zgodnie z RFC 1951.</p>
+
+<p>Kompresja zlib zaimplementowana w <b>OpenSSL 0.9.8</b> i nowszych nie jest kompatybilna implementacj&#x105; <b>OpenSSL 0.9.7</b>.</p>
+
+</dd>
+<dt id="debug-PODSYSTEM-.POZIOM"><b>debug</b> = [PODSYSTEM].POZIOM</dt>
+<dd>
+
+<p>szczeg&oacute;&#x142;owo&#x15B;&#x107; logowania</p>
+
+<p>Poziom logowania mo&#x17C;na okre&#x15B;li&#x107; przy pomocy jednej z nazw lub liczb: emerg (0), alert (1), crit (2), err (3), warning (4), notice (5), info (6) lub debug (7). Zapisywane s&#x105; komunikaty o poziomie ni&#x17C;szym (numerycznie) lub r&oacute;wnym podanemu. Do uzyskania najwy&#x17C;szego poziomu szczeg&oacute;&#x142;owo&#x15B;ci mo&#x17C;na u&#x17C;y&#x107; opcji <i>debug = debug</i> lub <i>debug = 7</i>. Domy&#x15B;lnym poziomem jest notice (5).</p>
+
+<p>O ile nie wyspecyfikowano podsystemu u&#x17C;yty b&#x119;dzie domy&#x15B;lny: daemon. Podsystemy nie s&#x105; wspierane przez platform&#x119; Win32.</p>
+
+<p>Wielko&#x15B;&#x107; liter jest ignorowana zar&oacute;wno dla poziomu jak podsystemu.</p>
+
+</dd>
+<dt id="EGD-CIEKA_DO_EGD-tylko-Unix"><b>EGD</b> = &#x15A;CIE&#x17B;KA_DO_EGD (tylko Unix)</dt>
+<dd>
+
+<p>&#x15B;cie&#x17C;ka do gniazda programu Entropy Gathering Daemon</p>
+
+<p>Opcja pozwala okre&#x15B;li&#x107; &#x15B;cie&#x17C;k&#x119; do gniazda programu Entropy Gathering Daemon u&#x17C;ywanego do zainicjalizowania generatora ci&#x105;g&oacute;w pseudolosowych biblioteki <b>OpenSSL</b>. Opcja jest dost&#x119;pna z bibliotek&#x105; <b>OpenSSL 0.9.5a</b> lub nowsz&#x105;.</p>
+
+</dd>
+<dt id="engine-auto-IDENTYFIKATOR_URZDZENIA"><b>engine</b> = auto | IDENTYFIKATOR_URZ&#x104;DZENIA</dt>
+<dd>
+
+<p>wyb&oacute;r sprz&#x119;towego urz&#x105;dzenia kryptograficznego</p>
+
+<p>domy&#x15B;lnie: bez wykorzystania urz&#x105;dze&#x144; kryptograficznych</p>
+
+<p>Przyk&#x142;adowa konfiguracja umo&#x17C;liwiaj&#x105;ca odczytanie klucza prywatnego z urz&#x105;dzenia zgodnego z OpenSC:</p>
+
+<pre><code>    engine=dynamic
+    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+    engineCtrl=ID:pkcs11
+    engineCtrl=LIST_ADD:1
+    engineCtrl=LOAD
+    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc-pkcs11.so
+    engineCtrl=INIT
+
+    [service]
+    engineNum=1
+    key=id_45</code></pre>
+
+</dd>
+<dt id="engineCtrl-KOMENDA-:PARAMETR"><b>engineCtrl</b> = KOMENDA[:PARAMETR]</dt>
+<dd>
+
+<p>konfiguracja urz&#x105;dzenia kryptograficznego</p>
+
+<p>Specjalne komendy &quot;LOAD&quot; i &quot;INIT&quot; pozwalaj&#x105; na za&#x142;adowanie i inicjalizacj&#x119; modu&#x142;u kryptograficznego urz&#x105;dzenia.</p>
+
+</dd>
+<dt id="engineDefault-LISTA_ZADA"><b>engineDefault</b> = LISTA_ZADA&#x143;</dt>
+<dd>
+
+<p>lista zada&#x144; OpenSSL oddelegowanych do bie&#x17C;&#x105;cego urz&#x105;dzenia</p>
+
+<p>Parametrem jest lista oddzielonych przecinkami zada&#x144; OpenSSL, kt&oacute;re maj&#x105; zosta&#x107; oddelegowane do bie&#x17C;&#x105;cego urz&#x105;dzenia kryptograficznego.</p>
+
+<p>W zale&#x17C;no&#x15B;ci od konkretnego urz&#x105;dzenia dost&#x119;pne mog&#x105; by&#x107; nast&#x119;puj&#x105;ce zadania: ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.</p>
+
+</dd>
+<dt id="fips-yes-no"><b>fips</b> = yes | no</dt>
+<dd>
+
+<p>tryb FIPS 140-2</p>
+
+<p>Opcja pozwala wy&#x142;&#x105;czy&#x107; wej&#x15B;cie w tryb FIPS, je&#x15B;li <b>stunnel</b> zosta&#x142; skompilowany ze wsparciem dla FIPS 140-2.</p>
+
+<p>domy&#x15B;lnie: no (od wersji 5.00)</p>
+
+</dd>
+<dt id="foreground-yes-no-tylko-Unix"><b>foreground</b> = yes | no (tylko Unix)</dt>
+<dd>
+
+<p>tryb pierwszoplanowy</p>
+
+<p>U&#x17C;ycie tej opcji powoduje, &#x17C;e <b>stunnel</b> nie przechodzi w t&#x142;o loguj&#x105;c swoje komunikaty na konsol&#x119; zamiast przez <i>syslog</i> (o ile nie u&#x17C;yto opcji <i>output</i>).</p>
+
+</dd>
+<dt id="iconActive-PLIK_Z_IKONK-tylko-GUI"><b>iconActive</b> = PLIK_Z_IKONK&#x104; (tylko GUI)</dt>
+<dd>
+
+<p>ikonka wy&#x15B;wietlana przy obecno&#x15B;ci aktywnych po&#x142;&#x105;cze&#x144; do us&#x142;ugi</p>
+
+<p>W systemie Windows ikonka to plik .ico zawieraj&#x105;cy obrazek 16x16 pikseli.</p>
+
+</dd>
+<dt id="iconError-PLIK_Z_IKONK-tylko-GUI"><b>iconError</b> = PLIK_Z_IKONK&#x104; (tylko GUI)</dt>
+<dd>
+
+<p>ikonka wy&#x15B;wietlana, je&#x17C;eli nie zosta&#x142; za&#x142;adowany poprawny plik konfiguracyjny</p>
+
+<p>W systemie Windows ikonka to plik .ico zawieraj&#x105;cy obrazek 16x16 pikseli.</p>
+
+</dd>
+<dt id="iconIdle-PLIK_Z_IKONK-tylko-GUI"><b>iconIdle</b> = PLIK_Z_IKONK&#x104; (tylko GUI)</dt>
+<dd>
+
+<p>ikonka wy&#x15B;wietlana przy braku aktywnych po&#x142;&#x105;cze&#x144; do us&#x142;ugi</p>
+
+<p>W systemie Windows ikonka to plik .ico zawieraj&#x105;cy obrazek 16x16 pikseli.</p>
+
+</dd>
+<dt id="log-append-overwrite"><b>log</b> = append | overwrite</dt>
+<dd>
+
+<p>log file handling</p>
+
+<p>This option allows to choose whether the log file (specified with the <i>output</i> option) is appended or overwritten when opened or re-opened.</p>
+
+<p>domy&#x15B;lnie: append</p>
+
+</dd>
+<dt id="output-PLIK"><b>output</b> = PLIK</dt>
+<dd>
+
+<p>plik, do kt&oacute;rego dopisane zostan&#x105; logi</p>
+
+<p>U&#x17C;ycie tej opcji powoduje dopisanie log&oacute;w do podanego pliku.</p>
+
+<p>Do kierowaniakomunikat&oacute;w na standardowe wyj&#x15B;cie (na przyk&#x142;ad po to, &#x17C;eby zalogowa&#x107; je programem splogger z pakietu daemontools) mo&#x17C;na poda&#x107; jako parametr urz&#x105;dzenie /dev/stdout.</p>
+
+</dd>
+<dt id="pid-PLIK-tylko-Unix"><b>pid</b> = PLIK (tylko Unix)</dt>
+<dd>
+
+<p>po&#x142;o&#x17C;enie pliku z numerem procesu</p>
+
+<p>Je&#x17C;eli argument jest pusty plik nie zostanie stworzony.</p>
+
+<p>Je&#x17C;eli zdefiniowano katalog <i>chroot</i>, to &#x15B;cie&#x17C;ka do <i>pid</i> jest okre&#x15B;lona wzgl&#x119;dem tego katalogu.</p>
+
+</dd>
+<dt id="RNDbytes-LICZBA_BAJTW"><b>RNDbytes</b> = LICZBA_BAJT&Oacute;W</dt>
+<dd>
+
+<p>liczba bajt&oacute;w do zainicjowania generatora pseudolosowego</p>
+
+<p>W wersjach biblioteki <b>OpenSSL</b> starszych ni&#x17C; <b>0.9.5a</b> opcja ta okre&#x15B;la r&oacute;wnie&#x17C; liczb&#x119; bajt&oacute;w wystarczaj&#x105;cych do zainicjowania PRNG. Nowsze wersje biblioteki maj&#x105; wbudowan&#x105; funkcj&#x119; okre&#x15B;laj&#x105;c&#x105;, czy dostarczona ilo&#x15B;&#x107; losowo&#x15B;ci jest wystarczaj&#x105;ca do zainicjowania generatora.</p>
+
+</dd>
+<dt id="RNDfile-PLIK"><b>RNDfile</b> = PLIK</dt>
+<dd>
+
+<p>&#x15B;cie&#x17C;ka do pliku zawieraj&#x105;cego losowe dane</p>
+
+<p>Biblioteka <b>OpenSSL</b> u&#x17C;yje danych z tego pliku do zainicjowania generatora pseudolosowego.</p>
+
+</dd>
+<dt id="RNDoverwrite-yes-no"><b>RNDoverwrite</b> = yes | no</dt>
+<dd>
+
+<p>nadpisz plik nowymi warto&#x15B;ciami pseudolosowymi</p>
+
+<p>domy&#x15B;lnie: yes (nadpisz)</p>
+
+</dd>
+<dt id="service-SERWIS-tylko-Unix"><b>service</b> = SERWIS (tylko Unix)</dt>
+<dd>
+
+<p>nazwa us&#x142;ugi</p>
+
+<p>Podana nazwa us&#x142;ugi b&#x119;dzie u&#x17C;ywana jako nazwa us&#x142;ugi dla inicjalizacji sysloga, oraz dla biblioteki TCP Wrapper w trybie <i>inetd</i>. Chocia&#x17C; technicznie mo&#x17C;na u&#x17C;y&#x107; tej opcji w trybie w sekcji us&#x142;ug, to jest ona u&#x17C;yteczna jedynie w opcjach globalnych.</p>
+
+<p>domy&#x15B;lnie: stunnel</p>
+
+</dd>
+<dt id="setgid-IDENTYFIKATOR_GRUPY-tylko-Unix"><b>setgid</b> = IDENTYFIKATOR_GRUPY (tylko Unix)</dt>
+<dd>
+
+<p>grupa z kt&oacute;rej prawami pracowa&#x142; b&#x119;dzie <b>stunnel</b></p>
+
+</dd>
+<dt id="setuid-IDENTYFIKATOR_UYTKOWNIKA-tylko-Unix"><b>setuid</b> = IDENTYFIKATOR_U&#x17B;YTKOWNIKA (tylko Unix)</dt>
+<dd>
+
+<p>u&#x17C;ytkownik, z kt&oacute;rego prawami pracowa&#x142; b&#x119;dzie <b>stunnel</b></p>
+
+</dd>
+<dt id="socket-a-l-r:OPCJA-WARTO-:WARTO"><b>socket</b> = a|l|r:OPCJA=WARTO&#x15A;&#x106;[:WARTO&#x15A;&#x106;]</dt>
+<dd>
+
+<p>ustaw opcj&#x119; na akceptuj&#x105;cym/lokalnym/zdalnym gnie&#x17A;dzie</p>
+
+<p>Dla opcji linger warto&#x15B;ci maj&#x105; posta&#x107; l_onof:l_linger. Dla opcji time warto&#x15B;ci maj&#x105; posta&#x107; tv_sec:tv_usec.</p>
+
+<p>Przyk&#x142;ady:</p>
+
+<pre><code>    socket = l:SO_LINGER=1:60
+        ustaw jednominutowe przeterminowanie
+        przy zamykaniu lokalnego gniazda
+    socket = r:SO_OOBINLINE=yes
+        umie&#x15B;&#x107; dane pozapasmowe (out-of-band)
+        bezpo&#x15B;rednio w strumieniu danych
+        wej&#x15B;ciowych dla zdalnych gniazd
+    socket = a:SO_REUSEADDR=no
+        zablokuj ponowne u&#x17C;ywanie portu
+        (domy&#x15B;lnie w&#x142;&#x105;czone)
+    socket = a:SO_BINDTODEVICE=lo
+        przyjmuj po&#x142;&#x105;czenia wy&#x142;&#x105;cznie na
+        interfejsie zwrotnym (ang. loopback)</code></pre>
+
+</dd>
+<dt id="syslog-yes-no-tylko-Unix"><b>syslog</b> = yes | no (tylko Unix)</dt>
+<dd>
+
+<p>w&#x142;&#x105;cz logowanie poprzez mechanizm syslog</p>
+
+<p>domy&#x15B;lnie: yes (w&#x142;&#x105;cz)</p>
+
+</dd>
+<dt id="taskbar-yes-no-tylko-WIN32"><b>taskbar</b> = yes | no (tylko WIN32)</dt>
+<dd>
+
+<p>w&#x142;&#x105;cz ikonk&#x119; w prawym dolnym rogu ekranu</p>
+
+<p>domy&#x15B;lnie: yes (w&#x142;&#x105;cz)</p>
+
+</dd>
+</dl>
+
+<h2 id="OPCJE-USUG">OPCJE US&#x141;UG</h2>
+
+<p>Ka&#x17C;da sekcja konfiguracji us&#x142;ugi zaczyna si&#x119; jej nazw&#x105; uj&#x119;t&#x105; w nawias kwadratowy. Nazwa us&#x142;ugi u&#x17C;ywana jest do kontroli dost&#x119;pu przez bibliotek&#x119; libwrap (TCP wrappers) oraz pozwala rozr&oacute;&#x17C;ni&#x107; poszczeg&oacute;lne us&#x142;ugi w logach.</p>
+
+<p>Je&#x17C;eli <b>stunnel</b> ma zosta&#x107; u&#x17C;yty w trybie <i>inetd</i>, gdzie za odebranie po&#x142;&#x105;czenia odpowiada osobny program (zwykle <i>inetd</i>, <i>xinetd</i> lub <i>tcpserver</i>), nale&#x17C;y przeczyta&#x107; sekcj&#x119; <i>TRYB INETD</i> poni&#x17C;ej.</p>
+
+<dl>
+
+<dt id="accept-HOST:-PORT"><b>accept</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>nas&#x142;uchuje na po&#x142;&#x105;czenia na podanym adresie i porcie</p>
+
+<p>Je&#x17C;eli nie zosta&#x142; podany adres, <b>stunnel</b> domy&#x15B;lnie nas&#x142;uchuje na wszystkich adresach IPv4 lokalnych interfejs&oacute;w.</p>
+
+<p>Aby nas&#x142;uchiwa&#x107; na wszystkich adresach IPv6 nale&#x17C;y u&#x17C;y&#x107;:</p>
+
+<pre><code>    accept = :::port</code></pre>
+
+</dd>
+<dt id="CApath-KATALOG_CA"><b>CApath</b> = KATALOG_CA</dt>
+<dd>
+
+<p>katalog Centrum Certyfikacji</p>
+
+<p>Opcja okre&#x15B;la katalog, w kt&oacute;rym <b>stunnel</b> b&#x119;dzie szuka&#x142; certyfikat&oacute;w, je&#x17C;eli u&#x17C;yta zosta&#x142;a opcja <i>verify</i>. Pliki z certyfikatami musz&#x105; posiada&#x107; specjalne nazwy XXXXXXXX.0, gdzie XXXXXXXX jest skr&oacute;tem kryptograficznym reprezentacji DER nazwy podmiotu certyfikatu.</p>
+
+<p>Funkcja skr&oacute;tu zosta&#x142;a zmieniona w <b>OpenSSL 1.0.0</b>. Nale&#x17C;y wykona&#x107; c_rehash przy zmianie <b>OpenSSL 0.x.x</b> na <b>1.x.x</b>.</p>
+
+<p>Je&#x17C;eli zdefiniowano katalog <i>chroot</i>, to &#x15B;cie&#x17C;ka do <i>CApath</i> jest okre&#x15B;lona wzgl&#x119;dem tego katalogu.</p>
+
+</dd>
+<dt id="CAfile-PLIK_CA"><b>CAfile</b> = PLIK_CA</dt>
+<dd>
+
+<p>plik Centrum Certyfikacji</p>
+
+<p>Opcja pozwala okre&#x15B;li&#x107; po&#x142;o&#x17C;enie pliku zawieraj&#x105;cego certyfikaty u&#x17C;ywane przez opcj&#x119; <i>verify</i>.</p>
+
+</dd>
+<dt id="cert-PLIK_PEM"><b>cert</b> = PLIK_PEM</dt>
+<dd>
+
+<p>plik z &#x142;a&#x144;cuchem certyfikat&oacute;w</p>
+
+<p>Opcja okre&#x15B;la po&#x142;o&#x17C;enie pliku zawieraj&#x105;cego certyfikaty u&#x17C;ywane przez program <b>stunnel</b> do uwierzytelnienia si&#x119; przed drug&#x105; stron&#x105; po&#x142;&#x105;czenia. Certyfikat jest konieczny, aby u&#x17C;ywa&#x107; programu w trybie serwera. W trybie klienta certyfikat jest opcjonalny.</p>
+
+</dd>
+<dt id="checkEmail-EMAIL"><b>checkEmail</b> = EMAIL</dt>
+<dd>
+
+<p>adres email przedstawionego certyfikatu</p>
+
+<p>Pojedyncza sekcja mo&#x17C;e zawiera&#x107; wiele wyst&#x105;pie&#x144; opcji <b>checkEmail</b>. Certyfikaty s&#x105; akceptowane, je&#x17C;eli sekcja nie zawiera opcji <b>checkEmail</b>, albo adres email przedstawionego certyfikatu pasuje do jednego z adres&oacute;w email okre&#x15B;lonych przy pomocy <b>checkEmail</b>.</p>
+
+</dd>
+<dt id="checkHost-NAZWA_SERWERA"><b>checkHost</b> = NAZWA_SERWERA</dt>
+<dd>
+
+<p>nazwa serwera przedstawionego certyfikatu</p>
+
+<p>Pojedyncza sekcja mo&#x17C;e zawiera&#x107; wiele wyst&#x105;pie&#x144; opcji <b>checkHost</b>. Certyfikaty s&#x105; akceptowane, je&#x17C;eli sekcja nie zawiera opcji <b>checkHost</b>, albo nazwa serwera przedstawionego certyfikatu pasuje do jednego nazw okre&#x15B;lonych przy pomocy <b>checkHost</b>.</p>
+
+</dd>
+<dt id="checkIP-IP"><b>checkIP</b> = IP</dt>
+<dd>
+
+<p>adres IP przedstawionego certyfikatu</p>
+
+<p>Pojedyncza sekcja mo&#x17C;e zawiera&#x107; wiele wyst&#x105;pie&#x144; opcji <b>checkIP</b>. Certyfikaty s&#x105; akceptowane, je&#x17C;eli sekcja nie zawiera opcji <b>checkIP</b>, albo adres IP przedstawionego certyfikatu pasuje do jednego z adres&oacute;w IP okre&#x15B;lonych przy pomocy <b>checkIP</b>.</p>
+
+</dd>
+<dt id="ciphers-LISTA_SZYFRW"><b>ciphers</b> = LISTA_SZYFR&Oacute;W</dt>
+<dd>
+
+<p>lista dozwolonych szyfr&oacute;w SSL</p>
+
+<p>Parametrem tej opcji jest lista szyfr&oacute;w, kt&oacute;re b&#x119;d&#x105; u&#x17C;yte przy otwieraniu nowych po&#x142;&#x105;cze&#x144; SSL, np.: DES-CBC3-SHA:IDEA-CBC-MD5</p>
+
+</dd>
+<dt id="client-yes-no"><b>client</b> = yes | no</dt>
+<dd>
+
+<p>tryb kliencki (zdalna us&#x142;uga u&#x17C;ywa SSL)</p>
+
+<p>domy&#x15B;lnie: no (tryb serwerowy)</p>
+
+</dd>
+<dt id="connect-HOST:-PORT"><b>connect</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>po&#x142;&#x105;cz si&#x119; ze zdalnym serwerem na podany port</p>
+
+<p>Je&#x17C;eli nie zosta&#x142; podany adres, <b>stunnel</b> domy&#x15B;lnie &#x142;&#x105;czy si&#x119; z lokalnym serwerem.</p>
+
+<p>Komenda mo&#x17C;e byc u&#x17C;yta wielokrotnie w pojedynczej sekcji celem zapewnienia wysokiej niezawodno&#x15B;ci lub roz&#x142;o&#x17C;enia ruchu pomi&#x119;dzy wiele serwer&oacute;w.</p>
+
+</dd>
+<dt id="CRLpath-KATALOG_CRL"><b>CRLpath</b> = KATALOG_CRL</dt>
+<dd>
+
+<p>katalog List Odwo&#x142;anych Certyfikat&oacute;w (CRL)</p>
+
+<p>Opcja okre&#x15B;la katalog, w kt&oacute;rym <b>stunnel</b> b&#x119;dzie szuka&#x142; list CRL, je&#x17C;eli u&#x17C;yta zosta&#x142;a opcja <i>verify</i>. Pliki z listami CRL musz&#x105; posiada&#x107; specjalne nazwy XXXXXXXX.r0, gdzie XXXXXXXX jest skr&oacute;tem listy CRL.</p>
+
+<p>Funkcja skr&oacute;tu zosta&#x142;a zmieniona <b>OpenSSL 1.0.0</b>. Nale&#x17C;y wykona&#x107; c_rehash przy zmianie <b>OpenSSL 0.x.x</b> na <b>1.x.x</b>.</p>
+
+<p>Je&#x17C;eli zdefiniowano katalog <i>chroot</i>, to &#x15B;cie&#x17C;ka do <i>CRLpath</i> jest okre&#x15B;lona wzgl&#x119;dem tego katalogu.</p>
+
+</dd>
+<dt id="CRLfile-PLIK_CRL"><b>CRLfile</b> = PLIK_CRL</dt>
+<dd>
+
+<p>plik List Odwo&#x142;anych Certyfikat&oacute;w (CRL)</p>
+
+<p>Opcja pozwala okre&#x15B;li&#x107; po&#x142;o&#x17C;enie pliku zawieraj&#x105;cego listy CRL u&#x17C;ywane przez opcj&#x119; <i>verify</i>.</p>
+
+</dd>
+<dt id="curve-NID"><b>curve</b> = NID</dt>
+<dd>
+
+<p>krzywa dla ECDH</p>
+
+<p>List&#x119; dost&#x119;pnych krzywych mo&#x17C;na uzyska&#x107; poleceniem:</p>
+
+<pre><code>    openssl ecparam -list_curves</code></pre>
+
+<p>domy&#x15B;lnie: prime256v1</p>
+
+</dd>
+<dt id="logId-TYP"><b>logId</b> = TYP</dt>
+<dd>
+
+<p>typ identyfikatora po&#x142;&#x105;czenia klienta</p>
+
+<p>Identyfikator ten pozwala rozr&oacute;&#x17C;ni&#x107; wpisy w logu wygenerowane dla poszczeg&oacute;lnych po&#x142;&#x105;cze&#x144;.</p>
+
+<p>Aktualnie wspierane typy:</p>
+
+<dl>
+
+<dt id="sequential"><i>sequential</i></dt>
+<dd>
+
+<p>Kolejny numer po&#x142;&#x105;czenia jest unikalny jedynie w obr&#x119;bie pojedynczej instancji programu <b>stunnel</b>, ale bardzo kr&oacute;tki. Jest on szczeg&oacute;lnie u&#x17C;ytczny przy r&#x119;cznej analizie log&oacute;w.</p>
+
+</dd>
+<dt id="unique"><i>unique</i></dt>
+<dd>
+
+<p>Ten rodzaj identyfikatora jest globalnie unikalny, ale znacznie d&#x142;u&#x17C;szy, ni&#x17C; kolejny numer po&#x142;&#x105;czenia. Jest on szczeg&oacute;lnie u&#x17C;yteczny przy zautomatyzowanej analizie log&oacute;w.</p>
+
+</dd>
+<dt id="thread"><i>thread</i></dt>
+<dd>
+
+<p>Identyfikator w&#x105;tku systemu operacyjnego nie jest ani unikalny (nawet w obr&#x119;bie pojedynczej instancji programu <b>stunnel</b>), ani kr&oacute;tki. Jest on szczeg&oacute;lnie u&#x17C;yteczny przy diagnozowaniu problem&oacute;w z oprogramowaniem lub konfiguracj&#x105;.</p>
+
+</dd>
+</dl>
+
+<p>domy&#x15B;lnie: sequential</p>
+
+</dd>
+<dt id="debug-POZIOM"><b>debug</b> = POZIOM</dt>
+<dd>
+
+<p>szczeg&oacute;&#x142;owo&#x15B;&#x107; logowania</p>
+
+<p>Poziom logowania mo&#x17C;na okre&#x15B;li&#x107; przy pomocy jednej z nazw lub liczb: emerg (0), alert (1), crit (2), err (3), warning (4), notice (5), info (6) lub debug (7). Zapisywane s&#x105; komunikaty o poziomie ni&#x17C;szym (numerycznie) lub r&oacute;wnym podanemu. Do uzyskania najwy&#x17C;szego poziomu szczeg&oacute;&#x142;owo&#x15B;ci mo&#x17C;na u&#x17C;y&#x107; opcji <i>debug = debug</i> lub <i>debug = 7</i>. Domy&#x15B;lnym poziomem jest notice (5).</p>
+
+</dd>
+<dt id="delay-yes-no"><b>delay</b> = yes | no</dt>
+<dd>
+
+<p>op&oacute;&#x17A;nij rozwini&#x119;cie adresu DNS podanego w opcji <i>connect</i></p>
+
+<p>Opcja jest przydatna przy dynamicznym DNS, albo gdy us&#x142;uga DNS nie jest dost&#x119;pna przy starcie programu <b>stunnel</b> (klient VPN, po&#x142;&#x105;czenie wdzwaniane).</p>
+
+<p>Op&oacute;&#x17A;nione rozwijanie adresu DNS jest w&#x142;&#x105;czane automatycznie, je&#x17C;eli nie powiedzie si&#x119; rozwini&#x119;cie kt&oacute;regokolwiek z adres&oacute;w <i>connect</i> dla danej us&#x142;ugi.</p>
+
+<p>Op&oacute;&#x17A;nione rozwijanie adresu automatycznie aktywuje <i>failover = prio</i>.</p>
+
+<p>default: no</p>
+
+</dd>
+<dt id="engineId-NUMER_URZDZENIA"><b>engineId</b> = NUMER_URZ&#x104;DZENIA</dt>
+<dd>
+
+<p>wybierz urz&#x105;dzenie dla us&#x142;ugi</p>
+
+</dd>
+<dt id="engineNum-NUMER_URZDZENIA"><b>engineNum</b> = NUMER_URZ&#x104;DZENIA</dt>
+<dd>
+
+<p>wybierz urz&#x105;dzenie dla us&#x142;ugi</p>
+
+<p>Urz&#x105;dzenia s&#x105; numerowane od 1 w g&oacute;r&#x119;.</p>
+
+</dd>
+<dt id="exec-CIEKA_DO_PROGRAMU"><b>exec</b> = &#x15A;CIE&#x17B;KA_DO_PROGRAMU</dt>
+<dd>
+
+<p>wykonaj lokalny program przystosowany do pracy z superdemonem inetd</p>
+
+<p>Je&#x17C;eli zdefiniowano katalog <i>chroot</i>, to &#x15B;cie&#x17C;ka do <i>exec</i> jest okre&#x15B;lona wzgl&#x119;dem tego katalogu.</p>
+
+<p>Na platformach Unix ustawiane s&#x105; nast&#x119;puj&#x105;ce zmienne &#x15B;rodowiskowe: REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.</p>
+
+</dd>
+<dt id="execArgs-0-1-2"><b>execArgs</b> = $0 $1 $2 ...</dt>
+<dd>
+
+<p>argumenty do opcji <i>exec</i> w&#x142;&#x105;cznie z nazw&#x105; programu ($0)</p>
+
+<p>Cytowanie nie jest wspierane w obecnej wersji programu. Argumenty s&#x105; rozdzielone dowoln&#x105; liczb&#x105; bia&#x142;ych znak&oacute;w.</p>
+
+</dd>
+<dt id="failover-rr-prio"><b>failover</b> = rr | prio</dt>
+<dd>
+
+<p>Strategia wybierania serwer&oacute;w wyspecyfikowanych parametrami &quot;connect&quot;.</p>
+
+<pre><code>    rr (round robin) - sprawiedliwe roz&#x142;o&#x17C;enie obci&#x105;&#x17C;enia
+    prio (priority) - u&#x17C;yj kolejno&#x15B;ci opcji w pliku konfiguracyjnym</code></pre>
+
+<p>domy&#x15B;lnie: rr</p>
+
+</dd>
+<dt id="ident-NAZWA_UYTKOWNIKA"><b>ident</b> = NAZWA_U&#x17B;YTKOWNIKA</dt>
+<dd>
+
+<p>weryfikuj nazw&#x119; zdalnego u&#x17C;ytkownika korzystaj&#x105;c z protoko&#x142;u IDENT (RFC 1413)</p>
+
+</dd>
+<dt id="include-KATALOG"><b>include</b> = KATALOG</dt>
+<dd>
+
+<p>wczytaj fragmenty plik&oacute;w konfiguracyjnych z podanego katalogu</p>
+
+<p>Pliki s&#x105; wczytywane w rosn&#x105;cej kolejno&#x15B;ci alfabetycznej ich nazw.</p>
+
+</dd>
+<dt id="key-PLIK_KLUCZA"><b>key</b> = PLIK_KLUCZA</dt>
+<dd>
+
+<p>klucz prywatny do certyfikatu podanego w opcji <i>cert</i></p>
+
+<p>Klucz prywatny jest potrzebny do uwierzytelnienia w&#x142;a&#x15B;ciciela certyfikatu. Poniewa&#x17C; powinien on by&#x107; zachowany w tajemnicy, prawa do jego odczytu powinien mie&#x107; wy&#x142;&#x105;cznie w&#x142;a&#x15B;ciciel pliku. W systemie Unix mo&#x17C;na to osi&#x105;gn&#x105;&#x107; komend&#x105;:</p>
+
+<pre><code>    chmod 600 keyfile</code></pre>
+
+<p>domy&#x15B;lnie: warto&#x15B;&#x107; opcji <i>cert</i></p>
+
+</dd>
+<dt id="libwrap-yes-no"><b>libwrap</b> = yes | no</dt>
+<dd>
+
+<p>w&#x142;&#x105;cz lub wy&#x142;&#x105;cz korzystanie z /etc/hosts.allow i /etc/hosts.deny.</p>
+
+<p>domy&#x15B;lnie: no (od wersji 5.00)</p>
+
+</dd>
+<dt id="local-HOST"><b>local</b> = HOST</dt>
+<dd>
+
+<p>IP &#x17A;r&oacute;d&#x142;a do nawi&#x105;zywania zdalnych po&#x142;&#x105;cze&#x144;</p>
+
+<p>Domy&#x15B;lnie u&#x17C;ywane jest IP najbardziej zewn&#x119;trznego interfejsu w stron&#x119; serwera, do kt&oacute;rego nawi&#x105;zywane jest po&#x142;&#x105;czenie.</p>
+
+</dd>
+<dt id="sni-USUGA:WZORZEC_NAZWY_SERWERA-tryb-serwera"><b>sni</b> = US&#x141;UGA:WZORZEC_NAZWY_SERWERA (tryb serwera)</dt>
+<dd>
+
+<p>U&#x17C;yj us&#x142;ugi jako podrz&#x119;dnej (virtualnego serwera) dla rozszerzenia TLS Server Name Indication (RFC 3546).</p>
+
+<p><i>nazwa_us&#x142;ugi</i> wskazuje us&#x142;ug&#x119; nadrz&#x119;dn&#x105;, kt&oacute;ra odbiera po&#x142;&#x105;czenia od klient&oacute;w przy pomocy opcji <i>accept</i>. <i>wzorzec_nazwy_serwera</i> wskazuje nazw&#x119; serwera wirtualnego. Wzorzec mo&#x17C;e zaczyna&#x107; si&#x119; znakiem &#39;*&#39;, np. &#39;*.example.com&quot;. Z pojedy&#x144;cz&#x105; us&#x142;ug&#x105; nadrz&#x119;dn&#x105; powi&#x105;zane jest zwykle wiele us&#x142;ug podrz&#x119;dnych. Opcja <i>sni</i> mo&#x17C;e by&#x107; rownie&#x17C; u&#x17C;yta wielokrotnie w ramach jednej us&#x142;ugi podrz&#x119;dnej.</p>
+
+<p>Zar&oacute;wno us&#x142;uga nadrz&#x119;dna jak i podrz&#x119;dna nie mo&#x17C;e by&#x107; skonfigurowana w trybie klienckim.</p>
+
+<p>Opcja <i>connect</i> us&#x142;ugi podrz&#x119;dnej jest ignorowana w po&#x142;&#x105;czeniu z opcj&#x105; <i>protocol</i>, gdy&#x17C; po&#x142;&#x105;czenie do zdalnego serwera jest w tym wypadku nawi&#x105;zywane przed negocjacj&#x105; TLS.</p>
+
+<p>Uwierzytelnienie przy pomocy biblioteki libwrap jest realizowane dwukrotnie: najpierw dla us&#x142;ugi nadrz&#x119;dnej po odebraniu po&#x142;&#x105;czenia TCP, a nast&#x119;pnie dla us&#x142;ugi podrz&#x119;dnej podczas negocjacji TLS.</p>
+
+<p>Opcja <i>sni</i> jest dost&#x119;pna pocz&#x105;wszy od <b>OpenSSL 1.0.0</b>.</p>
+
+</dd>
+<dt id="sni-HOST-tryb-klienta"><b>sni</b> = HOST (tryb klienta)</dt>
+<dd>
+
+<p>U&#x17C;yj parametru jako warto&#x15B;ci rozszerzenia TLS Server Name Indication (RFC 3546).</p>
+
+<p>Opcja <i>sni</i> jest dost&#x119;pna pocz&#x105;wszy od <b>OpenSSL 1.0.0</b>.</p>
+
+</dd>
+<dt id="OCSP-URL"><b>OCSP</b> = URL</dt>
+<dd>
+
+<p>serwer OCSP do weryfikacji certyfikat&oacute;w</p>
+
+</dd>
+<dt id="OCSPaia-yes-no"><b>OCSPaia</b> = yes | no</dt>
+<dd>
+
+<p>weryfikuj certyfikaty przy u&#x17C;yciu respondert&oacute;w AIA</p>
+
+<p>Opcja <i>OCSPaia</i> pozwala na weryfikowanie certyfikat&oacute;w przy pomocy listy URLi serwer&oacute;w OCSP przes&#x142;anych w rozszerzeniach AIA (Authority Information Access).</p>
+
+</dd>
+<dt id="OCSPflag-FLAGA_OCSP"><b>OCSPflag</b> = FLAGA_OCSP</dt>
+<dd>
+
+<p>flaga serwera OCSP</p>
+
+<p>aktualnie wspierane flagi: NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY, NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME</p>
+
+<p>Aby wyspecyfikowa&#x107; kilka flag nale&#x17C;y u&#x17C;y&#x107; <i>OCSPflag</i> wielokrotnie.</p>
+
+</dd>
+<dt id="options-OPCJE_SSL"><b>options</b> = OPCJE_SSL</dt>
+<dd>
+
+<p>opcje biblioteki <b>OpenSSL</b></p>
+
+<p>Parametrem jest nazwa opcji zgodnie z opisem w <i>SSL_CTX_set_options(3ssl)</i>, ale bez przedrostka <i>SSL_OP_</i>. <i>stunnel -options</i> wy&#x15B;wietla opcje dozwolone w aktualnej kombinacji programu <i>stunnel</i> i biblioteki <i>OpenSSL</i>.</p>
+
+<p>Aby wyspecyfikowa&#x107; kilka opcji nale&#x17C;y u&#x17C;y&#x107; <i>options</i> wielokrotnie. Nazwa opcji mo&#x17C;e by&#x107; poprzedzona my&#x15B;lnikiem (&quot;-&quot;) celem wy&#x142;&#x105;czenia opcji.</p>
+
+<p>Na przyk&#x142;ad, dla zachowania kompatybilno&#x15B;ci z b&#x142;&#x119;dami implementacji SSL w programie Eudora, mo&#x17C;na u&#x17C;y&#x107; opcji:</p>
+
+<pre><code>    options = DONT_INSERT_EMPTY_FRAGMENTS</code></pre>
+
+<p>domy&#x15B;lnie:</p>
+
+<pre><code>    options = NO_SSLv2
+    options = NO_SSLv3</code></pre>
+
+</dd>
+<dt id="protocol-PROTOK"><b>protocol</b> = PROTOK&Oacute;&#x141;</dt>
+<dd>
+
+<p>negocjuj SSL podanym protoko&#x142;em aplikacyjnym</p>
+
+<p>Opcja ta w&#x142;&#x105;cza wst&#x119;pn&#x105; negocjacj&#x119; szyfrowania SSL dla wybranego protoko&#x142;u aplikacyjnego. Opcji <i>protocol</i> nie nale&#x17C;y u&#x17C;ywa&#x107; z szyfrowaniem SSL na osobnym porcie.</p>
+
+<p>Aktualnie wspierane protoko&#x142;y:</p>
+
+<dl>
+
+<dt id="cifs"><i>cifs</i></dt>
+<dd>
+
+<p>Unieudokumentowane rozszerzenie protoko&#x142;u CIFS wspierane przez serwer Samba. Wsparcie dla tego rozrzeczenia zosta&#x142;o zarzucone w wersji 3.0.0 serwera Samba.</p>
+
+</dd>
+<dt id="connect"><i>connect</i></dt>
+<dd>
+
+<p>Negocjacja RFC 2817 - <i>Upgrading to TLS Within HTTP/1.1</i>, rozdzia&#x142; 5.2 - <i>Requesting a Tunnel with CONNECT</i></p>
+
+<p>Ten protok&oacute;&#x142; jest wspierany wy&#x142;&#x105;cznie w trybie klienckim.</p>
+
+</dd>
+<dt id="imap"><i>imap</i></dt>
+<dd>
+
+<p>Negocjacja RFC 2595 - <i>Using TLS with IMAP, POP3 and ACAP</i></p>
+
+</dd>
+<dt id="nntp"><i>nntp</i></dt>
+<dd>
+
+<p>Negocjacja RFC 4642 - <i>Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)</i></p>
+
+<p>Ten protok&oacute;&#x142; jest wspierany wy&#x142;&#x105;cznie w trybie klienckim.</p>
+
+</dd>
+<dt id="pgsql"><i>pgsql</i></dt>
+<dd>
+
+<p>Negocjacja http://www.postgresql.org/docs/8.3/static/protocol-flow.html#AEN73982</p>
+
+</dd>
+<dt id="pop3"><i>pop3</i></dt>
+<dd>
+
+<p>Negocjacja RFC 2449 - <i>POP3 Extension Mechanism</i></p>
+
+</dd>
+<dt id="proxy"><i>proxy</i></dt>
+<dd>
+
+<p>Przekazywanie adresu IP haproxy http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt</p>
+
+</dd>
+<dt id="smtp"><i>smtp</i></dt>
+<dd>
+
+<p>Negocjacja RFC 2487 - <i>SMTP Service Extension for Secure SMTP over TLS</i></p>
+
+</dd>
+<dt id="socks"><i>socks</i></dt>
+<dd>
+
+<p>Wspierany jest protok&oacute;&#x142; SOCKS w wersjach 4, 4a i 5. Protok&oacute;&#x142; SOCKS enkapsulowany jest w protokole SSL/TLS, wi&#x119;c adres serwera docelowego nie jest widoczny dla napastnika przechwytuj&#x105;cego ruch sieciowy.</p>
+
+<p><i>http://www.openssh.com/txt/socks4.protocol</i></p>
+
+<p><i>http://www.openssh.com/txt/socks4a.protocol</i></p>
+
+<p>Nie jest wspierana komenda BIND protoko&#x142;u SOCKS. Przes&#x142;ana warto&#x15B;&#x107; parametru USERID jest ignorowana.</p>
+
+<p>Sekcja PRZYK&#x141;ADY zawiera przyk&#x142;adowe pliki konfiguracyjne VPNa zbudowanego w oparciu o szyfrowany protok&oacute;&#x142; SOCKS.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="protocolAuthentication-basic-ntlm"><b>protocolAuthentication</b> = basic | ntlm</dt>
+<dd>
+
+<p>rodzaj uwierzytelnienia do negocjacji protoko&#x142;u</p>
+
+<p>Obecnie typ uwierzytelnienia ma zastosowanie wy&#x142;&#x105;cznie w protokole &#39;connect&#39;.</p>
+
+<p>domy&#x15B;lnie: basic</p>
+
+</dd>
+<dt id="protocolHost-HOST:PORT"><b>protocolHost</b> = HOST:PORT</dt>
+<dd>
+
+<p>adres docelowy do negocjacji protoko&#x142;u</p>
+
+<p><i>protocolHost</i> okre&#x15B;la docelowy serwer SSL, do kt&oacute;rego po&#x142;&#x105;czy&#x107; ma si&#x119; proxy. Nie jest to adres serwera proxy, do kt&oacute;rego po&#x142;&#x105;czenie zestawia <b>stunnel</b>. Adres serwera proxy powinien by&#x107; okre&#x15B;lony przy pomocy opcji &#39;connect&#39;.</p>
+
+<p>W obecnej wersji adres docelowy protoko&#x142;u ma zastosowanie wy&#x142;&#x105;cznie w protokole &#39;connect&#39;.</p>
+
+</dd>
+<dt id="protocolPassword-HASO"><b>protocolPassword</b> = HAS&#x141;O</dt>
+<dd>
+
+<p>has&#x142;o do negocjacji protoko&#x142;u</p>
+
+</dd>
+<dt id="protocolUsername-UYTKOWNIK"><b>protocolUsername</b> = U&#x17B;YTKOWNIK</dt>
+<dd>
+
+<p>nazwa u&#x17C;ytkownika do negocjacji protoko&#x142;u</p>
+
+</dd>
+<dt id="PSKidentity-TOSAMO"><b>PSKidentity</b> = TO&#x17B;SAMO&#x15A;&#x106;</dt>
+<dd>
+
+<p>to&#x17C;samo&#x15B;&#x107; klienta PSK</p>
+
+<p><i>PSKidentity</i> mo&#x17C;e zosta&#x107; u&#x17C;yte w sekcjach klienckich do wybrania to&#x17C;samo&#x15B;ci u&#x17C;ytej do uwierzytelnienia PSK. Opcja jest ignorowana w sekcjach serwerowych.</p>
+
+<p>domy&#x15B;lnie: pierwsza to&#x17C;samo&#x15B;&#x107; zdefiniowana w pliku <i>PSKsecrets</i></p>
+
+</dd>
+<dt id="PSKsecrets-PLIK"><b>PSKsecrets</b> = PLIK</dt>
+<dd>
+
+<p>plik z to&#x17C;samo&#x15B;ciami i kluczami PSK</p>
+
+<p>Ka&#x17C;da linia pliku jest w nast&#x119;puj&#x105;cym formacie:</p>
+
+<pre><code>    TO&#x17B;SAMO&#x15A;&#x106;:KLUCZ</code></pre>
+
+<p>Klucz musi by&#x107; mie&#x107; przynajmniej 20 znak&oacute;w. Nale&#x17C;y ograniczy&#x107; dost&#x119;p do czytania lub pisania do tego pliku.</p>
+
+</dd>
+<dt id="pty-yes-no-tylko-Unix"><b>pty</b> = yes | no (tylko Unix)</dt>
+<dd>
+
+<p>alokuj pseudoterminal dla programu uruchamianego w opcji &#39;exec&#39;</p>
+
+</dd>
+<dt id="redirect-HOST:-PORT"><b>redirect</b> = [HOST:]PORT</dt>
+<dd>
+
+<p>przekieruj klienta, kt&oacute;remu nie uda&#x142;o si&#x119; poprawnie uwierzytelni&#x107; przy pomocy certyfikatu</p>
+
+<p>Opcja dzia&#x142;a wy&#x142;&#x105;cznie w trybie serwera. Cz&#x119;&#x15B;&#x107; negocjacji protoko&#x142;&oacute;w jest niekompatybilna z opcj&#x105; <i>redirect</i>.</p>
+
+</dd>
+<dt id="renegotiation-yes-no"><b>renegotiation</b> = yes | no</dt>
+<dd>
+
+<p>pozwalaj na renegocjacj&#x119; SSL</p>
+
+<p>W&#x15B;r&oacute;d zastosowa&#x144; renegocjacji SSL s&#x105; niekt&oacute;re scenariusze uwierzytelnienia, oraz renegocjacja kluczy dla d&#x142;ugotrwa&#x142;ych po&#x142;&#x105;cze&#x144;.</p>
+
+<p>Z drugiej strony w&#x142;asno&#x15B;&#x107; na mo&#x17C;e u&#x142;atwi&#x107; trywialny atak DoS poprzez wygenerowanie obci&#x105;&#x17C;enia procesora:</p>
+
+<p>http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html</p>
+
+<p>Warto zauwa&#x17C;y&#x107;, &#x17C;e zablokowanie renegocjacji SSL nie zebezpiecza w pe&#x142;ni przed opisanym problemem.</p>
+
+<p>domy&#x15B;lnie: yes (o ile wspierane przez <b>OpenSSL</b>)</p>
+
+</dd>
+<dt id="reset-yes-no"><b>reset</b> = yes | no</dt>
+<dd>
+
+<p>sygnalizuj wyst&#x105;pienie b&#x142;&#x119;du przy pomocy flagi TCP RST</p>
+
+<p>Opcja nie jest wspierana na niekt&oacute;rych platformach.</p>
+
+<p>domy&#x15B;lnie: yes</p>
+
+</dd>
+<dt id="retry-yes-no"><b>retry</b> = yes | no</dt>
+<dd>
+
+<p>po&#x142;&#x105;cz ponownie sekcj&#x119; connect+exec po roz&#x142;&#x105;czeniu</p>
+
+<p>domy&#x15B;lnie: no</p>
+
+</dd>
+<dt id="sessionCacheSize-LICZBA_POZYCJI_CACHE"><b>sessionCacheSize</b> = LICZBA_POZYCJI_CACHE</dt>
+<dd>
+
+<p>rozmiar pami&#x119;ci podr&#x119;cznej sesji SSL</p>
+
+<p>Parametr okre&#x15B;la maksymaln&#x105; liczb&#x119; pozycji wewn&#x119;trznej pami&#x119;ci podr&#x119;cznej sesji.</p>
+
+<p>Warto&#x15B;&#x107; 0 oznacza brak ograniczenia rozmiaru. Nie jest to zalecane dla system&oacute;w produkcyjnych z uwagi na ryzyko ataku DoS przez wyczerpanie pami&#x119;ci RAM.</p>
+
+</dd>
+<dt id="sessionCacheTimeout-LICZBA_SEKUND"><b>sessionCacheTimeout</b> = LICZBA_SEKUND</dt>
+<dd>
+
+<p>przeterminowanie pami&#x119;ci podr&#x119;cznej sesji SSL</p>
+
+<p>Parametr okre&#x15B;la czas w sekundach, po kt&oacute;rym sesja SSL zostanie usuni&#x119;ta z pami&#x119;ci podr&#x119;cznej.</p>
+
+</dd>
+<dt id="sessiond-HOST:PORT"><b>sessiond</b> = HOST:PORT</dt>
+<dd>
+
+<p>adres sessiond - servera cache sesji SSL</p>
+
+</dd>
+<dt id="sslVersion-WERSJA_SSL"><b>sslVersion</b> = WERSJA_SSL</dt>
+<dd>
+
+<p>wersja protoko&#x142;u SSL</p>
+
+<p>Wspierane opcje: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2</p>
+
+<p>Dost&#x119;pno&#x15B;&#x107; konkretnych protoko&#x142;&oacute;w zale&#x17C;y od u&#x17C;ytej wersji OpenSSL. Starsze wersje OpenSSL nie wspieraj&#x105; TLSv1.1 i TLSv1.2. Nowsze wersje OpenSSL nie wspieraj&#x105; SSLv2.</p>
+
+<p>Przestarza&#x142;e protoko&#x142;y SSLv2 i SSLv3 s&#x105; domy&#x15B;lnie wy&#x142;&#x105;czone. Szczeg&oacute;&#x142;owe informacje dost&#x119;pne s&#x105; w opisie opcji <b>options</b>.</p>
+
+</dd>
+<dt id="stack-LICZBA_BAJTW-z-wyjtkiem-modelu-FORK"><b>stack</b> = LICZBA_BAJT&Oacute;W (z wyj&#x105;tkiem modelu FORK)</dt>
+<dd>
+
+<p>rozmiar stosu procesora w&#x105;tku</p>
+
+</dd>
+<dt id="TIMEOUTbusy-LICZBA_SEKUND"><b>TIMEOUTbusy</b> = LICZBA_SEKUND</dt>
+<dd>
+
+<p>czas oczekiwania na spodziewane dane</p>
+
+</dd>
+<dt id="TIMEOUTclose-LICZBA_SEKUND"><b>TIMEOUTclose</b> = LICZBA_SEKUND</dt>
+<dd>
+
+<p>czas oczekiwania na close_notify (ustaw na 0, je&#x17C;eli klientem jest MSIE)</p>
+
+</dd>
+<dt id="TIMEOUTconnect-LICZBA_SEKUND"><b>TIMEOUTconnect</b> = LICZBA_SEKUND</dt>
+<dd>
+
+<p>czas oczekiwania na nawi&#x105;zanie po&#x142;&#x105;czenia</p>
+
+</dd>
+<dt id="TIMEOUTidle-LICZBA_SEKUND"><b>TIMEOUTidle</b> = LICZBA_SEKUND</dt>
+<dd>
+
+<p>maksymalny czas utrzymywania bezczynnego po&#x142;&#x105;czenia</p>
+
+</dd>
+<dt id="transparent-none-source-destination-both-tylko-Unix"><b>transparent</b> = none | source | destination | both (tylko Unix)</dt>
+<dd>
+
+<p>tryb przezroczystego proxy na wspieranych platformach</p>
+
+<p>Wspierane opcje:</p>
+
+<dl>
+
+<dt id="none"><b>none</b></dt>
+<dd>
+
+<p>Zablokuj wsparcie dla przezroczystago proxy. Jest to warto&#x15B;&#x107; domy&#x15B;lna.</p>
+
+</dd>
+<dt id="source"><b>source</b></dt>
+<dd>
+
+<p>Przepisz adres, aby nawi&#x105;zywane po&#x142;&#x105;czenie wydawa&#x142;o si&#x119; pochodzi&#x107; bezpo&#x15B;rednio od klienta, a nie od programu <b>stunnel</b>.</p>
+
+<p>Opcja jest aktualnie obs&#x142;ugiwana w:</p>
+
+<dl>
+
+<dt id="Trybie-zdalnym-opcja-connect-w-systemie-Linux-2.6.28">Trybie zdalnym (opcja <i>connect</i>) w systemie <i>Linux &gt;=2.6.28</i></dt>
+<dd>
+
+<p>Konfiguracja wymaga nast&#x119;puj&#x105;cych ustawie&#x144; iptables oraz routingu (na przyk&#x142;ad w pliku /etc/rc.local lub analogicznym):</p>
+
+<pre><code>    iptables -t mangle -N DIVERT
+    iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT
+    iptables -t mangle -A DIVERT -j MARK --set-mark 1
+    iptables -t mangle -A DIVERT -j ACCEPT
+    ip rule add fwmark 1 lookup 100
+    ip route add local 0.0.0.0/0 dev lo table 100
+    echo 0 &gt;/proc/sys/net/ipv4/conf/lo/rp_filter</code></pre>
+
+<p>Konfiguracja ta wymaga, aby <b>stunnel</b> by&#x142; wykonywany jako root i bez opcji <i>setuid</i>.</p>
+
+</dd>
+<dt id="Trybie-zdalnym-opcja-connect-w-systemie-Linux-2.2.x">Trybie zdalnym (opcja <i>connect</i>) w systemie <i>Linux 2.2.x</i></dt>
+<dd>
+
+<p>Konfiguracja ta wymaga skompilowania j&#x105;dra z opcj&#x105; <i>transparent proxy</i>. Docelowa us&#x142;uga musi by&#x107; umieszczona na osobnej maszynie, do kt&oacute;rej routing kierowany jest poprzez serwer <b>stunnela</b>.</p>
+
+<p>Dodatkowo <b>stunnel</b> powinien by&#x107; wykonywany jako root i bez opcji <i>setuid</i>.</p>
+
+</dd>
+<dt id="Trybie-zdalnym-opcja-connect-w-systemie-FreeBSD-8.0">Trybie zdalnym (opcja <i>connect</i>) w systemie <i>FreeBSD &gt;=8.0</i></dt>
+<dd>
+
+<p>Konfiguracja ta wymaga skonfigurowania firewalla i routingu. <b>stunnel</b> musi by&#x107; wykonywany jako root i bez opcji <i>setuid</i>.</p>
+
+</dd>
+<dt id="Trybie-lokalnym-opcja-exec">Trybie lokalnym (opcja <i>exec</i>)</dt>
+<dd>
+
+<p>Konfiguracja ta jest realizowana przy pomocy biblioteki <i>libstunnel.so</i>. Do za&#x142;adowania biblioteki wykorzystywana jest zmienna &#x15B;rodowiskowa _RLD_LIST na platformie Tru64 lub LD_PRELOAD na innych platformach.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="destination"><i>destination</i></dt>
+<dd>
+
+<p>Oryginalny adres docelowy jest u&#x17C;ywany zamiast opcji <i>connect</i>.</p>
+
+<p>Przyk&#x142;adowana konfiguracja przezroczystego adresu docelowego:</p>
+
+<pre><code>    [transparent]
+    client=yes
+    accept=&lt;port_stunnela&gt;
+    transparent=destination</code></pre>
+
+<p>Konfiguracja wymaga ustawie&#x144; iptables, na przyk&#x142;ad w pliku /etc/rc.local lub analogicznym.</p>
+
+<p>W przypadku docelowej us&#x142;ugi umieszczonej na tej samej maszynie:</p>
+
+<pre><code>    /sbin/iptables -t nat -I OUTPUT -p tcp --dport &lt;port_przekierowany&gt; \
+        -m ! --uid-owner &lt;identyfikator_u&#x17C;ytkownika_stunnela&gt; \
+        -j DNAT --to-destination &lt;lokalne_ip&gt;:&lt;lokalny_port&gt;</code></pre>
+
+<p>W przypadku docelowej us&#x142;ugi umieszczonej na zdalnej maszynie:</p>
+
+<pre><code>    /sbin/iptables -I INPUT -i eth0 -p tcp --dport &lt;port_stunnela&gt; -j ACCEPT
+    /sbin/iptables -t nat -I PREROUTING -p tcp --dport &lt;port_przekierowany&gt; \
+        -i eth0 -j DNAT --to-destination &lt;lokalne_ip&gt;:&lt;port_stunnela&gt;</code></pre>
+
+<p>Przezroczysty adres docelowy jest aktualnie wspierany wy&#x142;&#x105;cznie w systemie Linux.</p>
+
+</dd>
+<dt id="both"><i>both</i></dt>
+<dd>
+
+<p>U&#x17C;yj przezroczystego proxy zar&oacute;wno dla adresu &#x17A;r&oacute;d&#x142;owego jak i docelowego.</p>
+
+</dd>
+</dl>
+
+<p>Dla zapewnienia kompatybilno&#x15B;ci z wcze&#x15B;niejszymim wersjami wspierane s&#x105; dwie dodatkowe opcje:</p>
+
+<dl>
+
+<dt id="yes"><i>yes</i></dt>
+<dd>
+
+<p>Opcja zosta&#x142;a przemianowana na <i>source</i>.</p>
+
+</dd>
+<dt id="no"><i>no</i></dt>
+<dd>
+
+<p>Opcja zosta&#x142;a przemianowana na <i>none</i>.</p>
+
+</dd>
+</dl>
+
+</dd>
+<dt id="verify-POZIOM"><b>verify</b> = POZIOM</dt>
+<dd>
+
+<p>weryfikuj certyfikat drugiej strony po&#x142;&#x105;czenia</p>
+
+<dl>
+
+<dt id="poziom-0"><i>poziom 0</i></dt>
+<dd>
+
+<p>zarz&#x105;daj certyfikatu i zignoruj go</p>
+
+</dd>
+<dt id="poziom-1"><i>poziom 1</i></dt>
+<dd>
+
+<p>weryfikuj, je&#x17C;eli zosta&#x142; przedstawiony</p>
+
+</dd>
+<dt id="poziom-2"><i>poziom 2</i></dt>
+<dd>
+
+<p>weryfikuj z zainstalowanym certyfikatem Centrum Certyfikacji</p>
+
+</dd>
+<dt id="poziom-3"><i>poziom 3</i></dt>
+<dd>
+
+<p>weryfikuj z lokalnie zainstalowanym certyfikatem drugiej strony</p>
+
+</dd>
+<dt id="poziom-4"><i>poziom 4</i></dt>
+<dd>
+
+<p>weryfikuj z certyfikatem drugiej strony ignoruj&#x105;c &#x142;a&#x144;cuch CA</p>
+
+</dd>
+<dt id="domylnie"><i>domy&#x15B;lnie</i></dt>
+<dd>
+
+<p>nie weryfikuj</p>
+
+</dd>
+</dl>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="ZWRACANA-WARTO">ZWRACANA WARTO&#x15A;&#x106;</h1></a>
+
+<p><b>stunnel</b> zwraca zero w przypadku sukcesu, lub warto&#x15B;&#x107; niezerow&#x105; w przypadku b&#x142;&#x119;du.</p>
+
+<a href="#_podtop_"><h1 id="SIGNAY">SIGNA&#x141;Y</h1></a>
+
+<p>Nast&#x119;puj&#x105;ce sygna&#x142;y mog&#x105; by&#x107; u&#x17C;yte do sterowania programem w systemie Unix:</p>
+
+<dl>
+
+<dt id="SIGHUP">SIGHUP</dt>
+<dd>
+
+<p>Za&#x142;aduj ponownie plik konfiguracyjny.</p>
+
+<p>Niekt&oacute;re globalne opcje nie b&#x119;d&#x105; prze&#x142;adowane:</p>
+
+<ul>
+
+<li><p>chroot</p>
+
+</li>
+<li><p>foreground</p>
+
+</li>
+<li><p>pid</p>
+
+</li>
+<li><p>setgid</p>
+
+</li>
+<li><p>setuid</p>
+
+</li>
+</ul>
+
+<p>Je&#x17C;eli wykorzystywana jest opcja &#39;setuid&#39; <b>stunnel</b> nie b&#x119;dzie m&oacute;g&#x142; za&#x142;adowa&#x107; ponownie konfiguracji wykorzystuj&#x105;cej uprzywilejowane (&lt;1024) porty.</p>
+
+<p>Je&#x17C;eli wykorzystywana jest opcja &#39;chroot&#39; <b>stunnel</b> b&#x119;dzie szuka&#x142; wszystkich potrzebnych plik&oacute;w (&#x142;&#x105;cznie z plikiem konfiguracyjnym, certyfikatami, logiem i plikiem pid) wewn&#x105;trz katalogu wskazanego przez &#39;chroot&#39;.</p>
+
+</dd>
+<dt id="SIGUSR1">SIGUSR1</dt>
+<dd>
+
+<p>Zamknij i otw&oacute;rz ponownie log. Funkcja ta mo&#x17C;e zosta&#x107; u&#x17C;yta w skrypcie rotuj&#x105;cym log programu <b>stunnel</b>.</p>
+
+</dd>
+<dt id="SIGTERM-SIGQUIT-SIGINT">SIGTERM, SIGQUIT, SIGINT</dt>
+<dd>
+
+<p>Zako&#x144;cz dzia&#x142;anie programu.</p>
+
+</dd>
+</dl>
+
+<p>Skutek wys&#x142;ania innych sygna&#x142;&oacute;w jest niezdefiniowany.</p>
+
+<a href="#_podtop_"><h1 id="PRZYKADY">PRZYK&#x141;ADY</h1></a>
+
+<p>Szyfrowanie po&#x142;&#x105;cze&#x144; do lokalnego serwera <i>imapd</i> mo&#x17C;na u&#x17C;y&#x107;:</p>
+
+<pre><code>    [imapd]
+    accept = 993
+    exec = /usr/sbin/imapd
+    execArgs = imapd</code></pre>
+
+<p>albo w trybie zdalnym:</p>
+
+<pre><code>    [imapd]
+    accept = 993
+    connect = 143</code></pre>
+
+<p>Aby umo&#x17C;liwi&#x107; lokalnemu klientowi poczty elektronicznej korzystanie z serwera <i>imapd</i> przez SSL nale&#x17C;y skonfigurowa&#x107; pobieranie poczty z adresu localhost i portu 119, oraz u&#x17C;y&#x107; nast&#x119;puj&#x105;cej konfiguracji:</p>
+
+<pre><code>    [imap]
+    client = yes
+    accept = 143
+    connect = serwer:993</code></pre>
+
+<p>W po&#x142;&#x105;czeniu z programem <i>pppd</i> <b>stunnel</b> pozwala zestawi&#x107; prosty VPN. Po stronie serwera nas&#x142;uchuj&#x105;cego na porcie 2020 jego konfiguracja mo&#x17C;e wygl&#x105;da&#x107; nast&#x119;puj&#x105;co:</p>
+
+<pre><code>    [vpn]
+    accept = 2020
+    exec = /usr/sbin/pppd
+    execArgs = pppd local
+    pty = yes</code></pre>
+
+<p>Poni&#x17C;szy plik konfiguracyjny mo&#x17C;e by&#x107; wykorzystany do uruchomienia programu <b>stunnel</b> w trybie <i>inetd</i>. Warto zauwa&#x17C;y&#x107;, &#x17C;e w pliku konfiguracyjnym nie ma sekcji <i>[nazwa_us&#x142;ugi]</i>.</p>
+
+<pre><code>    exec = /usr/sbin/imapd
+    execArgs = imapd</code></pre>
+
+<p>Aby skonfigurowa&#x107; VPN mo&#x17C;na u&#x17C;y&#x107; nast&#x119;puj&#x105;cej konfiguracji klienta:</p>
+
+<pre><code>    [socks_client]
+    client = yes
+    accept = 127.0.0.1:1080
+    connect = vpn_server:9080
+    verify = 4
+    CAfile = stunnel.pem</code></pre>
+
+<p>Odpowiadaj&#x105;ca jej konfiguracja serwera vpn_server:</p>
+
+<pre><code>    [socks_server]
+    protocol = socks
+    accept = 9080
+    cert = stunnel.pem
+    key = stunnel.key</code></pre>
+
+<p>Do przetestowania konfiguracji mo&#x17C;na wyda&#x107; na maszynie klienckiej komend&#x119;:</p>
+
+<pre><code>    curl --socks4a localhost http://www.example.com/</code></pre>
+
+<a href="#_podtop_"><h1 id="NOTKI">NOTKI</h1></a>
+
+<h2 id="OGRANICZENIA">OGRANICZENIA</h2>
+
+<p><b>stunnel</b> nie mo&#x17C;e by&#x107; u&#x17C;ywany do szyfrowania protoko&#x142;u <i>FTP</i>, poniewa&#x17C; do przesy&#x142;ania poszczeg&oacute;lnych plik&oacute;w u&#x17C;ywa on dodatkowych po&#x142;&#x105;cze&#x144; otwieranych na portach o dynamicznie przydzielanych numerach. Istniej&#x105; jednak specjalne wersje klient&oacute;w i serwer&oacute;w FTP pozwalaj&#x105;ce na szyfrowanie przesy&#x142;anych danych przy pomocy protoko&#x142;u <i>SSL</i>.</p>
+
+<h2 id="TRYB-INETD-tylko-Unix">TRYB INETD (tylko Unix)</h2>
+
+<p>W wi&#x119;kszo&#x15B;ci zastosowa&#x144; <b>stunnel</b> samodzielnie nas&#x142;uchuje na porcie podanym w pliku konfiguracyjnym i tworzy po&#x142;&#x105;czenie z innym portem podanym w opcji <i>connect</i> lub nowym programem podanym w opcji <i>exec</i>. Niekt&oacute;rzy wol&#x105; jednak wykorzystywa&#x107; oddzielny program, kt&oacute;ry odbiera po&#x142;&#x105;czenia, po czym uruchamia program <b>stunnel</b>. Przyk&#x142;adami takich program&oacute;w s&#x105; inetd, xinetd i tcpserver.</p>
+
+<p>Przyk&#x142;adowa linia pliku /etc/inetd.conf mo&#x17C;e wygl&#x105;da&#x107; tak:</p>
+
+<pre><code>    imaps stream tcp nowait root @bindir@/stunnel
+        stunnel @sysconfdir@/stunnel/imaps.conf</code></pre>
+
+<p>Poniewa&#x17C; w takich przypadkach po&#x142;&#x105;czenie na zdefiniowanym porcie (tutaj <i>imaps</i>) nawi&#x105;zuje osobny program (tutaj <i>inetd</i>), <b>stunnel</b> nie mo&#x17C;e u&#x17C;ywa&#x107; opcji <i>accept</i>. W pliku konfiguracyjnym nie mo&#x17C;e by&#x107; r&oacute;wnie&#x17C; zdefiniowana &#x17C;adna us&#x142;uga (<i>[nazwa_us&#x142;ugi]</i>), poniewa&#x17C; konfiguracja taka pozwala na nawi&#x105;zanie tylko jednego po&#x142;&#x105;czenia. Wszystkie <i>OPCJE US&#x141;UG</i> powinny by&#x107; umieszczone razem z opcjami globalnymi. Przyk&#x142;ad takiej konfiguracji znajduje si&#x119; w sekcji <i>PRZYK&#x141;ADY</i>.</p>
+
+<h2 id="CERTYFIKATY">CERTYFIKATY</h2>
+
+<p>Protok&oacute;&#x142; SSL wymaga, aby ka&#x17C;dy serwer przedstawia&#x142; si&#x119; nawi&#x105;zuj&#x105;cemu po&#x142;&#x105;czenie klientowi prawid&#x142;owym certyfikatem X.509. Potwierdzenie to&#x17C;samo&#x15B;ci serwera polega na wykazaniu, &#x17C;e posiada on odpowiadaj&#x105;cy certyfikatowi klucz prywatny. Najprostsz&#x105; metod&#x105; uzyskania certyfikatu jest wygenerowanie go przy pomocy wolnego pakietu <b>OpenSSL</b>. Wi&#x119;cej informacji na temat generowania certyfikat&oacute;w mo&#x17C;na znale&#x17A;&#x107; na umieszczonych poni&#x17C;ej stronach.</p>
+
+<p>Istotn&#x105; kwesti&#x105; jest kolejno&#x15B;&#x107; zawarto&#x15B;ci pliku <i>.pem</i>. W pierwszej kolejno&#x15B;ci powinien on zawiera&#x107; klucz prywatny, a dopiero za nim podpisany certyfikat (nie &#x17C;&#x105;danie certyfikatu). Po certyfikacie i kluczu prywatnym powinny znajdowa&#x107; si&#x119; puste linie. Je&#x17C;eli przed certyfikatem znajduj&#x105; si&#x119; dodatkowe informacje tekstowe, to powinny one zosta&#x107; usuni&#x119;te. Otrzymany plik powinien mie&#x107; nast&#x119;puj&#x105;c&#x105; posta&#x107;:</p>
+
+<pre><code>    -----BEGIN RSA PRIVATE KEY-----
+    [zakodowany klucz]
+    -----END RSA PRIVATE KEY-----
+    [pusta linia]
+    -----BEGIN CERTIFICATE-----
+    [zakodowany certyfikat]
+    -----END CERTIFICATE-----
+    [pusta linia]</code></pre>
+
+<h2 id="LOSOWO">LOSOWO&#x15A;&#x106;</h2>
+
+<p><b>stunnel</b> potrzebuje zainicjowa&#x107; PRNG (generator liczb pseudolosowych), gdy&#x17C; protok&oacute;&#x142; SSL wymaga do bezpiecze&#x144;stwa kryptograficznego &#x17A;r&oacute;d&#x142;a dobrej losowo&#x15B;ci. Nast&#x119;puj&#x105;ce &#x17A;r&oacute;d&#x142;a s&#x105; kolejno odczytywane a&#x17C; do uzyskania wystarczaj&#x105;cej ilo&#x15B;ci entropii:</p>
+
+<ul>
+
+<li><p>Zawarto&#x15B;&#x107; pliku podanego w opcji <i>RNDfile</i>.</p>
+
+</li>
+<li><p>Zawarto&#x15B;&#x107; pliku o nazwie okre&#x15B;lonej przez zmienn&#x105; &#x15B;rodowiskow&#x105; RANDFILE, o ile jest ona ustawiona.</p>
+
+</li>
+<li><p>Plik .rnd umieszczony w katalogu domowym u&#x17C;ytkownika, je&#x17C;eli zmienna RANDFILE nie jest ustawiona.</p>
+
+</li>
+<li><p>Plik podany w opcji &#39;--with-random&#39; w czasie konfiguracji programu.</p>
+
+</li>
+<li><p>Zawarto&#x15B;&#x107; ekranu w systemie Windows.</p>
+
+</li>
+<li><p>Gniazdo egd, je&#x17C;eli u&#x17C;yta zosta&#x142;a opcja <i>EGD</i>.</p>
+
+</li>
+<li><p>Gniazdo egd podane w opcji &#39;--with-egd-socket&#39; w czasie konfiguracji programu.</p>
+
+</li>
+<li><p>Urz&#x105;dzenie /dev/urandom.</p>
+
+</li>
+</ul>
+
+<p>Wsp&oacute;&#x142;czesne (<b>0.9.5a</b> lub nowsze) wersje biblioteki <b>OpenSSL</b> automatycznie zaprzestaj&#x105; &#x142;adowania kolejnych danych w momencie uzyskania wystarczaj&#x105;cej ilo&#x15B;ci entropii. Wcze&#x15B;niejsze wersje biblioteki wykorzystaj&#x105; wszystkie powy&#x17C;sze &#x17A;r&oacute;d&#x142;a, gdy&#x17C; nie istnieje tam funkcja pozwalaj&#x105;ca okre&#x15B;li&#x107;, czy uzyskano ju&#x17C; wystarczaj&#x105;co du&#x17C;o danych.</p>
+
+<p>Warto zwr&oacute;ci&#x107; uwag&#x119;, &#x17C;e na maszynach z systemem Windows, na kt&oacute;rych konsoli nie pracuje u&#x17C;ytkownik, zawarto&#x15B;&#x107; ekranu nie jest wystarczaj&#x105;co zmienna, aby zainicjowa&#x107; PRNG. W takim przypadku do zainicjowania generatora nale&#x17C;y u&#x17C;y&#x107; opcji <i>RNDfile</i>.</p>
+
+<p>Plik <i>RNDfile</i> powinien zawiera&#x107; dane losowe -- r&oacute;wnie&#x17C; w tym sensie, &#x17C;e powinny by&#x107; one inne przy ka&#x17C;dym uruchomieniu programu <b>stunnel</b>. O ile nie u&#x17C;yta zosta&#x142;a opcja <i>RNDoverwrite</i> jest to robione automatycznie. Do r&#x119;cznego uzyskania takiego pliku u&#x17C;yteczna mo&#x17C;e by&#x107; komenda <i>openssl rand</i> dostarczana ze wsp&oacute;&#x142;czesnymi wersjami pakietu <b>OpenSSL</b>.</p>
+
+<p>Jeszcze jedna istotna informacja -- je&#x17C;eli dost&#x119;pne jest urz&#x105;dzenie <i>/dev/urandom</i> biblioteka <b>OpenSSL</b> ma zwyczaj zasilania nim PRNG w trakcie sprawdzania stanu generatora. W systemach z <i>/dev/urandom</i> urz&#x105;dzenie to b&#x119;dzie najprawdopodobniej u&#x17C;yte, pomimo &#x17C;e znajduje si&#x119; na samym ko&#x144;cu powy&#x17C;szej listy. Jest to w&#x142;a&#x15B;ciwo&#x15B;&#x107; biblioteki <b>OpenSSL</b>, a nie programu <b>stunnel</b>.</p>
+
+<h2 id="PARAMETRY-DH">PARAMETRY DH</h2>
+
+<p>Pocz&#x105;wszy od wersji 4.40 <b>stunnel</b> zawiera w kodzie programu 2048-bitowe parametry DH. Od wersji 5.18 te pocz&#x105;tkowe warto&#x15B;ci parametr&oacute;w DH s&#x105; wymieniane na autogenerowane parametry tymczasowe. Wygenerowanie parametr&oacute;w DH mo&#x17C;e zaj&#x105;&#x107; nawet wiele minut.</p>
+
+<p>Alternatywnie parametry DH mo&#x17C;na umie&#x15B;ci&#x107; w pliku razem z certyfikatem, co wy&#x142;&#x105;cza generowanie parametr&oacute;w tymczasowych:</p>
+
+<pre><code>    openssl dhparam 2048 &gt;&gt; stunnel.pem</code></pre>
+
+<a href="#_podtop_"><h1 id="PLIKI">PLIKI</h1></a>
+
+<dl>
+
+<dt id="sysconfdir-stunnel-stunnel.conf"><i>@sysconfdir@/stunnel/stunnel.conf</i></dt>
+<dd>
+
+<p>plik konfiguracyjny programu</p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="BDY">B&#x141;&#x118;DY</h1></a>
+
+<p>Opcja <i>execArgs</i> oraz linia komend Win32 nie obs&#x142;uguje cytowania.</p>
+
+<a href="#_podtop_"><h1 id="ZOBACZ-RWNIE">ZOBACZ R&Oacute;WNIE&#x17B;</h1></a>
+
+<dl>
+
+<dt id="tcpd-8"><a href="http://man.he.net/man8/tcpd">tcpd(8)</a></dt>
+<dd>
+
+<p>biblioteka kontroli dost&#x119;pu do us&#x142;ug internetowych</p>
+
+</dd>
+<dt id="inetd-8"><a href="http://man.he.net/man8/inetd">inetd(8)</a></dt>
+<dd>
+
+<p>&#39;super-serwer&#39; internetowy</p>
+
+</dd>
+<dt id="http:-www.stunnel.org"><i>http://www.stunnel.org/</i></dt>
+<dd>
+
+<p>strona domowa programu <b>stunnel</b></p>
+
+</dd>
+<dt id="http:-www.openssl.org"><i>http://www.openssl.org/</i></dt>
+<dd>
+
+<p>strona projektu <b>OpenSSL</b></p>
+
+</dd>
+</dl>
+
+<a href="#_podtop_"><h1 id="AUTOR">AUTOR</h1></a>
+
+<dl>
+
+<dt id="Micha-Trojnara">Micha&#x142; Trojnara</dt>
+<dd>
+
+<p>&lt;<i>Michal.Trojnara@mirt.net</i>&gt;</p>
+
+</dd>
+</dl>
+
+<table border="0" width="100%" cellspacing="0" cellpadding="3">
+<tr><td class="_podblock_" style="background-color: #cccccc; color: #000" valign="middle">
+<big><strong><span class="_podblock_">&nbsp;stunnel TLS Proxy</span></strong></big>
+</td></tr>
+</table>
+
+</body>
+
+</html>
+
+
diff --git a/doc/stunnel.pl.pod.in b/doc/stunnel.pl.pod.in
new file mode 100644
index 0000000..6c07bb2
--- /dev/null
+++ b/doc/stunnel.pl.pod.in
@@ -0,0 +1,1408 @@
+=head1 NAZWA
+
+=encoding utf8
+
+stunnel - uniwersalny tunel protokołu SSL
+
+
+=head1 SKŁADNIA
+
+=over 4
+
+=item B<Unix:>
+
+B<stunnel> [S<PLIK>] | S<-fd N> | S<-help> | S<-version> | S<-sockets> | S<-options>
+
+=item B<WIN32:>
+
+B<stunnel> [ [ S<-install> | S<-uninstall> | S<-start> | S<-stop> |
+    S<-reload> | S<-reopen> | S<-exit> ] [S<-quiet>] [S<PLIK>] ] |
+    S<-help> | S<-version> | S<-sockets> | S<-options>
+
+=back
+
+
+=head1 OPIS
+
+Program B<stunnel> został zaprojektowany do opakowywania w protokół I<SSL>
+połączeń pomiędzy zdalnymi klientami a lokalnymi lub zdalnymi serwerami.
+Przez serwer lokalny rozumiana jest aplikacja przeznaczona do uruchamiania
+przy pomocy I<inetd>.
+Stunnel pozwala na proste zestawienie komunikacji serwerów nie posiadających
+funkcjonalności I<SSL> poprzez bezpieczne kanały I<SSL>.
+
+B<stunnel> pozwala dodać funkcjonalność I<SSL> do powszechnie stosowanych
+demonów I<inetd>, np. I<pop3> lub I<imap>, do samodzielnych demonów,
+np. I<nntp>, I<smtp> lub I<http>, a nawet tunelować ppp poprzez gniazda sieciowe
+bez zmian w kodzie źródłowym.
+
+
+=head1 OPCJE
+
+=over 4
+
+=item B<PLIK>
+
+użyj podanego pliku konfiguracyjnego
+
+=item B<-fd N> (tylko Unix)
+
+wczytaj konfigurację z podanego deskryptora pliku
+
+=item B<-help>
+
+drukuj listę wspieranych opcji
+
+=item B<-version>
+
+drukuj wersję programu i domyślne wartości parametrów
+
+=item B<-sockets>
+
+drukuj domyślne opcje gniazd
+
+=item B<-options>
+
+drukuj wspierane opcje SSL
+
+=item B<-install> (tylko Windows NT lub nowszy)
+
+instaluj serwis NT
+
+=item B<-uninstall> (tylko Windows NT lub nowszy)
+
+odinstaluj serwis NT
+
+=item B<-start> (tylko Windows NT lub nowszy)
+
+uruchom serwis NT
+
+=item B<-stop> (tylko Windows NT lub nowszy)
+
+zatrzymaj serwis NT
+
+=item B<-reload> (tylko Windows NT lub nowszy)
+
+przeładuj plik konfiguracyjny uruchomionego serwisu NT
+
+=item B<-reopen> (tylko Windows NT lub nowszy)
+
+otwórz ponownie log uruchomionego serwisu NT
+
+=item B<-exit> (tylko Win32)
+
+zatrzymaj uruchomiony program
+
+=item B<-quiet> (tylko Win32)
+
+nie wyświetlaj okienek z komunikatami
+
+=back
+
+
+=head1 PLIK KONFIGURACYJNY
+
+Linia w pliku konfiguracyjnym może być:
+
+=over 4
+
+=item *
+
+pusta (ignorowana)
+
+=item *
+
+komentarzem rozpoczynającym się znakiem ';' (ignorowana)
+
+=item *
+
+parą 'nazwa_opcji = wartość_opcji'
+
+=item *
+
+tekstem '[nazwa_usługi]' wskazującym początek definicji usługi
+
+=back
+
+Parametr adres może być:
+
+=over 4
+
+=item *
+
+numerem portu
+
+=item *
+
+oddzieloną średnikiem parą adresu (IPv4, IPv6, lub nazwą domenową) i numeru portu
+
+=item *
+
+ścieżką do gniazda Unix (tylko Unix)
+
+=back
+
+=head2 OPCJE GLOBALNE
+
+=over 4
+
+=item B<chroot> = KATALOG (tylko Unix)
+
+katalog roboczego korzenia systemu plików
+
+Opcja określa katalog, w którym uwięziony zostanie proces programu
+B<stunnel> tuż po jego inicjalizacji, a przed rozpoczęciem odbierania
+połączeń.  Ścieżki podane w opcjach I<CApath>, I<CRLpath>, I<pid>
+oraz I<exec> muszą być umieszczone wewnątrz katalogu podanego w opcji
+I<chroot> i określone względem tego katalogu.
+
+Niektóre funkcje systemu operacyjnego mogą wymagać dodatkowych plików umieszczonych w katalogu podanego w parametrze chroot:
+
+=over 4
+
+=item *
+
+opóźnione rozwinięcie adresów DNS typowo wymaga /etc/nsswitch.conf i /etc/resolv.conf
+
+=item *
+
+lokalizacja strefy czasowej w logach wymaga pliku /etc/timezone
+
+=item *
+
+niektóre inne pliki mogą potrzebować plików urządzeń, np. /dev/zero lub /dev/null
+
+=back
+
+=item B<compression> = deflate | zlib
+
+wybór algorytmu kompresji przesyłanych danych
+
+domyślnie: bez kompresji
+
+Algorytm deflate jest standardową metodą kompresji zgodnie z RFC 1951.
+
+Kompresja zlib zaimplementowana w B<OpenSSL 0.9.8> i nowszych nie jest
+kompatybilna implementacją B<OpenSSL 0.9.7>.
+
+=item B<debug> = [PODSYSTEM].POZIOM
+
+szczegółowość logowania
+
+Poziom logowania można określić przy pomocy jednej z nazw lub liczb:
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6) lub debug (7).
+Zapisywane są komunikaty o poziomie niższym (numerycznie) lub równym podanemu.
+Do uzyskania najwyższego poziomu szczegółowości można użyć opcji
+I<debug = debug> lub I<debug = 7>.  Domyślnym poziomem jest notice (5).
+
+O ile nie wyspecyfikowano podsystemu użyty będzie domyślny: daemon.
+Podsystemy nie są wspierane przez platformę Win32.
+
+Wielkość liter jest ignorowana zarówno dla poziomu jak podsystemu.
+
+=item B<EGD> = ŚCIEŻKA_DO_EGD (tylko Unix)
+
+ścieżka do gniazda programu Entropy Gathering Daemon
+
+Opcja pozwala określić ścieżkę do gniazda programu Entropy Gathering Daemon
+używanego do zainicjalizowania generatora ciągów pseudolosowych biblioteki
+B<OpenSSL>.  Opcja jest dostępna z biblioteką B<OpenSSL 0.9.5a> lub nowszą.
+
+=item B<engine> = auto | IDENTYFIKATOR_URZĄDZENIA
+
+wybór sprzętowego urządzenia kryptograficznego
+
+domyślnie: bez wykorzystania urządzeń kryptograficznych
+
+Przykładowa konfiguracja umożliwiająca odczytanie klucza prywatnego z
+urządzenia zgodnego z OpenSC:
+
+    engine=dynamic
+    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+    engineCtrl=ID:pkcs11
+    engineCtrl=LIST_ADD:1
+    engineCtrl=LOAD
+    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc-pkcs11.so
+    engineCtrl=INIT
+
+    [service]
+    engineNum=1
+    key=id_45
+
+=item B<engineCtrl> = KOMENDA[:PARAMETR]
+
+konfiguracja urządzenia kryptograficznego
+
+Specjalne komendy "LOAD" i "INIT" pozwalają na załadowanie i inicjalizację
+modułu kryptograficznego urządzenia.
+
+=item B<engineDefault> = LISTA_ZADAŃ
+
+lista zadań OpenSSL oddelegowanych do bieżącego urządzenia
+
+Parametrem jest lista oddzielonych przecinkami zadań OpenSSL, które mają
+zostać oddelegowane do bieżącego urządzenia kryptograficznego.
+
+W zależności od konkretnego urządzenia dostępne mogą być następujące zadania:
+ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO,
+PKEY_ASN1.
+
+=item B<fips> = yes | no
+
+tryb FIPS 140-2
+
+Opcja pozwala wyłączyć wejście w tryb FIPS, jeśli B<stunnel> został
+skompilowany ze wsparciem dla FIPS 140-2.
+
+domyślnie: no (od wersji 5.00)
+
+=item B<foreground> = yes | no (tylko Unix)
+
+tryb pierwszoplanowy
+
+Użycie tej opcji powoduje, że B<stunnel> nie przechodzi w tło logując
+swoje komunikaty na konsolę zamiast przez I<syslog> (o ile nie użyto
+opcji I<output>).
+
+=item B<iconActive> = PLIK_Z_IKONKĄ (tylko GUI)
+
+ikonka wyświetlana przy obecności aktywnych połączeń do usługi
+
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+
+=item B<iconError> = PLIK_Z_IKONKĄ (tylko GUI)
+
+ikonka wyświetlana, jeżeli nie został załadowany poprawny plik konfiguracyjny
+
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+
+=item B<iconIdle> = PLIK_Z_IKONKĄ (tylko GUI)
+
+ikonka wyświetlana przy braku aktywnych połączeń do usługi
+
+W systemie Windows ikonka to plik .ico zawierający obrazek 16x16 pikseli.
+
+=item B<log> = append | overwrite
+
+log file handling
+
+This option allows to choose whether the log file (specified with the I<output>
+option) is appended or overwritten when opened or re-opened.
+
+domyślnie: append
+
+=item B<output> = PLIK
+
+plik, do którego dopisane zostaną logi
+
+Użycie tej opcji powoduje dopisanie logów do podanego pliku.
+
+Do kierowaniakomunikatów na standardowe wyjście (na przykład po to, żeby
+zalogować je programem splogger z pakietu daemontools) można podać jako
+parametr urządzenie /dev/stdout.
+
+=item B<pid> = PLIK (tylko Unix)
+
+położenie pliku z numerem procesu
+
+Jeżeli argument jest pusty plik nie zostanie stworzony.
+
+Jeżeli zdefiniowano katalog I<chroot>, to ścieżka do I<pid> jest określona
+względem tego katalogu.
+
+=item B<RNDbytes> = LICZBA_BAJTÓW
+
+liczba bajtów do zainicjowania generatora pseudolosowego
+
+W wersjach biblioteki B<OpenSSL> starszych niż B<0.9.5a> opcja ta określa
+również liczbę bajtów wystarczających do zainicjowania PRNG.
+Nowsze wersje biblioteki mają wbudowaną funkcję określającą, czy
+dostarczona ilość losowości jest wystarczająca do zainicjowania generatora.
+
+=item B<RNDfile> = PLIK
+
+ścieżka do pliku zawierającego losowe dane
+
+Biblioteka B<OpenSSL> użyje danych z tego pliku do zainicjowania
+generatora pseudolosowego.
+
+=item B<RNDoverwrite> = yes | no
+
+nadpisz plik nowymi wartościami pseudolosowymi
+
+domyślnie: yes (nadpisz)
+
+=item B<service> = SERWIS (tylko Unix)
+
+nazwa usługi
+
+Podana nazwa usługi będzie używana jako nazwa usługi dla inicjalizacji sysloga,
+oraz dla biblioteki TCP Wrapper w trybie I<inetd>.  Chociaż technicznie można
+użyć tej opcji w trybie w sekcji usług, to jest ona użyteczna jedynie w opcjach
+globalnych.
+
+domyślnie: stunnel
+
+=item B<setgid> = IDENTYFIKATOR_GRUPY (tylko Unix)
+
+grupa z której prawami pracował będzie B<stunnel>
+
+=item B<setuid> = IDENTYFIKATOR_UŻYTKOWNIKA (tylko Unix)
+
+użytkownik, z którego prawami pracował będzie B<stunnel>
+
+=item B<socket> = a|l|r:OPCJA=WARTOŚĆ[:WARTOŚĆ]
+
+ustaw opcję na akceptującym/lokalnym/zdalnym gnieździe
+
+Dla opcji linger wartości mają postać l_onof:l_linger.
+Dla opcji time wartości mają postać tv_sec:tv_usec.
+
+Przykłady:
+
+    socket = l:SO_LINGER=1:60
+        ustaw jednominutowe przeterminowanie
+        przy zamykaniu lokalnego gniazda
+    socket = r:SO_OOBINLINE=yes
+        umieść dane pozapasmowe (out-of-band)
+        bezpośrednio w strumieniu danych
+        wejściowych dla zdalnych gniazd
+    socket = a:SO_REUSEADDR=no
+        zablokuj ponowne używanie portu
+        (domyślnie włączone)
+    socket = a:SO_BINDTODEVICE=lo
+        przyjmuj połączenia wyłącznie na
+        interfejsie zwrotnym (ang. loopback)
+
+=item B<syslog> = yes | no (tylko Unix)
+
+włącz logowanie poprzez mechanizm syslog
+
+domyślnie: yes (włącz)
+
+=item B<taskbar> = yes | no (tylko WIN32)
+
+włącz ikonkę w prawym dolnym rogu ekranu
+
+domyślnie: yes (włącz)
+
+=back
+
+
+=head2 OPCJE USŁUG
+
+Każda sekcja konfiguracji usługi zaczyna się jej nazwą ujętą w nawias
+kwadratowy.  Nazwa usługi używana jest do kontroli dostępu przez
+bibliotekę libwrap (TCP wrappers) oraz pozwala rozróżnić poszczególne
+usługi w logach.
+
+Jeżeli B<stunnel> ma zostać użyty w trybie I<inetd>, gdzie za odebranie
+połączenia odpowiada osobny program (zwykle I<inetd>, I<xinetd>
+lub I<tcpserver>), należy przeczytać sekcję I<TRYB INETD> poniżej.
+
+=over 4
+
+=item B<accept> = [HOST:]PORT
+
+nasłuchuje na połączenia na podanym adresie i porcie
+
+Jeżeli nie został podany adres, B<stunnel> domyślnie nasłuchuje
+na wszystkich adresach IPv4 lokalnych interfejsów.
+
+Aby nasłuchiwać na wszystkich adresach IPv6 należy użyć:
+
+    accept = :::port
+
+=item B<CApath> = KATALOG_CA
+
+katalog Centrum Certyfikacji
+
+Opcja określa katalog, w którym B<stunnel> będzie szukał certyfikatów,
+jeżeli użyta została opcja I<verify>.  Pliki z certyfikatami muszą
+posiadać specjalne nazwy XXXXXXXX.0, gdzie XXXXXXXX jest skrótem
+kryptograficznym reprezentacji DER nazwy podmiotu certyfikatu.
+
+Funkcja skrótu została zmieniona w B<OpenSSL 1.0.0>.
+Należy wykonać c_rehash przy zmianie B<OpenSSL 0.x.x> na B<1.x.x>.
+
+Jeżeli zdefiniowano katalog I<chroot>, to ścieżka do I<CApath> jest określona
+względem tego katalogu.
+
+=item B<CAfile> = PLIK_CA
+
+plik Centrum Certyfikacji
+
+Opcja pozwala określić położenie pliku zawierającego certyfikaty używane
+przez opcję I<verify>.
+
+=item B<cert> = PLIK_PEM
+
+plik z łańcuchem certyfikatów
+
+Opcja określa położenie pliku zawierającego certyfikaty używane przez
+program B<stunnel> do uwierzytelnienia się przed drugą stroną połączenia.
+Certyfikat jest konieczny, aby używać programu w trybie serwera.
+W trybie klienta certyfikat jest opcjonalny.
+
+=item B<checkEmail> = EMAIL
+
+adres email przedstawionego certyfikatu
+
+Pojedyncza sekcja może zawierać wiele wystąpień opcji B<checkEmail>.
+Certyfikaty są akceptowane, jeżeli sekcja nie zawiera opcji B<checkEmail>,
+albo adres email przedstawionego certyfikatu pasuje do jednego z adresów
+email określonych przy pomocy B<checkEmail>.
+
+=item B<checkHost> = NAZWA_SERWERA
+
+nazwa serwera przedstawionego certyfikatu
+
+Pojedyncza sekcja może zawierać wiele wystąpień opcji B<checkHost>.
+Certyfikaty są akceptowane, jeżeli sekcja nie zawiera opcji B<checkHost>, albo
+nazwa serwera przedstawionego certyfikatu pasuje do jednego nazw określonych
+przy pomocy B<checkHost>.
+
+=item B<checkIP> = IP
+
+adres IP przedstawionego certyfikatu
+
+Pojedyncza sekcja może zawierać wiele wystąpień opcji B<checkIP>.  Certyfikaty
+są akceptowane, jeżeli sekcja nie zawiera opcji B<checkIP>, albo adres IP
+przedstawionego certyfikatu pasuje do jednego z adresów IP określonych przy
+pomocy B<checkIP>.
+
+=item B<ciphers> = LISTA_SZYFRÓW
+
+lista dozwolonych szyfrów SSL
+
+Parametrem tej opcji jest lista szyfrów, które będą użyte przy
+otwieraniu nowych połączeń SSL, np.:  DES-CBC3-SHA:IDEA-CBC-MD5
+
+=item B<client> = yes | no
+
+tryb kliencki (zdalna usługa używa SSL)
+
+domyślnie: no (tryb serwerowy)
+
+=item B<connect> = [HOST:]PORT
+
+połącz się ze zdalnym serwerem na podany port
+
+Jeżeli nie został podany adres, B<stunnel> domyślnie łączy się
+z lokalnym serwerem.
+
+Komenda może byc użyta wielokrotnie w pojedynczej sekcji
+celem zapewnienia wysokiej niezawodności lub rozłożenia
+ruchu pomiędzy wiele serwerów.
+
+=item B<CRLpath> = KATALOG_CRL
+
+katalog List Odwołanych Certyfikatów (CRL)
+
+Opcja określa katalog, w którym B<stunnel> będzie szukał list CRL,
+jeżeli użyta została opcja I<verify>.  Pliki z listami CRL muszą
+posiadać specjalne nazwy XXXXXXXX.r0, gdzie XXXXXXXX jest skrótem
+listy CRL.
+
+Funkcja skrótu została zmieniona B<OpenSSL 1.0.0>.
+Należy wykonać c_rehash przy zmianie B<OpenSSL 0.x.x> na B<1.x.x>.
+
+Jeżeli zdefiniowano katalog I<chroot>, to ścieżka do I<CRLpath> jest określona
+względem tego katalogu.
+
+=item B<CRLfile> = PLIK_CRL
+
+plik List Odwołanych Certyfikatów (CRL)
+
+Opcja pozwala określić położenie pliku zawierającego listy CRL używane
+przez opcję I<verify>.
+
+=item B<curve> = NID
+
+krzywa dla ECDH
+
+Listę dostępnych krzywych można uzyskać poleceniem:
+
+    openssl ecparam -list_curves
+
+domyślnie: prime256v1
+
+=item B<logId> = TYP
+
+typ identyfikatora połączenia klienta
+
+Identyfikator ten pozwala rozróżnić wpisy w logu wygenerowane dla
+poszczególnych połączeń.
+
+Aktualnie wspierane typy:
+
+=over 4
+
+=item I<sequential>
+
+Kolejny numer połączenia jest unikalny jedynie w obrębie pojedynczej instancji
+programu B<stunnel>, ale bardzo krótki.  Jest on szczególnie użytczny przy
+ręcznej analizie logów.
+
+=item I<unique>
+
+Ten rodzaj identyfikatora jest globalnie unikalny, ale znacznie dłuższy, niż
+kolejny numer połączenia.  Jest on szczególnie użyteczny przy zautomatyzowanej
+analizie logów.
+
+=item I<thread>
+
+Identyfikator wątku systemu operacyjnego nie jest ani unikalny (nawet w obrębie
+pojedynczej instancji programu B<stunnel>), ani krótki.  Jest on szczególnie
+użyteczny przy diagnozowaniu problemów z oprogramowaniem lub konfiguracją.
+
+=back
+
+domyślnie: sequential
+
+=item B<debug> = POZIOM
+
+szczegółowość logowania
+
+Poziom logowania można określić przy pomocy jednej z nazw lub liczb:
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6) lub debug (7).
+Zapisywane są komunikaty o poziomie niższym (numerycznie) lub równym podanemu.
+Do uzyskania najwyższego poziomu szczegółowości można użyć opcji
+I<debug = debug> lub I<debug = 7>.  Domyślnym poziomem jest notice (5).
+
+=item B<delay> = yes | no
+
+opóźnij rozwinięcie adresu DNS podanego w opcji I<connect>
+
+Opcja jest przydatna przy dynamicznym DNS, albo gdy usługa DNS nie jest
+dostępna przy starcie programu B<stunnel> (klient VPN, połączenie wdzwaniane).
+
+Opóźnione rozwijanie adresu DNS jest włączane automatycznie, jeżeli nie
+powiedzie się rozwinięcie któregokolwiek z adresów I<connect> dla danej
+usługi.
+
+Opóźnione rozwijanie adresu automatycznie aktywuje I<failover = prio>.
+
+default: no
+
+=item B<engineId> = NUMER_URZĄDZENIA
+
+wybierz urządzenie dla usługi
+
+=item B<engineNum> = NUMER_URZĄDZENIA
+
+wybierz urządzenie dla usługi
+
+Urządzenia są numerowane od 1 w górę.
+
+=item B<exec> = ŚCIEŻKA_DO_PROGRAMU
+
+wykonaj lokalny program przystosowany do pracy z superdemonem inetd
+
+Jeżeli zdefiniowano katalog I<chroot>, to ścieżka do I<exec> jest określona
+względem tego katalogu.
+
+Na platformach Unix ustawiane są następujące zmienne środowiskowe:
+REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.
+
+=item B<execArgs> = $0 $1 $2 ...
+
+argumenty do opcji I<exec> włącznie z nazwą programu ($0)
+
+Cytowanie nie jest wspierane w obecnej wersji programu.
+Argumenty są rozdzielone dowolną liczbą białych znaków.
+
+=item B<failover> = rr | prio
+
+Strategia wybierania serwerów wyspecyfikowanych parametrami "connect".
+
+    rr (round robin) - sprawiedliwe rozłożenie obciążenia
+    prio (priority) - użyj kolejności opcji w pliku konfiguracyjnym
+
+domyślnie: rr
+
+=item B<ident> = NAZWA_UŻYTKOWNIKA
+
+weryfikuj nazwę zdalnego użytkownika korzystając z protokołu IDENT (RFC 1413)
+
+=item B<include> = KATALOG
+
+wczytaj fragmenty plików konfiguracyjnych z podanego katalogu
+
+Pliki są wczytywane w rosnącej kolejności alfabetycznej ich nazw.
+
+=item B<key> = PLIK_KLUCZA
+
+klucz prywatny do certyfikatu podanego w opcji I<cert>
+
+Klucz prywatny jest potrzebny do uwierzytelnienia właściciela certyfikatu.
+Ponieważ powinien on być zachowany w tajemnicy, prawa do jego odczytu
+powinien mieć wyłącznie właściciel pliku.  W systemie Unix można to osiągnąć
+komendą:
+
+    chmod 600 keyfile
+
+domyślnie: wartość opcji I<cert>
+
+=item B<libwrap> = yes | no
+
+włącz lub wyłącz korzystanie z /etc/hosts.allow i /etc/hosts.deny.
+
+domyślnie: no (od wersji 5.00)
+
+=item B<local> = HOST
+
+IP źródła do nawiązywania zdalnych połączeń
+
+Domyślnie używane jest IP najbardziej zewnętrznego interfejsu w stronę
+serwera, do którego nawiązywane jest połączenie.
+
+=item B<sni> = USŁUGA:WZORZEC_NAZWY_SERWERA (tryb serwera)
+
+Użyj usługi jako podrzędnej (virtualnego serwera) dla rozszerzenia TLS Server
+Name Indication (RFC 3546).
+
+I<nazwa_usługi> wskazuje usługę nadrzędną, która odbiera połączenia od klientów
+przy pomocy opcji I<accept>.  I<wzorzec_nazwy_serwera> wskazuje nazwę serwera
+wirtualnego.  Wzorzec może zaczynać się znakiem '*', np. '*.example.com".
+Z pojedyńczą usługą nadrzędną powiązane jest zwykle wiele usług podrzędnych.
+Opcja I<sni> może być rownież użyta wielokrotnie w ramach jednej usługi
+podrzędnej.
+
+Zarówno usługa nadrzędna jak i podrzędna nie może być skonfigurowana w trybie
+klienckim.
+
+Opcja I<connect> usługi podrzędnej jest ignorowana w połączeniu z opcją
+I<protocol>, gdyż połączenie do zdalnego serwera jest w tym wypadku nawiązywane
+przed negocjacją TLS.
+
+Uwierzytelnienie przy pomocy biblioteki libwrap jest realizowane dwukrotnie:
+najpierw dla usługi nadrzędnej po odebraniu połączenia TCP, a następnie dla
+usługi podrzędnej podczas negocjacji TLS.
+
+Opcja I<sni> jest dostępna począwszy od B<OpenSSL 1.0.0>.
+
+=item B<sni> = HOST (tryb klienta)
+
+Użyj parametru jako wartości rozszerzenia TLS Server Name Indication
+(RFC 3546).
+
+Opcja I<sni> jest dostępna począwszy od B<OpenSSL 1.0.0>.
+
+=item B<OCSP> = URL
+
+serwer OCSP do weryfikacji certyfikatów
+
+=item B<OCSPaia> = yes | no
+
+weryfikuj certyfikaty przy użyciu respondertów AIA
+
+Opcja I<OCSPaia> pozwala na weryfikowanie certyfikatów przy pomocy listy URLi
+serwerów OCSP przesłanych w rozszerzeniach AIA (Authority Information Access).
+
+=item B<OCSPflag> = FLAGA_OCSP
+
+flaga serwera OCSP
+
+aktualnie wspierane flagi: NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY,
+NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME
+
+Aby wyspecyfikować kilka flag należy użyć I<OCSPflag> wielokrotnie.
+
+=item B<options> = OPCJE_SSL
+
+opcje biblioteki B<OpenSSL>
+
+Parametrem jest nazwa opcji zgodnie z opisem w I<SSL_CTX_set_options(3ssl)>,
+ale bez przedrostka I<SSL_OP_>.
+I<stunnel -options> wyświetla opcje dozwolone w aktualnej kombinacji
+programu I<stunnel> i biblioteki I<OpenSSL>.
+
+Aby wyspecyfikować kilka opcji należy użyć I<options> wielokrotnie.
+Nazwa opcji może być poprzedzona myślnikiem ("-") celem wyłączenia opcji.
+
+Na przykład, dla zachowania kompatybilności z błędami implementacji SSL
+w programie Eudora, można użyć opcji:
+
+    options = DONT_INSERT_EMPTY_FRAGMENTS
+
+domyślnie:
+
+    options = NO_SSLv2
+    options = NO_SSLv3
+
+=item B<protocol> = PROTOKÓŁ
+
+negocjuj SSL podanym protokołem aplikacyjnym
+
+Opcja ta włącza wstępną negocjację szyfrowania SSL dla wybranego protokołu
+aplikacyjnego.
+Opcji I<protocol> nie należy używać z szyfrowaniem SSL na osobnym porcie.
+
+Aktualnie wspierane protokoły:
+
+=over 4
+
+=item I<cifs>
+
+Unieudokumentowane rozszerzenie protokołu CIFS wspierane przez serwer Samba.
+Wsparcie dla tego rozrzeczenia zostało zarzucone w wersji 3.0.0 serwera Samba.
+
+=item I<connect>
+
+Negocjacja RFC 2817 - I<Upgrading to TLS Within HTTP/1.1>, rozdział 5.2 - I<Requesting a Tunnel with CONNECT>
+
+Ten protokół jest wspierany wyłącznie w trybie klienckim.
+
+=item I<imap>
+
+Negocjacja RFC 2595 - I<Using TLS with IMAP, POP3 and ACAP>
+
+=item I<nntp>
+
+Negocjacja RFC 4642 - I<Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)>
+
+Ten protokół jest wspierany wyłącznie w trybie klienckim.
+
+=item I<pgsql>
+
+Negocjacja http://www.postgresql.org/docs/8.3/static/protocol-flow.html#AEN73982
+
+=item I<pop3>
+
+Negocjacja RFC 2449 - I<POP3 Extension Mechanism>
+
+=item I<proxy>
+
+Przekazywanie adresu IP haproxy http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt
+
+=item I<smtp>
+
+Negocjacja RFC 2487 - I<SMTP Service Extension for Secure SMTP over TLS>
+
+=item I<socks>
+
+Wspierany jest protokół SOCKS w wersjach 4, 4a i 5.
+Protokół SOCKS enkapsulowany jest w protokole SSL/TLS, więc adres serwera
+docelowego nie jest widoczny dla napastnika przechwytującego ruch sieciowy.
+
+F<http://www.openssh.com/txt/socks4.protocol>
+
+F<http://www.openssh.com/txt/socks4a.protocol>
+
+Nie jest wspierana komenda BIND protokołu SOCKS.
+Przesłana wartość parametru USERID jest ignorowana.
+
+Sekcja PRZYKŁADY zawiera przykładowe pliki konfiguracyjne VPNa zbudowanego
+w oparciu o szyfrowany protokół SOCKS.
+
+=back
+
+=item B<protocolAuthentication> = basic | ntlm
+
+rodzaj uwierzytelnienia do negocjacji protokołu
+
+Obecnie typ uwierzytelnienia ma zastosowanie wyłącznie w protokole 'connect'.
+
+domyślnie: basic
+
+=item B<protocolHost> = HOST:PORT
+
+adres docelowy do negocjacji protokołu
+
+I<protocolHost> określa docelowy serwer SSL, do którego połączyć ma się proxy.
+Nie jest to adres serwera proxy, do którego połączenie zestawia B<stunnel>.
+Adres serwera proxy powinien być określony przy pomocy opcji 'connect'.
+
+W obecnej wersji adres docelowy protokołu ma zastosowanie wyłącznie w protokole
+'connect'.
+
+=item B<protocolPassword> = HASŁO
+
+hasło do negocjacji protokołu
+
+=item B<protocolUsername> = UŻYTKOWNIK
+
+nazwa użytkownika do negocjacji protokołu
+
+=item B<PSKidentity> = TOŻSAMOŚĆ
+
+tożsamość klienta PSK
+
+I<PSKidentity> może zostać użyte w sekcjach klienckich do wybrania
+tożsamości użytej do uwierzytelnienia PSK.
+Opcja jest ignorowana w sekcjach serwerowych.
+
+domyślnie: pierwsza tożsamość zdefiniowana w pliku I<PSKsecrets>
+
+=item B<PSKsecrets> = PLIK
+
+plik z tożsamościami i kluczami PSK
+
+Każda linia pliku jest w następującym formacie:
+
+    TOŻSAMOŚĆ:KLUCZ
+
+Klucz musi być mieć przynajmniej 20 znaków.
+Należy ograniczyć dostęp do czytania lub pisania do tego pliku.
+
+=item B<pty> = yes | no (tylko Unix)
+
+alokuj pseudoterminal dla programu uruchamianego w opcji 'exec'
+
+=item B<redirect> = [HOST:]PORT
+
+przekieruj klienta, któremu nie udało się poprawnie uwierzytelnić przy pomocy certyfikatu
+
+Opcja działa wyłącznie w trybie serwera.
+Część negocjacji protokołów jest niekompatybilna z opcją I<redirect>.
+
+=item B<renegotiation> = yes | no
+
+pozwalaj na renegocjację SSL
+
+Wśród zastosowań renegocjacji SSL są niektóre scenariusze uwierzytelnienia,
+oraz renegocjacja kluczy dla długotrwałych połączeń.
+
+Z drugiej strony własność na może ułatwić trywialny atak DoS poprzez
+wygenerowanie obciążenia procesora:
+
+http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html
+
+Warto zauważyć, że zablokowanie renegocjacji SSL nie zebezpiecza w pełni
+przed opisanym problemem.
+
+domyślnie: yes (o ile wspierane przez B<OpenSSL>)
+
+=item B<reset> = yes | no
+
+sygnalizuj wystąpienie błędu przy pomocy flagi TCP RST
+
+Opcja nie jest wspierana na niektórych platformach.
+
+domyślnie: yes
+
+=item B<retry> = yes | no
+
+połącz ponownie sekcję connect+exec po rozłączeniu
+
+domyślnie: no
+
+=item B<sessionCacheSize> = LICZBA_POZYCJI_CACHE
+
+rozmiar pamięci podręcznej sesji SSL
+
+Parametr określa maksymalną liczbę pozycji wewnętrznej pamięci podręcznej
+sesji.
+
+Wartość 0 oznacza brak ograniczenia rozmiaru.  Nie jest to zalecane dla
+systemów produkcyjnych z uwagi na ryzyko ataku DoS przez wyczerpanie pamięci
+RAM.
+
+=item B<sessionCacheTimeout> = LICZBA_SEKUND
+
+przeterminowanie pamięci podręcznej sesji SSL
+
+Parametr określa czas w sekundach, po którym sesja SSL zostanie usunięta z
+pamięci podręcznej.
+
+=item B<sessiond> = HOST:PORT
+
+adres sessiond - servera cache sesji SSL
+
+=item B<sslVersion> = WERSJA_SSL
+
+wersja protokołu SSL
+
+Wspierane opcje: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2
+
+Dostępność konkretnych protokołów zależy od użytej wersji OpenSSL.
+Starsze wersje OpenSSL nie wspierają TLSv1.1 i TLSv1.2.
+Nowsze wersje OpenSSL nie wspierają SSLv2.
+
+Przestarzałe protokoły SSLv2 i SSLv3 są domyślnie wyłączone.
+Szczegółowe informacje dostępne są w opisie opcji B<options>.
+
+=item B<stack> = LICZBA_BAJTÓW (z wyjątkiem modelu FORK)
+
+rozmiar stosu procesora wątku 
+
+=item B<TIMEOUTbusy> = LICZBA_SEKUND
+
+czas oczekiwania na spodziewane dane
+
+=item B<TIMEOUTclose> = LICZBA_SEKUND
+
+czas oczekiwania na close_notify (ustaw na 0, jeżeli klientem jest MSIE)
+
+=item B<TIMEOUTconnect> = LICZBA_SEKUND
+
+czas oczekiwania na nawiązanie połączenia
+
+=item B<TIMEOUTidle> = LICZBA_SEKUND
+
+maksymalny czas utrzymywania bezczynnego połączenia
+
+=item B<transparent> = none | source | destination | both (tylko Unix)
+
+tryb przezroczystego proxy na wspieranych platformach
+
+Wspierane opcje:
+
+=over 4
+
+=item B<none>
+
+Zablokuj wsparcie dla przezroczystago proxy.  Jest to wartość domyślna.
+
+=item B<source>
+
+Przepisz adres, aby nawiązywane połączenie wydawało się pochodzić
+bezpośrednio od klienta, a nie od programu B<stunnel>.
+
+Opcja jest aktualnie obsługiwana w:
+
+=over 4
+
+=item Trybie zdalnym (opcja I<connect>) w systemie I<Linux E<gt>=2.6.28>
+
+Konfiguracja wymaga następujących ustawień iptables oraz routingu
+(na przykład w pliku /etc/rc.local lub analogicznym):
+
+    iptables -t mangle -N DIVERT
+    iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT
+    iptables -t mangle -A DIVERT -j MARK --set-mark 1
+    iptables -t mangle -A DIVERT -j ACCEPT
+    ip rule add fwmark 1 lookup 100
+    ip route add local 0.0.0.0/0 dev lo table 100
+    echo 0 >/proc/sys/net/ipv4/conf/lo/rp_filter
+
+Konfiguracja ta wymaga, aby B<stunnel> był wykonywany jako root i bez opcji I<setuid>.
+
+=item Trybie zdalnym (opcja I<connect>) w systemie I<Linux 2.2.x>
+
+Konfiguracja ta wymaga skompilowania jądra z opcją I<transparent proxy>.
+Docelowa usługa musi być umieszczona na osobnej maszynie, do której routing
+kierowany jest poprzez serwer B<stunnela>.
+
+Dodatkowo B<stunnel> powinien być wykonywany jako root i bez opcji I<setuid>.
+
+=item Trybie zdalnym (opcja I<connect>) w systemie I<FreeBSD E<gt>=8.0>
+
+Konfiguracja ta wymaga skonfigurowania firewalla i routingu.
+B<stunnel> musi być wykonywany jako root i bez opcji I<setuid>.
+
+=item Trybie lokalnym (opcja I<exec>)
+
+Konfiguracja ta jest realizowana przy pomocy biblioteki I<libstunnel.so>.
+Do załadowania biblioteki wykorzystywana jest zmienna środowiskowa _RLD_LIST na
+platformie Tru64 lub LD_PRELOAD na innych platformach.
+
+=back
+
+=item I<destination>
+
+Oryginalny adres docelowy jest używany zamiast opcji I<connect>.
+
+Przykładowana konfiguracja przezroczystego adresu docelowego:
+
+    [transparent]
+    client=yes
+    accept=<port_stunnela>
+    transparent=destination
+
+Konfiguracja wymaga ustawień iptables, na przykład w pliku
+/etc/rc.local lub analogicznym.
+
+W przypadku docelowej usługi umieszczonej na tej samej maszynie:
+
+    /sbin/iptables -t nat -I OUTPUT -p tcp --dport <port_przekierowany> \
+        -m ! --uid-owner <identyfikator_użytkownika_stunnela> \
+        -j DNAT --to-destination <lokalne_ip>:<lokalny_port>
+
+W przypadku docelowej usługi umieszczonej na zdalnej maszynie:
+
+    /sbin/iptables -I INPUT -i eth0 -p tcp --dport <port_stunnela> -j ACCEPT
+    /sbin/iptables -t nat -I PREROUTING -p tcp --dport <port_przekierowany> \
+        -i eth0 -j DNAT --to-destination <lokalne_ip>:<port_stunnela>
+
+Przezroczysty adres docelowy jest aktualnie wspierany wyłącznie w systemie Linux.
+
+=item I<both>
+
+Użyj przezroczystego proxy zarówno dla adresu źródłowego jak i docelowego.
+
+=back
+
+Dla zapewnienia kompatybilności z wcześniejszymim wersjami wspierane są dwie
+dodatkowe opcje:
+
+=over 4
+
+=item I<yes>
+
+Opcja została przemianowana na I<source>.
+
+=item I<no>
+
+Opcja została przemianowana na I<none>.
+
+=back
+
+=item B<verify> = POZIOM
+
+weryfikuj certyfikat drugiej strony połączenia
+
+=over 4
+
+=item I<poziom 0>
+
+zarządaj certyfikatu i zignoruj go
+
+=item I<poziom 1>
+
+weryfikuj, jeżeli został przedstawiony
+
+=item I<poziom 2>
+
+weryfikuj z zainstalowanym certyfikatem Centrum Certyfikacji
+
+=item I<poziom 3>
+
+weryfikuj z lokalnie zainstalowanym certyfikatem drugiej strony
+
+=item I<poziom 4>
+
+weryfikuj z certyfikatem drugiej strony ignorując łańcuch CA
+
+=item I<domyślnie>
+
+nie weryfikuj
+
+=back
+
+=back
+
+
+=head1 ZWRACANA WARTOŚĆ
+
+B<stunnel> zwraca zero w przypadku sukcesu, lub wartość niezerową
+w przypadku błędu.
+
+
+=head1 SIGNAŁY
+
+Następujące sygnały mogą być użyte do sterowania programem w systemie Unix:
+
+=over 4
+
+=item SIGHUP
+
+Załaduj ponownie plik konfiguracyjny.
+
+Niektóre globalne opcje nie będą przeładowane:
+
+=over 4
+
+=item *
+
+chroot
+
+=item *
+
+foreground
+
+=item *
+
+pid
+
+=item *
+
+setgid
+
+=item *
+
+setuid
+
+=back
+
+Jeżeli wykorzystywana jest opcja 'setuid' B<stunnel> nie będzie mógł załadować
+ponownie konfiguracji wykorzystującej uprzywilejowane (<1024) porty.
+
+Jeżeli wykorzystywana jest opcja 'chroot' B<stunnel> będzie szukał wszystkich
+potrzebnych plików (łącznie z plikiem konfiguracyjnym, certyfikatami, logiem i
+plikiem pid) wewnątrz katalogu wskazanego przez 'chroot'.
+
+=item SIGUSR1
+
+Zamknij i otwórz ponownie log.
+Funkcja ta może zostać użyta w skrypcie rotującym log programu B<stunnel>.
+
+=item SIGTERM, SIGQUIT, SIGINT
+
+Zakończ działanie programu.
+
+=back
+
+Skutek wysłania innych sygnałów jest niezdefiniowany.
+
+
+=head1 PRZYKŁADY
+
+Szyfrowanie połączeń do lokalnego serwera I<imapd> można użyć:
+
+    [imapd]
+    accept = 993
+    exec = /usr/sbin/imapd
+    execArgs = imapd
+
+albo w trybie zdalnym:
+
+    [imapd]
+    accept = 993
+    connect = 143
+
+Aby umożliwić lokalnemu klientowi poczty elektronicznej korzystanie z serwera
+I<imapd> przez SSL należy skonfigurować pobieranie poczty z adresu localhost i
+portu 119, oraz użyć następującej konfiguracji:
+
+    [imap]
+    client = yes
+    accept = 143
+    connect = serwer:993
+
+W połączeniu z programem I<pppd> B<stunnel> pozwala zestawić prosty VPN.
+Po stronie serwera nasłuchującego na porcie 2020 jego konfiguracja
+może wyglądać następująco:
+
+    [vpn]
+    accept = 2020
+    exec = /usr/sbin/pppd
+    execArgs = pppd local
+    pty = yes
+
+Poniższy plik konfiguracyjny może być wykorzystany do uruchomienia
+programu B<stunnel> w trybie I<inetd>.  Warto zauważyć, że w pliku
+konfiguracyjnym nie ma sekcji I<[nazwa_usługi]>.
+
+    exec = /usr/sbin/imapd
+    execArgs = imapd
+
+Aby skonfigurować VPN można użyć następującej konfiguracji klienta:
+
+    [socks_client]
+    client = yes
+    accept = 127.0.0.1:1080
+    connect = vpn_server:9080
+    verify = 4
+    CAfile = stunnel.pem
+
+Odpowiadająca jej konfiguracja serwera vpn_server:
+
+    [socks_server]
+    protocol = socks
+    accept = 9080
+    cert = stunnel.pem
+    key = stunnel.key
+
+Do przetestowania konfiguracji można wydać na maszynie klienckiej komendę:
+
+    curl --socks4a localhost http://www.example.com/
+
+=head1 NOTKI
+
+=head2 OGRANICZENIA
+
+B<stunnel> nie może być używany do szyfrowania protokołu I<FTP>,
+ponieważ do przesyłania poszczególnych plików używa on dodatkowych
+połączeń otwieranych na portach o dynamicznie przydzielanych numerach.
+Istnieją jednak specjalne wersje klientów i serwerów FTP pozwalające
+na szyfrowanie przesyłanych danych przy pomocy protokołu I<SSL>.
+
+=head2 TRYB INETD (tylko Unix)
+
+W większości zastosowań B<stunnel> samodzielnie nasłuchuje na porcie
+podanym w pliku konfiguracyjnym i tworzy połączenie z innym portem
+podanym w opcji I<connect> lub nowym programem podanym w opcji I<exec>.
+Niektórzy wolą jednak wykorzystywać oddzielny program, który odbiera
+połączenia, po czym uruchamia program B<stunnel>.  Przykładami takich
+programów są inetd, xinetd i tcpserver.
+
+Przykładowa linia pliku /etc/inetd.conf może wyglądać tak:
+
+    imaps stream tcp nowait root @bindir@/stunnel
+        stunnel @sysconfdir@/stunnel/imaps.conf
+
+Ponieważ w takich przypadkach połączenie na zdefiniowanym porcie
+(tutaj I<imaps>) nawiązuje osobny program (tutaj I<inetd>), B<stunnel>
+nie może używać opcji I<accept>.  W pliku konfiguracyjnym nie może
+być również zdefiniowana żadna usługa (I<[nazwa_usługi]>), ponieważ
+konfiguracja taka pozwala na nawiązanie tylko jednego połączenia.
+Wszystkie I<OPCJE USŁUG> powinny być umieszczone razem z opcjami
+globalnymi.  Przykład takiej konfiguracji znajduje się w sekcji
+I<PRZYKŁADY>.
+
+=head2 CERTYFIKATY
+
+Protokół SSL wymaga, aby każdy serwer przedstawiał się nawiązującemu
+połączenie klientowi prawidłowym certyfikatem X.509.
+Potwierdzenie tożsamości serwera polega na wykazaniu, że posiada on
+odpowiadający certyfikatowi klucz prywatny.
+Najprostszą metodą uzyskania certyfikatu jest wygenerowanie go przy pomocy
+wolnego pakietu B<OpenSSL>.  Więcej informacji na temat generowania
+certyfikatów można znaleźć na umieszczonych poniżej stronach.
+
+Istotną kwestią jest kolejność zawartości pliku I<.pem>.
+W pierwszej kolejności powinien on zawierać klucz prywatny,
+a dopiero za nim podpisany certyfikat (nie żądanie certyfikatu).
+Po certyfikacie i kluczu prywatnym powinny znajdować się puste linie.
+Jeżeli przed certyfikatem znajdują się dodatkowe informacje tekstowe,
+to powinny one zostać usunięte.  Otrzymany plik powinien mieć
+następującą postać:
+
+    -----BEGIN RSA PRIVATE KEY-----
+    [zakodowany klucz]
+    -----END RSA PRIVATE KEY-----
+    [pusta linia]
+    -----BEGIN CERTIFICATE-----
+    [zakodowany certyfikat]
+    -----END CERTIFICATE-----
+    [pusta linia]
+
+=head2 LOSOWOŚĆ
+
+B<stunnel> potrzebuje zainicjować PRNG (generator liczb pseudolosowych),
+gdyż protokół SSL wymaga do bezpieczeństwa kryptograficznego źródła
+dobrej losowości.  Następujące źródła są kolejno odczytywane aż do
+uzyskania  wystarczającej ilości entropii:
+
+=over 4
+
+=item *
+
+Zawartość pliku podanego w opcji I<RNDfile>.
+
+=item *
+
+Zawartość pliku o nazwie określonej przez zmienną środowiskową
+RANDFILE, o ile jest ona ustawiona.
+
+=item *
+
+Plik .rnd umieszczony w katalogu domowym użytkownika,
+jeżeli zmienna RANDFILE nie jest ustawiona.
+
+=item *
+
+Plik podany w opcji '--with-random' w czasie konfiguracji programu.
+
+=item *
+
+Zawartość ekranu w systemie Windows.
+
+=item *
+
+Gniazdo egd, jeżeli użyta została opcja I<EGD>.
+
+=item *
+
+Gniazdo egd podane w opcji '--with-egd-socket' w czasie konfiguracji
+programu.
+
+=item *
+
+Urządzenie /dev/urandom.
+
+=back
+
+Współczesne (B<0.9.5a> lub nowsze) wersje biblioteki B<OpenSSL> automatycznie
+zaprzestają ładowania kolejnych danych w momencie uzyskania wystarczającej
+ilości entropii.  Wcześniejsze wersje biblioteki wykorzystają wszystkie
+powyższe źródła, gdyż nie istnieje tam funkcja pozwalająca określić, czy
+uzyskano już wystarczająco dużo danych.
+
+Warto zwrócić uwagę, że na maszynach z systemem Windows, na których
+konsoli nie pracuje użytkownik, zawartość ekranu nie jest wystarczająco
+zmienna, aby zainicjować PRNG.  W takim przypadku do zainicjowania
+generatora należy użyć opcji I<RNDfile>.
+
+Plik I<RNDfile> powinien zawierać dane losowe -- również w tym sensie,
+że powinny być one inne przy każdym uruchomieniu programu B<stunnel>.
+O ile nie użyta została opcja I<RNDoverwrite> jest to robione
+automatycznie.  Do ręcznego uzyskania takiego pliku użyteczna
+może być komenda I<openssl rand> dostarczana ze współczesnymi
+wersjami pakietu B<OpenSSL>.
+
+Jeszcze jedna istotna informacja -- jeżeli dostępne jest urządzenie
+I</dev/urandom> biblioteka B<OpenSSL> ma zwyczaj zasilania nim PRNG w trakcie
+sprawdzania stanu generatora.  W systemach z I</dev/urandom> urządzenie
+to będzie najprawdopodobniej użyte, pomimo że znajduje się na samym końcu
+powyższej listy.  Jest to właściwość biblioteki B<OpenSSL>, a nie programu
+B<stunnel>.
+
+=head2 PARAMETRY DH
+
+Począwszy od wersji 4.40 B<stunnel> zawiera w kodzie programu 2048-bitowe
+parametry DH.  Od wersji 5.18 te początkowe wartości parametrów DH są
+wymieniane na autogenerowane parametry tymczasowe.
+Wygenerowanie parametrów DH może zająć nawet wiele minut.
+
+Alternatywnie parametry DH można umieścić w pliku razem z certyfikatem,
+co wyłącza generowanie parametrów tymczasowych:
+
+    openssl dhparam 2048 >> stunnel.pem
+
+
+=head1 PLIKI
+
+=over 4
+
+=item F<@sysconfdir@/stunnel/stunnel.conf>
+
+plik konfiguracyjny programu
+
+=back
+
+
+=head1 BŁĘDY
+
+Opcja I<execArgs> oraz linia komend Win32 nie obsługuje cytowania.
+
+
+=head1 ZOBACZ RÓWNIEŻ
+
+=over 4
+
+=item L<tcpd(8)>
+
+biblioteka kontroli dostępu do usług internetowych
+
+=item L<inetd(8)>
+
+'super-serwer' internetowy
+
+=item F<http://www.stunnel.org/>
+
+strona domowa programu B<stunnel>
+
+=item F<http://www.openssl.org/>
+
+strona projektu B<OpenSSL>
+
+=back
+
+
+=head1 AUTOR
+
+=over 4
+
+=item Michał Trojnara
+
+<F<Michal.Trojnara@mirt.net>>
+
+=back
+
+=for comment
+vim:spelllang=pl:spell
diff --git a/doc/stunnel.pod.in b/doc/stunnel.pod.in
new file mode 100644
index 0000000..b94b532
--- /dev/null
+++ b/doc/stunnel.pod.in
@@ -0,0 +1,1382 @@
+=head1 NAME
+
+=encoding utf8
+
+stunnel - TLS offloading and load-balancing proxy
+
+
+=head1 SYNOPSIS
+
+=over 4
+
+=item B<Unix:>
+
+B<stunnel> [S<FILE>] | S<-fd N> | S<-help> | S<-version> | S<-sockets> | S<-options>
+
+=item B<WIN32:>
+
+B<stunnel> [ [ S<-install> | S<-uninstall> | S<-start> | S<-stop> |
+    S<-reload> | S<-reopen> | S<-exit> ] [S<-quiet>] [S<FILE>] ] |
+    S<-help> | S<-version> | S<-sockets> | S<-options>
+
+=back
+
+
+=head1 DESCRIPTION
+
+The B<stunnel> program is designed to work as I<SSL> encryption wrapper 
+between remote clients and local (I<inetd>-startable) or remote
+servers. The concept is that having non-SSL aware daemons running on
+your system you can easily set them up to communicate with clients over
+secure SSL channels.
+
+B<stunnel> can be used to add SSL functionality to commonly used I<Inetd>
+daemons like POP-2, POP-3, and IMAP servers, to standalone daemons like
+NNTP, SMTP and HTTP, and in tunneling PPP over network sockets without
+changes to the source code.
+
+This product includes cryptographic software written by
+Eric Young (eay@cryptsoft.com)
+
+
+=head1 OPTIONS
+
+=over 4
+
+=item B<FILE>
+
+Use specified configuration file
+
+=item B<-fd N> (Unix only)
+
+Read the config file from specified file descriptor
+
+=item B<-help>
+
+Print B<stunnel> help menu
+
+=item B<-version>
+
+Print B<stunnel> version and compile time defaults
+
+=item B<-sockets>
+
+Print default socket options
+
+=item B<-options>
+
+Print supported SSL options
+
+=item B<-install> (Windows NT and later only)
+
+Install NT Service
+
+=item B<-uninstall> (Windows NT and later only)
+
+Uninstall NT Service
+
+=item B<-start> (Windows NT and later only)
+
+Start NT Service
+
+=item B<-stop> (Windows NT and later only)
+
+Stop NT Service
+
+=item B<-reload> (Windows NT and later only)
+
+Reload the configuration file of the running NT Service
+
+=item B<-reopen> (Windows NT and later only)
+
+Reopen the log file of the running NT Service
+
+=item B<-exit> (Win32 only)
+
+Exit an already started stunnel
+
+=item B<-quiet> (Win32 only)
+
+Don't display any message boxes
+
+=back
+
+
+=head1 CONFIGURATION FILE
+
+Each line of the configuration file can be either:
+
+=over 4
+
+=item *
+
+An empty line (ignored).
+
+=item *
+
+A comment starting with ';' (ignored).
+
+=item *
+
+An 'option_name = option_value' pair.
+
+=item *
+
+'[service_name]' indicating a start of a service definition.
+
+=back
+
+An address parameter of an option may be either:
+
+=over 4
+
+=item *
+
+A port number.
+
+=item *
+
+A colon-separated pair of IP address (either IPv4, IPv6, or domain name) and port number.
+
+=item *
+
+A Unix socket path (Unix only).
+
+=back
+
+=head2 GLOBAL OPTIONS
+
+=over 4
+
+=item B<chroot> = DIRECTORY (Unix only)
+
+directory to chroot B<stunnel> process
+
+B<chroot> keeps B<stunnel> in a chrooted jail.  I<CApath>, I<CRLpath>, I<pid>
+and I<exec> are located inside the jail and the patches have to be relative
+to the directory specified with B<chroot>.
+
+Several functions of the operating system also need their files to be located within the chroot jail, e.g.:
+
+=over 4
+
+=item *
+
+Delayed resolver typically needs /etc/nsswitch.conf and /etc/resolv.conf.
+
+=item *
+
+Local time in log files needs /etc/timezone.
+
+=item *
+
+Some other functions may need devices, e.g. /dev/zero or /dev/null.
+
+=back
+
+=item B<compression> = deflate | zlib
+
+select data compression algorithm
+
+default: no compression
+
+deflate is the standard compression method as described in RFC 1951.
+
+zlib compression of B<OpenSSL 0.9.8> or above is not backward compatible with
+B<OpenSSL 0.9.7>.
+
+=item B<debug> = [FACILITY.]LEVEL
+
+debugging level
+
+Level is one of the syslog level names or numbers
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6), or debug (7).  All logs for the specified level and
+all levels numerically less than it will be shown.  Use I<debug = debug> or
+I<debug = 7> for greatest debugging output.  The default is notice (5).
+
+The syslog facility 'daemon' will be used unless a facility name is supplied.
+(Facilities are not supported on Win32.)
+
+Case is ignored for both facilities and levels.
+
+=item B<EGD> = EGD_PATH (Unix only)
+
+path to Entropy Gathering Daemon socket
+
+Entropy Gathering Daemon socket to use to feed the B<OpenSSL> random number
+generator.  (Available only if compiled with B<OpenSSL 0.9.5a> or higher)
+
+=item B<engine> = auto | ENGINE_ID
+
+select hardware engine
+
+default: software-only cryptography
+
+Here is an example of advanced engine configuration to read the private key from an
+OpenSC engine
+
+    engine=dynamic
+    engineCtrl=SO_PATH:/usr/lib/opensc/engine_pkcs11.so
+    engineCtrl=ID:pkcs11
+    engineCtrl=LIST_ADD:1
+    engineCtrl=LOAD
+    engineCtrl=MODULE_PATH:/usr/lib/pkcs11/opensc-pkcs11.so
+    engineCtrl=INIT
+
+    [service]
+    engineNum=1
+    key=id_45
+
+=item B<engineCtrl> = COMMAND[:PARAMETER]
+
+control hardware engine
+
+Special commands "LOAD" and "INIT" can be used to load and initialize the
+engine cryptogaphic module.
+
+=item B<engineDefault> = TASK_LIST
+
+set OpenSSL tasks delegated to the current engine
+
+The parameter specifies a comma-separated list of task to be delegated to the
+current engine.
+
+The following tasks may be available, if supported by the engine: ALL, RSA,
+DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.
+
+=item B<fips> = yes | no
+
+Enable or disable FIPS 140-2 mode.
+
+This option allows you to disable entering FIPS mode if B<stunnel> was compiled
+with FIPS 140-2 support.
+
+default: no (since version 5.00)
+
+=item B<foreground> = yes | no (Unix only)
+
+foreground mode
+
+Stay in foreground (don't fork) and log to stderr
+instead of via syslog (unless I<output> is specified).
+
+default: background in daemon mode
+
+=item B<iconActive> = ICON_FILE (GUI only)
+
+GUI icon to be displayed when there are established connections
+
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+
+=item B<iconError> = ICON_FILE (GUI only)
+
+GUI icon to be displayed when no valid configuration is loaded
+
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+
+=item B<iconIdle> = ICON_FILE (GUI only)
+
+GUI icon to be displayed when there are no established connections
+
+On Windows platform the parameter should be an .ico file containing a 16x16
+pixel image.
+
+=item B<log> = append | overwrite
+
+log file handling
+
+This option allows you to choose whether the log file (specified with the I<output>
+option) is appended or overwritten when opened or re-opened.
+
+default: append
+
+=item B<output> = FILE
+
+append log messages to a file
+
+/dev/stdout device can be used to send log messages to the standard
+output (for example to log them with daemontools splogger).
+
+=item B<pid> = FILE (Unix only)
+
+pid file location
+
+If the argument is empty, then no pid file will be created.
+
+I<pid> path is relative to the I<chroot> directory if specified.
+
+=item B<RNDbytes> = BYTES
+
+bytes to read from random seed files
+
+Number of bytes of data read from random seed files.  With SSL versions less
+than B<0.9.5a>, also determines how many bytes of data are considered
+sufficient to seed the PRNG.  More recent B<OpenSSL> versions have a builtin
+function to determine when sufficient randomness is available.
+
+=item B<RNDfile> = FILE
+
+path to file with random seed data
+
+The SSL library will use data from this file first to seed the random
+number generator.
+
+=item B<RNDoverwrite> = yes | no
+
+overwrite the random seed files with new random data
+
+default: yes
+
+=item B<service> = SERVICE (Unix only)
+
+stunnel service name
+
+The specified service name is used for syslog and as the I<inetd> mode service
+name for TCP Wrappers.  While this option can technically be specified in the
+service sections, it is only useful in global options.
+
+default: stunnel
+
+=item B<setgid> = GROUP (Unix only)
+
+setgid() to the specified group in daemon mode and clear all other groups
+
+=item B<setuid> = USER (Unix only)
+
+setuid() to the specified user in daemon mode
+
+=item B<socket> = a|l|r:OPTION=VALUE[:VALUE]
+
+Set an option on the accept/local/remote socket
+
+The values for the linger option are l_onof:l_linger.
+The values for the time are tv_sec:tv_usec.
+
+Examples:
+
+    socket = l:SO_LINGER=1:60
+        set one minute timeout for closing local socket
+    socket = r:SO_OOBINLINE=yes
+        place out-of-band data directly into the
+        receive data stream for remote sockets
+    socket = a:SO_REUSEADDR=no
+        disable address reuse (enabled by default)
+    socket = a:SO_BINDTODEVICE=lo
+        only accept connections on loopback interface
+
+=item B<syslog> = yes | no (Unix only)
+
+enable logging via syslog
+
+default: yes
+
+=item B<taskbar> = yes | no (WIN32 only)
+
+enable the taskbar icon
+
+default: yes
+
+=back
+
+
+=head2 SERVICE-LEVEL OPTIONS
+
+Each configuration section begins with a service name in square brackets.
+The service name is used for libwrap (TCP Wrappers) access control and lets
+you distinguish B<stunnel> services in your log files.
+
+Note that if you wish to run B<stunnel> in I<inetd> mode (where it
+is provided a network socket by a server such as I<inetd>, I<xinetd>,
+or I<tcpserver>) then you should read the section entitled I<INETD MODE>
+below.
+
+
+=over 4
+
+=item B<accept> = [HOST:]PORT
+
+accept connections on specified address
+
+If no host specified, defaults to all IPv4 addresses for the local host.
+
+To listen on all IPv6 addresses use:
+
+    accept = :::PORT
+
+=item B<CApath> = DIRECTORY
+
+Certificate Authority directory
+
+This is the directory in which B<stunnel> will look for certificates when using
+the I<verify> option.  Note that the certificates in this directory should be named
+XXXXXXXX.0 where XXXXXXXX is the hash value of the DER encoded subject of the
+cert.
+
+The hash algorithm has been changed in B<OpenSSL 1.0.0>.  It is required to
+c_rehash the directory on upgrade from B<OpenSSL 0.x.x> to B<OpenSSL 1.x.x>.
+
+I<CApath> path is relative to the I<chroot> directory if specified.
+
+=item B<CAfile> = CERT_FILE
+
+Certificate Authority file
+
+This file contains multiple CA certificates, used with the I<verify> option.
+
+=item B<cert> = PEM_FILE
+
+certificate chain PEM file name
+
+The certificates must be in PEM format, and must be from the
+actual server/client certificate to the self-signed root CA certificate.
+
+A certificate is required in server mode, and optional in client mode.
+
+=item B<checkEmail> = EMAIL
+
+email address of the peer certificate subject
+
+Multiple I<checkEmail> options are allowed in a single service section.
+Certificates are accepted if no I<checkEmail> option was specified, or the
+email address of the peer certificate matches any of the email addresses
+specified with I<checkEmail>.
+
+=item B<checkHost> = HOST
+
+host of the peer certificate subject
+
+Multiple I<checkHost> options are allowed in a single service section.
+Certificates are accepted if no I<checkHost> option was specified, or the host
+name of the peer certificate matches any of the hosts specified with
+I<checkHost>.
+
+=item B<checkIP> = IP
+
+IP address of the peer certificate subject
+
+Multiple I<checkIP> options are allowed in a single service section.
+Certificates are accepted if no I<checkIP> option was specified, or the IP
+address of the peer certificate matches any of the IP addresses specified with
+I<checkIP>.
+
+=item B<ciphers> = CIPHER_LIST
+
+Select permitted SSL ciphers
+
+A colon-delimited list of the ciphers to allow in the SSL connection,
+for example DES-CBC3-SHA:IDEA-CBC-MD5.
+
+=item B<client> = yes | no
+
+client mode (remote service uses SSL)
+
+default: no (server mode)
+
+=item B<connect> = [HOST:]PORT
+
+connect to a remote address
+
+If no host is specified, the host defaults to localhost.
+
+Multiple I<connect> options are allowed in a single service section.
+
+If host resolves to multiple addresses and/or if multiple I<connect>
+options are specified, then the remote address is chosen using a
+round-robin algorithm.
+
+=item B<CRLpath> = DIRECTORY
+
+Certificate Revocation Lists directory
+
+This is the directory in which B<stunnel> will look for CRLs when
+using the I<verify> option. Note that the CRLs in this directory should
+be named XXXXXXXX.r0 where XXXXXXXX is the hash value of the CRL.
+
+The hash algorithm has been changed in B<OpenSSL 1.0.0>.  It is required to
+c_rehash the directory on upgrade from B<OpenSSL 0.x.x> to B<OpenSSL 1.x.x>.
+
+I<CRLpath> path is relative to the I<chroot> directory if specified.
+
+=item B<CRLfile> = CERT_FILE
+
+Certificate Revocation Lists file
+
+This file contains multiple CRLs, used with the I<verify> option.
+
+=item B<curve> = NID
+
+specify ECDH curve name
+
+To get a list of supported curves use:
+
+    openssl ecparam -list_curves
+
+default: prime256v1
+
+=item B<logId> = TYPE
+
+connection identifier type
+
+This identifier allows you to distinguish log entries generated for each of the
+connections.
+
+Currently supported types:
+
+=over 4
+
+=item I<sequential>
+
+The numeric sequential identifier is only unique within a single instance of
+B<stunnel>, but very compact.  It is most useful for manual log analysis.
+
+=item I<unique>
+
+This alphanumeric identifier is globally unique, but longer than the sequential
+number.  It is most useful for automated log analysis.
+
+=item I<thread>
+
+The operating system thread identifier is neither unique (even within a single
+instance of B<stunnel>) nor short.  It is most useful for debugging software
+or configuration issues.
+
+=back
+
+default: sequential
+
+=item B<debug> = LEVEL
+
+debugging level
+
+Level is a one of the syslog level names or numbers
+emerg (0), alert (1), crit (2), err (3), warning (4), notice (5),
+info (6), or debug (7).  All logs for the specified level and
+all levels numerically less than it will be shown.  Use I<debug = debug> or
+I<debug = 7> for greatest debugging output.  The default is notice (5).
+
+=item B<delay> = yes | no
+
+delay DNS lookup for the I<connect> option
+
+This option is useful for dynamic DNS, or when DNS is not available during
+B<stunnel> startup (road warrior VPN, dial-up configurations).
+
+Delayed resolver mode is automatically engaged when stunnel fails to resolve on
+startup any of the I<connect> targets for a service.
+
+Delayed resolver inflicts I<failover = prio>.
+
+default: no
+
+=item B<engineId> = ENGINE_ID
+
+select engine ID for the service
+
+=item B<engineNum> = ENGINE_NUMBER
+
+select engine number for the service
+
+The engines are numbered starting from 1.
+
+=item B<exec> = EXECUTABLE_PATH
+
+execute a local inetd-type program 
+
+I<exec> path is relative to the I<chroot> directory if specified.
+
+The following environmental variables are set on Unix platforms:
+REMOTE_HOST, REMOTE_PORT, SSL_CLIENT_DN, SSL_CLIENT_I_DN.
+
+=item B<execArgs> = $0 $1 $2 ...
+
+arguments for I<exec> including the program name ($0)
+
+Quoting is currently not supported.
+Arguments are separated with an arbitrary amount of whitespace.
+
+=item B<failover> = rr | prio
+
+Failover strategy for multiple "connect" targets.
+
+    rr (round robin) - fair load distribution
+    prio (priority) - use the order specified in config file
+
+default: rr
+
+=item B<ident> = USERNAME
+
+use IDENT (RFC 1413) username checking
+
+=item B<include> = DIRECTORY
+
+include all configuration file parts located in DIRECTORY
+
+The files are included in the ascending alphabetical order of their names.
+
+=item B<key> = KEY_FILE
+
+private key for the certificate specified with I<cert> option
+
+A private key is needed to authenticate the certificate owner.
+Since this file should be kept secret it should only be readable
+by its owner.  On Unix systems you can use the following command:
+
+    chmod 600 keyfile
+
+default: the value of the I<cert> option
+
+=item B<libwrap> = yes | no
+
+Enable or disable the use of /etc/hosts.allow and /etc/hosts.deny.
+
+default: no (since version 5.00)
+
+=item B<local> = HOST
+
+By default, the IP address of the outgoing interface is used as the source for remote connections.
+Use this option to bind a static local IP address instead.
+
+=item B<sni> = SERVICE:SERVER_PATTERN (server mode)
+
+Use the service as a slave service (a name-based virtual server) for Server
+Name Indication TLS extension (RFC 3546).
+
+I<service_name> specifies the master service that accepts client connections
+with the I<accept> option.  I<server_name_pattern> specifies the host name to be
+redirected.  The pattern may start with the '*' character, e.g. '*.example.com'.
+Multiple slave services are normally specified for a single master service.
+The I<sni> option can also be specified more than once within a single slave
+service.
+
+This service, as well as the master service, may not be configured in client
+mode.
+
+The I<connect> option of the slave service is ignored when the I<protocol> option is
+specified, as I<protocol> connects to the remote host before TLS handshake.
+
+Libwrap checks (Unix only) are performed twice: with the master service name after
+TCP connection is accepted, and with the slave service name during the TLS handshake.
+
+The I<sni> option is only available when compiled with B<OpenSSL 1.0.0> and later.
+
+=item B<sni> = SERVER (client mode)
+
+Use the parameter as the value of TLS Server Name Indication (RFC 3546)
+extension.
+
+The I<sni> option is only available when compiled with B<OpenSSL 1.0.0> and later.
+
+=item B<OCSP> = URL
+
+select OCSP server for certificate verification
+
+=item B<OCSPaia> = yes | no
+
+validate certificates with their AIA OCSP responders
+
+This option enables I<stunnel> to validate certificates with the list of
+OCSP responder URLs retrieved from their AIA (Authority Information Access)
+extension.
+
+=item B<OCSPflag> = OCSP_FLAG
+
+specify OCSP server flag
+
+Several I<OCSPflag> can be used to specify multiple flags.
+
+currently supported flags: NOCERTS, NOINTERN NOSIGS, NOCHAIN, NOVERIFY,
+NOEXPLICIT, NOCASIGN, NODELEGATED, NOCHECKS, TRUSTOTHER, RESPID_KEY, NOTIME
+
+=item B<options> = SSL_OPTIONS
+
+B<OpenSSL> library options
+
+The parameter is the B<OpenSSL> option name as described in the
+I<SSL_CTX_set_options(3ssl)> manual, but without I<SSL_OP_> prefix.
+I<stunnel -options> lists the options found to be allowed in the
+current combination of I<stunnel> and the I<OpenSSL> library used
+to build it.
+
+Several I<options> can be used to specify multiple options.
+An option name can be prepended with a dash ("-") to disable the option.
+
+For example, for compatibility with the erroneous Eudora SSL
+implementation, the following option can be used:
+
+    options = DONT_INSERT_EMPTY_FRAGMENTS
+
+default:
+
+    options = NO_SSLv2
+    options = NO_SSLv3
+
+=item B<protocol> = PROTO
+
+application protocol to negotiate SSL
+
+This option enables initial, protocol-specific negotiation of the SSL/TLS
+encryption.
+The I<protocol> option should not be used with SSL encryption on a separate port.
+
+Currently supported protocols:
+
+=over 4
+
+=item I<cifs>
+
+Proprietary (undocummented) extension of CIFS protocol implemented in Samba.
+Support for this extension was dropped in Samba 3.0.0.
+
+=item I<connect>
+
+Based on RFC 2817 - I<Upgrading to TLS Within HTTP/1.1>, section 5.2 - I<Requesting a Tunnel with CONNECT>
+
+This protocol is only supported in client mode.
+
+=item I<imap>
+
+Based on RFC 2595 - I<Using TLS with IMAP, POP3 and ACAP>
+
+=item I<nntp>
+
+Based on RFC 4642 - I<Using Transport Layer Security (TLS) with Network News Transfer Protocol (NNTP)>
+
+This protocol is only supported in client mode.
+
+=item I<pgsql>
+
+Based on
+F<http://www.postgresql.org/docs/8.3/static/protocol-flow.html#AEN73982>
+
+=item I<pop3>
+
+Based on RFC 2449 - I<POP3 Extension Mechanism>
+
+=item I<proxy>
+
+Haproxy client IP address
+F<http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt>
+
+=item I<smtp>
+
+Based on RFC 2487 - I<SMTP Service Extension for Secure SMTP over TLS>
+
+=item I<socks>
+
+SOCKS versions 4, 4a, and 5 are supported.  The SOCKS protocol itself
+is encapsulated within SSL/TLS encryption layer to protect the final
+destination address.
+
+F<http://www.openssh.com/txt/socks4.protocol>
+
+F<http://www.openssh.com/txt/socks4a.protocol>
+
+The BIND command of the SOCKS protocol is not supported.
+The USERID parameter is ignored.
+
+See Examples section for sample configuration files for VPN based on SOCKS
+encryption.
+
+=back
+
+=item B<protocolAuthentication> = basic | ntlm
+
+authentication type for protocol negotiations
+
+Currently the authentication type only applies to the 'connect' protocol.
+
+default: basic
+
+=item B<protocolHost> = HOST:PORT
+
+destination address for protocol negotiations
+
+I<protocolHost> specifies the final SSL server to be connected to by the proxy,
+and not the proxy server directly connected by B<stunnel>.
+The proxy server should be specified with the 'connect' option.
+
+Currently the protocol destination address only applies to 'connect' protocol.
+
+=item B<protocolPassword> = PASSWORD
+
+password for protocol negotiations
+
+=item B<protocolUsername> = USERNAME
+
+username for protocol negotiations
+
+=item B<PSKidentity> = IDENTITY
+
+PSK identity for the PSK client
+
+I<PSKidentity> can be used on B<stunnel> clients to select the PSK identity
+used for authentication.  This option is ignored in server sections.
+
+default: the first identity specified in the I<PSKsecrets> file.
+
+=item B<PSKsecrets> = FILE
+
+file with PSK identities and corresponding keys
+
+Each line of the file in the following format:
+
+    IDENTITY:KEY
+
+The key is required to be at least 20 characters long.
+The file should not be world-readable nor world-writable.
+
+=item B<pty> = yes | no (Unix only)
+
+allocate a pseudoterminal for 'exec' option
+
+=item B<redirect> = [HOST:]PORT
+
+redirect SSL client connections on certificate-based authentication failures
+
+This option only works in server mode.
+Some protocol negotiations are also incompatible with the I<redirect> option.
+
+=item B<renegotiation> = yes | no
+
+support SSL renegotiation
+
+Applications of the SSL renegotiation include some authentication scenarios,
+or re-keying long lasting connections.
+
+On the other hand this feature can facilitate a trivial CPU-exhaustion
+DoS attack:
+
+F<http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html>
+
+Please note that disabling SSL renegotiation does not fully mitigate
+this issue.
+
+default: yes (if supported by B<OpenSSL>)
+
+=item B<reset> = yes | no
+
+attempt to use the TCP RST flag to indicate an error
+
+This option is not supported on some platforms.
+
+default: yes
+
+=item B<retry> = yes | no
+
+reconnect a connect+exec section after it's disconnected
+
+default: no
+
+=item B<sessionCacheSize> = NUM_ENTRIES
+
+session cache size
+
+I<sessionCacheSize> specifies the maximum number of the internal session cache
+entries.
+
+The value of 0 can be used for unlimited size.  It is not recommended
+for production use due to the risk of a memory exhaustion DoS attack.
+
+=item B<sessionCacheTimeout> = TIMEOUT
+
+session cache timeout
+
+This is the number of seconds to keep cached SSL sessions.
+
+=item B<sessiond> = HOST:PORT
+
+address of sessiond SSL cache server
+
+=item B<sslVersion> = SSL_VERSION
+
+select the SSL protocol version
+
+Supported values: all, SSLv2, SSLv3, TLSv1, TLSv1.1, TLSv1.2
+
+Availability of specific protocols depends on the linked OpenSSL library.
+Older versions of OpenSSL do not support TLSv1.1 and TLSv1.2.
+Newer versions of OpenSSL do not support SSLv2.
+
+Obsolete SSLv2 and SSLv3 are currently disabled by default.
+See the B<options> option documentation for details.
+
+=item B<stack> = BYTES (except for FORK model)
+
+thread stack size
+
+=item B<TIMEOUTbusy> = SECONDS
+
+time to wait for expected data
+
+=item B<TIMEOUTclose> = SECONDS
+
+time to wait for close_notify (set to 0 for buggy MSIE)
+
+=item B<TIMEOUTconnect> = SECONDS
+
+time to wait to connect to a remote host
+
+=item B<TIMEOUTidle> = SECONDS
+
+time to keep an idle connection
+
+=item B<transparent> = none | source | destination | both (Unix only)
+
+enable transparent proxy support on selected platforms
+
+Supported values:
+
+=over 4
+
+=item I<none>
+
+Disable transparent proxy support.  This is the default.
+
+=item I<source>
+
+Re-write the address to appear as if a wrapped daemon is connecting
+from the SSL client machine instead of the machine running B<stunnel>.
+
+This option is currently available in:
+
+=over 4
+
+=item Remote mode (I<connect> option) on I<Linux E<gt>=2.6.28>
+
+This configuration requires B<stunnel> to be executed as root and without
+the I<setuid> option.
+
+This configuration requires the following setup for iptables and routing
+(possibly in /etc/rc.local or equivalent file):
+
+    iptables -t mangle -N DIVERT
+    iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT
+    iptables -t mangle -A DIVERT -j MARK --set-mark 1
+    iptables -t mangle -A DIVERT -j ACCEPT
+    ip rule add fwmark 1 lookup 100
+    ip route add local 0.0.0.0/0 dev lo table 100
+    echo 0 >/proc/sys/net/ipv4/conf/lo/rp_filter
+
+B<stunnel> must also to be executed as root and without the I<setuid> option.
+
+=item Remote mode (I<connect> option) on I<Linux 2.2.x>
+
+This configuration requires the kernel to be compiled with the I<transparent proxy>
+option.
+Connected service must be installed on a separate host.
+Routing towards the clients has to go through the B<stunnel> box.
+
+B<stunnel> must also to be executed as root and without the I<setuid> option.
+
+=item Remote mode (I<connect> option) on I<FreeBSD E<gt>=8.0>
+
+This configuration requires additional firewall and routing setup.
+B<stunnel> must also to be executed as root and without the I<setuid> option.
+
+=item Local mode (I<exec> option)
+
+This configuration works by pre-loading the I<libstunnel.so> shared library.
+_RLD_LIST environment variable is used on Tru64, and LD_PRELOAD variable on
+other platforms.
+
+=back
+
+=item I<destination>
+
+The original destination is used instead of the I<connect> option.
+
+A service section for transparent destination may look like this:
+
+    [transparent]
+    client=yes
+    accept=<stunnel_port>
+    transparent=destination
+
+This configuration requires iptables setup to work,
+possibly in /etc/rc.local or equivalent file.
+
+For a connect target installed on the same host:
+
+    /sbin/iptables -t nat -I OUTPUT -p tcp --dport <redirected_port> \
+        -m ! --uid-owner <stunnel_user_id> \
+        -j DNAT --to-destination <local_ip>:<stunnel_port>
+
+For a connect target installed on a remote host:
+
+    /sbin/iptables -I INPUT -i eth0 -p tcp --dport <stunnel_port> -j ACCEPT
+    /sbin/iptables -t nat -I PREROUTING -p tcp --dport <redirected_port> \
+        -i eth0 -j DNAT --to-destination <local_ip>:<stunnel_port>
+
+The transparent destination option is currently only supported on Linux.
+
+=item I<both>
+
+Use both I<source> and I<destination> transparent proxy.
+
+=back
+
+Two legacy options are also supported for backward compatibility:
+
+=over 4
+
+=item I<yes>
+
+This option has been renamed to I<source>.
+
+=item I<no>
+
+This option has been renamed to I<none>.
+
+=back
+
+
+=item B<verify> = LEVEL
+
+verify the peer certificate
+
+=over 4
+
+=item level 0
+
+Request and ignore the peer certificate.
+
+=item level 1
+
+Verify the peer certificate if present.
+
+=item level 2
+
+Verify the peer certificate.
+
+=item level 3
+
+Verify the peer with locally installed certificate.
+
+=item level 4
+
+Ignore the CA chain and only verify the peer certificate.
+
+=item default
+
+No verify.
+
+=back
+
+It is important to understand that this option was solely designed for access
+control and not for authorization.  Specifically for level 2 every non-revoked
+certificate is accepted regardless of its Common Name.  For this reason a
+dedicated CA should be used with level 2, and not a generic CA commonly used
+for webservers.  Level 3 is preferred for point-to-point connections.
+
+=back
+
+
+=head1 RETURN VALUE
+
+B<stunnel> returns zero on success, non-zero on error.
+
+
+=head1 SIGNALS
+
+The following signals can be used to control B<stunnel> in Unix environment:
+
+=over 4
+
+=item SIGHUP
+
+Force a reload of the configuration file.
+
+Some global options will not be reloaded:
+
+=over 4
+
+=item *
+
+chroot
+
+=item *
+
+foreground
+
+=item *
+
+pid
+
+=item *
+
+setgid
+
+=item *
+
+setuid
+
+=back
+
+The use of the 'setuid' option will also prevent B<stunnel> from binding to privileged
+(<1024) ports during configuration reloading.
+
+When the 'chroot' option is used, B<stunnel> will look for all its files (including
+the configuration file, certificates, the log file and the pid file) within the chroot
+jail.
+
+=item SIGUSR1
+
+Close and reopen the B<stunnel> log file.
+This function can be used for log rotation.
+
+=item SIGTERM, SIGQUIT, SIGINT
+
+Shut B<stunnel> down.
+
+=back
+
+The result of sending any other signals to the server is undefined.
+
+
+=head1 EXAMPLES
+
+In order to provide SSL encapsulation to your local I<imapd> service, use:
+
+    [imapd]
+    accept = 993
+    exec = /usr/sbin/imapd
+    execArgs = imapd
+
+or in remote mode:
+
+    [imapd]
+    accept = 993
+    connect = 143
+
+In order to let your local e-mail client connect to an SSL-enabled I<imapd>
+service on another server, configure the e-mail client to connect to localhost
+on port 119 and use:
+
+    [imap]
+    client = yes
+    accept = 143
+    connect = servername:993
+
+If you want to provide tunneling to your I<pppd> daemon on port 2020,
+use something like:
+
+    [vpn]
+    accept = 2020
+    exec = /usr/sbin/pppd
+    execArgs = pppd local
+    pty = yes
+
+If you want to use B<stunnel> in I<inetd> mode to launch your imapd
+process, you'd use this I<stunnel.conf>.
+Note there must be no I<[service_name]> section.
+
+    exec = /usr/sbin/imapd
+    execArgs = imapd
+
+To setup SOCKS VPN configure the following client service:
+
+    [socks_client]
+    client = yes
+    accept = 127.0.0.1:1080
+    connect = vpn_server:9080
+    verify = 4
+    CAfile = stunnel.pem
+
+The corresponding configuration on the vpn_server host:
+
+    [socks_server]
+    protocol = socks
+    accept = 9080
+    cert = stunnel.pem
+    key = stunnel.key
+
+Now test your configuration on the client machine with:
+
+    curl --socks4a localhost http://www.example.com/
+
+=head1 NOTES
+
+=head2 RESTRICTIONS
+
+B<stunnel> cannot be used for the FTP daemon because of the nature
+of the FTP protocol which utilizes multiple ports for data transfers.
+There are available SSL-enabled versions of FTP and telnet daemons, however.
+
+
+=head2 INETD MODE
+
+The most common use of B<stunnel> is to listen on a network
+port and establish communication with either a new port
+via the connect option, or a new program via the I<exec> option.
+However there is a special case when you wish to have
+some other program accept incoming connections and
+launch B<stunnel>, for example with I<inetd>, I<xinetd>,
+or I<tcpserver>.
+
+For example, if you have the following line in I<inetd.conf>:
+
+    imaps stream tcp nowait root @bindir@/stunnel stunnel @sysconfdir@/stunnel/imaps.conf
+
+In these cases, the I<inetd>-style program is responsible
+for binding a network socket (I<imaps> above) and handing
+it to B<stunnel> when a connection is received.
+Thus you do not want B<stunnel> to have any I<accept> option.
+All the I<Service Level Options> should be placed in the
+global options section, and no I<[service_name]> section
+will be present.  See the I<EXAMPLES> section for example
+configurations.
+
+=head2 CERTIFICATES
+
+Each SSL-enabled daemon needs to present a valid X.509 certificate
+to the peer. It also needs a private key to decrypt the incoming
+data. The easiest way to obtain a certificate and a key is to 
+generate them with the free B<OpenSSL> package. You can find more
+information on certificates generation on pages listed below.
+
+The order of contents of the I<.pem> file is important.  It should contain the
+unencrypted private key first, then a signed certificate (not certificate
+request).  There should also be empty lines after the certificate and the private key.
+Any plaintext certificate information appended on the top of generated certificate
+should be discarded. So the file should look like this:
+
+    -----BEGIN RSA PRIVATE KEY-----
+    [encoded key]
+    -----END RSA PRIVATE KEY-----
+    [empty line]
+    -----BEGIN CERTIFICATE-----
+    [encoded certificate]
+    -----END CERTIFICATE-----
+    [empty line]
+
+=head2 RANDOMNESS
+
+B<stunnel> needs to seed the PRNG (pseudo-random number generator) in
+order for SSL to use good randomness.  The following sources are loaded
+in order until sufficient random data has been gathered:
+
+=over 4
+
+=item *
+
+The file specified with the I<RNDfile> flag.
+
+=item *
+
+The file specified by the RANDFILE environment variable, if set.
+
+=item *
+
+The file .rnd in your home directory, if RANDFILE not set.
+
+=item *
+
+The file specified with '--with-random' at compile time.
+
+=item *
+
+The contents of the screen if running on Windows.
+
+=item *
+
+The egd socket specified with the I<EGD> flag.
+
+=item *
+
+The egd socket specified with '--with-egd-sock' at compile time.
+
+=item *
+
+The /dev/urandom device.
+
+=back
+
+With recent (B<OpenSSL 0.9.5a> or later) version of SSL it will stop loading
+random data automatically when sufficient entropy has been gathered.  With
+previous versions it will continue to gather from all the above sources since
+no SSL function exists to tell when enough data is available.
+
+Note that on Windows machines that do not have console user interaction
+(mouse movements, creating windows, etc.) the screen contents are not
+variable enough to be sufficient, and you should provide a random file
+for use with the I<RNDfile> flag.
+
+Note that the file specified with the I<RNDfile> flag should contain
+random data -- that means it should contain different information
+each time B<stunnel> is run.  This is handled automatically
+unless the I<RNDoverwrite> flag is used.  If you wish to update this file
+manually, the I<openssl rand> command in recent versions of B<OpenSSL>,
+would be useful.
+
+Important note: If /dev/urandom is available, B<OpenSSL> often seeds the PRNG
+with it while checking the random state.  On systems with /dev/urandom
+B<OpenSSL> is likely to use it even though it is listed at the very bottom of
+the list above.  This is the behaviour of B<OpenSSL> and not B<stunnel>.
+
+=head2 DH PARAMETERS
+
+B<stunnel> 4.40 and later contains hardcoded 2048-bit DH parameters.  Starting
+with B<stunnel> 5.18, these hardcoded DH parameters are replaced every 24 hours
+with autogenerated temporary DH parameters.  DH parameter generation may take
+several minutes.
+
+Alternatively, it is possible to specify static DH parameters in the
+certificate file, which disables generating temporary DH parameters:
+
+    openssl dhparam 2048 >> stunnel.pem
+
+
+=head1 FILES
+
+=over 4
+
+=item F<@sysconfdir@/stunnel/stunnel.conf>
+
+B<stunnel> configuration file
+
+=back
+
+
+=head1 BUGS
+
+The I<execArgs> option and the Win32 command line do not support quoting.
+
+
+=head1 SEE ALSO
+
+=over 4
+
+=item L<tcpd(8)>
+
+access control facility for internet services
+
+=item L<inetd(8)>
+
+internet 'super-server'
+
+=item F<http://www.stunnel.org/>
+
+B<stunnel> homepage
+
+=item F<http://www.openssl.org/>
+
+B<OpenSSL> project website
+
+=back
+
+
+=head1 AUTHOR
+
+=over 4
+
+=item Michał Trojnara
+
+<F<Michal.Trojnara@mirt.net>>
+
+=back
+
+=for comment
+vim:spelllang=en:spell
diff --git a/m4/ax_append_compile_flags.m4 b/m4/ax_append_compile_flags.m4
new file mode 100644
index 0000000..dc7b866
--- /dev/null
+++ b/m4/ax_append_compile_flags.m4
@@ -0,0 +1,65 @@
+# ===========================================================================
+#  http://www.gnu.org/software/autoconf-archive/ax_append_compile_flags.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_APPEND_COMPILE_FLAGS([FLAG1 FLAG2 ...], [FLAGS-VARIABLE], [EXTRA-FLAGS])
+#
+# DESCRIPTION
+#
+#   For every FLAG1, FLAG2 it is checked whether the compiler works with the
+#   flag.  If it does, the flag is added FLAGS-VARIABLE
+#
+#   If FLAGS-VARIABLE is not specified, the current language's flags (e.g.
+#   CFLAGS) is used.  During the check the flag is always added to the
+#   current language's flags.
+#
+#   If EXTRA-FLAGS is defined, it is added to the current language's default
+#   flags (e.g. CFLAGS) when the check is done.  The check is thus made with
+#   the flags: "CFLAGS EXTRA-FLAGS FLAG".  This can for example be used to
+#   force the compiler to issue an error when a bad flag is given.
+#
+#   NOTE: This macro depends on the AX_APPEND_FLAG and
+#   AX_CHECK_COMPILE_FLAG. Please keep this macro in sync with
+#   AX_APPEND_LINK_FLAGS.
+#
+# LICENSE
+#
+#   Copyright (c) 2011 Maarten Bosmans <mkbosmans@gmail.com>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 4
+
+AC_DEFUN([AX_APPEND_COMPILE_FLAGS],
+[AX_REQUIRE_DEFINED([AX_CHECK_COMPILE_FLAG])
+AX_REQUIRE_DEFINED([AX_APPEND_FLAG])
+for flag in $1; do
+  AX_CHECK_COMPILE_FLAG([$flag], [AX_APPEND_FLAG([$flag], [$2])], [], [$3])
+done
+])dnl AX_APPEND_COMPILE_FLAGS
diff --git a/m4/ax_append_flag.m4 b/m4/ax_append_flag.m4
new file mode 100644
index 0000000..1d38b76
--- /dev/null
+++ b/m4/ax_append_flag.m4
@@ -0,0 +1,69 @@
+# ===========================================================================
+#      http://www.gnu.org/software/autoconf-archive/ax_append_flag.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_APPEND_FLAG(FLAG, [FLAGS-VARIABLE])
+#
+# DESCRIPTION
+#
+#   FLAG is appended to the FLAGS-VARIABLE shell variable, with a space
+#   added in between.
+#
+#   If FLAGS-VARIABLE is not specified, the current language's flags (e.g.
+#   CFLAGS) is used.  FLAGS-VARIABLE is not changed if it already contains
+#   FLAG.  If FLAGS-VARIABLE is unset in the shell, it is set to exactly
+#   FLAG.
+#
+#   NOTE: Implementation based on AX_CFLAGS_GCC_OPTION.
+#
+# LICENSE
+#
+#   Copyright (c) 2008 Guido U. Draheim <guidod@gmx.de>
+#   Copyright (c) 2011 Maarten Bosmans <mkbosmans@gmail.com>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 2
+
+AC_DEFUN([AX_APPEND_FLAG],
+[AC_PREREQ(2.59)dnl for _AC_LANG_PREFIX
+AS_VAR_PUSHDEF([FLAGS], [m4_default($2,_AC_LANG_PREFIX[FLAGS])])dnl
+AS_VAR_SET_IF(FLAGS,
+  [case " AS_VAR_GET(FLAGS) " in
+    *" $1 "*)
+      AC_RUN_LOG([: FLAGS already contains $1])
+      ;;
+    *)
+      AC_RUN_LOG([: FLAGS="$FLAGS $1"])
+      AS_VAR_SET(FLAGS, ["AS_VAR_GET(FLAGS) $1"])
+      ;;
+   esac],
+  [AS_VAR_SET(FLAGS,["$1"])])
+AS_VAR_POPDEF([FLAGS])dnl
+])dnl AX_APPEND_FLAG
diff --git a/m4/ax_append_link_flags.m4 b/m4/ax_append_link_flags.m4
new file mode 100644
index 0000000..c73ddaf
--- /dev/null
+++ b/m4/ax_append_link_flags.m4
@@ -0,0 +1,63 @@
+# ===========================================================================
+#   http://www.gnu.org/software/autoconf-archive/ax_append_link_flags.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_APPEND_LINK_FLAGS([FLAG1 FLAG2 ...], [FLAGS-VARIABLE], [EXTRA-FLAGS])
+#
+# DESCRIPTION
+#
+#   For every FLAG1, FLAG2 it is checked whether the linker works with the
+#   flag.  If it does, the flag is added FLAGS-VARIABLE
+#
+#   If FLAGS-VARIABLE is not specified, the linker's flags (LDFLAGS) is
+#   used. During the check the flag is always added to the linker's flags.
+#
+#   If EXTRA-FLAGS is defined, it is added to the linker's default flags
+#   when the check is done.  The check is thus made with the flags: "LDFLAGS
+#   EXTRA-FLAGS FLAG".  This can for example be used to force the linker to
+#   issue an error when a bad flag is given.
+#
+#   NOTE: This macro depends on the AX_APPEND_FLAG and AX_CHECK_LINK_FLAG.
+#   Please keep this macro in sync with AX_APPEND_COMPILE_FLAGS.
+#
+# LICENSE
+#
+#   Copyright (c) 2011 Maarten Bosmans <mkbosmans@gmail.com>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 4
+
+AC_DEFUN([AX_APPEND_LINK_FLAGS],
+[AX_REQUIRE_DEFINED([AX_CHECK_LINK_FLAG])
+AX_REQUIRE_DEFINED([AX_APPEND_FLAG])
+for flag in $1; do
+  AX_CHECK_LINK_FLAG([$flag], [AX_APPEND_FLAG([$flag], [m4_default([$2], [LDFLAGS])])], [], [$3])
+done
+])dnl AX_APPEND_LINK_FLAGS
diff --git a/m4/ax_check_compile_flag.m4 b/m4/ax_check_compile_flag.m4
new file mode 100644
index 0000000..51df0c0
--- /dev/null
+++ b/m4/ax_check_compile_flag.m4
@@ -0,0 +1,74 @@
+# ===========================================================================
+#   http://www.gnu.org/software/autoconf-archive/ax_check_compile_flag.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_CHECK_COMPILE_FLAG(FLAG, [ACTION-SUCCESS], [ACTION-FAILURE], [EXTRA-FLAGS], [INPUT])
+#
+# DESCRIPTION
+#
+#   Check whether the given FLAG works with the current language's compiler
+#   or gives an error.  (Warnings, however, are ignored)
+#
+#   ACTION-SUCCESS/ACTION-FAILURE are shell commands to execute on
+#   success/failure.
+#
+#   If EXTRA-FLAGS is defined, it is added to the current language's default
+#   flags (e.g. CFLAGS) when the check is done.  The check is thus made with
+#   the flags: "CFLAGS EXTRA-FLAGS FLAG".  This can for example be used to
+#   force the compiler to issue an error when a bad flag is given.
+#
+#   INPUT gives an alternative input source to AC_COMPILE_IFELSE.
+#
+#   NOTE: Implementation based on AX_CFLAGS_GCC_OPTION. Please keep this
+#   macro in sync with AX_CHECK_{PREPROC,LINK}_FLAG.
+#
+# LICENSE
+#
+#   Copyright (c) 2008 Guido U. Draheim <guidod@gmx.de>
+#   Copyright (c) 2011 Maarten Bosmans <mkbosmans@gmail.com>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 3
+
+AC_DEFUN([AX_CHECK_COMPILE_FLAG],
+[AC_PREREQ(2.59)dnl for _AC_LANG_PREFIX
+AS_VAR_PUSHDEF([CACHEVAR],[ax_cv_check_[]_AC_LANG_ABBREV[]flags_$4_$1])dnl
+AC_CACHE_CHECK([whether _AC_LANG compiler accepts $1], CACHEVAR, [
+  ax_check_save_flags=$[]_AC_LANG_PREFIX[]FLAGS
+  _AC_LANG_PREFIX[]FLAGS="$[]_AC_LANG_PREFIX[]FLAGS $4 $1"
+  AC_COMPILE_IFELSE([m4_default([$5],[AC_LANG_PROGRAM()])],
+    [AS_VAR_SET(CACHEVAR,[yes])],
+    [AS_VAR_SET(CACHEVAR,[no])])
+  _AC_LANG_PREFIX[]FLAGS=$ax_check_save_flags])
+AS_IF([test x"AS_VAR_GET(CACHEVAR)" = xyes],
+  [m4_default([$2], :)],
+  [m4_default([$3], :)])
+AS_VAR_POPDEF([CACHEVAR])dnl
+])dnl AX_CHECK_COMPILE_FLAGS
diff --git a/m4/ax_check_link_flag.m4 b/m4/ax_check_link_flag.m4
new file mode 100644
index 0000000..db899dd
--- /dev/null
+++ b/m4/ax_check_link_flag.m4
@@ -0,0 +1,73 @@
+# ===========================================================================
+#    http://www.gnu.org/software/autoconf-archive/ax_check_link_flag.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_CHECK_LINK_FLAG(FLAG, [ACTION-SUCCESS], [ACTION-FAILURE], [EXTRA-FLAGS], [INPUT])
+#
+# DESCRIPTION
+#
+#   Check whether the given FLAG works with the linker or gives an error.
+#   (Warnings, however, are ignored)
+#
+#   ACTION-SUCCESS/ACTION-FAILURE are shell commands to execute on
+#   success/failure.
+#
+#   If EXTRA-FLAGS is defined, it is added to the linker's default flags
+#   when the check is done.  The check is thus made with the flags: "LDFLAGS
+#   EXTRA-FLAGS FLAG".  This can for example be used to force the linker to
+#   issue an error when a bad flag is given.
+#
+#   INPUT gives an alternative input source to AC_LINK_IFELSE.
+#
+#   NOTE: Implementation based on AX_CFLAGS_GCC_OPTION. Please keep this
+#   macro in sync with AX_CHECK_{PREPROC,COMPILE}_FLAG.
+#
+# LICENSE
+#
+#   Copyright (c) 2008 Guido U. Draheim <guidod@gmx.de>
+#   Copyright (c) 2011 Maarten Bosmans <mkbosmans@gmail.com>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 3
+
+AC_DEFUN([AX_CHECK_LINK_FLAG],
+[AS_VAR_PUSHDEF([CACHEVAR],[ax_cv_check_ldflags_$4_$1])dnl
+AC_CACHE_CHECK([whether the linker accepts $1], CACHEVAR, [
+  ax_check_save_flags=$LDFLAGS
+  LDFLAGS="$LDFLAGS $4 $1"
+  AC_LINK_IFELSE([m4_default([$5],[AC_LANG_PROGRAM()])],
+    [AS_VAR_SET(CACHEVAR,[yes])],
+    [AS_VAR_SET(CACHEVAR,[no])])
+  LDFLAGS=$ax_check_save_flags])
+AS_IF([test x"AS_VAR_GET(CACHEVAR)" = xyes],
+  [m4_default([$2], :)],
+  [m4_default([$3], :)])
+AS_VAR_POPDEF([CACHEVAR])dnl
+])dnl AX_CHECK_LINK_FLAGS
diff --git a/m4/ax_pthread.m4 b/m4/ax_pthread.m4
new file mode 100644
index 0000000..d383ad5
--- /dev/null
+++ b/m4/ax_pthread.m4
@@ -0,0 +1,332 @@
+# ===========================================================================
+#        http://www.gnu.org/software/autoconf-archive/ax_pthread.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_PTHREAD([ACTION-IF-FOUND[, ACTION-IF-NOT-FOUND]])
+#
+# DESCRIPTION
+#
+#   This macro figures out how to build C programs using POSIX threads. It
+#   sets the PTHREAD_LIBS output variable to the threads library and linker
+#   flags, and the PTHREAD_CFLAGS output variable to any special C compiler
+#   flags that are needed. (The user can also force certain compiler
+#   flags/libs to be tested by setting these environment variables.)
+#
+#   Also sets PTHREAD_CC to any special C compiler that is needed for
+#   multi-threaded programs (defaults to the value of CC otherwise). (This
+#   is necessary on AIX to use the special cc_r compiler alias.)
+#
+#   NOTE: You are assumed to not only compile your program with these flags,
+#   but also link it with them as well. e.g. you should link with
+#   $PTHREAD_CC $CFLAGS $PTHREAD_CFLAGS $LDFLAGS ... $PTHREAD_LIBS $LIBS
+#
+#   If you are only building threads programs, you may wish to use these
+#   variables in your default LIBS, CFLAGS, and CC:
+#
+#     LIBS="$PTHREAD_LIBS $LIBS"
+#     CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+#     CC="$PTHREAD_CC"
+#
+#   In addition, if the PTHREAD_CREATE_JOINABLE thread-attribute constant
+#   has a nonstandard name, defines PTHREAD_CREATE_JOINABLE to that name
+#   (e.g. PTHREAD_CREATE_UNDETACHED on AIX).
+#
+#   Also HAVE_PTHREAD_PRIO_INHERIT is defined if pthread is found and the
+#   PTHREAD_PRIO_INHERIT symbol is defined when compiling with
+#   PTHREAD_CFLAGS.
+#
+#   ACTION-IF-FOUND is a list of shell commands to run if a threads library
+#   is found, and ACTION-IF-NOT-FOUND is a list of commands to run it if it
+#   is not found. If ACTION-IF-FOUND is not specified, the default action
+#   will define HAVE_PTHREAD.
+#
+#   Please let the authors know if this macro fails on any platform, or if
+#   you have any other suggestions or comments. This macro was based on work
+#   by SGJ on autoconf scripts for FFTW (http://www.fftw.org/) (with help
+#   from M. Frigo), as well as ac_pthread and hb_pthread macros posted by
+#   Alejandro Forero Cuervo to the autoconf macro repository. We are also
+#   grateful for the helpful feedback of numerous users.
+#
+#   Updated for Autoconf 2.68 by Daniel Richard G.
+#
+# LICENSE
+#
+#   Copyright (c) 2008 Steven G. Johnson <stevenj@alum.mit.edu>
+#   Copyright (c) 2011 Daniel Richard G. <skunk@iSKUNK.ORG>
+#
+#   This program is free software: you can redistribute it and/or modify it
+#   under the terms of the GNU General Public License as published by the
+#   Free Software Foundation, either version 3 of the License, or (at your
+#   option) any later version.
+#
+#   This program is distributed in the hope that it will be useful, but
+#   WITHOUT ANY WARRANTY; without even the implied warranty of
+#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
+#   Public License for more details.
+#
+#   You should have received a copy of the GNU General Public License along
+#   with this program. If not, see <http://www.gnu.org/licenses/>.
+#
+#   As a special exception, the respective Autoconf Macro's copyright owner
+#   gives unlimited permission to copy, distribute and modify the configure
+#   scripts that are the output of Autoconf when processing the Macro. You
+#   need not follow the terms of the GNU General Public License when using
+#   or distributing such scripts, even though portions of the text of the
+#   Macro appear in them. The GNU General Public License (GPL) does govern
+#   all other use of the material that constitutes the Autoconf Macro.
+#
+#   This special exception to the GPL applies to versions of the Autoconf
+#   Macro released by the Autoconf Archive. When you make and distribute a
+#   modified version of the Autoconf Macro, you may extend this special
+#   exception to the GPL to apply to your modified version as well.
+
+#serial 21
+
+AU_ALIAS([ACX_PTHREAD], [AX_PTHREAD])
+AC_DEFUN([AX_PTHREAD], [
+AC_REQUIRE([AC_CANONICAL_HOST])
+AC_LANG_PUSH([C])
+ax_pthread_ok=no
+
+# We used to check for pthread.h first, but this fails if pthread.h
+# requires special compiler flags (e.g. on True64 or Sequent).
+# It gets checked for in the link test anyway.
+
+# First of all, check if the user has set any of the PTHREAD_LIBS,
+# etcetera environment variables, and if threads linking works using
+# them:
+if test x"$PTHREAD_LIBS$PTHREAD_CFLAGS" != x; then
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        AC_MSG_CHECKING([for pthread_join in LIBS=$PTHREAD_LIBS with CFLAGS=$PTHREAD_CFLAGS])
+        AC_TRY_LINK_FUNC([pthread_join], [ax_pthread_ok=yes])
+        AC_MSG_RESULT([$ax_pthread_ok])
+        if test x"$ax_pthread_ok" = xno; then
+                PTHREAD_LIBS=""
+                PTHREAD_CFLAGS=""
+        fi
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+fi
+
+# We must check for the threads library under a number of different
+# names; the ordering is very important because some systems
+# (e.g. DEC) have both -lpthread and -lpthreads, where one of the
+# libraries is broken (non-POSIX).
+
+# Create a list of thread flags to try.  Items starting with a "-" are
+# C compiler flags, and other items are library names, except for "none"
+# which indicates that we try without any flags at all, and "pthread-config"
+# which is a program returning the flags for the Pth emulation library.
+
+ax_pthread_flags="pthreads none -Kthread -kthread lthread -pthread -pthreads -mthreads pthread --thread-safe -mt pthread-config"
+
+# The ordering *is* (sometimes) important.  Some notes on the
+# individual items follow:
+
+# pthreads: AIX (must check this before -lpthread)
+# none: in case threads are in libc; should be tried before -Kthread and
+#       other compiler flags to prevent continual compiler warnings
+# -Kthread: Sequent (threads in libc, but -Kthread needed for pthread.h)
+# -kthread: FreeBSD kernel threads (preferred to -pthread since SMP-able)
+# lthread: LinuxThreads port on FreeBSD (also preferred to -pthread)
+# -pthread: Linux/gcc (kernel threads), BSD/gcc (userland threads)
+# -pthreads: Solaris/gcc
+# -mthreads: Mingw32/gcc, Lynx/gcc
+# -mt: Sun Workshop C (may only link SunOS threads [-lthread], but it
+#      doesn't hurt to check since this sometimes defines pthreads too;
+#      also defines -D_REENTRANT)
+#      ... -mt is also the pthreads flag for HP/aCC
+# pthread: Linux, etcetera
+# --thread-safe: KAI C++
+# pthread-config: use pthread-config program (for GNU Pth library)
+
+case ${host_os} in
+        solaris*)
+
+        # On Solaris (at least, for some versions), libc contains stubbed
+        # (non-functional) versions of the pthreads routines, so link-based
+        # tests will erroneously succeed.  (We need to link with -pthreads/-mt/
+        # -lpthread.)  (The stubs are missing pthread_cleanup_push, or rather
+        # a function called by this macro, so we could check for that, but
+        # who knows whether they'll stub that too in a future libc.)  So,
+        # we'll just look for -pthreads and -lpthread first:
+
+        ax_pthread_flags="-pthreads pthread -mt -pthread $ax_pthread_flags"
+        ;;
+
+        darwin*)
+        ax_pthread_flags="-pthread $ax_pthread_flags"
+        ;;
+esac
+
+# Clang doesn't consider unrecognized options an error unless we specify
+# -Werror. We throw in some extra Clang-specific options to ensure that
+# this doesn't happen for GCC, which also accepts -Werror.
+
+AC_MSG_CHECKING([if compiler needs -Werror to reject unknown flags])
+save_CFLAGS="$CFLAGS"
+ax_pthread_extra_flags="-Werror"
+CFLAGS="$CFLAGS $ax_pthread_extra_flags -Wunknown-warning-option -Wsizeof-array-argument"
+AC_COMPILE_IFELSE([AC_LANG_PROGRAM([int foo(void);],[foo()])],
+                  [AC_MSG_RESULT([yes])],
+                  [ax_pthread_extra_flags=
+                   AC_MSG_RESULT([no])])
+CFLAGS="$save_CFLAGS"
+
+if test x"$ax_pthread_ok" = xno; then
+for flag in $ax_pthread_flags; do
+
+        case $flag in
+                none)
+                AC_MSG_CHECKING([whether pthreads work without any flags])
+                ;;
+
+                -*)
+                AC_MSG_CHECKING([whether pthreads work with $flag])
+                PTHREAD_CFLAGS="$flag"
+                ;;
+
+                pthread-config)
+                AC_CHECK_PROG([ax_pthread_config], [pthread-config], [yes], [no])
+                if test x"$ax_pthread_config" = xno; then continue; fi
+                PTHREAD_CFLAGS="`pthread-config --cflags`"
+                PTHREAD_LIBS="`pthread-config --ldflags` `pthread-config --libs`"
+                ;;
+
+                *)
+                AC_MSG_CHECKING([for the pthreads library -l$flag])
+                PTHREAD_LIBS="-l$flag"
+                ;;
+        esac
+
+        save_LIBS="$LIBS"
+        save_CFLAGS="$CFLAGS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS $ax_pthread_extra_flags"
+
+        # Check for various functions.  We must include pthread.h,
+        # since some functions may be macros.  (On the Sequent, we
+        # need a special flag -Kthread to make this header compile.)
+        # We check for pthread_join because it is in -lpthread on IRIX
+        # while pthread_create is in libc.  We check for pthread_attr_init
+        # due to DEC craziness with -lpthreads.  We check for
+        # pthread_cleanup_push because it is one of the few pthread
+        # functions on Solaris that doesn't have a non-functional libc stub.
+        # We try pthread_create on general principles.
+        AC_LINK_IFELSE([AC_LANG_PROGRAM([#include <pthread.h>
+                        static void routine(void *a) { a = 0; }
+                        static void *start_routine(void *a) { return a; }],
+                       [pthread_t th; pthread_attr_t attr;
+                        pthread_create(&th, 0, start_routine, 0);
+                        pthread_join(th, 0);
+                        pthread_attr_init(&attr);
+                        pthread_cleanup_push(routine, 0);
+                        pthread_cleanup_pop(0) /* ; */])],
+                [ax_pthread_ok=yes],
+                [])
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        AC_MSG_RESULT([$ax_pthread_ok])
+        if test "x$ax_pthread_ok" = xyes; then
+                break;
+        fi
+
+        PTHREAD_LIBS=""
+        PTHREAD_CFLAGS=""
+done
+fi
+
+# Various other checks:
+if test "x$ax_pthread_ok" = xyes; then
+        save_LIBS="$LIBS"
+        LIBS="$PTHREAD_LIBS $LIBS"
+        save_CFLAGS="$CFLAGS"
+        CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
+
+        # Detect AIX lossage: JOINABLE attribute is called UNDETACHED.
+        AC_MSG_CHECKING([for joinable pthread attribute])
+        attr_name=unknown
+        for attr in PTHREAD_CREATE_JOINABLE PTHREAD_CREATE_UNDETACHED; do
+            AC_LINK_IFELSE([AC_LANG_PROGRAM([#include <pthread.h>],
+                           [int attr = $attr; return attr /* ; */])],
+                [attr_name=$attr; break],
+                [])
+        done
+        AC_MSG_RESULT([$attr_name])
+        if test "$attr_name" != PTHREAD_CREATE_JOINABLE; then
+            AC_DEFINE_UNQUOTED([PTHREAD_CREATE_JOINABLE], [$attr_name],
+                               [Define to necessary symbol if this constant
+                                uses a non-standard name on your system.])
+        fi
+
+        AC_MSG_CHECKING([if more special flags are required for pthreads])
+        flag=no
+        case ${host_os} in
+            aix* | freebsd* | darwin*) flag="-D_THREAD_SAFE";;
+            osf* | hpux*) flag="-D_REENTRANT";;
+            solaris*)
+            if test "$GCC" = "yes"; then
+                flag="-D_REENTRANT"
+            else
+                # TODO: What about Clang on Solaris?
+                flag="-mt -D_REENTRANT"
+            fi
+            ;;
+        esac
+        AC_MSG_RESULT([$flag])
+        if test "x$flag" != xno; then
+            PTHREAD_CFLAGS="$flag $PTHREAD_CFLAGS"
+        fi
+
+        AC_CACHE_CHECK([for PTHREAD_PRIO_INHERIT],
+            [ax_cv_PTHREAD_PRIO_INHERIT], [
+                AC_LINK_IFELSE([AC_LANG_PROGRAM([[#include <pthread.h>]],
+                                                [[int i = PTHREAD_PRIO_INHERIT;]])],
+                    [ax_cv_PTHREAD_PRIO_INHERIT=yes],
+                    [ax_cv_PTHREAD_PRIO_INHERIT=no])
+            ])
+        AS_IF([test "x$ax_cv_PTHREAD_PRIO_INHERIT" = "xyes"],
+            [AC_DEFINE([HAVE_PTHREAD_PRIO_INHERIT], [1], [Have PTHREAD_PRIO_INHERIT.])])
+
+        LIBS="$save_LIBS"
+        CFLAGS="$save_CFLAGS"
+
+        # More AIX lossage: compile with *_r variant
+        if test "x$GCC" != xyes; then
+            case $host_os in
+                aix*)
+                AS_CASE(["x/$CC"],
+                  [x*/c89|x*/c89_128|x*/c99|x*/c99_128|x*/cc|x*/cc128|x*/xlc|x*/xlc_v6|x*/xlc128|x*/xlc128_v6],
+                  [#handle absolute path differently from PATH based program lookup
+                   AS_CASE(["x$CC"],
+                     [x/*],
+                     [AS_IF([AS_EXECUTABLE_P([${CC}_r])],[PTHREAD_CC="${CC}_r"])],
+                     [AC_CHECK_PROGS([PTHREAD_CC],[${CC}_r],[$CC])])])
+                ;;
+            esac
+        fi
+fi
+
+test -n "$PTHREAD_CC" || PTHREAD_CC="$CC"
+
+AC_SUBST([PTHREAD_LIBS])
+AC_SUBST([PTHREAD_CFLAGS])
+AC_SUBST([PTHREAD_CC])
+
+# Finally, execute ACTION-IF-FOUND/ACTION-IF-NOT-FOUND:
+if test x"$ax_pthread_ok" = xyes; then
+        ifelse([$1],,[AC_DEFINE([HAVE_PTHREAD],[1],[Define if you have POSIX threads libraries and header files.])],[$1])
+        :
+else
+        ax_pthread_ok=no
+        $2
+fi
+AC_LANG_POP
+])dnl AX_PTHREAD
diff --git a/m4/ax_require_defined.m4 b/m4/ax_require_defined.m4
new file mode 100644
index 0000000..cae1111
--- /dev/null
+++ b/m4/ax_require_defined.m4
@@ -0,0 +1,37 @@
+# ===========================================================================
+#    http://www.gnu.org/software/autoconf-archive/ax_require_defined.html
+# ===========================================================================
+#
+# SYNOPSIS
+#
+#   AX_REQUIRE_DEFINED(MACRO)
+#
+# DESCRIPTION
+#
+#   AX_REQUIRE_DEFINED is a simple helper for making sure other macros have
+#   been defined and thus are available for use.  This avoids random issues
+#   where a macro isn't expanded.  Instead the configure script emits a
+#   non-fatal:
+#
+#     ./configure: line 1673: AX_CFLAGS_WARN_ALL: command not found
+#
+#   It's like AC_REQUIRE except it doesn't expand the required macro.
+#
+#   Here's an example:
+#
+#     AX_REQUIRE_DEFINED([AX_CHECK_LINK_FLAG])
+#
+# LICENSE
+#
+#   Copyright (c) 2014 Mike Frysinger <vapier@gentoo.org>
+#
+#   Copying and distribution of this file, with or without modification, are
+#   permitted in any medium without royalty provided the copyright notice
+#   and this notice are preserved. This file is offered as-is, without any
+#   warranty.
+
+#serial 1
+
+AC_DEFUN([AX_REQUIRE_DEFINED], [dnl
+  m4_ifndef([$1], [m4_fatal([macro ]$1[ is not defined; is a m4 file missing?])])
+])dnl AX_REQUIRE_DEFINED
diff --git a/m4/libtool.m4 b/m4/libtool.m4
new file mode 100644
index 0000000..d7c043f
--- /dev/null
+++ b/m4/libtool.m4
@@ -0,0 +1,7997 @@
+# libtool.m4 - Configure libtool for the host system. -*-Autoconf-*-
+#
+#   Copyright (C) 1996, 1997, 1998, 1999, 2000, 2001, 2003, 2004, 2005,
+#                 2006, 2007, 2008, 2009, 2010, 2011 Free Software
+#                 Foundation, Inc.
+#   Written by Gordon Matzigkeit, 1996
+#
+# This file is free software; the Free Software Foundation gives
+# unlimited permission to copy and/or distribute it, with or without
+# modifications, as long as this notice is preserved.
+
+m4_define([_LT_COPYING], [dnl
+#   Copyright (C) 1996, 1997, 1998, 1999, 2000, 2001, 2003, 2004, 2005,
+#                 2006, 2007, 2008, 2009, 2010, 2011 Free Software
+#                 Foundation, Inc.
+#   Written by Gordon Matzigkeit, 1996
+#
+#   This file is part of GNU Libtool.
+#
+# GNU Libtool is free software; you can redistribute it and/or
+# modify it under the terms of the GNU General Public License as
+# published by the Free Software Foundation; either version 2 of
+# the License, or (at your option) any later version.
+#
+# As a special exception to the GNU General Public License,
+# if you distribute this file as part of a program or library that
+# is built using GNU Libtool, you may include this file under the
+# same distribution terms that you use for the rest of that program.
+#
+# GNU Libtool is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with GNU Libtool; see the file COPYING.  If not, a copy
+# can be downloaded from http://www.gnu.org/licenses/gpl.html, or
+# obtained by writing to the Free Software Foundation, Inc.,
+# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
+])
+
+# serial 57 LT_INIT
+
+
+# LT_PREREQ(VERSION)
+# ------------------
+# Complain and exit if this libtool version is less that VERSION.
+m4_defun([LT_PREREQ],
+[m4_if(m4_version_compare(m4_defn([LT_PACKAGE_VERSION]), [$1]), -1,
+       [m4_default([$3],
+		   [m4_fatal([Libtool version $1 or higher is required],
+		             63)])],
+       [$2])])
+
+
+# _LT_CHECK_BUILDDIR
+# ------------------
+# Complain if the absolute build directory name contains unusual characters
+m4_defun([_LT_CHECK_BUILDDIR],
+[case `pwd` in
+  *\ * | *\	*)
+    AC_MSG_WARN([Libtool does not cope well with whitespace in `pwd`]) ;;
+esac
+])
+
+
+# LT_INIT([OPTIONS])
+# ------------------
+AC_DEFUN([LT_INIT],
+[AC_PREREQ([2.58])dnl We use AC_INCLUDES_DEFAULT
+AC_REQUIRE([AC_CONFIG_AUX_DIR_DEFAULT])dnl
+AC_BEFORE([$0], [LT_LANG])dnl
+AC_BEFORE([$0], [LT_OUTPUT])dnl
+AC_BEFORE([$0], [LTDL_INIT])dnl
+m4_require([_LT_CHECK_BUILDDIR])dnl
+
+dnl Autoconf doesn't catch unexpanded LT_ macros by default:
+m4_pattern_forbid([^_?LT_[A-Z_]+$])dnl
+m4_pattern_allow([^(_LT_EOF|LT_DLGLOBAL|LT_DLLAZY_OR_NOW|LT_MULTI_MODULE)$])dnl
+dnl aclocal doesn't pull ltoptions.m4, ltsugar.m4, or ltversion.m4
+dnl unless we require an AC_DEFUNed macro:
+AC_REQUIRE([LTOPTIONS_VERSION])dnl
+AC_REQUIRE([LTSUGAR_VERSION])dnl
+AC_REQUIRE([LTVERSION_VERSION])dnl
+AC_REQUIRE([LTOBSOLETE_VERSION])dnl
+m4_require([_LT_PROG_LTMAIN])dnl
+
+_LT_SHELL_INIT([SHELL=${CONFIG_SHELL-/bin/sh}])
+
+dnl Parse OPTIONS
+_LT_SET_OPTIONS([$0], [$1])
+
+# This can be used to rebuild libtool when needed
+LIBTOOL_DEPS="$ltmain"
+
+# Always use our own libtool.
+LIBTOOL='$(SHELL) $(top_builddir)/libtool'
+AC_SUBST(LIBTOOL)dnl
+
+_LT_SETUP
+
+# Only expand once:
+m4_define([LT_INIT])
+])# LT_INIT
+
+# Old names:
+AU_ALIAS([AC_PROG_LIBTOOL], [LT_INIT])
+AU_ALIAS([AM_PROG_LIBTOOL], [LT_INIT])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_PROG_LIBTOOL], [])
+dnl AC_DEFUN([AM_PROG_LIBTOOL], [])
+
+
+# _LT_CC_BASENAME(CC)
+# -------------------
+# Calculate cc_basename.  Skip known compiler wrappers and cross-prefix.
+m4_defun([_LT_CC_BASENAME],
+[for cc_temp in $1""; do
+  case $cc_temp in
+    compile | *[[\\/]]compile | ccache | *[[\\/]]ccache ) ;;
+    distcc | *[[\\/]]distcc | purify | *[[\\/]]purify ) ;;
+    \-*) ;;
+    *) break;;
+  esac
+done
+cc_basename=`$ECHO "$cc_temp" | $SED "s%.*/%%; s%^$host_alias-%%"`
+])
+
+
+# _LT_FILEUTILS_DEFAULTS
+# ----------------------
+# It is okay to use these file commands and assume they have been set
+# sensibly after `m4_require([_LT_FILEUTILS_DEFAULTS])'.
+m4_defun([_LT_FILEUTILS_DEFAULTS],
+[: ${CP="cp -f"}
+: ${MV="mv -f"}
+: ${RM="rm -f"}
+])# _LT_FILEUTILS_DEFAULTS
+
+
+# _LT_SETUP
+# ---------
+m4_defun([_LT_SETUP],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+AC_REQUIRE([AC_CANONICAL_BUILD])dnl
+AC_REQUIRE([_LT_PREPARE_SED_QUOTE_VARS])dnl
+AC_REQUIRE([_LT_PROG_ECHO_BACKSLASH])dnl
+
+_LT_DECL([], [PATH_SEPARATOR], [1], [The PATH separator for the build system])dnl
+dnl
+_LT_DECL([], [host_alias], [0], [The host system])dnl
+_LT_DECL([], [host], [0])dnl
+_LT_DECL([], [host_os], [0])dnl
+dnl
+_LT_DECL([], [build_alias], [0], [The build system])dnl
+_LT_DECL([], [build], [0])dnl
+_LT_DECL([], [build_os], [0])dnl
+dnl
+AC_REQUIRE([AC_PROG_CC])dnl
+AC_REQUIRE([LT_PATH_LD])dnl
+AC_REQUIRE([LT_PATH_NM])dnl
+dnl
+AC_REQUIRE([AC_PROG_LN_S])dnl
+test -z "$LN_S" && LN_S="ln -s"
+_LT_DECL([], [LN_S], [1], [Whether we need soft or hard links])dnl
+dnl
+AC_REQUIRE([LT_CMD_MAX_LEN])dnl
+_LT_DECL([objext], [ac_objext], [0], [Object file suffix (normally "o")])dnl
+_LT_DECL([], [exeext], [0], [Executable file suffix (normally "")])dnl
+dnl
+m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_CHECK_SHELL_FEATURES])dnl
+m4_require([_LT_PATH_CONVERSION_FUNCTIONS])dnl
+m4_require([_LT_CMD_RELOAD])dnl
+m4_require([_LT_CHECK_MAGIC_METHOD])dnl
+m4_require([_LT_CHECK_SHAREDLIB_FROM_LINKLIB])dnl
+m4_require([_LT_CMD_OLD_ARCHIVE])dnl
+m4_require([_LT_CMD_GLOBAL_SYMBOLS])dnl
+m4_require([_LT_WITH_SYSROOT])dnl
+
+_LT_CONFIG_LIBTOOL_INIT([
+# See if we are running on zsh, and set the options which allow our
+# commands through without removal of \ escapes INIT.
+if test -n "\${ZSH_VERSION+set}" ; then
+   setopt NO_GLOB_SUBST
+fi
+])
+if test -n "${ZSH_VERSION+set}" ; then
+   setopt NO_GLOB_SUBST
+fi
+
+_LT_CHECK_OBJDIR
+
+m4_require([_LT_TAG_COMPILER])dnl
+
+case $host_os in
+aix3*)
+  # AIX sometimes has problems with the GCC collect2 program.  For some
+  # reason, if we set the COLLECT_NAMES environment variable, the problems
+  # vanish in a puff of smoke.
+  if test "X${COLLECT_NAMES+set}" != Xset; then
+    COLLECT_NAMES=
+    export COLLECT_NAMES
+  fi
+  ;;
+esac
+
+# Global variables:
+ofile=libtool
+can_build_shared=yes
+
+# All known linkers require a `.a' archive for static linking (except MSVC,
+# which needs '.lib').
+libext=a
+
+with_gnu_ld="$lt_cv_prog_gnu_ld"
+
+old_CC="$CC"
+old_CFLAGS="$CFLAGS"
+
+# Set sane defaults for various variables
+test -z "$CC" && CC=cc
+test -z "$LTCC" && LTCC=$CC
+test -z "$LTCFLAGS" && LTCFLAGS=$CFLAGS
+test -z "$LD" && LD=ld
+test -z "$ac_objext" && ac_objext=o
+
+_LT_CC_BASENAME([$compiler])
+
+# Only perform the check for file, if the check method requires it
+test -z "$MAGIC_CMD" && MAGIC_CMD=file
+case $deplibs_check_method in
+file_magic*)
+  if test "$file_magic_cmd" = '$MAGIC_CMD'; then
+    _LT_PATH_MAGIC
+  fi
+  ;;
+esac
+
+# Use C for the default configuration in the libtool script
+LT_SUPPORTED_TAG([CC])
+_LT_LANG_C_CONFIG
+_LT_LANG_DEFAULT_CONFIG
+_LT_CONFIG_COMMANDS
+])# _LT_SETUP
+
+
+# _LT_PREPARE_SED_QUOTE_VARS
+# --------------------------
+# Define a few sed substitution that help us do robust quoting.
+m4_defun([_LT_PREPARE_SED_QUOTE_VARS],
+[# Backslashify metacharacters that are still active within
+# double-quoted strings.
+sed_quote_subst='s/\([["`$\\]]\)/\\\1/g'
+
+# Same as above, but do not quote variable references.
+double_quote_subst='s/\([["`\\]]\)/\\\1/g'
+
+# Sed substitution to delay expansion of an escaped shell variable in a
+# double_quote_subst'ed string.
+delay_variable_subst='s/\\\\\\\\\\\$/\\\\\\$/g'
+
+# Sed substitution to delay expansion of an escaped single quote.
+delay_single_quote_subst='s/'\''/'\'\\\\\\\'\''/g'
+
+# Sed substitution to avoid accidental globbing in evaled expressions
+no_glob_subst='s/\*/\\\*/g'
+])
+
+# _LT_PROG_LTMAIN
+# ---------------
+# Note that this code is called both from `configure', and `config.status'
+# now that we use AC_CONFIG_COMMANDS to generate libtool.  Notably,
+# `config.status' has no value for ac_aux_dir unless we are using Automake,
+# so we pass a copy along to make sure it has a sensible value anyway.
+m4_defun([_LT_PROG_LTMAIN],
+[m4_ifdef([AC_REQUIRE_AUX_FILE], [AC_REQUIRE_AUX_FILE([ltmain.sh])])dnl
+_LT_CONFIG_LIBTOOL_INIT([ac_aux_dir='$ac_aux_dir'])
+ltmain="$ac_aux_dir/ltmain.sh"
+])# _LT_PROG_LTMAIN
+
+
+## ------------------------------------- ##
+## Accumulate code for creating libtool. ##
+## ------------------------------------- ##
+
+# So that we can recreate a full libtool script including additional
+# tags, we accumulate the chunks of code to send to AC_CONFIG_COMMANDS
+# in macros and then make a single call at the end using the `libtool'
+# label.
+
+
+# _LT_CONFIG_LIBTOOL_INIT([INIT-COMMANDS])
+# ----------------------------------------
+# Register INIT-COMMANDS to be passed to AC_CONFIG_COMMANDS later.
+m4_define([_LT_CONFIG_LIBTOOL_INIT],
+[m4_ifval([$1],
+          [m4_append([_LT_OUTPUT_LIBTOOL_INIT],
+                     [$1
+])])])
+
+# Initialize.
+m4_define([_LT_OUTPUT_LIBTOOL_INIT])
+
+
+# _LT_CONFIG_LIBTOOL([COMMANDS])
+# ------------------------------
+# Register COMMANDS to be passed to AC_CONFIG_COMMANDS later.
+m4_define([_LT_CONFIG_LIBTOOL],
+[m4_ifval([$1],
+          [m4_append([_LT_OUTPUT_LIBTOOL_COMMANDS],
+                     [$1
+])])])
+
+# Initialize.
+m4_define([_LT_OUTPUT_LIBTOOL_COMMANDS])
+
+
+# _LT_CONFIG_SAVE_COMMANDS([COMMANDS], [INIT_COMMANDS])
+# -----------------------------------------------------
+m4_defun([_LT_CONFIG_SAVE_COMMANDS],
+[_LT_CONFIG_LIBTOOL([$1])
+_LT_CONFIG_LIBTOOL_INIT([$2])
+])
+
+
+# _LT_FORMAT_COMMENT([COMMENT])
+# -----------------------------
+# Add leading comment marks to the start of each line, and a trailing
+# full-stop to the whole comment if one is not present already.
+m4_define([_LT_FORMAT_COMMENT],
+[m4_ifval([$1], [
+m4_bpatsubst([m4_bpatsubst([$1], [^ *], [# ])],
+              [['`$\]], [\\\&])]m4_bmatch([$1], [[!?.]$], [], [.])
+)])
+
+
+
+## ------------------------ ##
+## FIXME: Eliminate VARNAME ##
+## ------------------------ ##
+
+
+# _LT_DECL([CONFIGNAME], VARNAME, VALUE, [DESCRIPTION], [IS-TAGGED?])
+# -------------------------------------------------------------------
+# CONFIGNAME is the name given to the value in the libtool script.
+# VARNAME is the (base) name used in the configure script.
+# VALUE may be 0, 1 or 2 for a computed quote escaped value based on
+# VARNAME.  Any other value will be used directly.
+m4_define([_LT_DECL],
+[lt_if_append_uniq([lt_decl_varnames], [$2], [, ],
+    [lt_dict_add_subkey([lt_decl_dict], [$2], [libtool_name],
+	[m4_ifval([$1], [$1], [$2])])
+    lt_dict_add_subkey([lt_decl_dict], [$2], [value], [$3])
+    m4_ifval([$4],
+	[lt_dict_add_subkey([lt_decl_dict], [$2], [description], [$4])])
+    lt_dict_add_subkey([lt_decl_dict], [$2],
+	[tagged?], [m4_ifval([$5], [yes], [no])])])
+])
+
+
+# _LT_TAGDECL([CONFIGNAME], VARNAME, VALUE, [DESCRIPTION])
+# --------------------------------------------------------
+m4_define([_LT_TAGDECL], [_LT_DECL([$1], [$2], [$3], [$4], [yes])])
+
+
+# lt_decl_tag_varnames([SEPARATOR], [VARNAME1...])
+# ------------------------------------------------
+m4_define([lt_decl_tag_varnames],
+[_lt_decl_filter([tagged?], [yes], $@)])
+
+
+# _lt_decl_filter(SUBKEY, VALUE, [SEPARATOR], [VARNAME1..])
+# ---------------------------------------------------------
+m4_define([_lt_decl_filter],
+[m4_case([$#],
+  [0], [m4_fatal([$0: too few arguments: $#])],
+  [1], [m4_fatal([$0: too few arguments: $#: $1])],
+  [2], [lt_dict_filter([lt_decl_dict], [$1], [$2], [], lt_decl_varnames)],
+  [3], [lt_dict_filter([lt_decl_dict], [$1], [$2], [$3], lt_decl_varnames)],
+  [lt_dict_filter([lt_decl_dict], $@)])[]dnl
+])
+
+
+# lt_decl_quote_varnames([SEPARATOR], [VARNAME1...])
+# --------------------------------------------------
+m4_define([lt_decl_quote_varnames],
+[_lt_decl_filter([value], [1], $@)])
+
+
+# lt_decl_dquote_varnames([SEPARATOR], [VARNAME1...])
+# ---------------------------------------------------
+m4_define([lt_decl_dquote_varnames],
+[_lt_decl_filter([value], [2], $@)])
+
+
+# lt_decl_varnames_tagged([SEPARATOR], [VARNAME1...])
+# ---------------------------------------------------
+m4_define([lt_decl_varnames_tagged],
+[m4_assert([$# <= 2])dnl
+_$0(m4_quote(m4_default([$1], [[, ]])),
+    m4_ifval([$2], [[$2]], [m4_dquote(lt_decl_tag_varnames)]),
+    m4_split(m4_normalize(m4_quote(_LT_TAGS)), [ ]))])
+m4_define([_lt_decl_varnames_tagged],
+[m4_ifval([$3], [lt_combine([$1], [$2], [_], $3)])])
+
+
+# lt_decl_all_varnames([SEPARATOR], [VARNAME1...])
+# ------------------------------------------------
+m4_define([lt_decl_all_varnames],
+[_$0(m4_quote(m4_default([$1], [[, ]])),
+     m4_if([$2], [],
+	   m4_quote(lt_decl_varnames),
+	m4_quote(m4_shift($@))))[]dnl
+])
+m4_define([_lt_decl_all_varnames],
+[lt_join($@, lt_decl_varnames_tagged([$1],
+			lt_decl_tag_varnames([[, ]], m4_shift($@))))dnl
+])
+
+
+# _LT_CONFIG_STATUS_DECLARE([VARNAME])
+# ------------------------------------
+# Quote a variable value, and forward it to `config.status' so that its
+# declaration there will have the same value as in `configure'.  VARNAME
+# must have a single quote delimited value for this to work.
+m4_define([_LT_CONFIG_STATUS_DECLARE],
+[$1='`$ECHO "$][$1" | $SED "$delay_single_quote_subst"`'])
+
+
+# _LT_CONFIG_STATUS_DECLARATIONS
+# ------------------------------
+# We delimit libtool config variables with single quotes, so when
+# we write them to config.status, we have to be sure to quote all
+# embedded single quotes properly.  In configure, this macro expands
+# each variable declared with _LT_DECL (and _LT_TAGDECL) into:
+#
+#    <var>='`$ECHO "$<var>" | $SED "$delay_single_quote_subst"`'
+m4_defun([_LT_CONFIG_STATUS_DECLARATIONS],
+[m4_foreach([_lt_var], m4_quote(lt_decl_all_varnames),
+    [m4_n([_LT_CONFIG_STATUS_DECLARE(_lt_var)])])])
+
+
+# _LT_LIBTOOL_TAGS
+# ----------------
+# Output comment and list of tags supported by the script
+m4_defun([_LT_LIBTOOL_TAGS],
+[_LT_FORMAT_COMMENT([The names of the tagged configurations supported by this script])dnl
+available_tags="_LT_TAGS"dnl
+])
+
+
+# _LT_LIBTOOL_DECLARE(VARNAME, [TAG])
+# -----------------------------------
+# Extract the dictionary values for VARNAME (optionally with TAG) and
+# expand to a commented shell variable setting:
+#
+#    # Some comment about what VAR is for.
+#    visible_name=$lt_internal_name
+m4_define([_LT_LIBTOOL_DECLARE],
+[_LT_FORMAT_COMMENT(m4_quote(lt_dict_fetch([lt_decl_dict], [$1],
+					   [description])))[]dnl
+m4_pushdef([_libtool_name],
+    m4_quote(lt_dict_fetch([lt_decl_dict], [$1], [libtool_name])))[]dnl
+m4_case(m4_quote(lt_dict_fetch([lt_decl_dict], [$1], [value])),
+    [0], [_libtool_name=[$]$1],
+    [1], [_libtool_name=$lt_[]$1],
+    [2], [_libtool_name=$lt_[]$1],
+    [_libtool_name=lt_dict_fetch([lt_decl_dict], [$1], [value])])[]dnl
+m4_ifval([$2], [_$2])[]m4_popdef([_libtool_name])[]dnl
+])
+
+
+# _LT_LIBTOOL_CONFIG_VARS
+# -----------------------
+# Produce commented declarations of non-tagged libtool config variables
+# suitable for insertion in the LIBTOOL CONFIG section of the `libtool'
+# script.  Tagged libtool config variables (even for the LIBTOOL CONFIG
+# section) are produced by _LT_LIBTOOL_TAG_VARS.
+m4_defun([_LT_LIBTOOL_CONFIG_VARS],
+[m4_foreach([_lt_var],
+    m4_quote(_lt_decl_filter([tagged?], [no], [], lt_decl_varnames)),
+    [m4_n([_LT_LIBTOOL_DECLARE(_lt_var)])])])
+
+
+# _LT_LIBTOOL_TAG_VARS(TAG)
+# -------------------------
+m4_define([_LT_LIBTOOL_TAG_VARS],
+[m4_foreach([_lt_var], m4_quote(lt_decl_tag_varnames),
+    [m4_n([_LT_LIBTOOL_DECLARE(_lt_var, [$1])])])])
+
+
+# _LT_TAGVAR(VARNAME, [TAGNAME])
+# ------------------------------
+m4_define([_LT_TAGVAR], [m4_ifval([$2], [$1_$2], [$1])])
+
+
+# _LT_CONFIG_COMMANDS
+# -------------------
+# Send accumulated output to $CONFIG_STATUS.  Thanks to the lists of
+# variables for single and double quote escaping we saved from calls
+# to _LT_DECL, we can put quote escaped variables declarations
+# into `config.status', and then the shell code to quote escape them in
+# for loops in `config.status'.  Finally, any additional code accumulated
+# from calls to _LT_CONFIG_LIBTOOL_INIT is expanded.
+m4_defun([_LT_CONFIG_COMMANDS],
+[AC_PROVIDE_IFELSE([LT_OUTPUT],
+	dnl If the libtool generation code has been placed in $CONFIG_LT,
+	dnl instead of duplicating it all over again into config.status,
+	dnl then we will have config.status run $CONFIG_LT later, so it
+	dnl needs to know what name is stored there:
+        [AC_CONFIG_COMMANDS([libtool],
+            [$SHELL $CONFIG_LT || AS_EXIT(1)], [CONFIG_LT='$CONFIG_LT'])],
+    dnl If the libtool generation code is destined for config.status,
+    dnl expand the accumulated commands and init code now:
+    [AC_CONFIG_COMMANDS([libtool],
+        [_LT_OUTPUT_LIBTOOL_COMMANDS], [_LT_OUTPUT_LIBTOOL_COMMANDS_INIT])])
+])#_LT_CONFIG_COMMANDS
+
+
+# Initialize.
+m4_define([_LT_OUTPUT_LIBTOOL_COMMANDS_INIT],
+[
+
+# The HP-UX ksh and POSIX shell print the target directory to stdout
+# if CDPATH is set.
+(unset CDPATH) >/dev/null 2>&1 && unset CDPATH
+
+sed_quote_subst='$sed_quote_subst'
+double_quote_subst='$double_quote_subst'
+delay_variable_subst='$delay_variable_subst'
+_LT_CONFIG_STATUS_DECLARATIONS
+LTCC='$LTCC'
+LTCFLAGS='$LTCFLAGS'
+compiler='$compiler_DEFAULT'
+
+# A function that is used when there is no print builtin or printf.
+func_fallback_echo ()
+{
+  eval 'cat <<_LTECHO_EOF
+\$[]1
+_LTECHO_EOF'
+}
+
+# Quote evaled strings.
+for var in lt_decl_all_varnames([[ \
+]], lt_decl_quote_varnames); do
+    case \`eval \\\\\$ECHO \\\\""\\\\\$\$var"\\\\"\` in
+    *[[\\\\\\\`\\"\\\$]]*)
+      eval "lt_\$var=\\\\\\"\\\`\\\$ECHO \\"\\\$\$var\\" | \\\$SED \\"\\\$sed_quote_subst\\"\\\`\\\\\\""
+      ;;
+    *)
+      eval "lt_\$var=\\\\\\"\\\$\$var\\\\\\""
+      ;;
+    esac
+done
+
+# Double-quote double-evaled strings.
+for var in lt_decl_all_varnames([[ \
+]], lt_decl_dquote_varnames); do
+    case \`eval \\\\\$ECHO \\\\""\\\\\$\$var"\\\\"\` in
+    *[[\\\\\\\`\\"\\\$]]*)
+      eval "lt_\$var=\\\\\\"\\\`\\\$ECHO \\"\\\$\$var\\" | \\\$SED -e \\"\\\$double_quote_subst\\" -e \\"\\\$sed_quote_subst\\" -e \\"\\\$delay_variable_subst\\"\\\`\\\\\\""
+      ;;
+    *)
+      eval "lt_\$var=\\\\\\"\\\$\$var\\\\\\""
+      ;;
+    esac
+done
+
+_LT_OUTPUT_LIBTOOL_INIT
+])
+
+# _LT_GENERATED_FILE_INIT(FILE, [COMMENT])
+# ------------------------------------
+# Generate a child script FILE with all initialization necessary to
+# reuse the environment learned by the parent script, and make the
+# file executable.  If COMMENT is supplied, it is inserted after the
+# `#!' sequence but before initialization text begins.  After this
+# macro, additional text can be appended to FILE to form the body of
+# the child script.  The macro ends with non-zero status if the
+# file could not be fully written (such as if the disk is full).
+m4_ifdef([AS_INIT_GENERATED],
+[m4_defun([_LT_GENERATED_FILE_INIT],[AS_INIT_GENERATED($@)])],
+[m4_defun([_LT_GENERATED_FILE_INIT],
+[m4_require([AS_PREPARE])]dnl
+[m4_pushdef([AS_MESSAGE_LOG_FD])]dnl
+[lt_write_fail=0
+cat >$1 <<_ASEOF || lt_write_fail=1
+#! $SHELL
+# Generated by $as_me.
+$2
+SHELL=\${CONFIG_SHELL-$SHELL}
+export SHELL
+_ASEOF
+cat >>$1 <<\_ASEOF || lt_write_fail=1
+AS_SHELL_SANITIZE
+_AS_PREPARE
+exec AS_MESSAGE_FD>&1
+_ASEOF
+test $lt_write_fail = 0 && chmod +x $1[]dnl
+m4_popdef([AS_MESSAGE_LOG_FD])])])# _LT_GENERATED_FILE_INIT
+
+# LT_OUTPUT
+# ---------
+# This macro allows early generation of the libtool script (before
+# AC_OUTPUT is called), incase it is used in configure for compilation
+# tests.
+AC_DEFUN([LT_OUTPUT],
+[: ${CONFIG_LT=./config.lt}
+AC_MSG_NOTICE([creating $CONFIG_LT])
+_LT_GENERATED_FILE_INIT(["$CONFIG_LT"],
+[# Run this file to recreate a libtool stub with the current configuration.])
+
+cat >>"$CONFIG_LT" <<\_LTEOF
+lt_cl_silent=false
+exec AS_MESSAGE_LOG_FD>>config.log
+{
+  echo
+  AS_BOX([Running $as_me.])
+} >&AS_MESSAGE_LOG_FD
+
+lt_cl_help="\
+\`$as_me' creates a local libtool stub from the current configuration,
+for use in further configure time tests before the real libtool is
+generated.
+
+Usage: $[0] [[OPTIONS]]
+
+  -h, --help      print this help, then exit
+  -V, --version   print version number, then exit
+  -q, --quiet     do not print progress messages
+  -d, --debug     don't remove temporary files
+
+Report bugs to <bug-libtool@gnu.org>."
+
+lt_cl_version="\
+m4_ifset([AC_PACKAGE_NAME], [AC_PACKAGE_NAME ])config.lt[]dnl
+m4_ifset([AC_PACKAGE_VERSION], [ AC_PACKAGE_VERSION])
+configured by $[0], generated by m4_PACKAGE_STRING.
+
+Copyright (C) 2011 Free Software Foundation, Inc.
+This config.lt script is free software; the Free Software Foundation
+gives unlimited permision to copy, distribute and modify it."
+
+while test $[#] != 0
+do
+  case $[1] in
+    --version | --v* | -V )
+      echo "$lt_cl_version"; exit 0 ;;
+    --help | --h* | -h )
+      echo "$lt_cl_help"; exit 0 ;;
+    --debug | --d* | -d )
+      debug=: ;;
+    --quiet | --q* | --silent | --s* | -q )
+      lt_cl_silent=: ;;
+
+    -*) AC_MSG_ERROR([unrecognized option: $[1]
+Try \`$[0] --help' for more information.]) ;;
+
+    *) AC_MSG_ERROR([unrecognized argument: $[1]
+Try \`$[0] --help' for more information.]) ;;
+  esac
+  shift
+done
+
+if $lt_cl_silent; then
+  exec AS_MESSAGE_FD>/dev/null
+fi
+_LTEOF
+
+cat >>"$CONFIG_LT" <<_LTEOF
+_LT_OUTPUT_LIBTOOL_COMMANDS_INIT
+_LTEOF
+
+cat >>"$CONFIG_LT" <<\_LTEOF
+AC_MSG_NOTICE([creating $ofile])
+_LT_OUTPUT_LIBTOOL_COMMANDS
+AS_EXIT(0)
+_LTEOF
+chmod +x "$CONFIG_LT"
+
+# configure is writing to config.log, but config.lt does its own redirection,
+# appending to config.log, which fails on DOS, as config.log is still kept
+# open by configure.  Here we exec the FD to /dev/null, effectively closing
+# config.log, so it can be properly (re)opened and appended to by config.lt.
+lt_cl_success=:
+test "$silent" = yes &&
+  lt_config_lt_args="$lt_config_lt_args --quiet"
+exec AS_MESSAGE_LOG_FD>/dev/null
+$SHELL "$CONFIG_LT" $lt_config_lt_args || lt_cl_success=false
+exec AS_MESSAGE_LOG_FD>>config.log
+$lt_cl_success || AS_EXIT(1)
+])# LT_OUTPUT
+
+
+# _LT_CONFIG(TAG)
+# ---------------
+# If TAG is the built-in tag, create an initial libtool script with a
+# default configuration from the untagged config vars.  Otherwise add code
+# to config.status for appending the configuration named by TAG from the
+# matching tagged config vars.
+m4_defun([_LT_CONFIG],
+[m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+_LT_CONFIG_SAVE_COMMANDS([
+  m4_define([_LT_TAG], m4_if([$1], [], [C], [$1]))dnl
+  m4_if(_LT_TAG, [C], [
+    # See if we are running on zsh, and set the options which allow our
+    # commands through without removal of \ escapes.
+    if test -n "${ZSH_VERSION+set}" ; then
+      setopt NO_GLOB_SUBST
+    fi
+
+    cfgfile="${ofile}T"
+    trap "$RM \"$cfgfile\"; exit 1" 1 2 15
+    $RM "$cfgfile"
+
+    cat <<_LT_EOF >> "$cfgfile"
+#! $SHELL
+
+# `$ECHO "$ofile" | sed 's%^.*/%%'` - Provide generalized library-building support services.
+# Generated automatically by $as_me ($PACKAGE$TIMESTAMP) $VERSION
+# Libtool was configured on host `(hostname || uname -n) 2>/dev/null | sed 1q`:
+# NOTE: Changes made to this file will be lost: look at ltmain.sh.
+#
+_LT_COPYING
+_LT_LIBTOOL_TAGS
+
+# ### BEGIN LIBTOOL CONFIG
+_LT_LIBTOOL_CONFIG_VARS
+_LT_LIBTOOL_TAG_VARS
+# ### END LIBTOOL CONFIG
+
+_LT_EOF
+
+  case $host_os in
+  aix3*)
+    cat <<\_LT_EOF >> "$cfgfile"
+# AIX sometimes has problems with the GCC collect2 program.  For some
+# reason, if we set the COLLECT_NAMES environment variable, the problems
+# vanish in a puff of smoke.
+if test "X${COLLECT_NAMES+set}" != Xset; then
+  COLLECT_NAMES=
+  export COLLECT_NAMES
+fi
+_LT_EOF
+    ;;
+  esac
+
+  _LT_PROG_LTMAIN
+
+  # We use sed instead of cat because bash on DJGPP gets confused if
+  # if finds mixed CR/LF and LF-only lines.  Since sed operates in
+  # text mode, it properly converts lines to CR/LF.  This bash problem
+  # is reportedly fixed, but why not run on old versions too?
+  sed '$q' "$ltmain" >> "$cfgfile" \
+     || (rm -f "$cfgfile"; exit 1)
+
+  _LT_PROG_REPLACE_SHELLFNS
+
+   mv -f "$cfgfile" "$ofile" ||
+    (rm -f "$ofile" && cp "$cfgfile" "$ofile" && rm -f "$cfgfile")
+  chmod +x "$ofile"
+],
+[cat <<_LT_EOF >> "$ofile"
+
+dnl Unfortunately we have to use $1 here, since _LT_TAG is not expanded
+dnl in a comment (ie after a #).
+# ### BEGIN LIBTOOL TAG CONFIG: $1
+_LT_LIBTOOL_TAG_VARS(_LT_TAG)
+# ### END LIBTOOL TAG CONFIG: $1
+_LT_EOF
+])dnl /m4_if
+],
+[m4_if([$1], [], [
+    PACKAGE='$PACKAGE'
+    VERSION='$VERSION'
+    TIMESTAMP='$TIMESTAMP'
+    RM='$RM'
+    ofile='$ofile'], [])
+])dnl /_LT_CONFIG_SAVE_COMMANDS
+])# _LT_CONFIG
+
+
+# LT_SUPPORTED_TAG(TAG)
+# ---------------------
+# Trace this macro to discover what tags are supported by the libtool
+# --tag option, using:
+#    autoconf --trace 'LT_SUPPORTED_TAG:$1'
+AC_DEFUN([LT_SUPPORTED_TAG], [])
+
+
+# C support is built-in for now
+m4_define([_LT_LANG_C_enabled], [])
+m4_define([_LT_TAGS], [])
+
+
+# LT_LANG(LANG)
+# -------------
+# Enable libtool support for the given language if not already enabled.
+AC_DEFUN([LT_LANG],
+[AC_BEFORE([$0], [LT_OUTPUT])dnl
+m4_case([$1],
+  [C],			[_LT_LANG(C)],
+  [C++],		[_LT_LANG(CXX)],
+  [Go],			[_LT_LANG(GO)],
+  [Java],		[_LT_LANG(GCJ)],
+  [Fortran 77],		[_LT_LANG(F77)],
+  [Fortran],		[_LT_LANG(FC)],
+  [Windows Resource],	[_LT_LANG(RC)],
+  [m4_ifdef([_LT_LANG_]$1[_CONFIG],
+    [_LT_LANG($1)],
+    [m4_fatal([$0: unsupported language: "$1"])])])dnl
+])# LT_LANG
+
+
+# _LT_LANG(LANGNAME)
+# ------------------
+m4_defun([_LT_LANG],
+[m4_ifdef([_LT_LANG_]$1[_enabled], [],
+  [LT_SUPPORTED_TAG([$1])dnl
+  m4_append([_LT_TAGS], [$1 ])dnl
+  m4_define([_LT_LANG_]$1[_enabled], [])dnl
+  _LT_LANG_$1_CONFIG($1)])dnl
+])# _LT_LANG
+
+
+m4_ifndef([AC_PROG_GO], [
+############################################################
+# NOTE: This macro has been submitted for inclusion into   #
+#  GNU Autoconf as AC_PROG_GO.  When it is available in    #
+#  a released version of Autoconf we should remove this    #
+#  macro and use it instead.                               #
+############################################################
+m4_defun([AC_PROG_GO],
+[AC_LANG_PUSH(Go)dnl
+AC_ARG_VAR([GOC],     [Go compiler command])dnl
+AC_ARG_VAR([GOFLAGS], [Go compiler flags])dnl
+_AC_ARG_VAR_LDFLAGS()dnl
+AC_CHECK_TOOL(GOC, gccgo)
+if test -z "$GOC"; then
+  if test -n "$ac_tool_prefix"; then
+    AC_CHECK_PROG(GOC, [${ac_tool_prefix}gccgo], [${ac_tool_prefix}gccgo])
+  fi
+fi
+if test -z "$GOC"; then
+  AC_CHECK_PROG(GOC, gccgo, gccgo, false)
+fi
+])#m4_defun
+])#m4_ifndef
+
+
+# _LT_LANG_DEFAULT_CONFIG
+# -----------------------
+m4_defun([_LT_LANG_DEFAULT_CONFIG],
+[AC_PROVIDE_IFELSE([AC_PROG_CXX],
+  [LT_LANG(CXX)],
+  [m4_define([AC_PROG_CXX], defn([AC_PROG_CXX])[LT_LANG(CXX)])])
+
+AC_PROVIDE_IFELSE([AC_PROG_F77],
+  [LT_LANG(F77)],
+  [m4_define([AC_PROG_F77], defn([AC_PROG_F77])[LT_LANG(F77)])])
+
+AC_PROVIDE_IFELSE([AC_PROG_FC],
+  [LT_LANG(FC)],
+  [m4_define([AC_PROG_FC], defn([AC_PROG_FC])[LT_LANG(FC)])])
+
+dnl The call to [A][M_PROG_GCJ] is quoted like that to stop aclocal
+dnl pulling things in needlessly.
+AC_PROVIDE_IFELSE([AC_PROG_GCJ],
+  [LT_LANG(GCJ)],
+  [AC_PROVIDE_IFELSE([A][M_PROG_GCJ],
+    [LT_LANG(GCJ)],
+    [AC_PROVIDE_IFELSE([LT_PROG_GCJ],
+      [LT_LANG(GCJ)],
+      [m4_ifdef([AC_PROG_GCJ],
+	[m4_define([AC_PROG_GCJ], defn([AC_PROG_GCJ])[LT_LANG(GCJ)])])
+       m4_ifdef([A][M_PROG_GCJ],
+	[m4_define([A][M_PROG_GCJ], defn([A][M_PROG_GCJ])[LT_LANG(GCJ)])])
+       m4_ifdef([LT_PROG_GCJ],
+	[m4_define([LT_PROG_GCJ], defn([LT_PROG_GCJ])[LT_LANG(GCJ)])])])])])
+
+AC_PROVIDE_IFELSE([AC_PROG_GO],
+  [LT_LANG(GO)],
+  [m4_define([AC_PROG_GO], defn([AC_PROG_GO])[LT_LANG(GO)])])
+
+AC_PROVIDE_IFELSE([LT_PROG_RC],
+  [LT_LANG(RC)],
+  [m4_define([LT_PROG_RC], defn([LT_PROG_RC])[LT_LANG(RC)])])
+])# _LT_LANG_DEFAULT_CONFIG
+
+# Obsolete macros:
+AU_DEFUN([AC_LIBTOOL_CXX], [LT_LANG(C++)])
+AU_DEFUN([AC_LIBTOOL_F77], [LT_LANG(Fortran 77)])
+AU_DEFUN([AC_LIBTOOL_FC], [LT_LANG(Fortran)])
+AU_DEFUN([AC_LIBTOOL_GCJ], [LT_LANG(Java)])
+AU_DEFUN([AC_LIBTOOL_RC], [LT_LANG(Windows Resource)])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_CXX], [])
+dnl AC_DEFUN([AC_LIBTOOL_F77], [])
+dnl AC_DEFUN([AC_LIBTOOL_FC], [])
+dnl AC_DEFUN([AC_LIBTOOL_GCJ], [])
+dnl AC_DEFUN([AC_LIBTOOL_RC], [])
+
+
+# _LT_TAG_COMPILER
+# ----------------
+m4_defun([_LT_TAG_COMPILER],
+[AC_REQUIRE([AC_PROG_CC])dnl
+
+_LT_DECL([LTCC], [CC], [1], [A C compiler])dnl
+_LT_DECL([LTCFLAGS], [CFLAGS], [1], [LTCC compiler flags])dnl
+_LT_TAGDECL([CC], [compiler], [1], [A language specific compiler])dnl
+_LT_TAGDECL([with_gcc], [GCC], [0], [Is the compiler the GNU compiler?])dnl
+
+# If no C compiler was specified, use CC.
+LTCC=${LTCC-"$CC"}
+
+# If no C compiler flags were specified, use CFLAGS.
+LTCFLAGS=${LTCFLAGS-"$CFLAGS"}
+
+# Allow CC to be a program name with arguments.
+compiler=$CC
+])# _LT_TAG_COMPILER
+
+
+# _LT_COMPILER_BOILERPLATE
+# ------------------------
+# Check for compiler boilerplate output or warnings with
+# the simple compiler test code.
+m4_defun([_LT_COMPILER_BOILERPLATE],
+[m4_require([_LT_DECL_SED])dnl
+ac_outfile=conftest.$ac_objext
+echo "$lt_simple_compile_test_code" >conftest.$ac_ext
+eval "$ac_compile" 2>&1 >/dev/null | $SED '/^$/d; /^ *+/d' >conftest.err
+_lt_compiler_boilerplate=`cat conftest.err`
+$RM conftest*
+])# _LT_COMPILER_BOILERPLATE
+
+
+# _LT_LINKER_BOILERPLATE
+# ----------------------
+# Check for linker boilerplate output or warnings with
+# the simple link test code.
+m4_defun([_LT_LINKER_BOILERPLATE],
+[m4_require([_LT_DECL_SED])dnl
+ac_outfile=conftest.$ac_objext
+echo "$lt_simple_link_test_code" >conftest.$ac_ext
+eval "$ac_link" 2>&1 >/dev/null | $SED '/^$/d; /^ *+/d' >conftest.err
+_lt_linker_boilerplate=`cat conftest.err`
+$RM -r conftest*
+])# _LT_LINKER_BOILERPLATE
+
+# _LT_REQUIRED_DARWIN_CHECKS
+# -------------------------
+m4_defun_once([_LT_REQUIRED_DARWIN_CHECKS],[
+  case $host_os in
+    rhapsody* | darwin*)
+    AC_CHECK_TOOL([DSYMUTIL], [dsymutil], [:])
+    AC_CHECK_TOOL([NMEDIT], [nmedit], [:])
+    AC_CHECK_TOOL([LIPO], [lipo], [:])
+    AC_CHECK_TOOL([OTOOL], [otool], [:])
+    AC_CHECK_TOOL([OTOOL64], [otool64], [:])
+    _LT_DECL([], [DSYMUTIL], [1],
+      [Tool to manipulate archived DWARF debug symbol files on Mac OS X])
+    _LT_DECL([], [NMEDIT], [1],
+      [Tool to change global to local symbols on Mac OS X])
+    _LT_DECL([], [LIPO], [1],
+      [Tool to manipulate fat objects and archives on Mac OS X])
+    _LT_DECL([], [OTOOL], [1],
+      [ldd/readelf like tool for Mach-O binaries on Mac OS X])
+    _LT_DECL([], [OTOOL64], [1],
+      [ldd/readelf like tool for 64 bit Mach-O binaries on Mac OS X 10.4])
+
+    AC_CACHE_CHECK([for -single_module linker flag],[lt_cv_apple_cc_single_mod],
+      [lt_cv_apple_cc_single_mod=no
+      if test -z "${LT_MULTI_MODULE}"; then
+	# By default we will add the -single_module flag. You can override
+	# by either setting the environment variable LT_MULTI_MODULE
+	# non-empty at configure time, or by adding -multi_module to the
+	# link flags.
+	rm -rf libconftest.dylib*
+	echo "int foo(void){return 1;}" > conftest.c
+	echo "$LTCC $LTCFLAGS $LDFLAGS -o libconftest.dylib \
+-dynamiclib -Wl,-single_module conftest.c" >&AS_MESSAGE_LOG_FD
+	$LTCC $LTCFLAGS $LDFLAGS -o libconftest.dylib \
+	  -dynamiclib -Wl,-single_module conftest.c 2>conftest.err
+        _lt_result=$?
+	# If there is a non-empty error log, and "single_module"
+	# appears in it, assume the flag caused a linker warning
+        if test -s conftest.err && $GREP single_module conftest.err; then
+	  cat conftest.err >&AS_MESSAGE_LOG_FD
+	# Otherwise, if the output was created with a 0 exit code from
+	# the compiler, it worked.
+	elif test -f libconftest.dylib && test $_lt_result -eq 0; then
+	  lt_cv_apple_cc_single_mod=yes
+	else
+	  cat conftest.err >&AS_MESSAGE_LOG_FD
+	fi
+	rm -rf libconftest.dylib*
+	rm -f conftest.*
+      fi])
+
+    AC_CACHE_CHECK([for -exported_symbols_list linker flag],
+      [lt_cv_ld_exported_symbols_list],
+      [lt_cv_ld_exported_symbols_list=no
+      save_LDFLAGS=$LDFLAGS
+      echo "_main" > conftest.sym
+      LDFLAGS="$LDFLAGS -Wl,-exported_symbols_list,conftest.sym"
+      AC_LINK_IFELSE([AC_LANG_PROGRAM([],[])],
+	[lt_cv_ld_exported_symbols_list=yes],
+	[lt_cv_ld_exported_symbols_list=no])
+	LDFLAGS="$save_LDFLAGS"
+    ])
+
+    AC_CACHE_CHECK([for -force_load linker flag],[lt_cv_ld_force_load],
+      [lt_cv_ld_force_load=no
+      cat > conftest.c << _LT_EOF
+int forced_loaded() { return 2;}
+_LT_EOF
+      echo "$LTCC $LTCFLAGS -c -o conftest.o conftest.c" >&AS_MESSAGE_LOG_FD
+      $LTCC $LTCFLAGS -c -o conftest.o conftest.c 2>&AS_MESSAGE_LOG_FD
+      echo "$AR cru libconftest.a conftest.o" >&AS_MESSAGE_LOG_FD
+      $AR cru libconftest.a conftest.o 2>&AS_MESSAGE_LOG_FD
+      echo "$RANLIB libconftest.a" >&AS_MESSAGE_LOG_FD
+      $RANLIB libconftest.a 2>&AS_MESSAGE_LOG_FD
+      cat > conftest.c << _LT_EOF
+int main() { return 0;}
+_LT_EOF
+      echo "$LTCC $LTCFLAGS $LDFLAGS -o conftest conftest.c -Wl,-force_load,./libconftest.a" >&AS_MESSAGE_LOG_FD
+      $LTCC $LTCFLAGS $LDFLAGS -o conftest conftest.c -Wl,-force_load,./libconftest.a 2>conftest.err
+      _lt_result=$?
+      if test -s conftest.err && $GREP force_load conftest.err; then
+	cat conftest.err >&AS_MESSAGE_LOG_FD
+      elif test -f conftest && test $_lt_result -eq 0 && $GREP forced_load conftest >/dev/null 2>&1 ; then
+	lt_cv_ld_force_load=yes
+      else
+	cat conftest.err >&AS_MESSAGE_LOG_FD
+      fi
+        rm -f conftest.err libconftest.a conftest conftest.c
+        rm -rf conftest.dSYM
+    ])
+    case $host_os in
+    rhapsody* | darwin1.[[012]])
+      _lt_dar_allow_undefined='${wl}-undefined ${wl}suppress' ;;
+    darwin1.*)
+      _lt_dar_allow_undefined='${wl}-flat_namespace ${wl}-undefined ${wl}suppress' ;;
+    darwin*) # darwin 5.x on
+      # if running on 10.5 or later, the deployment target defaults
+      # to the OS version, if on x86, and 10.4, the deployment
+      # target defaults to 10.4. Don't you love it?
+      case ${MACOSX_DEPLOYMENT_TARGET-10.0},$host in
+	10.0,*86*-darwin8*|10.0,*-darwin[[91]]*)
+	  _lt_dar_allow_undefined='${wl}-undefined ${wl}dynamic_lookup' ;;
+	10.[[012]]*)
+	  _lt_dar_allow_undefined='${wl}-flat_namespace ${wl}-undefined ${wl}suppress' ;;
+	10.*)
+	  _lt_dar_allow_undefined='${wl}-undefined ${wl}dynamic_lookup' ;;
+      esac
+    ;;
+  esac
+    if test "$lt_cv_apple_cc_single_mod" = "yes"; then
+      _lt_dar_single_mod='$single_module'
+    fi
+    if test "$lt_cv_ld_exported_symbols_list" = "yes"; then
+      _lt_dar_export_syms=' ${wl}-exported_symbols_list,$output_objdir/${libname}-symbols.expsym'
+    else
+      _lt_dar_export_syms='~$NMEDIT -s $output_objdir/${libname}-symbols.expsym ${lib}'
+    fi
+    if test "$DSYMUTIL" != ":" && test "$lt_cv_ld_force_load" = "no"; then
+      _lt_dsymutil='~$DSYMUTIL $lib || :'
+    else
+      _lt_dsymutil=
+    fi
+    ;;
+  esac
+])
+
+
+# _LT_DARWIN_LINKER_FEATURES([TAG])
+# ---------------------------------
+# Checks for linker and compiler features on darwin
+m4_defun([_LT_DARWIN_LINKER_FEATURES],
+[
+  m4_require([_LT_REQUIRED_DARWIN_CHECKS])
+  _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+  _LT_TAGVAR(hardcode_direct, $1)=no
+  _LT_TAGVAR(hardcode_automatic, $1)=yes
+  _LT_TAGVAR(hardcode_shlibpath_var, $1)=unsupported
+  if test "$lt_cv_ld_force_load" = "yes"; then
+    _LT_TAGVAR(whole_archive_flag_spec, $1)='`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience ${wl}-force_load,$conv\"; done; func_echo_all \"$new_convenience\"`'
+    m4_case([$1], [F77], [_LT_TAGVAR(compiler_needs_object, $1)=yes],
+                  [FC],  [_LT_TAGVAR(compiler_needs_object, $1)=yes])
+  else
+    _LT_TAGVAR(whole_archive_flag_spec, $1)=''
+  fi
+  _LT_TAGVAR(link_all_deplibs, $1)=yes
+  _LT_TAGVAR(allow_undefined_flag, $1)="$_lt_dar_allow_undefined"
+  case $cc_basename in
+     ifort*) _lt_dar_can_shared=yes ;;
+     *) _lt_dar_can_shared=$GCC ;;
+  esac
+  if test "$_lt_dar_can_shared" = "yes"; then
+    output_verbose_link_cmd=func_echo_all
+    _LT_TAGVAR(archive_cmds, $1)="\$CC -dynamiclib \$allow_undefined_flag -o \$lib \$libobjs \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring $_lt_dar_single_mod${_lt_dsymutil}"
+    _LT_TAGVAR(module_cmds, $1)="\$CC \$allow_undefined_flag -o \$lib -bundle \$libobjs \$deplibs \$compiler_flags${_lt_dsymutil}"
+    _LT_TAGVAR(archive_expsym_cmds, $1)="sed 's,^,_,' < \$export_symbols > \$output_objdir/\${libname}-symbols.expsym~\$CC -dynamiclib \$allow_undefined_flag -o \$lib \$libobjs \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring ${_lt_dar_single_mod}${_lt_dar_export_syms}${_lt_dsymutil}"
+    _LT_TAGVAR(module_expsym_cmds, $1)="sed -e 's,^,_,' < \$export_symbols > \$output_objdir/\${libname}-symbols.expsym~\$CC \$allow_undefined_flag -o \$lib -bundle \$libobjs \$deplibs \$compiler_flags${_lt_dar_export_syms}${_lt_dsymutil}"
+    m4_if([$1], [CXX],
+[   if test "$lt_cv_apple_cc_single_mod" != "yes"; then
+      _LT_TAGVAR(archive_cmds, $1)="\$CC -r -keep_private_externs -nostdlib -o \${lib}-master.o \$libobjs~\$CC -dynamiclib \$allow_undefined_flag -o \$lib \${lib}-master.o \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring${_lt_dsymutil}"
+      _LT_TAGVAR(archive_expsym_cmds, $1)="sed 's,^,_,' < \$export_symbols > \$output_objdir/\${libname}-symbols.expsym~\$CC -r -keep_private_externs -nostdlib -o \${lib}-master.o \$libobjs~\$CC -dynamiclib \$allow_undefined_flag -o \$lib \${lib}-master.o \$deplibs \$compiler_flags -install_name \$rpath/\$soname \$verstring${_lt_dar_export_syms}${_lt_dsymutil}"
+    fi
+],[])
+  else
+  _LT_TAGVAR(ld_shlibs, $1)=no
+  fi
+])
+
+# _LT_SYS_MODULE_PATH_AIX([TAGNAME])
+# ----------------------------------
+# Links a minimal program and checks the executable
+# for the system default hardcoded library path. In most cases,
+# this is /usr/lib:/lib, but when the MPI compilers are used
+# the location of the communication and MPI libs are included too.
+# If we don't find anything, use the default library path according
+# to the aix ld manual.
+# Store the results from the different compilers for each TAGNAME.
+# Allow to override them for all tags through lt_cv_aix_libpath.
+m4_defun([_LT_SYS_MODULE_PATH_AIX],
+[m4_require([_LT_DECL_SED])dnl
+if test "${lt_cv_aix_libpath+set}" = set; then
+  aix_libpath=$lt_cv_aix_libpath
+else
+  AC_CACHE_VAL([_LT_TAGVAR([lt_cv_aix_libpath_], [$1])],
+  [AC_LINK_IFELSE([AC_LANG_PROGRAM],[
+  lt_aix_libpath_sed='[
+      /Import File Strings/,/^$/ {
+	  /^0/ {
+	      s/^0  *\([^ ]*\) *$/\1/
+	      p
+	  }
+      }]'
+  _LT_TAGVAR([lt_cv_aix_libpath_], [$1])=`dump -H conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  # Check for a 64-bit object if we didn't find anything.
+  if test -z "$_LT_TAGVAR([lt_cv_aix_libpath_], [$1])"; then
+    _LT_TAGVAR([lt_cv_aix_libpath_], [$1])=`dump -HX64 conftest$ac_exeext 2>/dev/null | $SED -n -e "$lt_aix_libpath_sed"`
+  fi],[])
+  if test -z "$_LT_TAGVAR([lt_cv_aix_libpath_], [$1])"; then
+    _LT_TAGVAR([lt_cv_aix_libpath_], [$1])="/usr/lib:/lib"
+  fi
+  ])
+  aix_libpath=$_LT_TAGVAR([lt_cv_aix_libpath_], [$1])
+fi
+])# _LT_SYS_MODULE_PATH_AIX
+
+
+# _LT_SHELL_INIT(ARG)
+# -------------------
+m4_define([_LT_SHELL_INIT],
+[m4_divert_text([M4SH-INIT], [$1
+])])# _LT_SHELL_INIT
+
+
+
+# _LT_PROG_ECHO_BACKSLASH
+# -----------------------
+# Find how we can fake an echo command that does not interpret backslash.
+# In particular, with Autoconf 2.60 or later we add some code to the start
+# of the generated configure script which will find a shell with a builtin
+# printf (which we can use as an echo command).
+m4_defun([_LT_PROG_ECHO_BACKSLASH],
+[ECHO='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO
+ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO$ECHO
+
+AC_MSG_CHECKING([how to print strings])
+# Test print first, because it will be a builtin if present.
+if test "X`( print -r -- -n ) 2>/dev/null`" = X-n && \
+   test "X`print -r -- $ECHO 2>/dev/null`" = "X$ECHO"; then
+  ECHO='print -r --'
+elif test "X`printf %s $ECHO 2>/dev/null`" = "X$ECHO"; then
+  ECHO='printf %s\n'
+else
+  # Use this function as a fallback that always works.
+  func_fallback_echo ()
+  {
+    eval 'cat <<_LTECHO_EOF
+$[]1
+_LTECHO_EOF'
+  }
+  ECHO='func_fallback_echo'
+fi
+
+# func_echo_all arg...
+# Invoke $ECHO with all args, space-separated.
+func_echo_all ()
+{
+    $ECHO "$*" 
+}
+
+case "$ECHO" in
+  printf*) AC_MSG_RESULT([printf]) ;;
+  print*) AC_MSG_RESULT([print -r]) ;;
+  *) AC_MSG_RESULT([cat]) ;;
+esac
+
+m4_ifdef([_AS_DETECT_SUGGESTED],
+[_AS_DETECT_SUGGESTED([
+  test -n "${ZSH_VERSION+set}${BASH_VERSION+set}" || (
+    ECHO='\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'
+    ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO
+    ECHO=$ECHO$ECHO$ECHO$ECHO$ECHO$ECHO
+    PATH=/empty FPATH=/empty; export PATH FPATH
+    test "X`printf %s $ECHO`" = "X$ECHO" \
+      || test "X`print -r -- $ECHO`" = "X$ECHO" )])])
+
+_LT_DECL([], [SHELL], [1], [Shell to use when invoking shell scripts])
+_LT_DECL([], [ECHO], [1], [An echo program that protects backslashes])
+])# _LT_PROG_ECHO_BACKSLASH
+
+
+# _LT_WITH_SYSROOT
+# ----------------
+AC_DEFUN([_LT_WITH_SYSROOT],
+[AC_MSG_CHECKING([for sysroot])
+AC_ARG_WITH([sysroot],
+[  --with-sysroot[=DIR] Search for dependent libraries within DIR
+                        (or the compiler's sysroot if not specified).],
+[], [with_sysroot=no])
+
+dnl lt_sysroot will always be passed unquoted.  We quote it here
+dnl in case the user passed a directory name.
+lt_sysroot=
+case ${with_sysroot} in #(
+ yes)
+   if test "$GCC" = yes; then
+     lt_sysroot=`$CC --print-sysroot 2>/dev/null`
+   fi
+   ;; #(
+ /*)
+   lt_sysroot=`echo "$with_sysroot" | sed -e "$sed_quote_subst"`
+   ;; #(
+ no|'')
+   ;; #(
+ *)
+   AC_MSG_RESULT([${with_sysroot}])
+   AC_MSG_ERROR([The sysroot must be an absolute path.])
+   ;;
+esac
+
+ AC_MSG_RESULT([${lt_sysroot:-no}])
+_LT_DECL([], [lt_sysroot], [0], [The root where to search for ]dnl
+[dependent libraries, and in which our libraries should be installed.])])
+
+# _LT_ENABLE_LOCK
+# ---------------
+m4_defun([_LT_ENABLE_LOCK],
+[AC_ARG_ENABLE([libtool-lock],
+  [AS_HELP_STRING([--disable-libtool-lock],
+    [avoid locking (might break parallel builds)])])
+test "x$enable_libtool_lock" != xno && enable_libtool_lock=yes
+
+# Some flags need to be propagated to the compiler or linker for good
+# libtool support.
+case $host in
+ia64-*-hpux*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if AC_TRY_EVAL(ac_compile); then
+    case `/usr/bin/file conftest.$ac_objext` in
+      *ELF-32*)
+	HPUX_IA64_MODE="32"
+	;;
+      *ELF-64*)
+	HPUX_IA64_MODE="64"
+	;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+*-*-irix6*)
+  # Find out which ABI we are using.
+  echo '[#]line '$LINENO' "configure"' > conftest.$ac_ext
+  if AC_TRY_EVAL(ac_compile); then
+    if test "$lt_cv_prog_gnu_ld" = yes; then
+      case `/usr/bin/file conftest.$ac_objext` in
+	*32-bit*)
+	  LD="${LD-ld} -melf32bsmip"
+	  ;;
+	*N32*)
+	  LD="${LD-ld} -melf32bmipn32"
+	  ;;
+	*64-bit*)
+	  LD="${LD-ld} -melf64bmip"
+	;;
+      esac
+    else
+      case `/usr/bin/file conftest.$ac_objext` in
+	*32-bit*)
+	  LD="${LD-ld} -32"
+	  ;;
+	*N32*)
+	  LD="${LD-ld} -n32"
+	  ;;
+	*64-bit*)
+	  LD="${LD-ld} -64"
+	  ;;
+      esac
+    fi
+  fi
+  rm -rf conftest*
+  ;;
+
+x86_64-*kfreebsd*-gnu|x86_64-*linux*|powerpc*-*linux*| \
+s390*-*linux*|s390*-*tpf*|sparc*-*linux*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if AC_TRY_EVAL(ac_compile); then
+    case `/usr/bin/file conftest.o` in
+      *32-bit*)
+	case $host in
+	  x86_64-*kfreebsd*-gnu)
+	    LD="${LD-ld} -m elf_i386_fbsd"
+	    ;;
+	  x86_64-*linux*)
+	    case `/usr/bin/file conftest.o` in
+	      *x86-64*)
+		LD="${LD-ld} -m elf32_x86_64"
+		;;
+	      *)
+		LD="${LD-ld} -m elf_i386"
+		;;
+	    esac
+	    ;;
+	  powerpc64le-*)
+	    LD="${LD-ld} -m elf32lppclinux"
+	    ;;
+	  powerpc64-*)
+	    LD="${LD-ld} -m elf32ppclinux"
+	    ;;
+	  s390x-*linux*)
+	    LD="${LD-ld} -m elf_s390"
+	    ;;
+	  sparc64-*linux*)
+	    LD="${LD-ld} -m elf32_sparc"
+	    ;;
+	esac
+	;;
+      *64-bit*)
+	case $host in
+	  x86_64-*kfreebsd*-gnu)
+	    LD="${LD-ld} -m elf_x86_64_fbsd"
+	    ;;
+	  x86_64-*linux*)
+	    LD="${LD-ld} -m elf_x86_64"
+	    ;;
+	  powerpcle-*)
+	    LD="${LD-ld} -m elf64lppc"
+	    ;;
+	  powerpc-*)
+	    LD="${LD-ld} -m elf64ppc"
+	    ;;
+	  s390*-*linux*|s390*-*tpf*)
+	    LD="${LD-ld} -m elf64_s390"
+	    ;;
+	  sparc*-*linux*)
+	    LD="${LD-ld} -m elf64_sparc"
+	    ;;
+	esac
+	;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+
+*-*-sco3.2v5*)
+  # On SCO OpenServer 5, we need -belf to get full-featured binaries.
+  SAVE_CFLAGS="$CFLAGS"
+  CFLAGS="$CFLAGS -belf"
+  AC_CACHE_CHECK([whether the C compiler needs -belf], lt_cv_cc_needs_belf,
+    [AC_LANG_PUSH(C)
+     AC_LINK_IFELSE([AC_LANG_PROGRAM([[]],[[]])],[lt_cv_cc_needs_belf=yes],[lt_cv_cc_needs_belf=no])
+     AC_LANG_POP])
+  if test x"$lt_cv_cc_needs_belf" != x"yes"; then
+    # this is probably gcc 2.8.0, egcs 1.0 or newer; no need for -belf
+    CFLAGS="$SAVE_CFLAGS"
+  fi
+  ;;
+*-*solaris*)
+  # Find out which ABI we are using.
+  echo 'int i;' > conftest.$ac_ext
+  if AC_TRY_EVAL(ac_compile); then
+    case `/usr/bin/file conftest.o` in
+    *64-bit*)
+      case $lt_cv_prog_gnu_ld in
+      yes*)
+        case $host in
+        i?86-*-solaris*)
+          LD="${LD-ld} -m elf_x86_64"
+          ;;
+        sparc*-*-solaris*)
+          LD="${LD-ld} -m elf64_sparc"
+          ;;
+        esac
+        # GNU ld 2.21 introduced _sol2 emulations.  Use them if available.
+        if ${LD-ld} -V | grep _sol2 >/dev/null 2>&1; then
+          LD="${LD-ld}_sol2"
+        fi
+        ;;
+      *)
+	if ${LD-ld} -64 -r -o conftest2.o conftest.o >/dev/null 2>&1; then
+	  LD="${LD-ld} -64"
+	fi
+	;;
+      esac
+      ;;
+    esac
+  fi
+  rm -rf conftest*
+  ;;
+esac
+
+need_locks="$enable_libtool_lock"
+])# _LT_ENABLE_LOCK
+
+
+# _LT_PROG_AR
+# -----------
+m4_defun([_LT_PROG_AR],
+[AC_CHECK_TOOLS(AR, [ar], false)
+: ${AR=ar}
+: ${AR_FLAGS=cru}
+_LT_DECL([], [AR], [1], [The archiver])
+_LT_DECL([], [AR_FLAGS], [1], [Flags to create an archive])
+
+AC_CACHE_CHECK([for archiver @FILE support], [lt_cv_ar_at_file],
+  [lt_cv_ar_at_file=no
+   AC_COMPILE_IFELSE([AC_LANG_PROGRAM],
+     [echo conftest.$ac_objext > conftest.lst
+      lt_ar_try='$AR $AR_FLAGS libconftest.a @conftest.lst >&AS_MESSAGE_LOG_FD'
+      AC_TRY_EVAL([lt_ar_try])
+      if test "$ac_status" -eq 0; then
+	# Ensure the archiver fails upon bogus file names.
+	rm -f conftest.$ac_objext libconftest.a
+	AC_TRY_EVAL([lt_ar_try])
+	if test "$ac_status" -ne 0; then
+          lt_cv_ar_at_file=@
+        fi
+      fi
+      rm -f conftest.* libconftest.a
+     ])
+  ])
+
+if test "x$lt_cv_ar_at_file" = xno; then
+  archiver_list_spec=
+else
+  archiver_list_spec=$lt_cv_ar_at_file
+fi
+_LT_DECL([], [archiver_list_spec], [1],
+  [How to feed a file listing to the archiver])
+])# _LT_PROG_AR
+
+
+# _LT_CMD_OLD_ARCHIVE
+# -------------------
+m4_defun([_LT_CMD_OLD_ARCHIVE],
+[_LT_PROG_AR
+
+AC_CHECK_TOOL(STRIP, strip, :)
+test -z "$STRIP" && STRIP=:
+_LT_DECL([], [STRIP], [1], [A symbol stripping program])
+
+AC_CHECK_TOOL(RANLIB, ranlib, :)
+test -z "$RANLIB" && RANLIB=:
+_LT_DECL([], [RANLIB], [1],
+    [Commands used to install an old-style archive])
+
+# Determine commands to create old-style static archives.
+old_archive_cmds='$AR $AR_FLAGS $oldlib$oldobjs'
+old_postinstall_cmds='chmod 644 $oldlib'
+old_postuninstall_cmds=
+
+if test -n "$RANLIB"; then
+  case $host_os in
+  openbsd*)
+    old_postinstall_cmds="$old_postinstall_cmds~\$RANLIB -t \$tool_oldlib"
+    ;;
+  *)
+    old_postinstall_cmds="$old_postinstall_cmds~\$RANLIB \$tool_oldlib"
+    ;;
+  esac
+  old_archive_cmds="$old_archive_cmds~\$RANLIB \$tool_oldlib"
+fi
+
+case $host_os in
+  darwin*)
+    lock_old_archive_extraction=yes ;;
+  *)
+    lock_old_archive_extraction=no ;;
+esac
+_LT_DECL([], [old_postinstall_cmds], [2])
+_LT_DECL([], [old_postuninstall_cmds], [2])
+_LT_TAGDECL([], [old_archive_cmds], [2],
+    [Commands used to build an old-style archive])
+_LT_DECL([], [lock_old_archive_extraction], [0],
+    [Whether to use a lock for old archive extraction])
+])# _LT_CMD_OLD_ARCHIVE
+
+
+# _LT_COMPILER_OPTION(MESSAGE, VARIABLE-NAME, FLAGS,
+#		[OUTPUT-FILE], [ACTION-SUCCESS], [ACTION-FAILURE])
+# ----------------------------------------------------------------
+# Check whether the given compiler option works
+AC_DEFUN([_LT_COMPILER_OPTION],
+[m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_DECL_SED])dnl
+AC_CACHE_CHECK([$1], [$2],
+  [$2=no
+   m4_if([$4], , [ac_outfile=conftest.$ac_objext], [ac_outfile=$4])
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+   lt_compiler_flag="$3"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   # The option is referenced via a variable to avoid confusing sed.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [[^ ]]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&AS_MESSAGE_LOG_FD)
+   (eval "$lt_compile" 2>conftest.err)
+   ac_status=$?
+   cat conftest.err >&AS_MESSAGE_LOG_FD
+   echo "$as_me:$LINENO: \$? = $ac_status" >&AS_MESSAGE_LOG_FD
+   if (exit $ac_status) && test -s "$ac_outfile"; then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings other than the usual output.
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' >conftest.exp
+     $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+     if test ! -s conftest.er2 || diff conftest.exp conftest.er2 >/dev/null; then
+       $2=yes
+     fi
+   fi
+   $RM conftest*
+])
+
+if test x"[$]$2" = xyes; then
+    m4_if([$5], , :, [$5])
+else
+    m4_if([$6], , :, [$6])
+fi
+])# _LT_COMPILER_OPTION
+
+# Old name:
+AU_ALIAS([AC_LIBTOOL_COMPILER_OPTION], [_LT_COMPILER_OPTION])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_COMPILER_OPTION], [])
+
+
+# _LT_LINKER_OPTION(MESSAGE, VARIABLE-NAME, FLAGS,
+#                  [ACTION-SUCCESS], [ACTION-FAILURE])
+# ----------------------------------------------------
+# Check whether the given linker option works
+AC_DEFUN([_LT_LINKER_OPTION],
+[m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_DECL_SED])dnl
+AC_CACHE_CHECK([$1], [$2],
+  [$2=no
+   save_LDFLAGS="$LDFLAGS"
+   LDFLAGS="$LDFLAGS $3"
+   echo "$lt_simple_link_test_code" > conftest.$ac_ext
+   if (eval $ac_link 2>conftest.err) && test -s conftest$ac_exeext; then
+     # The linker can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     if test -s conftest.err; then
+       # Append any errors to the config.log.
+       cat conftest.err 1>&AS_MESSAGE_LOG_FD
+       $ECHO "$_lt_linker_boilerplate" | $SED '/^$/d' > conftest.exp
+       $SED '/^$/d; /^ *+/d' conftest.err >conftest.er2
+       if diff conftest.exp conftest.er2 >/dev/null; then
+         $2=yes
+       fi
+     else
+       $2=yes
+     fi
+   fi
+   $RM -r conftest*
+   LDFLAGS="$save_LDFLAGS"
+])
+
+if test x"[$]$2" = xyes; then
+    m4_if([$4], , :, [$4])
+else
+    m4_if([$5], , :, [$5])
+fi
+])# _LT_LINKER_OPTION
+
+# Old name:
+AU_ALIAS([AC_LIBTOOL_LINKER_OPTION], [_LT_LINKER_OPTION])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_LINKER_OPTION], [])
+
+
+# LT_CMD_MAX_LEN
+#---------------
+AC_DEFUN([LT_CMD_MAX_LEN],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+# find the maximum length of command line arguments
+AC_MSG_CHECKING([the maximum length of command line arguments])
+AC_CACHE_VAL([lt_cv_sys_max_cmd_len], [dnl
+  i=0
+  teststring="ABCD"
+
+  case $build_os in
+  msdosdjgpp*)
+    # On DJGPP, this test can blow up pretty badly due to problems in libc
+    # (any single argument exceeding 2000 bytes causes a buffer overrun
+    # during glob expansion).  Even if it were fixed, the result of this
+    # check would be larger than it should be.
+    lt_cv_sys_max_cmd_len=12288;    # 12K is about right
+    ;;
+
+  gnu*)
+    # Under GNU Hurd, this test is not required because there is
+    # no limit to the length of command line arguments.
+    # Libtool will interpret -1 as no limit whatsoever
+    lt_cv_sys_max_cmd_len=-1;
+    ;;
+
+  cygwin* | mingw* | cegcc*)
+    # On Win9x/ME, this test blows up -- it succeeds, but takes
+    # about 5 minutes as the teststring grows exponentially.
+    # Worse, since 9x/ME are not pre-emptively multitasking,
+    # you end up with a "frozen" computer, even though with patience
+    # the test eventually succeeds (with a max line length of 256k).
+    # Instead, let's just punt: use the minimum linelength reported by
+    # all of the supported platforms: 8192 (on NT/2K/XP).
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  mint*)
+    # On MiNT this can take a long time and run out of memory.
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  amigaos*)
+    # On AmigaOS with pdksh, this test takes hours, literally.
+    # So we just punt and use a minimum line length of 8192.
+    lt_cv_sys_max_cmd_len=8192;
+    ;;
+
+  netbsd* | freebsd* | openbsd* | darwin* | dragonfly*)
+    # This has been around since 386BSD, at least.  Likely further.
+    if test -x /sbin/sysctl; then
+      lt_cv_sys_max_cmd_len=`/sbin/sysctl -n kern.argmax`
+    elif test -x /usr/sbin/sysctl; then
+      lt_cv_sys_max_cmd_len=`/usr/sbin/sysctl -n kern.argmax`
+    else
+      lt_cv_sys_max_cmd_len=65536	# usable default for all BSDs
+    fi
+    # And add a safety zone
+    lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 4`
+    lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \* 3`
+    ;;
+
+  interix*)
+    # We know the value 262144 and hardcode it with a safety zone (like BSD)
+    lt_cv_sys_max_cmd_len=196608
+    ;;
+
+  os2*)
+    # The test takes a long time on OS/2.
+    lt_cv_sys_max_cmd_len=8192
+    ;;
+
+  osf*)
+    # Dr. Hans Ekkehard Plesser reports seeing a kernel panic running configure
+    # due to this test when exec_disable_arg_limit is 1 on Tru64. It is not
+    # nice to cause kernel panics so lets avoid the loop below.
+    # First set a reasonable default.
+    lt_cv_sys_max_cmd_len=16384
+    #
+    if test -x /sbin/sysconfig; then
+      case `/sbin/sysconfig -q proc exec_disable_arg_limit` in
+        *1*) lt_cv_sys_max_cmd_len=-1 ;;
+      esac
+    fi
+    ;;
+  sco3.2v5*)
+    lt_cv_sys_max_cmd_len=102400
+    ;;
+  sysv5* | sco5v6* | sysv4.2uw2*)
+    kargmax=`grep ARG_MAX /etc/conf/cf.d/stune 2>/dev/null`
+    if test -n "$kargmax"; then
+      lt_cv_sys_max_cmd_len=`echo $kargmax | sed 's/.*[[	 ]]//'`
+    else
+      lt_cv_sys_max_cmd_len=32768
+    fi
+    ;;
+  *)
+    lt_cv_sys_max_cmd_len=`(getconf ARG_MAX) 2> /dev/null`
+    if test -n "$lt_cv_sys_max_cmd_len" && \
+	test undefined != "$lt_cv_sys_max_cmd_len"; then
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 4`
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \* 3`
+    else
+      # Make teststring a little bigger before we do anything with it.
+      # a 1K string should be a reasonable start.
+      for i in 1 2 3 4 5 6 7 8 ; do
+        teststring=$teststring$teststring
+      done
+      SHELL=${SHELL-${CONFIG_SHELL-/bin/sh}}
+      # If test is not a shell built-in, we'll probably end up computing a
+      # maximum length that is only half of the actual maximum length, but
+      # we can't tell.
+      while { test "X"`env echo "$teststring$teststring" 2>/dev/null` \
+	         = "X$teststring$teststring"; } >/dev/null 2>&1 &&
+	      test $i != 17 # 1/2 MB should be enough
+      do
+        i=`expr $i + 1`
+        teststring=$teststring$teststring
+      done
+      # Only check the string length outside the loop.
+      lt_cv_sys_max_cmd_len=`expr "X$teststring" : ".*" 2>&1`
+      teststring=
+      # Add a significant safety factor because C++ compilers can tack on
+      # massive amounts of additional arguments before passing them to the
+      # linker.  It appears as though 1/2 is a usable value.
+      lt_cv_sys_max_cmd_len=`expr $lt_cv_sys_max_cmd_len \/ 2`
+    fi
+    ;;
+  esac
+])
+if test -n $lt_cv_sys_max_cmd_len ; then
+  AC_MSG_RESULT($lt_cv_sys_max_cmd_len)
+else
+  AC_MSG_RESULT(none)
+fi
+max_cmd_len=$lt_cv_sys_max_cmd_len
+_LT_DECL([], [max_cmd_len], [0],
+    [What is the maximum length of a command?])
+])# LT_CMD_MAX_LEN
+
+# Old name:
+AU_ALIAS([AC_LIBTOOL_SYS_MAX_CMD_LEN], [LT_CMD_MAX_LEN])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_SYS_MAX_CMD_LEN], [])
+
+
+# _LT_HEADER_DLFCN
+# ----------------
+m4_defun([_LT_HEADER_DLFCN],
+[AC_CHECK_HEADERS([dlfcn.h], [], [], [AC_INCLUDES_DEFAULT])dnl
+])# _LT_HEADER_DLFCN
+
+
+# _LT_TRY_DLOPEN_SELF (ACTION-IF-TRUE, ACTION-IF-TRUE-W-USCORE,
+#                      ACTION-IF-FALSE, ACTION-IF-CROSS-COMPILING)
+# ----------------------------------------------------------------
+m4_defun([_LT_TRY_DLOPEN_SELF],
+[m4_require([_LT_HEADER_DLFCN])dnl
+if test "$cross_compiling" = yes; then :
+  [$4]
+else
+  lt_dlunknown=0; lt_dlno_uscore=1; lt_dlneed_uscore=2
+  lt_status=$lt_dlunknown
+  cat > conftest.$ac_ext <<_LT_EOF
+[#line $LINENO "configure"
+#include "confdefs.h"
+
+#if HAVE_DLFCN_H
+#include <dlfcn.h>
+#endif
+
+#include <stdio.h>
+
+#ifdef RTLD_GLOBAL
+#  define LT_DLGLOBAL		RTLD_GLOBAL
+#else
+#  ifdef DL_GLOBAL
+#    define LT_DLGLOBAL		DL_GLOBAL
+#  else
+#    define LT_DLGLOBAL		0
+#  endif
+#endif
+
+/* We may have to define LT_DLLAZY_OR_NOW in the command line if we
+   find out it does not work in some platform. */
+#ifndef LT_DLLAZY_OR_NOW
+#  ifdef RTLD_LAZY
+#    define LT_DLLAZY_OR_NOW		RTLD_LAZY
+#  else
+#    ifdef DL_LAZY
+#      define LT_DLLAZY_OR_NOW		DL_LAZY
+#    else
+#      ifdef RTLD_NOW
+#        define LT_DLLAZY_OR_NOW	RTLD_NOW
+#      else
+#        ifdef DL_NOW
+#          define LT_DLLAZY_OR_NOW	DL_NOW
+#        else
+#          define LT_DLLAZY_OR_NOW	0
+#        endif
+#      endif
+#    endif
+#  endif
+#endif
+
+/* When -fvisbility=hidden is used, assume the code has been annotated
+   correspondingly for the symbols needed.  */
+#if defined(__GNUC__) && (((__GNUC__ == 3) && (__GNUC_MINOR__ >= 3)) || (__GNUC__ > 3))
+int fnord () __attribute__((visibility("default")));
+#endif
+
+int fnord () { return 42; }
+int main ()
+{
+  void *self = dlopen (0, LT_DLGLOBAL|LT_DLLAZY_OR_NOW);
+  int status = $lt_dlunknown;
+
+  if (self)
+    {
+      if (dlsym (self,"fnord"))       status = $lt_dlno_uscore;
+      else
+        {
+	  if (dlsym( self,"_fnord"))  status = $lt_dlneed_uscore;
+          else puts (dlerror ());
+	}
+      /* dlclose (self); */
+    }
+  else
+    puts (dlerror ());
+
+  return status;
+}]
+_LT_EOF
+  if AC_TRY_EVAL(ac_link) && test -s conftest${ac_exeext} 2>/dev/null; then
+    (./conftest; exit; ) >&AS_MESSAGE_LOG_FD 2>/dev/null
+    lt_status=$?
+    case x$lt_status in
+      x$lt_dlno_uscore) $1 ;;
+      x$lt_dlneed_uscore) $2 ;;
+      x$lt_dlunknown|x*) $3 ;;
+    esac
+  else :
+    # compilation failed
+    $3
+  fi
+fi
+rm -fr conftest*
+])# _LT_TRY_DLOPEN_SELF
+
+
+# LT_SYS_DLOPEN_SELF
+# ------------------
+AC_DEFUN([LT_SYS_DLOPEN_SELF],
+[m4_require([_LT_HEADER_DLFCN])dnl
+if test "x$enable_dlopen" != xyes; then
+  enable_dlopen=unknown
+  enable_dlopen_self=unknown
+  enable_dlopen_self_static=unknown
+else
+  lt_cv_dlopen=no
+  lt_cv_dlopen_libs=
+
+  case $host_os in
+  beos*)
+    lt_cv_dlopen="load_add_on"
+    lt_cv_dlopen_libs=
+    lt_cv_dlopen_self=yes
+    ;;
+
+  mingw* | pw32* | cegcc*)
+    lt_cv_dlopen="LoadLibrary"
+    lt_cv_dlopen_libs=
+    ;;
+
+  cygwin*)
+    lt_cv_dlopen="dlopen"
+    lt_cv_dlopen_libs=
+    ;;
+
+  darwin*)
+  # if libdl is installed we need to link against it
+    AC_CHECK_LIB([dl], [dlopen],
+		[lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-ldl"],[
+    lt_cv_dlopen="dyld"
+    lt_cv_dlopen_libs=
+    lt_cv_dlopen_self=yes
+    ])
+    ;;
+
+  *)
+    AC_CHECK_FUNC([shl_load],
+	  [lt_cv_dlopen="shl_load"],
+      [AC_CHECK_LIB([dld], [shl_load],
+	    [lt_cv_dlopen="shl_load" lt_cv_dlopen_libs="-ldld"],
+	[AC_CHECK_FUNC([dlopen],
+	      [lt_cv_dlopen="dlopen"],
+	  [AC_CHECK_LIB([dl], [dlopen],
+		[lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-ldl"],
+	    [AC_CHECK_LIB([svld], [dlopen],
+		  [lt_cv_dlopen="dlopen" lt_cv_dlopen_libs="-lsvld"],
+	      [AC_CHECK_LIB([dld], [dld_link],
+		    [lt_cv_dlopen="dld_link" lt_cv_dlopen_libs="-ldld"])
+	      ])
+	    ])
+	  ])
+	])
+      ])
+    ;;
+  esac
+
+  if test "x$lt_cv_dlopen" != xno; then
+    enable_dlopen=yes
+  else
+    enable_dlopen=no
+  fi
+
+  case $lt_cv_dlopen in
+  dlopen)
+    save_CPPFLAGS="$CPPFLAGS"
+    test "x$ac_cv_header_dlfcn_h" = xyes && CPPFLAGS="$CPPFLAGS -DHAVE_DLFCN_H"
+
+    save_LDFLAGS="$LDFLAGS"
+    wl=$lt_prog_compiler_wl eval LDFLAGS=\"\$LDFLAGS $export_dynamic_flag_spec\"
+
+    save_LIBS="$LIBS"
+    LIBS="$lt_cv_dlopen_libs $LIBS"
+
+    AC_CACHE_CHECK([whether a program can dlopen itself],
+	  lt_cv_dlopen_self, [dnl
+	  _LT_TRY_DLOPEN_SELF(
+	    lt_cv_dlopen_self=yes, lt_cv_dlopen_self=yes,
+	    lt_cv_dlopen_self=no, lt_cv_dlopen_self=cross)
+    ])
+
+    if test "x$lt_cv_dlopen_self" = xyes; then
+      wl=$lt_prog_compiler_wl eval LDFLAGS=\"\$LDFLAGS $lt_prog_compiler_static\"
+      AC_CACHE_CHECK([whether a statically linked program can dlopen itself],
+	  lt_cv_dlopen_self_static, [dnl
+	  _LT_TRY_DLOPEN_SELF(
+	    lt_cv_dlopen_self_static=yes, lt_cv_dlopen_self_static=yes,
+	    lt_cv_dlopen_self_static=no,  lt_cv_dlopen_self_static=cross)
+      ])
+    fi
+
+    CPPFLAGS="$save_CPPFLAGS"
+    LDFLAGS="$save_LDFLAGS"
+    LIBS="$save_LIBS"
+    ;;
+  esac
+
+  case $lt_cv_dlopen_self in
+  yes|no) enable_dlopen_self=$lt_cv_dlopen_self ;;
+  *) enable_dlopen_self=unknown ;;
+  esac
+
+  case $lt_cv_dlopen_self_static in
+  yes|no) enable_dlopen_self_static=$lt_cv_dlopen_self_static ;;
+  *) enable_dlopen_self_static=unknown ;;
+  esac
+fi
+_LT_DECL([dlopen_support], [enable_dlopen], [0],
+	 [Whether dlopen is supported])
+_LT_DECL([dlopen_self], [enable_dlopen_self], [0],
+	 [Whether dlopen of programs is supported])
+_LT_DECL([dlopen_self_static], [enable_dlopen_self_static], [0],
+	 [Whether dlopen of statically linked programs is supported])
+])# LT_SYS_DLOPEN_SELF
+
+# Old name:
+AU_ALIAS([AC_LIBTOOL_DLOPEN_SELF], [LT_SYS_DLOPEN_SELF])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_DLOPEN_SELF], [])
+
+
+# _LT_COMPILER_C_O([TAGNAME])
+# ---------------------------
+# Check to see if options -c and -o are simultaneously supported by compiler.
+# This macro does not hard code the compiler like AC_PROG_CC_C_O.
+m4_defun([_LT_COMPILER_C_O],
+[m4_require([_LT_DECL_SED])dnl
+m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_TAG_COMPILER])dnl
+AC_CACHE_CHECK([if $compiler supports -c -o file.$ac_objext],
+  [_LT_TAGVAR(lt_cv_prog_compiler_c_o, $1)],
+  [_LT_TAGVAR(lt_cv_prog_compiler_c_o, $1)=no
+   $RM -r conftest 2>/dev/null
+   mkdir conftest
+   cd conftest
+   mkdir out
+   echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+
+   lt_compiler_flag="-o out/conftest2.$ac_objext"
+   # Insert the option either (1) after the last *FLAGS variable, or
+   # (2) before a word containing "conftest.", or (3) at the end.
+   # Note that $ac_compile itself does not contain backslashes and begins
+   # with a dollar sign (not a hyphen), so the echo should work correctly.
+   lt_compile=`echo "$ac_compile" | $SED \
+   -e 's:.*FLAGS}\{0,1\} :&$lt_compiler_flag :; t' \
+   -e 's: [[^ ]]*conftest\.: $lt_compiler_flag&:; t' \
+   -e 's:$: $lt_compiler_flag:'`
+   (eval echo "\"\$as_me:$LINENO: $lt_compile\"" >&AS_MESSAGE_LOG_FD)
+   (eval "$lt_compile" 2>out/conftest.err)
+   ac_status=$?
+   cat out/conftest.err >&AS_MESSAGE_LOG_FD
+   echo "$as_me:$LINENO: \$? = $ac_status" >&AS_MESSAGE_LOG_FD
+   if (exit $ac_status) && test -s out/conftest2.$ac_objext
+   then
+     # The compiler can only warn and ignore the option if not recognized
+     # So say no if there are warnings
+     $ECHO "$_lt_compiler_boilerplate" | $SED '/^$/d' > out/conftest.exp
+     $SED '/^$/d; /^ *+/d' out/conftest.err >out/conftest.er2
+     if test ! -s out/conftest.er2 || diff out/conftest.exp out/conftest.er2 >/dev/null; then
+       _LT_TAGVAR(lt_cv_prog_compiler_c_o, $1)=yes
+     fi
+   fi
+   chmod u+w . 2>&AS_MESSAGE_LOG_FD
+   $RM conftest*
+   # SGI C++ compiler will create directory out/ii_files/ for
+   # template instantiation
+   test -d out/ii_files && $RM out/ii_files/* && rmdir out/ii_files
+   $RM out/* && rmdir out
+   cd ..
+   $RM -r conftest
+   $RM conftest*
+])
+_LT_TAGDECL([compiler_c_o], [lt_cv_prog_compiler_c_o], [1],
+	[Does compiler simultaneously support -c and -o options?])
+])# _LT_COMPILER_C_O
+
+
+# _LT_COMPILER_FILE_LOCKS([TAGNAME])
+# ----------------------------------
+# Check to see if we can do hard links to lock some files if needed
+m4_defun([_LT_COMPILER_FILE_LOCKS],
+[m4_require([_LT_ENABLE_LOCK])dnl
+m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+_LT_COMPILER_C_O([$1])
+
+hard_links="nottested"
+if test "$_LT_TAGVAR(lt_cv_prog_compiler_c_o, $1)" = no && test "$need_locks" != no; then
+  # do not overwrite the value of need_locks provided by the user
+  AC_MSG_CHECKING([if we can lock with hard links])
+  hard_links=yes
+  $RM conftest*
+  ln conftest.a conftest.b 2>/dev/null && hard_links=no
+  touch conftest.a
+  ln conftest.a conftest.b 2>&5 || hard_links=no
+  ln conftest.a conftest.b 2>/dev/null && hard_links=no
+  AC_MSG_RESULT([$hard_links])
+  if test "$hard_links" = no; then
+    AC_MSG_WARN([`$CC' does not support `-c -o', so `make -j' may be unsafe])
+    need_locks=warn
+  fi
+else
+  need_locks=no
+fi
+_LT_DECL([], [need_locks], [1], [Must we lock files when doing compilation?])
+])# _LT_COMPILER_FILE_LOCKS
+
+
+# _LT_CHECK_OBJDIR
+# ----------------
+m4_defun([_LT_CHECK_OBJDIR],
+[AC_CACHE_CHECK([for objdir], [lt_cv_objdir],
+[rm -f .libs 2>/dev/null
+mkdir .libs 2>/dev/null
+if test -d .libs; then
+  lt_cv_objdir=.libs
+else
+  # MS-DOS does not allow filenames that begin with a dot.
+  lt_cv_objdir=_libs
+fi
+rmdir .libs 2>/dev/null])
+objdir=$lt_cv_objdir
+_LT_DECL([], [objdir], [0],
+         [The name of the directory that contains temporary libtool files])dnl
+m4_pattern_allow([LT_OBJDIR])dnl
+AC_DEFINE_UNQUOTED(LT_OBJDIR, "$lt_cv_objdir/",
+  [Define to the sub-directory in which libtool stores uninstalled libraries.])
+])# _LT_CHECK_OBJDIR
+
+
+# _LT_LINKER_HARDCODE_LIBPATH([TAGNAME])
+# --------------------------------------
+# Check hardcoding attributes.
+m4_defun([_LT_LINKER_HARDCODE_LIBPATH],
+[AC_MSG_CHECKING([how to hardcode library paths into programs])
+_LT_TAGVAR(hardcode_action, $1)=
+if test -n "$_LT_TAGVAR(hardcode_libdir_flag_spec, $1)" ||
+   test -n "$_LT_TAGVAR(runpath_var, $1)" ||
+   test "X$_LT_TAGVAR(hardcode_automatic, $1)" = "Xyes" ; then
+
+  # We can hardcode non-existent directories.
+  if test "$_LT_TAGVAR(hardcode_direct, $1)" != no &&
+     # If the only mechanism to avoid hardcoding is shlibpath_var, we
+     # have to relink, otherwise we might link with an installed library
+     # when we should be linking with a yet-to-be-installed one
+     ## test "$_LT_TAGVAR(hardcode_shlibpath_var, $1)" != no &&
+     test "$_LT_TAGVAR(hardcode_minus_L, $1)" != no; then
+    # Linking always hardcodes the temporary library directory.
+    _LT_TAGVAR(hardcode_action, $1)=relink
+  else
+    # We can link without hardcoding, and we can hardcode nonexisting dirs.
+    _LT_TAGVAR(hardcode_action, $1)=immediate
+  fi
+else
+  # We cannot hardcode anything, or else we can only hardcode existing
+  # directories.
+  _LT_TAGVAR(hardcode_action, $1)=unsupported
+fi
+AC_MSG_RESULT([$_LT_TAGVAR(hardcode_action, $1)])
+
+if test "$_LT_TAGVAR(hardcode_action, $1)" = relink ||
+   test "$_LT_TAGVAR(inherit_rpath, $1)" = yes; then
+  # Fast installation is not supported
+  enable_fast_install=no
+elif test "$shlibpath_overrides_runpath" = yes ||
+     test "$enable_shared" = no; then
+  # Fast installation is not necessary
+  enable_fast_install=needless
+fi
+_LT_TAGDECL([], [hardcode_action], [0],
+    [How to hardcode a shared library path into an executable])
+])# _LT_LINKER_HARDCODE_LIBPATH
+
+
+# _LT_CMD_STRIPLIB
+# ----------------
+m4_defun([_LT_CMD_STRIPLIB],
+[m4_require([_LT_DECL_EGREP])
+striplib=
+old_striplib=
+AC_MSG_CHECKING([whether stripping libraries is possible])
+if test -n "$STRIP" && $STRIP -V 2>&1 | $GREP "GNU strip" >/dev/null; then
+  test -z "$old_striplib" && old_striplib="$STRIP --strip-debug"
+  test -z "$striplib" && striplib="$STRIP --strip-unneeded"
+  AC_MSG_RESULT([yes])
+else
+# FIXME - insert some real tests, host_os isn't really good enough
+  case $host_os in
+  darwin*)
+    if test -n "$STRIP" ; then
+      striplib="$STRIP -x"
+      old_striplib="$STRIP -S"
+      AC_MSG_RESULT([yes])
+    else
+      AC_MSG_RESULT([no])
+    fi
+    ;;
+  *)
+    AC_MSG_RESULT([no])
+    ;;
+  esac
+fi
+_LT_DECL([], [old_striplib], [1], [Commands to strip libraries])
+_LT_DECL([], [striplib], [1])
+])# _LT_CMD_STRIPLIB
+
+
+# _LT_SYS_DYNAMIC_LINKER([TAG])
+# -----------------------------
+# PORTME Fill in your ld.so characteristics
+m4_defun([_LT_SYS_DYNAMIC_LINKER],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+m4_require([_LT_DECL_EGREP])dnl
+m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_DECL_OBJDUMP])dnl
+m4_require([_LT_DECL_SED])dnl
+m4_require([_LT_CHECK_SHELL_FEATURES])dnl
+AC_MSG_CHECKING([dynamic linker characteristics])
+m4_if([$1],
+	[], [
+if test "$GCC" = yes; then
+  case $host_os in
+    darwin*) lt_awk_arg="/^libraries:/,/LR/" ;;
+    *) lt_awk_arg="/^libraries:/" ;;
+  esac
+  case $host_os in
+    mingw* | cegcc*) lt_sed_strip_eq="s,=\([[A-Za-z]]:\),\1,g" ;;
+    *) lt_sed_strip_eq="s,=/,/,g" ;;
+  esac
+  lt_search_path_spec=`$CC -print-search-dirs | awk $lt_awk_arg | $SED -e "s/^libraries://" -e $lt_sed_strip_eq`
+  case $lt_search_path_spec in
+  *\;*)
+    # if the path contains ";" then we assume it to be the separator
+    # otherwise default to the standard path separator (i.e. ":") - it is
+    # assumed that no part of a normal pathname contains ";" but that should
+    # okay in the real world where ";" in dirpaths is itself problematic.
+    lt_search_path_spec=`$ECHO "$lt_search_path_spec" | $SED 's/;/ /g'`
+    ;;
+  *)
+    lt_search_path_spec=`$ECHO "$lt_search_path_spec" | $SED "s/$PATH_SEPARATOR/ /g"`
+    ;;
+  esac
+  # Ok, now we have the path, separated by spaces, we can step through it
+  # and add multilib dir if necessary.
+  lt_tmp_lt_search_path_spec=
+  lt_multi_os_dir=`$CC $CPPFLAGS $CFLAGS $LDFLAGS -print-multi-os-directory 2>/dev/null`
+  for lt_sys_path in $lt_search_path_spec; do
+    if test -d "$lt_sys_path/$lt_multi_os_dir"; then
+      lt_tmp_lt_search_path_spec="$lt_tmp_lt_search_path_spec $lt_sys_path/$lt_multi_os_dir"
+    else
+      test -d "$lt_sys_path" && \
+	lt_tmp_lt_search_path_spec="$lt_tmp_lt_search_path_spec $lt_sys_path"
+    fi
+  done
+  lt_search_path_spec=`$ECHO "$lt_tmp_lt_search_path_spec" | awk '
+BEGIN {RS=" "; FS="/|\n";} {
+  lt_foo="";
+  lt_count=0;
+  for (lt_i = NF; lt_i > 0; lt_i--) {
+    if ($lt_i != "" && $lt_i != ".") {
+      if ($lt_i == "..") {
+        lt_count++;
+      } else {
+        if (lt_count == 0) {
+          lt_foo="/" $lt_i lt_foo;
+        } else {
+          lt_count--;
+        }
+      }
+    }
+  }
+  if (lt_foo != "") { lt_freq[[lt_foo]]++; }
+  if (lt_freq[[lt_foo]] == 1) { print lt_foo; }
+}'`
+  # AWK program above erroneously prepends '/' to C:/dos/paths
+  # for these hosts.
+  case $host_os in
+    mingw* | cegcc*) lt_search_path_spec=`$ECHO "$lt_search_path_spec" |\
+      $SED 's,/\([[A-Za-z]]:\),\1,g'` ;;
+  esac
+  sys_lib_search_path_spec=`$ECHO "$lt_search_path_spec" | $lt_NL2SP`
+else
+  sys_lib_search_path_spec="/lib /usr/lib /usr/local/lib"
+fi])
+library_names_spec=
+libname_spec='lib$name'
+soname_spec=
+shrext_cmds=".so"
+postinstall_cmds=
+postuninstall_cmds=
+finish_cmds=
+finish_eval=
+shlibpath_var=
+shlibpath_overrides_runpath=unknown
+version_type=none
+dynamic_linker="$host_os ld.so"
+sys_lib_dlsearch_path_spec="/lib /usr/lib"
+need_lib_prefix=unknown
+hardcode_into_libs=no
+
+# when you set need_version to no, make sure it does not cause -set_version
+# flags to be left without arguments
+need_version=unknown
+
+case $host_os in
+aix3*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix $libname.a'
+  shlibpath_var=LIBPATH
+
+  # AIX 3 has no versioning support, so we append a major version to the name.
+  soname_spec='${libname}${release}${shared_ext}$major'
+  ;;
+
+aix[[4-9]]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  hardcode_into_libs=yes
+  if test "$host_cpu" = ia64; then
+    # AIX 5 supports IA64
+    library_names_spec='${libname}${release}${shared_ext}$major ${libname}${release}${shared_ext}$versuffix $libname${shared_ext}'
+    shlibpath_var=LD_LIBRARY_PATH
+  else
+    # With GCC up to 2.95.x, collect2 would create an import file
+    # for dependence libraries.  The import file would start with
+    # the line `#! .'.  This would cause the generated library to
+    # depend on `.', always an invalid library.  This was fixed in
+    # development snapshots of GCC prior to 3.0.
+    case $host_os in
+      aix4 | aix4.[[01]] | aix4.[[01]].*)
+      if { echo '#if __GNUC__ > 2 || (__GNUC__ == 2 && __GNUC_MINOR__ >= 97)'
+	   echo ' yes '
+	   echo '#endif'; } | ${CC} -E - | $GREP yes > /dev/null; then
+	:
+      else
+	can_build_shared=no
+      fi
+      ;;
+    esac
+    # AIX (on Power*) has no versioning support, so currently we can not hardcode correct
+    # soname into executable. Probably we can add versioning support to
+    # collect2, so additional links can be useful in future.
+    if test "$aix_use_runtimelinking" = yes; then
+      # If using run time linking (on AIX 4.2 or later) use lib<name>.so
+      # instead of lib<name>.a to let people know that these are not
+      # typical AIX shared libraries.
+      library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    else
+      # We preserve .a as extension for shared libraries through AIX4.2
+      # and later when we are not doing run time linking.
+      library_names_spec='${libname}${release}.a $libname.a'
+      soname_spec='${libname}${release}${shared_ext}$major'
+    fi
+    shlibpath_var=LIBPATH
+  fi
+  ;;
+
+amigaos*)
+  case $host_cpu in
+  powerpc)
+    # Since July 2007 AmigaOS4 officially supports .so libraries.
+    # When compiling the executable, add -use-dynld -Lsobjs: to the compileline.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    ;;
+  m68k)
+    library_names_spec='$libname.ixlibrary $libname.a'
+    # Create ${libname}_ixlibrary.a entries in /sys/libs.
+    finish_eval='for lib in `ls $libdir/*.ixlibrary 2>/dev/null`; do libname=`func_echo_all "$lib" | $SED '\''s%^.*/\([[^/]]*\)\.ixlibrary$%\1%'\''`; test $RM /sys/libs/${libname}_ixlibrary.a; $show "cd /sys/libs && $LN_S $lib ${libname}_ixlibrary.a"; cd /sys/libs && $LN_S $lib ${libname}_ixlibrary.a || exit 1; done'
+    ;;
+  esac
+  ;;
+
+beos*)
+  library_names_spec='${libname}${shared_ext}'
+  dynamic_linker="$host_os ld.so"
+  shlibpath_var=LIBRARY_PATH
+  ;;
+
+bsdi[[45]]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  sys_lib_search_path_spec="/shlib /usr/lib /usr/X11/lib /usr/contrib/lib /lib /usr/local/lib"
+  sys_lib_dlsearch_path_spec="/shlib /usr/lib /usr/local/lib"
+  # the default ld.so.conf also contains /usr/contrib/lib and
+  # /usr/X11R6/lib (/usr/X11 is a link to /usr/X11R6), but let us allow
+  # libtool to hard-code these into programs
+  ;;
+
+cygwin* | mingw* | pw32* | cegcc*)
+  version_type=windows
+  shrext_cmds=".dll"
+  need_version=no
+  need_lib_prefix=no
+
+  case $GCC,$cc_basename in
+  yes,*)
+    # gcc
+    library_names_spec='$libname.dll.a'
+    # DLL is installed to $(libdir)/../bin by postinstall_cmds
+    postinstall_cmds='base_file=`basename \${file}`~
+      dlpath=`$SHELL 2>&1 -c '\''. $dir/'\''\${base_file}'\''i; echo \$dlname'\''`~
+      dldir=$destdir/`dirname \$dlpath`~
+      test -d \$dldir || mkdir -p \$dldir~
+      $install_prog $dir/$dlname \$dldir/$dlname~
+      chmod a+x \$dldir/$dlname~
+      if test -n '\''$stripme'\'' && test -n '\''$striplib'\''; then
+        eval '\''$striplib \$dldir/$dlname'\'' || exit \$?;
+      fi'
+    postuninstall_cmds='dldll=`$SHELL 2>&1 -c '\''. $file; echo \$dlname'\''`~
+      dlpath=$dir/\$dldll~
+       $RM \$dlpath'
+    shlibpath_overrides_runpath=yes
+
+    case $host_os in
+    cygwin*)
+      # Cygwin DLLs use 'cyg' prefix rather than 'lib'
+      soname_spec='`echo ${libname} | sed -e 's/^lib/cyg/'``echo ${release} | $SED -e 's/[[.]]/-/g'`${versuffix}${shared_ext}'
+m4_if([$1], [],[
+      sys_lib_search_path_spec="$sys_lib_search_path_spec /usr/lib/w32api"])
+      ;;
+    mingw* | cegcc*)
+      # MinGW DLLs use traditional 'lib' prefix
+      soname_spec='${libname}`echo ${release} | $SED -e 's/[[.]]/-/g'`${versuffix}${shared_ext}'
+      ;;
+    pw32*)
+      # pw32 DLLs use 'pw' prefix rather than 'lib'
+      library_names_spec='`echo ${libname} | sed -e 's/^lib/pw/'``echo ${release} | $SED -e 's/[[.]]/-/g'`${versuffix}${shared_ext}'
+      ;;
+    esac
+    dynamic_linker='Win32 ld.exe'
+    ;;
+
+  *,cl*)
+    # Native MSVC
+    libname_spec='$name'
+    soname_spec='${libname}`echo ${release} | $SED -e 's/[[.]]/-/g'`${versuffix}${shared_ext}'
+    library_names_spec='${libname}.dll.lib'
+
+    case $build_os in
+    mingw*)
+      sys_lib_search_path_spec=
+      lt_save_ifs=$IFS
+      IFS=';'
+      for lt_path in $LIB
+      do
+        IFS=$lt_save_ifs
+        # Let DOS variable expansion print the short 8.3 style file name.
+        lt_path=`cd "$lt_path" 2>/dev/null && cmd //C "for %i in (".") do @echo %~si"`
+        sys_lib_search_path_spec="$sys_lib_search_path_spec $lt_path"
+      done
+      IFS=$lt_save_ifs
+      # Convert to MSYS style.
+      sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | sed -e 's|\\\\|/|g' -e 's| \\([[a-zA-Z]]\\):| /\\1|g' -e 's|^ ||'`
+      ;;
+    cygwin*)
+      # Convert to unix form, then to dos form, then back to unix form
+      # but this time dos style (no spaces!) so that the unix form looks
+      # like /cygdrive/c/PROGRA~1:/cygdr...
+      sys_lib_search_path_spec=`cygpath --path --unix "$LIB"`
+      sys_lib_search_path_spec=`cygpath --path --dos "$sys_lib_search_path_spec" 2>/dev/null`
+      sys_lib_search_path_spec=`cygpath --path --unix "$sys_lib_search_path_spec" | $SED -e "s/$PATH_SEPARATOR/ /g"`
+      ;;
+    *)
+      sys_lib_search_path_spec="$LIB"
+      if $ECHO "$sys_lib_search_path_spec" | [$GREP ';[c-zC-Z]:/' >/dev/null]; then
+        # It is most probably a Windows format PATH.
+        sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | $SED -e 's/;/ /g'`
+      else
+        sys_lib_search_path_spec=`$ECHO "$sys_lib_search_path_spec" | $SED -e "s/$PATH_SEPARATOR/ /g"`
+      fi
+      # FIXME: find the short name or the path components, as spaces are
+      # common. (e.g. "Program Files" -> "PROGRA~1")
+      ;;
+    esac
+
+    # DLL is installed to $(libdir)/../bin by postinstall_cmds
+    postinstall_cmds='base_file=`basename \${file}`~
+      dlpath=`$SHELL 2>&1 -c '\''. $dir/'\''\${base_file}'\''i; echo \$dlname'\''`~
+      dldir=$destdir/`dirname \$dlpath`~
+      test -d \$dldir || mkdir -p \$dldir~
+      $install_prog $dir/$dlname \$dldir/$dlname'
+    postuninstall_cmds='dldll=`$SHELL 2>&1 -c '\''. $file; echo \$dlname'\''`~
+      dlpath=$dir/\$dldll~
+       $RM \$dlpath'
+    shlibpath_overrides_runpath=yes
+    dynamic_linker='Win32 link.exe'
+    ;;
+
+  *)
+    # Assume MSVC wrapper
+    library_names_spec='${libname}`echo ${release} | $SED -e 's/[[.]]/-/g'`${versuffix}${shared_ext} $libname.lib'
+    dynamic_linker='Win32 ld.exe'
+    ;;
+  esac
+  # FIXME: first we should search . and the directory the executable is in
+  shlibpath_var=PATH
+  ;;
+
+darwin* | rhapsody*)
+  dynamic_linker="$host_os dyld"
+  version_type=darwin
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${major}$shared_ext ${libname}$shared_ext'
+  soname_spec='${libname}${release}${major}$shared_ext'
+  shlibpath_overrides_runpath=yes
+  shlibpath_var=DYLD_LIBRARY_PATH
+  shrext_cmds='`test .$module = .yes && echo .so || echo .dylib`'
+m4_if([$1], [],[
+  sys_lib_search_path_spec="$sys_lib_search_path_spec /usr/local/lib"])
+  sys_lib_dlsearch_path_spec='/usr/local/lib /lib /usr/lib'
+  ;;
+
+dgux*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname$shared_ext'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  ;;
+
+freebsd* | dragonfly*)
+  # DragonFly does not have aout.  When/if they implement a new
+  # versioning mechanism, adjust this.
+  if test -x /usr/bin/objformat; then
+    objformat=`/usr/bin/objformat`
+  else
+    case $host_os in
+    freebsd[[23]].*) objformat=aout ;;
+    *) objformat=elf ;;
+    esac
+  fi
+  version_type=freebsd-$objformat
+  case $version_type in
+    freebsd-elf*)
+      library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext} $libname${shared_ext}'
+      need_version=no
+      need_lib_prefix=no
+      ;;
+    freebsd-*)
+      library_names_spec='${libname}${release}${shared_ext}$versuffix $libname${shared_ext}$versuffix'
+      need_version=yes
+      ;;
+  esac
+  shlibpath_var=LD_LIBRARY_PATH
+  case $host_os in
+  freebsd2.*)
+    shlibpath_overrides_runpath=yes
+    ;;
+  freebsd3.[[01]]* | freebsdelf3.[[01]]*)
+    shlibpath_overrides_runpath=yes
+    hardcode_into_libs=yes
+    ;;
+  freebsd3.[[2-9]]* | freebsdelf3.[[2-9]]* | \
+  freebsd4.[[0-5]] | freebsdelf4.[[0-5]] | freebsd4.1.1 | freebsdelf4.1.1)
+    shlibpath_overrides_runpath=no
+    hardcode_into_libs=yes
+    ;;
+  *) # from 4.6 on, and DragonFly
+    shlibpath_overrides_runpath=yes
+    hardcode_into_libs=yes
+    ;;
+  esac
+  ;;
+
+haiku*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  dynamic_linker="$host_os runtime_loader"
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}${major} ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  sys_lib_dlsearch_path_spec='/boot/home/config/lib /boot/common/lib /boot/system/lib'
+  hardcode_into_libs=yes
+  ;;
+
+hpux9* | hpux10* | hpux11*)
+  # Give a soname corresponding to the major version so that dld.sl refuses to
+  # link against other versions.
+  version_type=sunos
+  need_lib_prefix=no
+  need_version=no
+  case $host_cpu in
+  ia64*)
+    shrext_cmds='.so'
+    hardcode_into_libs=yes
+    dynamic_linker="$host_os dld.so"
+    shlibpath_var=LD_LIBRARY_PATH
+    shlibpath_overrides_runpath=yes # Unless +noenvvar is specified.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    if test "X$HPUX_IA64_MODE" = X32; then
+      sys_lib_search_path_spec="/usr/lib/hpux32 /usr/local/lib/hpux32 /usr/local/lib"
+    else
+      sys_lib_search_path_spec="/usr/lib/hpux64 /usr/local/lib/hpux64"
+    fi
+    sys_lib_dlsearch_path_spec=$sys_lib_search_path_spec
+    ;;
+  hppa*64*)
+    shrext_cmds='.sl'
+    hardcode_into_libs=yes
+    dynamic_linker="$host_os dld.sl"
+    shlibpath_var=LD_LIBRARY_PATH # How should we handle SHLIB_PATH
+    shlibpath_overrides_runpath=yes # Unless +noenvvar is specified.
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    sys_lib_search_path_spec="/usr/lib/pa20_64 /usr/ccs/lib/pa20_64"
+    sys_lib_dlsearch_path_spec=$sys_lib_search_path_spec
+    ;;
+  *)
+    shrext_cmds='.sl'
+    dynamic_linker="$host_os dld.sl"
+    shlibpath_var=SHLIB_PATH
+    shlibpath_overrides_runpath=no # +s is required to enable SHLIB_PATH
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    ;;
+  esac
+  # HP-UX runs *really* slowly unless shared libraries are mode 555, ...
+  postinstall_cmds='chmod 555 $lib'
+  # or fails outright, so override atomically:
+  install_override_mode=555
+  ;;
+
+interix[[3-9]]*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  dynamic_linker='Interix 3.x ld.so.1 (PE, like ELF)'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  ;;
+
+irix5* | irix6* | nonstopux*)
+  case $host_os in
+    nonstopux*) version_type=nonstopux ;;
+    *)
+	if test "$lt_cv_prog_gnu_ld" = yes; then
+		version_type=linux # correct to gnu/linux during the next big refactor
+	else
+		version_type=irix
+	fi ;;
+  esac
+  need_lib_prefix=no
+  need_version=no
+  soname_spec='${libname}${release}${shared_ext}$major'
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${release}${shared_ext} $libname${shared_ext}'
+  case $host_os in
+  irix5* | nonstopux*)
+    libsuff= shlibsuff=
+    ;;
+  *)
+    case $LD in # libtool.m4 will add one of these switches to LD
+    *-32|*"-32 "|*-melf32bsmip|*"-melf32bsmip ")
+      libsuff= shlibsuff= libmagic=32-bit;;
+    *-n32|*"-n32 "|*-melf32bmipn32|*"-melf32bmipn32 ")
+      libsuff=32 shlibsuff=N32 libmagic=N32;;
+    *-64|*"-64 "|*-melf64bmip|*"-melf64bmip ")
+      libsuff=64 shlibsuff=64 libmagic=64-bit;;
+    *) libsuff= shlibsuff= libmagic=never-match;;
+    esac
+    ;;
+  esac
+  shlibpath_var=LD_LIBRARY${shlibsuff}_PATH
+  shlibpath_overrides_runpath=no
+  sys_lib_search_path_spec="/usr/lib${libsuff} /lib${libsuff} /usr/local/lib${libsuff}"
+  sys_lib_dlsearch_path_spec="/usr/lib${libsuff} /lib${libsuff}"
+  hardcode_into_libs=yes
+  ;;
+
+# No shared lib support for Linux oldld, aout, or coff.
+linux*oldld* | linux*aout* | linux*coff*)
+  dynamic_linker=no
+  ;;
+
+# This must be glibc/ELF.
+linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig -n $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+
+  # Some binutils ld are patched to set DT_RUNPATH
+  AC_CACHE_VAL([lt_cv_shlibpath_overrides_runpath],
+    [lt_cv_shlibpath_overrides_runpath=no
+    save_LDFLAGS=$LDFLAGS
+    save_libdir=$libdir
+    eval "libdir=/foo; wl=\"$_LT_TAGVAR(lt_prog_compiler_wl, $1)\"; \
+	 LDFLAGS=\"\$LDFLAGS $_LT_TAGVAR(hardcode_libdir_flag_spec, $1)\""
+    AC_LINK_IFELSE([AC_LANG_PROGRAM([],[])],
+      [AS_IF([ ($OBJDUMP -p conftest$ac_exeext) 2>/dev/null | grep "RUNPATH.*$libdir" >/dev/null],
+	 [lt_cv_shlibpath_overrides_runpath=yes])])
+    LDFLAGS=$save_LDFLAGS
+    libdir=$save_libdir
+    ])
+  shlibpath_overrides_runpath=$lt_cv_shlibpath_overrides_runpath
+
+  # This implies no fast_install, which is unacceptable.
+  # Some rework will be needed to allow for fast_install
+  # before this can be enabled.
+  hardcode_into_libs=yes
+
+  # Append ld.so.conf contents to the search path
+  if test -f /etc/ld.so.conf; then
+    lt_ld_extra=`awk '/^include / { system(sprintf("cd /etc; cat %s 2>/dev/null", \[$]2)); skip = 1; } { if (!skip) print \[$]0; skip = 0; }' < /etc/ld.so.conf | $SED -e 's/#.*//;/^[	 ]*hwcap[	 ]/d;s/[:,	]/ /g;s/=[^=]*$//;s/=[^= ]* / /g;s/"//g;/^$/d' | tr '\n' ' '`
+    sys_lib_dlsearch_path_spec="/lib /usr/lib $lt_ld_extra"
+  fi
+
+  # We used to test for /lib/ld.so.1 and disable shared libraries on
+  # powerpc, because MkLinux only supported shared libraries with the
+  # GNU dynamic linker.  Since this was broken with cross compilers,
+  # most powerpc-linux boxes support dynamic linking these days and
+  # people can always --disable-shared, the test was removed, and we
+  # assume the GNU/Linux dynamic linker is in use.
+  dynamic_linker='GNU/Linux ld.so'
+  ;;
+
+netbsdelf*-gnu)
+  version_type=linux
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  dynamic_linker='NetBSD ld.elf_so'
+  ;;
+
+netbsd*)
+  version_type=sunos
+  need_lib_prefix=no
+  need_version=no
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+    finish_cmds='PATH="\$PATH:/sbin" ldconfig -m $libdir'
+    dynamic_linker='NetBSD (a.out) ld.so'
+  else
+    library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major ${libname}${shared_ext}'
+    soname_spec='${libname}${release}${shared_ext}$major'
+    dynamic_linker='NetBSD ld.elf_so'
+  fi
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  ;;
+
+newsos6)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  ;;
+
+*nto* | *qnx*)
+  version_type=qnx
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  dynamic_linker='ldqnx.so'
+  ;;
+
+openbsd*)
+  version_type=sunos
+  sys_lib_dlsearch_path_spec="/usr/lib"
+  need_lib_prefix=no
+  # Some older versions of OpenBSD (3.3 at least) *do* need versioned libs.
+  case $host_os in
+    openbsd3.3 | openbsd3.3.*)	need_version=yes ;;
+    *)				need_version=no  ;;
+  esac
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+  finish_cmds='PATH="\$PATH:/sbin" ldconfig -m $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+    case $host_os in
+      openbsd2.[[89]] | openbsd2.[[89]].*)
+	shlibpath_overrides_runpath=no
+	;;
+      *)
+	shlibpath_overrides_runpath=yes
+	;;
+      esac
+  else
+    shlibpath_overrides_runpath=yes
+  fi
+  ;;
+
+os2*)
+  libname_spec='$name'
+  shrext_cmds=".dll"
+  need_lib_prefix=no
+  library_names_spec='$libname${shared_ext} $libname.a'
+  dynamic_linker='OS/2 ld.exe'
+  shlibpath_var=LIBPATH
+  ;;
+
+osf3* | osf4* | osf5*)
+  version_type=osf
+  need_lib_prefix=no
+  need_version=no
+  soname_spec='${libname}${release}${shared_ext}$major'
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  sys_lib_search_path_spec="/usr/shlib /usr/ccs/lib /usr/lib/cmplrs/cc /usr/lib /usr/local/lib /var/shlib"
+  sys_lib_dlsearch_path_spec="$sys_lib_search_path_spec"
+  ;;
+
+rdos*)
+  dynamic_linker=no
+  ;;
+
+solaris*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  # ldd complains unless libraries are executable
+  postinstall_cmds='chmod +x $lib'
+  ;;
+
+sunos4*)
+  version_type=sunos
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${shared_ext}$versuffix'
+  finish_cmds='PATH="\$PATH:/usr/etc" ldconfig $libdir'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  if test "$with_gnu_ld" = yes; then
+    need_lib_prefix=no
+  fi
+  need_version=yes
+  ;;
+
+sysv4 | sysv4.3*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  case $host_vendor in
+    sni)
+      shlibpath_overrides_runpath=no
+      need_lib_prefix=no
+      runpath_var=LD_RUN_PATH
+      ;;
+    siemens)
+      need_lib_prefix=no
+      ;;
+    motorola)
+      need_lib_prefix=no
+      need_version=no
+      shlibpath_overrides_runpath=no
+      sys_lib_search_path_spec='/lib /usr/lib /usr/ccs/lib'
+      ;;
+  esac
+  ;;
+
+sysv4*MP*)
+  if test -d /usr/nec ;then
+    version_type=linux # correct to gnu/linux during the next big refactor
+    library_names_spec='$libname${shared_ext}.$versuffix $libname${shared_ext}.$major $libname${shared_ext}'
+    soname_spec='$libname${shared_ext}.$major'
+    shlibpath_var=LD_LIBRARY_PATH
+  fi
+  ;;
+
+sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX* | sysv4*uw2*)
+  version_type=freebsd-elf
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext} $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=yes
+  hardcode_into_libs=yes
+  if test "$with_gnu_ld" = yes; then
+    sys_lib_search_path_spec='/usr/local/lib /usr/gnu/lib /usr/ccs/lib /usr/lib /lib'
+  else
+    sys_lib_search_path_spec='/usr/ccs/lib /usr/lib'
+    case $host_os in
+      sco3.2v5*)
+        sys_lib_search_path_spec="$sys_lib_search_path_spec /lib"
+	;;
+    esac
+  fi
+  sys_lib_dlsearch_path_spec='/usr/lib'
+  ;;
+
+tpf*)
+  # TPF is a cross-target only.  Preferred cross-host = GNU/Linux.
+  version_type=linux # correct to gnu/linux during the next big refactor
+  need_lib_prefix=no
+  need_version=no
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  shlibpath_var=LD_LIBRARY_PATH
+  shlibpath_overrides_runpath=no
+  hardcode_into_libs=yes
+  ;;
+
+uts4*)
+  version_type=linux # correct to gnu/linux during the next big refactor
+  library_names_spec='${libname}${release}${shared_ext}$versuffix ${libname}${release}${shared_ext}$major $libname${shared_ext}'
+  soname_spec='${libname}${release}${shared_ext}$major'
+  shlibpath_var=LD_LIBRARY_PATH
+  ;;
+
+*)
+  dynamic_linker=no
+  ;;
+esac
+AC_MSG_RESULT([$dynamic_linker])
+test "$dynamic_linker" = no && can_build_shared=no
+
+variables_saved_for_relink="PATH $shlibpath_var $runpath_var"
+if test "$GCC" = yes; then
+  variables_saved_for_relink="$variables_saved_for_relink GCC_EXEC_PREFIX COMPILER_PATH LIBRARY_PATH"
+fi
+
+if test "${lt_cv_sys_lib_search_path_spec+set}" = set; then
+  sys_lib_search_path_spec="$lt_cv_sys_lib_search_path_spec"
+fi
+if test "${lt_cv_sys_lib_dlsearch_path_spec+set}" = set; then
+  sys_lib_dlsearch_path_spec="$lt_cv_sys_lib_dlsearch_path_spec"
+fi
+
+_LT_DECL([], [variables_saved_for_relink], [1],
+    [Variables whose values should be saved in libtool wrapper scripts and
+    restored at link time])
+_LT_DECL([], [need_lib_prefix], [0],
+    [Do we need the "lib" prefix for modules?])
+_LT_DECL([], [need_version], [0], [Do we need a version for libraries?])
+_LT_DECL([], [version_type], [0], [Library versioning type])
+_LT_DECL([], [runpath_var], [0],  [Shared library runtime path variable])
+_LT_DECL([], [shlibpath_var], [0],[Shared library path variable])
+_LT_DECL([], [shlibpath_overrides_runpath], [0],
+    [Is shlibpath searched before the hard-coded library search path?])
+_LT_DECL([], [libname_spec], [1], [Format of library name prefix])
+_LT_DECL([], [library_names_spec], [1],
+    [[List of archive names.  First name is the real one, the rest are links.
+    The last name is the one that the linker finds with -lNAME]])
+_LT_DECL([], [soname_spec], [1],
+    [[The coded name of the library, if different from the real name]])
+_LT_DECL([], [install_override_mode], [1],
+    [Permission mode override for installation of shared libraries])
+_LT_DECL([], [postinstall_cmds], [2],
+    [Command to use after installation of a shared archive])
+_LT_DECL([], [postuninstall_cmds], [2],
+    [Command to use after uninstallation of a shared archive])
+_LT_DECL([], [finish_cmds], [2],
+    [Commands used to finish a libtool library installation in a directory])
+_LT_DECL([], [finish_eval], [1],
+    [[As "finish_cmds", except a single script fragment to be evaled but
+    not shown]])
+_LT_DECL([], [hardcode_into_libs], [0],
+    [Whether we should hardcode library paths into libraries])
+_LT_DECL([], [sys_lib_search_path_spec], [2],
+    [Compile-time system search path for libraries])
+_LT_DECL([], [sys_lib_dlsearch_path_spec], [2],
+    [Run-time system search path for libraries])
+])# _LT_SYS_DYNAMIC_LINKER
+
+
+# _LT_PATH_TOOL_PREFIX(TOOL)
+# --------------------------
+# find a file program which can recognize shared library
+AC_DEFUN([_LT_PATH_TOOL_PREFIX],
+[m4_require([_LT_DECL_EGREP])dnl
+AC_MSG_CHECKING([for $1])
+AC_CACHE_VAL(lt_cv_path_MAGIC_CMD,
+[case $MAGIC_CMD in
+[[\\/*] |  ?:[\\/]*])
+  lt_cv_path_MAGIC_CMD="$MAGIC_CMD" # Let the user override the test with a path.
+  ;;
+*)
+  lt_save_MAGIC_CMD="$MAGIC_CMD"
+  lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+dnl $ac_dummy forces splitting on constant user-supplied paths.
+dnl POSIX.2 word splitting is done only on the output of word expansions,
+dnl not every word.  This closes a longstanding sh security hole.
+  ac_dummy="m4_if([$2], , $PATH, [$2])"
+  for ac_dir in $ac_dummy; do
+    IFS="$lt_save_ifs"
+    test -z "$ac_dir" && ac_dir=.
+    if test -f $ac_dir/$1; then
+      lt_cv_path_MAGIC_CMD="$ac_dir/$1"
+      if test -n "$file_magic_test_file"; then
+	case $deplibs_check_method in
+	"file_magic "*)
+	  file_magic_regex=`expr "$deplibs_check_method" : "file_magic \(.*\)"`
+	  MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+	  if eval $file_magic_cmd \$file_magic_test_file 2> /dev/null |
+	    $EGREP "$file_magic_regex" > /dev/null; then
+	    :
+	  else
+	    cat <<_LT_EOF 1>&2
+
+*** Warning: the command libtool uses to detect shared libraries,
+*** $file_magic_cmd, produces output that libtool cannot recognize.
+*** The result is that libtool may fail to recognize shared libraries
+*** as such.  This will affect the creation of libtool libraries that
+*** depend on shared libraries, but programs linked with such libtool
+*** libraries will work regardless of this problem.  Nevertheless, you
+*** may want to report the problem to your system manager and/or to
+*** bug-libtool@gnu.org
+
+_LT_EOF
+	  fi ;;
+	esac
+      fi
+      break
+    fi
+  done
+  IFS="$lt_save_ifs"
+  MAGIC_CMD="$lt_save_MAGIC_CMD"
+  ;;
+esac])
+MAGIC_CMD="$lt_cv_path_MAGIC_CMD"
+if test -n "$MAGIC_CMD"; then
+  AC_MSG_RESULT($MAGIC_CMD)
+else
+  AC_MSG_RESULT(no)
+fi
+_LT_DECL([], [MAGIC_CMD], [0],
+	 [Used to examine libraries when file_magic_cmd begins with "file"])dnl
+])# _LT_PATH_TOOL_PREFIX
+
+# Old name:
+AU_ALIAS([AC_PATH_TOOL_PREFIX], [_LT_PATH_TOOL_PREFIX])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_PATH_TOOL_PREFIX], [])
+
+
+# _LT_PATH_MAGIC
+# --------------
+# find a file program which can recognize a shared library
+m4_defun([_LT_PATH_MAGIC],
+[_LT_PATH_TOOL_PREFIX(${ac_tool_prefix}file, /usr/bin$PATH_SEPARATOR$PATH)
+if test -z "$lt_cv_path_MAGIC_CMD"; then
+  if test -n "$ac_tool_prefix"; then
+    _LT_PATH_TOOL_PREFIX(file, /usr/bin$PATH_SEPARATOR$PATH)
+  else
+    MAGIC_CMD=:
+  fi
+fi
+])# _LT_PATH_MAGIC
+
+
+# LT_PATH_LD
+# ----------
+# find the pathname to the GNU or non-GNU linker
+AC_DEFUN([LT_PATH_LD],
+[AC_REQUIRE([AC_PROG_CC])dnl
+AC_REQUIRE([AC_CANONICAL_HOST])dnl
+AC_REQUIRE([AC_CANONICAL_BUILD])dnl
+m4_require([_LT_DECL_SED])dnl
+m4_require([_LT_DECL_EGREP])dnl
+m4_require([_LT_PROG_ECHO_BACKSLASH])dnl
+
+AC_ARG_WITH([gnu-ld],
+    [AS_HELP_STRING([--with-gnu-ld],
+	[assume the C compiler uses GNU ld @<:@default=no@:>@])],
+    [test "$withval" = no || with_gnu_ld=yes],
+    [with_gnu_ld=no])dnl
+
+ac_prog=ld
+if test "$GCC" = yes; then
+  # Check if gcc -print-prog-name=ld gives a path.
+  AC_MSG_CHECKING([for ld used by $CC])
+  case $host in
+  *-*-mingw*)
+    # gcc leaves a trailing carriage return which upsets mingw
+    ac_prog=`($CC -print-prog-name=ld) 2>&5 | tr -d '\015'` ;;
+  *)
+    ac_prog=`($CC -print-prog-name=ld) 2>&5` ;;
+  esac
+  case $ac_prog in
+    # Accept absolute paths.
+    [[\\/]]* | ?:[[\\/]]*)
+      re_direlt='/[[^/]][[^/]]*/\.\./'
+      # Canonicalize the pathname of ld
+      ac_prog=`$ECHO "$ac_prog"| $SED 's%\\\\%/%g'`
+      while $ECHO "$ac_prog" | $GREP "$re_direlt" > /dev/null 2>&1; do
+	ac_prog=`$ECHO $ac_prog| $SED "s%$re_direlt%/%"`
+      done
+      test -z "$LD" && LD="$ac_prog"
+      ;;
+  "")
+    # If it fails, then pretend we aren't using GCC.
+    ac_prog=ld
+    ;;
+  *)
+    # If it is relative, then search for the first ld in PATH.
+    with_gnu_ld=unknown
+    ;;
+  esac
+elif test "$with_gnu_ld" = yes; then
+  AC_MSG_CHECKING([for GNU ld])
+else
+  AC_MSG_CHECKING([for non-GNU ld])
+fi
+AC_CACHE_VAL(lt_cv_path_LD,
+[if test -z "$LD"; then
+  lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+  for ac_dir in $PATH; do
+    IFS="$lt_save_ifs"
+    test -z "$ac_dir" && ac_dir=.
+    if test -f "$ac_dir/$ac_prog" || test -f "$ac_dir/$ac_prog$ac_exeext"; then
+      lt_cv_path_LD="$ac_dir/$ac_prog"
+      # Check to see if the program is GNU ld.  I'd rather use --version,
+      # but apparently some variants of GNU ld only accept -v.
+      # Break only if it was the GNU/non-GNU ld that we prefer.
+      case `"$lt_cv_path_LD" -v 2>&1 </dev/null` in
+      *GNU* | *'with BFD'*)
+	test "$with_gnu_ld" != no && break
+	;;
+      *)
+	test "$with_gnu_ld" != yes && break
+	;;
+      esac
+    fi
+  done
+  IFS="$lt_save_ifs"
+else
+  lt_cv_path_LD="$LD" # Let the user override the test with a path.
+fi])
+LD="$lt_cv_path_LD"
+if test -n "$LD"; then
+  AC_MSG_RESULT($LD)
+else
+  AC_MSG_RESULT(no)
+fi
+test -z "$LD" && AC_MSG_ERROR([no acceptable ld found in \$PATH])
+_LT_PATH_LD_GNU
+AC_SUBST([LD])
+
+_LT_TAGDECL([], [LD], [1], [The linker used to build libraries])
+])# LT_PATH_LD
+
+# Old names:
+AU_ALIAS([AM_PROG_LD], [LT_PATH_LD])
+AU_ALIAS([AC_PROG_LD], [LT_PATH_LD])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AM_PROG_LD], [])
+dnl AC_DEFUN([AC_PROG_LD], [])
+
+
+# _LT_PATH_LD_GNU
+#- --------------
+m4_defun([_LT_PATH_LD_GNU],
+[AC_CACHE_CHECK([if the linker ($LD) is GNU ld], lt_cv_prog_gnu_ld,
+[# I'd rather use --version here, but apparently some GNU lds only accept -v.
+case `$LD -v 2>&1 </dev/null` in
+*GNU* | *'with BFD'*)
+  lt_cv_prog_gnu_ld=yes
+  ;;
+*)
+  lt_cv_prog_gnu_ld=no
+  ;;
+esac])
+with_gnu_ld=$lt_cv_prog_gnu_ld
+])# _LT_PATH_LD_GNU
+
+
+# _LT_CMD_RELOAD
+# --------------
+# find reload flag for linker
+#   -- PORTME Some linkers may need a different reload flag.
+m4_defun([_LT_CMD_RELOAD],
+[AC_CACHE_CHECK([for $LD option to reload object files],
+  lt_cv_ld_reload_flag,
+  [lt_cv_ld_reload_flag='-r'])
+reload_flag=$lt_cv_ld_reload_flag
+case $reload_flag in
+"" | " "*) ;;
+*) reload_flag=" $reload_flag" ;;
+esac
+reload_cmds='$LD$reload_flag -o $output$reload_objs'
+case $host_os in
+  cygwin* | mingw* | pw32* | cegcc*)
+    if test "$GCC" != yes; then
+      reload_cmds=false
+    fi
+    ;;
+  darwin*)
+    if test "$GCC" = yes; then
+      reload_cmds='$LTCC $LTCFLAGS -nostdlib ${wl}-r -o $output$reload_objs'
+    else
+      reload_cmds='$LD$reload_flag -o $output$reload_objs'
+    fi
+    ;;
+esac
+_LT_TAGDECL([], [reload_flag], [1], [How to create reloadable object files])dnl
+_LT_TAGDECL([], [reload_cmds], [2])dnl
+])# _LT_CMD_RELOAD
+
+
+# _LT_CHECK_MAGIC_METHOD
+# ----------------------
+# how to check for library dependencies
+#  -- PORTME fill in with the dynamic library characteristics
+m4_defun([_LT_CHECK_MAGIC_METHOD],
+[m4_require([_LT_DECL_EGREP])
+m4_require([_LT_DECL_OBJDUMP])
+AC_CACHE_CHECK([how to recognize dependent libraries],
+lt_cv_deplibs_check_method,
+[lt_cv_file_magic_cmd='$MAGIC_CMD'
+lt_cv_file_magic_test_file=
+lt_cv_deplibs_check_method='unknown'
+# Need to set the preceding variable on all platforms that support
+# interlibrary dependencies.
+# 'none' -- dependencies not supported.
+# `unknown' -- same as none, but documents that we really don't know.
+# 'pass_all' -- all dependencies passed with no checks.
+# 'test_compile' -- check by making test program.
+# 'file_magic [[regex]]' -- check by looking for files in library path
+# which responds to the $file_magic_cmd with a given extended regex.
+# If you have `file' or equivalent on your system and you're not sure
+# whether `pass_all' will *always* work, you probably want this one.
+
+case $host_os in
+aix[[4-9]]*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+beos*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+bsdi[[45]]*)
+  lt_cv_deplibs_check_method='file_magic ELF [[0-9]][[0-9]]*-bit [[ML]]SB (shared object|dynamic lib)'
+  lt_cv_file_magic_cmd='/usr/bin/file -L'
+  lt_cv_file_magic_test_file=/shlib/libc.so
+  ;;
+
+cygwin*)
+  # func_win32_libid is a shell function defined in ltmain.sh
+  lt_cv_deplibs_check_method='file_magic ^x86 archive import|^x86 DLL'
+  lt_cv_file_magic_cmd='func_win32_libid'
+  ;;
+
+mingw* | pw32*)
+  # Base MSYS/MinGW do not provide the 'file' command needed by
+  # func_win32_libid shell function, so use a weaker test based on 'objdump',
+  # unless we find 'file', for example because we are cross-compiling.
+  # func_win32_libid assumes BSD nm, so disallow it if using MS dumpbin.
+  if ( test "$lt_cv_nm_interface" = "BSD nm" && file / ) >/dev/null 2>&1; then
+    lt_cv_deplibs_check_method='file_magic ^x86 archive import|^x86 DLL'
+    lt_cv_file_magic_cmd='func_win32_libid'
+  else
+    # Keep this pattern in sync with the one in func_win32_libid.
+    lt_cv_deplibs_check_method='file_magic file format (pei*-i386(.*architecture: i386)?|pe-arm-wince|pe-x86-64)'
+    lt_cv_file_magic_cmd='$OBJDUMP -f'
+  fi
+  ;;
+
+cegcc*)
+  # use the weaker test based on 'objdump'. See mingw*.
+  lt_cv_deplibs_check_method='file_magic file format pe-arm-.*little(.*architecture: arm)?'
+  lt_cv_file_magic_cmd='$OBJDUMP -f'
+  ;;
+
+darwin* | rhapsody*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+freebsd* | dragonfly*)
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ > /dev/null; then
+    case $host_cpu in
+    i*86 )
+      # Not sure whether the presence of OpenBSD here was a mistake.
+      # Let's accept both of them until this is cleared up.
+      lt_cv_deplibs_check_method='file_magic (FreeBSD|OpenBSD|DragonFly)/i[[3-9]]86 (compact )?demand paged shared library'
+      lt_cv_file_magic_cmd=/usr/bin/file
+      lt_cv_file_magic_test_file=`echo /usr/lib/libc.so.*`
+      ;;
+    esac
+  else
+    lt_cv_deplibs_check_method=pass_all
+  fi
+  ;;
+
+haiku*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+hpux10.20* | hpux11*)
+  lt_cv_file_magic_cmd=/usr/bin/file
+  case $host_cpu in
+  ia64*)
+    lt_cv_deplibs_check_method='file_magic (s[[0-9]][[0-9]][[0-9]]|ELF-[[0-9]][[0-9]]) shared object file - IA64'
+    lt_cv_file_magic_test_file=/usr/lib/hpux32/libc.so
+    ;;
+  hppa*64*)
+    [lt_cv_deplibs_check_method='file_magic (s[0-9][0-9][0-9]|ELF[ -][0-9][0-9])(-bit)?( [LM]SB)? shared object( file)?[, -]* PA-RISC [0-9]\.[0-9]']
+    lt_cv_file_magic_test_file=/usr/lib/pa20_64/libc.sl
+    ;;
+  *)
+    lt_cv_deplibs_check_method='file_magic (s[[0-9]][[0-9]][[0-9]]|PA-RISC[[0-9]]\.[[0-9]]) shared library'
+    lt_cv_file_magic_test_file=/usr/lib/libc.sl
+    ;;
+  esac
+  ;;
+
+interix[[3-9]]*)
+  # PIC code is broken on Interix 3.x, that's why |\.a not |_pic\.a here
+  lt_cv_deplibs_check_method='match_pattern /lib[[^/]]+(\.so|\.a)$'
+  ;;
+
+irix5* | irix6* | nonstopux*)
+  case $LD in
+  *-32|*"-32 ") libmagic=32-bit;;
+  *-n32|*"-n32 ") libmagic=N32;;
+  *-64|*"-64 ") libmagic=64-bit;;
+  *) libmagic=never-match;;
+  esac
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+# This must be glibc/ELF.
+linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+netbsd* | netbsdelf*-gnu)
+  if echo __ELF__ | $CC -E - | $GREP __ELF__ > /dev/null; then
+    lt_cv_deplibs_check_method='match_pattern /lib[[^/]]+(\.so\.[[0-9]]+\.[[0-9]]+|_pic\.a)$'
+  else
+    lt_cv_deplibs_check_method='match_pattern /lib[[^/]]+(\.so|_pic\.a)$'
+  fi
+  ;;
+
+newos6*)
+  lt_cv_deplibs_check_method='file_magic ELF [[0-9]][[0-9]]*-bit [[ML]]SB (executable|dynamic lib)'
+  lt_cv_file_magic_cmd=/usr/bin/file
+  lt_cv_file_magic_test_file=/usr/lib/libnls.so
+  ;;
+
+*nto* | *qnx*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+openbsd*)
+  if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+    lt_cv_deplibs_check_method='match_pattern /lib[[^/]]+(\.so\.[[0-9]]+\.[[0-9]]+|\.so|_pic\.a)$'
+  else
+    lt_cv_deplibs_check_method='match_pattern /lib[[^/]]+(\.so\.[[0-9]]+\.[[0-9]]+|_pic\.a)$'
+  fi
+  ;;
+
+osf3* | osf4* | osf5*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+rdos*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+solaris*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX* | sysv4*uw2*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+
+sysv4 | sysv4.3*)
+  case $host_vendor in
+  motorola)
+    lt_cv_deplibs_check_method='file_magic ELF [[0-9]][[0-9]]*-bit [[ML]]SB (shared object|dynamic lib) M[[0-9]][[0-9]]* Version [[0-9]]'
+    lt_cv_file_magic_test_file=`echo /usr/lib/libc.so*`
+    ;;
+  ncr)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  sequent)
+    lt_cv_file_magic_cmd='/bin/file'
+    lt_cv_deplibs_check_method='file_magic ELF [[0-9]][[0-9]]*-bit [[LM]]SB (shared object|dynamic lib )'
+    ;;
+  sni)
+    lt_cv_file_magic_cmd='/bin/file'
+    lt_cv_deplibs_check_method="file_magic ELF [[0-9]][[0-9]]*-bit [[LM]]SB dynamic lib"
+    lt_cv_file_magic_test_file=/lib/libc.so
+    ;;
+  siemens)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  pc)
+    lt_cv_deplibs_check_method=pass_all
+    ;;
+  esac
+  ;;
+
+tpf*)
+  lt_cv_deplibs_check_method=pass_all
+  ;;
+esac
+])
+
+file_magic_glob=
+want_nocaseglob=no
+if test "$build" = "$host"; then
+  case $host_os in
+  mingw* | pw32*)
+    if ( shopt | grep nocaseglob ) >/dev/null 2>&1; then
+      want_nocaseglob=yes
+    else
+      file_magic_glob=`echo aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ | $SED -e "s/\(..\)/s\/[[\1]]\/[[\1]]\/g;/g"`
+    fi
+    ;;
+  esac
+fi
+
+file_magic_cmd=$lt_cv_file_magic_cmd
+deplibs_check_method=$lt_cv_deplibs_check_method
+test -z "$deplibs_check_method" && deplibs_check_method=unknown
+
+_LT_DECL([], [deplibs_check_method], [1],
+    [Method to check whether dependent libraries are shared objects])
+_LT_DECL([], [file_magic_cmd], [1],
+    [Command to use when deplibs_check_method = "file_magic"])
+_LT_DECL([], [file_magic_glob], [1],
+    [How to find potential files when deplibs_check_method = "file_magic"])
+_LT_DECL([], [want_nocaseglob], [1],
+    [Find potential files using nocaseglob when deplibs_check_method = "file_magic"])
+])# _LT_CHECK_MAGIC_METHOD
+
+
+# LT_PATH_NM
+# ----------
+# find the pathname to a BSD- or MS-compatible name lister
+AC_DEFUN([LT_PATH_NM],
+[AC_REQUIRE([AC_PROG_CC])dnl
+AC_CACHE_CHECK([for BSD- or MS-compatible name lister (nm)], lt_cv_path_NM,
+[if test -n "$NM"; then
+  # Let the user override the test.
+  lt_cv_path_NM="$NM"
+else
+  lt_nm_to_check="${ac_tool_prefix}nm"
+  if test -n "$ac_tool_prefix" && test "$build" = "$host"; then
+    lt_nm_to_check="$lt_nm_to_check nm"
+  fi
+  for lt_tmp_nm in $lt_nm_to_check; do
+    lt_save_ifs="$IFS"; IFS=$PATH_SEPARATOR
+    for ac_dir in $PATH /usr/ccs/bin/elf /usr/ccs/bin /usr/ucb /bin; do
+      IFS="$lt_save_ifs"
+      test -z "$ac_dir" && ac_dir=.
+      tmp_nm="$ac_dir/$lt_tmp_nm"
+      if test -f "$tmp_nm" || test -f "$tmp_nm$ac_exeext" ; then
+	# Check to see if the nm accepts a BSD-compat flag.
+	# Adding the `sed 1q' prevents false positives on HP-UX, which says:
+	#   nm: unknown option "B" ignored
+	# Tru64's nm complains that /dev/null is an invalid object file
+	case `"$tmp_nm" -B /dev/null 2>&1 | sed '1q'` in
+	*/dev/null* | *'Invalid file or object type'*)
+	  lt_cv_path_NM="$tmp_nm -B"
+	  break
+	  ;;
+	*)
+	  case `"$tmp_nm" -p /dev/null 2>&1 | sed '1q'` in
+	  */dev/null*)
+	    lt_cv_path_NM="$tmp_nm -p"
+	    break
+	    ;;
+	  *)
+	    lt_cv_path_NM=${lt_cv_path_NM="$tmp_nm"} # keep the first match, but
+	    continue # so that we can try to find one that supports BSD flags
+	    ;;
+	  esac
+	  ;;
+	esac
+      fi
+    done
+    IFS="$lt_save_ifs"
+  done
+  : ${lt_cv_path_NM=no}
+fi])
+if test "$lt_cv_path_NM" != "no"; then
+  NM="$lt_cv_path_NM"
+else
+  # Didn't find any BSD compatible name lister, look for dumpbin.
+  if test -n "$DUMPBIN"; then :
+    # Let the user override the test.
+  else
+    AC_CHECK_TOOLS(DUMPBIN, [dumpbin "link -dump"], :)
+    case `$DUMPBIN -symbols /dev/null 2>&1 | sed '1q'` in
+    *COFF*)
+      DUMPBIN="$DUMPBIN -symbols"
+      ;;
+    *)
+      DUMPBIN=:
+      ;;
+    esac
+  fi
+  AC_SUBST([DUMPBIN])
+  if test "$DUMPBIN" != ":"; then
+    NM="$DUMPBIN"
+  fi
+fi
+test -z "$NM" && NM=nm
+AC_SUBST([NM])
+_LT_DECL([], [NM], [1], [A BSD- or MS-compatible name lister])dnl
+
+AC_CACHE_CHECK([the name lister ($NM) interface], [lt_cv_nm_interface],
+  [lt_cv_nm_interface="BSD nm"
+  echo "int some_variable = 0;" > conftest.$ac_ext
+  (eval echo "\"\$as_me:$LINENO: $ac_compile\"" >&AS_MESSAGE_LOG_FD)
+  (eval "$ac_compile" 2>conftest.err)
+  cat conftest.err >&AS_MESSAGE_LOG_FD
+  (eval echo "\"\$as_me:$LINENO: $NM \\\"conftest.$ac_objext\\\"\"" >&AS_MESSAGE_LOG_FD)
+  (eval "$NM \"conftest.$ac_objext\"" 2>conftest.err > conftest.out)
+  cat conftest.err >&AS_MESSAGE_LOG_FD
+  (eval echo "\"\$as_me:$LINENO: output\"" >&AS_MESSAGE_LOG_FD)
+  cat conftest.out >&AS_MESSAGE_LOG_FD
+  if $GREP 'External.*some_variable' conftest.out > /dev/null; then
+    lt_cv_nm_interface="MS dumpbin"
+  fi
+  rm -f conftest*])
+])# LT_PATH_NM
+
+# Old names:
+AU_ALIAS([AM_PROG_NM], [LT_PATH_NM])
+AU_ALIAS([AC_PROG_NM], [LT_PATH_NM])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AM_PROG_NM], [])
+dnl AC_DEFUN([AC_PROG_NM], [])
+
+# _LT_CHECK_SHAREDLIB_FROM_LINKLIB
+# --------------------------------
+# how to determine the name of the shared library
+# associated with a specific link library.
+#  -- PORTME fill in with the dynamic library characteristics
+m4_defun([_LT_CHECK_SHAREDLIB_FROM_LINKLIB],
+[m4_require([_LT_DECL_EGREP])
+m4_require([_LT_DECL_OBJDUMP])
+m4_require([_LT_DECL_DLLTOOL])
+AC_CACHE_CHECK([how to associate runtime and link libraries],
+lt_cv_sharedlib_from_linklib_cmd,
+[lt_cv_sharedlib_from_linklib_cmd='unknown'
+
+case $host_os in
+cygwin* | mingw* | pw32* | cegcc*)
+  # two different shell functions defined in ltmain.sh
+  # decide which to use based on capabilities of $DLLTOOL
+  case `$DLLTOOL --help 2>&1` in
+  *--identify-strict*)
+    lt_cv_sharedlib_from_linklib_cmd=func_cygming_dll_for_implib
+    ;;
+  *)
+    lt_cv_sharedlib_from_linklib_cmd=func_cygming_dll_for_implib_fallback
+    ;;
+  esac
+  ;;
+*)
+  # fallback: assume linklib IS sharedlib
+  lt_cv_sharedlib_from_linklib_cmd="$ECHO"
+  ;;
+esac
+])
+sharedlib_from_linklib_cmd=$lt_cv_sharedlib_from_linklib_cmd
+test -z "$sharedlib_from_linklib_cmd" && sharedlib_from_linklib_cmd=$ECHO
+
+_LT_DECL([], [sharedlib_from_linklib_cmd], [1],
+    [Command to associate shared and link libraries])
+])# _LT_CHECK_SHAREDLIB_FROM_LINKLIB
+
+
+# _LT_PATH_MANIFEST_TOOL
+# ----------------------
+# locate the manifest tool
+m4_defun([_LT_PATH_MANIFEST_TOOL],
+[AC_CHECK_TOOL(MANIFEST_TOOL, mt, :)
+test -z "$MANIFEST_TOOL" && MANIFEST_TOOL=mt
+AC_CACHE_CHECK([if $MANIFEST_TOOL is a manifest tool], [lt_cv_path_mainfest_tool],
+  [lt_cv_path_mainfest_tool=no
+  echo "$as_me:$LINENO: $MANIFEST_TOOL '-?'" >&AS_MESSAGE_LOG_FD
+  $MANIFEST_TOOL '-?' 2>conftest.err > conftest.out
+  cat conftest.err >&AS_MESSAGE_LOG_FD
+  if $GREP 'Manifest Tool' conftest.out > /dev/null; then
+    lt_cv_path_mainfest_tool=yes
+  fi
+  rm -f conftest*])
+if test "x$lt_cv_path_mainfest_tool" != xyes; then
+  MANIFEST_TOOL=:
+fi
+_LT_DECL([], [MANIFEST_TOOL], [1], [Manifest tool])dnl
+])# _LT_PATH_MANIFEST_TOOL
+
+
+# LT_LIB_M
+# --------
+# check for math library
+AC_DEFUN([LT_LIB_M],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+LIBM=
+case $host in
+*-*-beos* | *-*-cegcc* | *-*-cygwin* | *-*-haiku* | *-*-pw32* | *-*-darwin*)
+  # These system don't have libm, or don't need it
+  ;;
+*-ncr-sysv4.3*)
+  AC_CHECK_LIB(mw, _mwvalidcheckl, LIBM="-lmw")
+  AC_CHECK_LIB(m, cos, LIBM="$LIBM -lm")
+  ;;
+*)
+  AC_CHECK_LIB(m, cos, LIBM="-lm")
+  ;;
+esac
+AC_SUBST([LIBM])
+])# LT_LIB_M
+
+# Old name:
+AU_ALIAS([AC_CHECK_LIBM], [LT_LIB_M])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_CHECK_LIBM], [])
+
+
+# _LT_COMPILER_NO_RTTI([TAGNAME])
+# -------------------------------
+m4_defun([_LT_COMPILER_NO_RTTI],
+[m4_require([_LT_TAG_COMPILER])dnl
+
+_LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)=
+
+if test "$GCC" = yes; then
+  case $cc_basename in
+  nvcc*)
+    _LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)=' -Xcompiler -fno-builtin' ;;
+  *)
+    _LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)=' -fno-builtin' ;;
+  esac
+
+  _LT_COMPILER_OPTION([if $compiler supports -fno-rtti -fno-exceptions],
+    lt_cv_prog_compiler_rtti_exceptions,
+    [-fno-rtti -fno-exceptions], [],
+    [_LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)="$_LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1) -fno-rtti -fno-exceptions"])
+fi
+_LT_TAGDECL([no_builtin_flag], [lt_prog_compiler_no_builtin_flag], [1],
+	[Compiler flag to turn off builtin functions])
+])# _LT_COMPILER_NO_RTTI
+
+
+# _LT_CMD_GLOBAL_SYMBOLS
+# ----------------------
+m4_defun([_LT_CMD_GLOBAL_SYMBOLS],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+AC_REQUIRE([AC_PROG_CC])dnl
+AC_REQUIRE([AC_PROG_AWK])dnl
+AC_REQUIRE([LT_PATH_NM])dnl
+AC_REQUIRE([LT_PATH_LD])dnl
+m4_require([_LT_DECL_SED])dnl
+m4_require([_LT_DECL_EGREP])dnl
+m4_require([_LT_TAG_COMPILER])dnl
+
+# Check for command to grab the raw symbol name followed by C symbol from nm.
+AC_MSG_CHECKING([command to parse $NM output from $compiler object])
+AC_CACHE_VAL([lt_cv_sys_global_symbol_pipe],
+[
+# These are sane defaults that work on at least a few old systems.
+# [They come from Ultrix.  What could be older than Ultrix?!! ;)]
+
+# Character class describing NM global symbol codes.
+symcode='[[BCDEGRST]]'
+
+# Regexp to match symbols that can be accessed directly from C.
+sympat='\([[_A-Za-z]][[_A-Za-z0-9]]*\)'
+
+# Define system-specific variables.
+case $host_os in
+aix*)
+  symcode='[[BCDT]]'
+  ;;
+cygwin* | mingw* | pw32* | cegcc*)
+  symcode='[[ABCDGISTW]]'
+  ;;
+hpux*)
+  if test "$host_cpu" = ia64; then
+    symcode='[[ABCDEGRST]]'
+  fi
+  ;;
+irix* | nonstopux*)
+  symcode='[[BCDEGRST]]'
+  ;;
+osf*)
+  symcode='[[BCDEGQRST]]'
+  ;;
+solaris*)
+  symcode='[[BDRT]]'
+  ;;
+sco3.2v5*)
+  symcode='[[DT]]'
+  ;;
+sysv4.2uw2*)
+  symcode='[[DT]]'
+  ;;
+sysv5* | sco5v6* | unixware* | OpenUNIX*)
+  symcode='[[ABDT]]'
+  ;;
+sysv4)
+  symcode='[[DFNSTU]]'
+  ;;
+esac
+
+# If we're using GNU nm, then use its standard symbol codes.
+case `$NM -V 2>&1` in
+*GNU* | *'with BFD'*)
+  symcode='[[ABCDGIRSTW]]' ;;
+esac
+
+# Transform an extracted symbol line into a proper C declaration.
+# Some systems (esp. on ia64) link data and code symbols differently,
+# so use this general approach.
+lt_cv_sys_global_symbol_to_cdecl="sed -n -e 's/^T .* \(.*\)$/extern int \1();/p' -e 's/^$symcode* .* \(.*\)$/extern char \1;/p'"
+
+# Transform an extracted symbol line into symbol name and symbol address
+lt_cv_sys_global_symbol_to_c_name_address="sed -n -e 's/^: \([[^ ]]*\)[[ ]]*$/  {\\\"\1\\\", (void *) 0},/p' -e 's/^$symcode* \([[^ ]]*\) \([[^ ]]*\)$/  {\"\2\", (void *) \&\2},/p'"
+lt_cv_sys_global_symbol_to_c_name_address_lib_prefix="sed -n -e 's/^: \([[^ ]]*\)[[ ]]*$/  {\\\"\1\\\", (void *) 0},/p' -e 's/^$symcode* \([[^ ]]*\) \(lib[[^ ]]*\)$/  {\"\2\", (void *) \&\2},/p' -e 's/^$symcode* \([[^ ]]*\) \([[^ ]]*\)$/  {\"lib\2\", (void *) \&\2},/p'"
+
+# Handle CRLF in mingw tool chain
+opt_cr=
+case $build_os in
+mingw*)
+  opt_cr=`$ECHO 'x\{0,1\}' | tr x '\015'` # option cr in regexp
+  ;;
+esac
+
+# Try without a prefix underscore, then with it.
+for ac_symprfx in "" "_"; do
+
+  # Transform symcode, sympat, and symprfx into a raw symbol and a C symbol.
+  symxfrm="\\1 $ac_symprfx\\2 \\2"
+
+  # Write the raw and C identifiers.
+  if test "$lt_cv_nm_interface" = "MS dumpbin"; then
+    # Fake it for dumpbin and say T for any non-static function
+    # and D for any global variable.
+    # Also find C++ and __fastcall symbols from MSVC++,
+    # which start with @ or ?.
+    lt_cv_sys_global_symbol_pipe="$AWK ['"\
+"     {last_section=section; section=\$ 3};"\
+"     /^COFF SYMBOL TABLE/{for(i in hide) delete hide[i]};"\
+"     /Section length .*#relocs.*(pick any)/{hide[last_section]=1};"\
+"     \$ 0!~/External *\|/{next};"\
+"     / 0+ UNDEF /{next}; / UNDEF \([^|]\)*()/{next};"\
+"     {if(hide[section]) next};"\
+"     {f=0}; \$ 0~/\(\).*\|/{f=1}; {printf f ? \"T \" : \"D \"};"\
+"     {split(\$ 0, a, /\||\r/); split(a[2], s)};"\
+"     s[1]~/^[@?]/{print s[1], s[1]; next};"\
+"     s[1]~prfx {split(s[1],t,\"@\"); print t[1], substr(t[1],length(prfx))}"\
+"     ' prfx=^$ac_symprfx]"
+  else
+    lt_cv_sys_global_symbol_pipe="sed -n -e 's/^.*[[	 ]]\($symcode$symcode*\)[[	 ]][[	 ]]*$ac_symprfx$sympat$opt_cr$/$symxfrm/p'"
+  fi
+  lt_cv_sys_global_symbol_pipe="$lt_cv_sys_global_symbol_pipe | sed '/ __gnu_lto/d'"
+
+  # Check to see that the pipe works correctly.
+  pipe_works=no
+
+  rm -f conftest*
+  cat > conftest.$ac_ext <<_LT_EOF
+#ifdef __cplusplus
+extern "C" {
+#endif
+char nm_test_var;
+void nm_test_func(void);
+void nm_test_func(void){}
+#ifdef __cplusplus
+}
+#endif
+int main(){nm_test_var='a';nm_test_func();return(0);}
+_LT_EOF
+
+  if AC_TRY_EVAL(ac_compile); then
+    # Now try to grab the symbols.
+    nlist=conftest.nm
+    if AC_TRY_EVAL(NM conftest.$ac_objext \| "$lt_cv_sys_global_symbol_pipe" \> $nlist) && test -s "$nlist"; then
+      # Try sorting and uniquifying the output.
+      if sort "$nlist" | uniq > "$nlist"T; then
+	mv -f "$nlist"T "$nlist"
+      else
+	rm -f "$nlist"T
+      fi
+
+      # Make sure that we snagged all the symbols we need.
+      if $GREP ' nm_test_var$' "$nlist" >/dev/null; then
+	if $GREP ' nm_test_func$' "$nlist" >/dev/null; then
+	  cat <<_LT_EOF > conftest.$ac_ext
+/* Keep this code in sync between libtool.m4, ltmain, lt_system.h, and tests.  */
+#if defined(_WIN32) || defined(__CYGWIN__) || defined(_WIN32_WCE)
+/* DATA imports from DLLs on WIN32 con't be const, because runtime
+   relocations are performed -- see ld's documentation on pseudo-relocs.  */
+# define LT@&t@_DLSYM_CONST
+#elif defined(__osf__)
+/* This system does not cope well with relocations in const data.  */
+# define LT@&t@_DLSYM_CONST
+#else
+# define LT@&t@_DLSYM_CONST const
+#endif
+
+#ifdef __cplusplus
+extern "C" {
+#endif
+
+_LT_EOF
+	  # Now generate the symbol file.
+	  eval "$lt_cv_sys_global_symbol_to_cdecl"' < "$nlist" | $GREP -v main >> conftest.$ac_ext'
+
+	  cat <<_LT_EOF >> conftest.$ac_ext
+
+/* The mapping between symbol names and symbols.  */
+LT@&t@_DLSYM_CONST struct {
+  const char *name;
+  void       *address;
+}
+lt__PROGRAM__LTX_preloaded_symbols[[]] =
+{
+  { "@PROGRAM@", (void *) 0 },
+_LT_EOF
+	  $SED "s/^$symcode$symcode* \(.*\) \(.*\)$/  {\"\2\", (void *) \&\2},/" < "$nlist" | $GREP -v main >> conftest.$ac_ext
+	  cat <<\_LT_EOF >> conftest.$ac_ext
+  {0, (void *) 0}
+};
+
+/* This works around a problem in FreeBSD linker */
+#ifdef FREEBSD_WORKAROUND
+static const void *lt_preloaded_setup() {
+  return lt__PROGRAM__LTX_preloaded_symbols;
+}
+#endif
+
+#ifdef __cplusplus
+}
+#endif
+_LT_EOF
+	  # Now try linking the two files.
+	  mv conftest.$ac_objext conftstm.$ac_objext
+	  lt_globsym_save_LIBS=$LIBS
+	  lt_globsym_save_CFLAGS=$CFLAGS
+	  LIBS="conftstm.$ac_objext"
+	  CFLAGS="$CFLAGS$_LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)"
+	  if AC_TRY_EVAL(ac_link) && test -s conftest${ac_exeext}; then
+	    pipe_works=yes
+	  fi
+	  LIBS=$lt_globsym_save_LIBS
+	  CFLAGS=$lt_globsym_save_CFLAGS
+	else
+	  echo "cannot find nm_test_func in $nlist" >&AS_MESSAGE_LOG_FD
+	fi
+      else
+	echo "cannot find nm_test_var in $nlist" >&AS_MESSAGE_LOG_FD
+      fi
+    else
+      echo "cannot run $lt_cv_sys_global_symbol_pipe" >&AS_MESSAGE_LOG_FD
+    fi
+  else
+    echo "$progname: failed program was:" >&AS_MESSAGE_LOG_FD
+    cat conftest.$ac_ext >&5
+  fi
+  rm -rf conftest* conftst*
+
+  # Do not use the global_symbol_pipe unless it works.
+  if test "$pipe_works" = yes; then
+    break
+  else
+    lt_cv_sys_global_symbol_pipe=
+  fi
+done
+])
+if test -z "$lt_cv_sys_global_symbol_pipe"; then
+  lt_cv_sys_global_symbol_to_cdecl=
+fi
+if test -z "$lt_cv_sys_global_symbol_pipe$lt_cv_sys_global_symbol_to_cdecl"; then
+  AC_MSG_RESULT(failed)
+else
+  AC_MSG_RESULT(ok)
+fi
+
+# Response file support.
+if test "$lt_cv_nm_interface" = "MS dumpbin"; then
+  nm_file_list_spec='@'
+elif $NM --help 2>/dev/null | grep '[[@]]FILE' >/dev/null; then
+  nm_file_list_spec='@'
+fi
+
+_LT_DECL([global_symbol_pipe], [lt_cv_sys_global_symbol_pipe], [1],
+    [Take the output of nm and produce a listing of raw symbols and C names])
+_LT_DECL([global_symbol_to_cdecl], [lt_cv_sys_global_symbol_to_cdecl], [1],
+    [Transform the output of nm in a proper C declaration])
+_LT_DECL([global_symbol_to_c_name_address],
+    [lt_cv_sys_global_symbol_to_c_name_address], [1],
+    [Transform the output of nm in a C name address pair])
+_LT_DECL([global_symbol_to_c_name_address_lib_prefix],
+    [lt_cv_sys_global_symbol_to_c_name_address_lib_prefix], [1],
+    [Transform the output of nm in a C name address pair when lib prefix is needed])
+_LT_DECL([], [nm_file_list_spec], [1],
+    [Specify filename containing input files for $NM])
+]) # _LT_CMD_GLOBAL_SYMBOLS
+
+
+# _LT_COMPILER_PIC([TAGNAME])
+# ---------------------------
+m4_defun([_LT_COMPILER_PIC],
+[m4_require([_LT_TAG_COMPILER])dnl
+_LT_TAGVAR(lt_prog_compiler_wl, $1)=
+_LT_TAGVAR(lt_prog_compiler_pic, $1)=
+_LT_TAGVAR(lt_prog_compiler_static, $1)=
+
+m4_if([$1], [CXX], [
+  # C++ specific cases for pic, static, wl, etc.
+  if test "$GXX" = yes; then
+    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+    _LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+
+    case $host_os in
+    aix*)
+      # All AIX code is PIC.
+      if test "$host_cpu" = ia64; then
+	# AIX 5 now supports IA64 processor
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+        ;;
+      m68k)
+            # FIXME: we need at least 68020 code to build shared libraries, but
+            # adding the `-m68020' flag to GCC prevents building anything better,
+            # like `-m68040'.
+            _LT_TAGVAR(lt_prog_compiler_pic, $1)='-m68020 -resident32 -malways-restore-a4'
+        ;;
+      esac
+      ;;
+
+    beos* | irix5* | irix6* | nonstopux* | osf3* | osf4* | osf5*)
+      # PIC is the default for these OSes.
+      ;;
+    mingw* | cygwin* | os2* | pw32* | cegcc*)
+      # This hack is so that the source file can tell whether it is being
+      # built for inclusion in a dll (and should export symbols for example).
+      # Although the cygwin gcc ignores -fPIC, still need this for old-style
+      # (--disable-auto-import) libraries
+      m4_if([$1], [GCJ], [],
+	[_LT_TAGVAR(lt_prog_compiler_pic, $1)='-DDLL_EXPORT'])
+      ;;
+    darwin* | rhapsody*)
+      # PIC is the default on this platform
+      # Common symbols not allowed in MH_DYLIB files
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fno-common'
+      ;;
+    *djgpp*)
+      # DJGPP does not support shared libraries at all
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)=
+      ;;
+    haiku*)
+      # PIC is the default for Haiku.
+      # The "-static" flag exists, but is broken.
+      _LT_TAGVAR(lt_prog_compiler_static, $1)=
+      ;;
+    interix[[3-9]]*)
+      # Interix 3.x gcc -fpic/-fPIC options generate broken code.
+      # Instead, we relocate shared libraries at runtime.
+      ;;
+    sysv4*MP*)
+      if test -d /usr/nec; then
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)=-Kconform_pic
+      fi
+      ;;
+    hpux*)
+      # PIC is the default for 64-bit PA HP-UX, but not for 32-bit
+      # PA HP-UX.  On IA64 HP-UX, PIC is the default but the pic flag
+      # sets the default TLS model and affects inlining.
+      case $host_cpu in
+      hppa*64*)
+	;;
+      *)
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	;;
+      esac
+      ;;
+    *qnx* | *nto*)
+      # QNX uses GNU C++, but need to define -shared option too, otherwise
+      # it will coredump.
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC -shared'
+      ;;
+    *)
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+      ;;
+    esac
+  else
+    case $host_os in
+      aix[[4-9]]*)
+	# All AIX code is PIC.
+	if test "$host_cpu" = ia64; then
+	  # AIX 5 now supports IA64 processor
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	else
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-bnso -bI:/lib/syscalls.exp'
+	fi
+	;;
+      chorus*)
+	case $cc_basename in
+	cxch68*)
+	  # Green Hills C++ Compiler
+	  # _LT_TAGVAR(lt_prog_compiler_static, $1)="--no_auto_instantiation -u __main -u __premain -u _abort -r $COOL_DIR/lib/libOrb.a $MVME_DIR/lib/CC/libC.a $MVME_DIR/lib/classix/libcx.s.a"
+	  ;;
+	esac
+	;;
+      mingw* | cygwin* | os2* | pw32* | cegcc*)
+	# This hack is so that the source file can tell whether it is being
+	# built for inclusion in a dll (and should export symbols for example).
+	m4_if([$1], [GCJ], [],
+	  [_LT_TAGVAR(lt_prog_compiler_pic, $1)='-DDLL_EXPORT'])
+	;;
+      dgux*)
+	case $cc_basename in
+	  ec++*)
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	    ;;
+	  ghcx*)
+	    # Green Hills C++ Compiler
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-pic'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      freebsd* | dragonfly*)
+	# FreeBSD uses GNU C++
+	;;
+      hpux9* | hpux10* | hpux11*)
+	case $cc_basename in
+	  CC*)
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='${wl}-a ${wl}archive'
+	    if test "$host_cpu" != ia64; then
+	      _LT_TAGVAR(lt_prog_compiler_pic, $1)='+Z'
+	    fi
+	    ;;
+	  aCC*)
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='${wl}-a ${wl}archive'
+	    case $host_cpu in
+	    hppa*64*|ia64*)
+	      # +Z the default
+	      ;;
+	    *)
+	      _LT_TAGVAR(lt_prog_compiler_pic, $1)='+Z'
+	      ;;
+	    esac
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      interix*)
+	# This is c89, which is MS Visual C++ (no shared libs)
+	# Anyone wants to do a port?
+	;;
+      irix5* | irix6* | nonstopux*)
+	case $cc_basename in
+	  CC*)
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+	    # CC pic flag -KPIC is the default.
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+	case $cc_basename in
+	  KCC*)
+	    # KAI C++ Compiler
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='--backend -Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	    ;;
+	  ecpc* )
+	    # old Intel C++ for x86_64 which still supported -KPIC.
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+	    ;;
+	  icpc* )
+	    # Intel C++, used to be incompatible with GCC.
+	    # ICC 10 doesn't accept -KPIC any more.
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+	    ;;
+	  pgCC* | pgcpp*)
+	    # Portland Group C++ compiler
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fpic'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	    ;;
+	  cxx*)
+	    # Compaq C++
+	    # Make sure the PIC flag is empty.  It appears that all Alpha
+	    # Linux and Compaq Tru64 Unix objects are PIC.
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)=
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+	    ;;
+	  xlc* | xlC* | bgxl[[cC]]* | mpixl[[cC]]*)
+	    # IBM XL 8.0, 9.0 on PPC and BlueGene
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-qpic'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-qstaticlink'
+	    ;;
+	  *)
+	    case `$CC -V 2>&1 | sed 5q` in
+	    *Sun\ C*)
+	      # Sun C++ 5.9
+	      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Qoption ld '
+	      ;;
+	    esac
+	    ;;
+	esac
+	;;
+      lynxos*)
+	;;
+      m88k*)
+	;;
+      mvs*)
+	case $cc_basename in
+	  cxx*)
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-W c,exportall'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      netbsd* | netbsdelf*-gnu)
+	;;
+      *qnx* | *nto*)
+        # QNX uses GNU C++, but need to define -shared option too, otherwise
+        # it will coredump.
+        _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC -shared'
+        ;;
+      osf3* | osf4* | osf5*)
+	case $cc_basename in
+	  KCC*)
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='--backend -Wl,'
+	    ;;
+	  RCC*)
+	    # Rational C++ 2.4.1
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-pic'
+	    ;;
+	  cxx*)
+	    # Digital/Compaq C++
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    # Make sure the PIC flag is empty.  It appears that all Alpha
+	    # Linux and Compaq Tru64 Unix objects are PIC.
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)=
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      psos*)
+	;;
+      solaris*)
+	case $cc_basename in
+	  CC* | sunCC*)
+	    # Sun C++ 4.2, 5.x and Centerline C++
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Qoption ld '
+	    ;;
+	  gcx*)
+	    # Green Hills C++ Compiler
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-PIC'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      sunos4*)
+	case $cc_basename in
+	  CC*)
+	    # Sun C++ 4.x
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-pic'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	    ;;
+	  lcc*)
+	    # Lucid
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-pic'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      sysv5* | unixware* | sco3.2v5* | sco5v6* | OpenUNIX*)
+	case $cc_basename in
+	  CC*)
+	    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	    _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	    ;;
+	esac
+	;;
+      tandem*)
+	case $cc_basename in
+	  NCC*)
+	    # NonStop-UX NCC 3.20
+	    _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	    ;;
+	  *)
+	    ;;
+	esac
+	;;
+      vxworks*)
+	;;
+      *)
+	_LT_TAGVAR(lt_prog_compiler_can_build_shared, $1)=no
+	;;
+    esac
+  fi
+],
+[
+  if test "$GCC" = yes; then
+    _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+    _LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+
+    case $host_os in
+      aix*)
+      # All AIX code is PIC.
+      if test "$host_cpu" = ia64; then
+	# AIX 5 now supports IA64 processor
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+        ;;
+      m68k)
+            # FIXME: we need at least 68020 code to build shared libraries, but
+            # adding the `-m68020' flag to GCC prevents building anything better,
+            # like `-m68040'.
+            _LT_TAGVAR(lt_prog_compiler_pic, $1)='-m68020 -resident32 -malways-restore-a4'
+        ;;
+      esac
+      ;;
+
+    beos* | irix5* | irix6* | nonstopux* | osf3* | osf4* | osf5*)
+      # PIC is the default for these OSes.
+      ;;
+
+    mingw* | cygwin* | pw32* | os2* | cegcc*)
+      # This hack is so that the source file can tell whether it is being
+      # built for inclusion in a dll (and should export symbols for example).
+      # Although the cygwin gcc ignores -fPIC, still need this for old-style
+      # (--disable-auto-import) libraries
+      m4_if([$1], [GCJ], [],
+	[_LT_TAGVAR(lt_prog_compiler_pic, $1)='-DDLL_EXPORT'])
+      ;;
+
+    darwin* | rhapsody*)
+      # PIC is the default on this platform
+      # Common symbols not allowed in MH_DYLIB files
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fno-common'
+      ;;
+
+    haiku*)
+      # PIC is the default for Haiku.
+      # The "-static" flag exists, but is broken.
+      _LT_TAGVAR(lt_prog_compiler_static, $1)=
+      ;;
+
+    hpux*)
+      # PIC is the default for 64-bit PA HP-UX, but not for 32-bit
+      # PA HP-UX.  On IA64 HP-UX, PIC is the default but the pic flag
+      # sets the default TLS model and affects inlining.
+      case $host_cpu in
+      hppa*64*)
+	# +Z the default
+	;;
+      *)
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	;;
+      esac
+      ;;
+
+    interix[[3-9]]*)
+      # Interix 3.x gcc -fpic/-fPIC options generate broken code.
+      # Instead, we relocate shared libraries at runtime.
+      ;;
+
+    msdosdjgpp*)
+      # Just because we use GCC doesn't mean we suddenly get shared libraries
+      # on systems that don't support them.
+      _LT_TAGVAR(lt_prog_compiler_can_build_shared, $1)=no
+      enable_shared=no
+      ;;
+
+    *nto* | *qnx*)
+      # QNX uses GNU C++, but need to define -shared option too, otherwise
+      # it will coredump.
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC -shared'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec; then
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)=-Kconform_pic
+      fi
+      ;;
+
+    *)
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+      ;;
+    esac
+
+    case $cc_basename in
+    nvcc*) # Cuda Compiler Driver 2.2
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Xlinker '
+      if test -n "$_LT_TAGVAR(lt_prog_compiler_pic, $1)"; then
+        _LT_TAGVAR(lt_prog_compiler_pic, $1)="-Xcompiler $_LT_TAGVAR(lt_prog_compiler_pic, $1)"
+      fi
+      ;;
+    esac
+  else
+    # PORTME Check for flag to pass linker flags through the system compiler.
+    case $host_os in
+    aix*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      if test "$host_cpu" = ia64; then
+	# AIX 5 now supports IA64 processor
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      else
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-bnso -bI:/lib/syscalls.exp'
+      fi
+      ;;
+
+    mingw* | cygwin* | pw32* | os2* | cegcc*)
+      # This hack is so that the source file can tell whether it is being
+      # built for inclusion in a dll (and should export symbols for example).
+      m4_if([$1], [GCJ], [],
+	[_LT_TAGVAR(lt_prog_compiler_pic, $1)='-DDLL_EXPORT'])
+      ;;
+
+    hpux9* | hpux10* | hpux11*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      # PIC is the default for IA64 HP-UX and 64-bit HP-UX, but
+      # not for PA HP-UX.
+      case $host_cpu in
+      hppa*64*|ia64*)
+	# +Z the default
+	;;
+      *)
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='+Z'
+	;;
+      esac
+      # Is there a better lt_prog_compiler_static that works with the bundled CC?
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='${wl}-a ${wl}archive'
+      ;;
+
+    irix5* | irix6* | nonstopux*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      # PIC (with -KPIC) is the default.
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+      ;;
+
+    linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+      case $cc_basename in
+      # old Intel for x86_64 which still supported -KPIC.
+      ecc*)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+        ;;
+      # icc used to be incompatible with GCC.
+      # ICC 10 doesn't accept -KPIC any more.
+      icc* | ifort*)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+        ;;
+      # Lahey Fortran 8.1.
+      lf95*)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='--shared'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='--static'
+	;;
+      nagfor*)
+	# NAG Fortran compiler
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,-Wl,,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-PIC'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	;;
+      pgcc* | pgf77* | pgf90* | pgf95* | pgfortran*)
+        # Portland Group compilers (*not* the Pentium gcc compiler,
+	# which looks to be a dead project)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-fpic'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+        ;;
+      ccc*)
+        _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+        # All Alpha code is PIC.
+        _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+        ;;
+      xl* | bgxl* | bgf* | mpixl*)
+	# IBM XL C 8.0/Fortran 10.1, 11.1 on PPC and BlueGene
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-qpic'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-qstaticlink'
+	;;
+      *)
+	case `$CC -V 2>&1 | sed 5q` in
+	*Sun\ Ceres\ Fortran* | *Sun*Fortran*\ [[1-7]].* | *Sun*Fortran*\ 8.[[0-3]]*)
+	  # Sun Fortran 8.3 passes all unrecognized flags to the linker
+	  _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	  _LT_TAGVAR(lt_prog_compiler_wl, $1)=''
+	  ;;
+	*Sun\ F* | *Sun*Fortran*)
+	  _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	  _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Qoption ld '
+	  ;;
+	*Sun\ C*)
+	  # Sun C 5.9
+	  _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	  _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	  ;;
+        *Intel*\ [[CF]]*Compiler*)
+	  _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	  _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC'
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-static'
+	  ;;
+	*Portland\ Group*)
+	  _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+	  _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fpic'
+	  _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+	  ;;
+	esac
+	;;
+      esac
+      ;;
+
+    newsos6)
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      ;;
+
+    *nto* | *qnx*)
+      # QNX uses GNU C++, but need to define -shared option too, otherwise
+      # it will coredump.
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-fPIC -shared'
+      ;;
+
+    osf3* | osf4* | osf5*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      # All OSF/1 code is PIC.
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+      ;;
+
+    rdos*)
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-non_shared'
+      ;;
+
+    solaris*)
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      case $cc_basename in
+      f77* | f90* | f95* | sunf77* | sunf90* | sunf95*)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Qoption ld ';;
+      *)
+	_LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,';;
+      esac
+      ;;
+
+    sunos4*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Qoption ld '
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-PIC'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      ;;
+
+    sysv4 | sysv4.2uw2* | sysv4.3*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec ;then
+	_LT_TAGVAR(lt_prog_compiler_pic, $1)='-Kconform_pic'
+	_LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      fi
+      ;;
+
+    sysv5* | unixware* | sco3.2v5* | sco5v6* | OpenUNIX*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-KPIC'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      ;;
+
+    unicos*)
+      _LT_TAGVAR(lt_prog_compiler_wl, $1)='-Wl,'
+      _LT_TAGVAR(lt_prog_compiler_can_build_shared, $1)=no
+      ;;
+
+    uts4*)
+      _LT_TAGVAR(lt_prog_compiler_pic, $1)='-pic'
+      _LT_TAGVAR(lt_prog_compiler_static, $1)='-Bstatic'
+      ;;
+
+    *)
+      _LT_TAGVAR(lt_prog_compiler_can_build_shared, $1)=no
+      ;;
+    esac
+  fi
+])
+case $host_os in
+  # For platforms which do not support PIC, -DPIC is meaningless:
+  *djgpp*)
+    _LT_TAGVAR(lt_prog_compiler_pic, $1)=
+    ;;
+  *)
+    _LT_TAGVAR(lt_prog_compiler_pic, $1)="$_LT_TAGVAR(lt_prog_compiler_pic, $1)@&t@m4_if([$1],[],[ -DPIC],[m4_if([$1],[CXX],[ -DPIC],[])])"
+    ;;
+esac
+
+AC_CACHE_CHECK([for $compiler option to produce PIC],
+  [_LT_TAGVAR(lt_cv_prog_compiler_pic, $1)],
+  [_LT_TAGVAR(lt_cv_prog_compiler_pic, $1)=$_LT_TAGVAR(lt_prog_compiler_pic, $1)])
+_LT_TAGVAR(lt_prog_compiler_pic, $1)=$_LT_TAGVAR(lt_cv_prog_compiler_pic, $1)
+
+#
+# Check to make sure the PIC flag actually works.
+#
+if test -n "$_LT_TAGVAR(lt_prog_compiler_pic, $1)"; then
+  _LT_COMPILER_OPTION([if $compiler PIC flag $_LT_TAGVAR(lt_prog_compiler_pic, $1) works],
+    [_LT_TAGVAR(lt_cv_prog_compiler_pic_works, $1)],
+    [$_LT_TAGVAR(lt_prog_compiler_pic, $1)@&t@m4_if([$1],[],[ -DPIC],[m4_if([$1],[CXX],[ -DPIC],[])])], [],
+    [case $_LT_TAGVAR(lt_prog_compiler_pic, $1) in
+     "" | " "*) ;;
+     *) _LT_TAGVAR(lt_prog_compiler_pic, $1)=" $_LT_TAGVAR(lt_prog_compiler_pic, $1)" ;;
+     esac],
+    [_LT_TAGVAR(lt_prog_compiler_pic, $1)=
+     _LT_TAGVAR(lt_prog_compiler_can_build_shared, $1)=no])
+fi
+_LT_TAGDECL([pic_flag], [lt_prog_compiler_pic], [1],
+	[Additional compiler flags for building library objects])
+
+_LT_TAGDECL([wl], [lt_prog_compiler_wl], [1],
+	[How to pass a linker flag through the compiler])
+#
+# Check to make sure the static flag actually works.
+#
+wl=$_LT_TAGVAR(lt_prog_compiler_wl, $1) eval lt_tmp_static_flag=\"$_LT_TAGVAR(lt_prog_compiler_static, $1)\"
+_LT_LINKER_OPTION([if $compiler static flag $lt_tmp_static_flag works],
+  _LT_TAGVAR(lt_cv_prog_compiler_static_works, $1),
+  $lt_tmp_static_flag,
+  [],
+  [_LT_TAGVAR(lt_prog_compiler_static, $1)=])
+_LT_TAGDECL([link_static_flag], [lt_prog_compiler_static], [1],
+	[Compiler flag to prevent dynamic linking])
+])# _LT_COMPILER_PIC
+
+
+# _LT_LINKER_SHLIBS([TAGNAME])
+# ----------------------------
+# See if the linker supports building shared libraries.
+m4_defun([_LT_LINKER_SHLIBS],
+[AC_REQUIRE([LT_PATH_LD])dnl
+AC_REQUIRE([LT_PATH_NM])dnl
+m4_require([_LT_PATH_MANIFEST_TOOL])dnl
+m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_DECL_EGREP])dnl
+m4_require([_LT_DECL_SED])dnl
+m4_require([_LT_CMD_GLOBAL_SYMBOLS])dnl
+m4_require([_LT_TAG_COMPILER])dnl
+AC_MSG_CHECKING([whether the $compiler linker ($LD) supports shared libraries])
+m4_if([$1], [CXX], [
+  _LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED '\''s/.* //'\'' | sort | uniq > $export_symbols'
+  _LT_TAGVAR(exclude_expsyms, $1)=['_GLOBAL_OFFSET_TABLE_|_GLOBAL__F[ID]_.*']
+  case $host_os in
+  aix[[4-9]]*)
+    # If we're using GNU nm, then we don't want the "-C" option.
+    # -C means demangle to AIX nm, but means don't demangle with GNU nm
+    # Also, AIX nm treats weak defined symbols like other global defined
+    # symbols, whereas GNU nm marks them as "W".
+    if $NM -V 2>&1 | $GREP 'GNU' > /dev/null; then
+      _LT_TAGVAR(export_symbols_cmds, $1)='$NM -Bpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B") || (\$ 2 == "W")) && ([substr](\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+    else
+      _LT_TAGVAR(export_symbols_cmds, $1)='$NM -BCpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B")) && ([substr](\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+    fi
+    ;;
+  pw32*)
+    _LT_TAGVAR(export_symbols_cmds, $1)="$ltdll_cmds"
+    ;;
+  cygwin* | mingw* | cegcc*)
+    case $cc_basename in
+    cl*)
+      _LT_TAGVAR(exclude_expsyms, $1)='_NULL_IMPORT_DESCRIPTOR|_IMPORT_DESCRIPTOR_.*'
+      ;;
+    *)
+      _LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED -e '\''/^[[BCDGRS]][[ ]]/s/.*[[ ]]\([[^ ]]*\)/\1 DATA/;s/^.*[[ ]]__nm__\([[^ ]]*\)[[ ]][[^ ]]*/\1 DATA/;/^I[[ ]]/d;/^[[AITW]][[ ]]/s/.* //'\'' | sort | uniq > $export_symbols'
+      _LT_TAGVAR(exclude_expsyms, $1)=['[_]+GLOBAL_OFFSET_TABLE_|[_]+GLOBAL__[FID]_.*|[_]+head_[A-Za-z0-9_]+_dll|[A-Za-z0-9_]+_dll_iname']
+      ;;
+    esac
+    ;;
+  linux* | k*bsd*-gnu | gnu*)
+    _LT_TAGVAR(link_all_deplibs, $1)=no
+    ;;
+  *)
+    _LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED '\''s/.* //'\'' | sort | uniq > $export_symbols'
+    ;;
+  esac
+], [
+  runpath_var=
+  _LT_TAGVAR(allow_undefined_flag, $1)=
+  _LT_TAGVAR(always_export_symbols, $1)=no
+  _LT_TAGVAR(archive_cmds, $1)=
+  _LT_TAGVAR(archive_expsym_cmds, $1)=
+  _LT_TAGVAR(compiler_needs_object, $1)=no
+  _LT_TAGVAR(enable_shared_with_static_runtimes, $1)=no
+  _LT_TAGVAR(export_dynamic_flag_spec, $1)=
+  _LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED '\''s/.* //'\'' | sort | uniq > $export_symbols'
+  _LT_TAGVAR(hardcode_automatic, $1)=no
+  _LT_TAGVAR(hardcode_direct, $1)=no
+  _LT_TAGVAR(hardcode_direct_absolute, $1)=no
+  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)=
+  _LT_TAGVAR(hardcode_libdir_separator, $1)=
+  _LT_TAGVAR(hardcode_minus_L, $1)=no
+  _LT_TAGVAR(hardcode_shlibpath_var, $1)=unsupported
+  _LT_TAGVAR(inherit_rpath, $1)=no
+  _LT_TAGVAR(link_all_deplibs, $1)=unknown
+  _LT_TAGVAR(module_cmds, $1)=
+  _LT_TAGVAR(module_expsym_cmds, $1)=
+  _LT_TAGVAR(old_archive_from_new_cmds, $1)=
+  _LT_TAGVAR(old_archive_from_expsyms_cmds, $1)=
+  _LT_TAGVAR(thread_safe_flag_spec, $1)=
+  _LT_TAGVAR(whole_archive_flag_spec, $1)=
+  # include_expsyms should be a list of space-separated symbols to be *always*
+  # included in the symbol list
+  _LT_TAGVAR(include_expsyms, $1)=
+  # exclude_expsyms can be an extended regexp of symbols to exclude
+  # it will be wrapped by ` (' and `)$', so one must not match beginning or
+  # end of line.  Example: `a|bc|.*d.*' will exclude the symbols `a' and `bc',
+  # as well as any symbol that contains `d'.
+  _LT_TAGVAR(exclude_expsyms, $1)=['_GLOBAL_OFFSET_TABLE_|_GLOBAL__F[ID]_.*']
+  # Although _GLOBAL_OFFSET_TABLE_ is a valid symbol C name, most a.out
+  # platforms (ab)use it in PIC code, but their linkers get confused if
+  # the symbol is explicitly referenced.  Since portable code cannot
+  # rely on this symbol name, it's probably fine to never include it in
+  # preloaded symbol tables.
+  # Exclude shared library initialization/finalization symbols.
+dnl Note also adjust exclude_expsyms for C++ above.
+  extract_expsyms_cmds=
+
+  case $host_os in
+  cygwin* | mingw* | pw32* | cegcc*)
+    # FIXME: the MSVC++ port hasn't been tested in a loooong time
+    # When not using gcc, we currently assume that we are using
+    # Microsoft Visual C++.
+    if test "$GCC" != yes; then
+      with_gnu_ld=no
+    fi
+    ;;
+  interix*)
+    # we just hope/assume this is gcc and not c89 (= MSVC++)
+    with_gnu_ld=yes
+    ;;
+  openbsd*)
+    with_gnu_ld=no
+    ;;
+  linux* | k*bsd*-gnu | gnu*)
+    _LT_TAGVAR(link_all_deplibs, $1)=no
+    ;;
+  esac
+
+  _LT_TAGVAR(ld_shlibs, $1)=yes
+
+  # On some targets, GNU ld is compatible enough with the native linker
+  # that we're better off using the native interface for both.
+  lt_use_gnu_ld_interface=no
+  if test "$with_gnu_ld" = yes; then
+    case $host_os in
+      aix*)
+	# The AIX port of GNU ld has always aspired to compatibility
+	# with the native linker.  However, as the warning in the GNU ld
+	# block says, versions before 2.19.5* couldn't really create working
+	# shared libraries, regardless of the interface used.
+	case `$LD -v 2>&1` in
+	  *\ \(GNU\ Binutils\)\ 2.19.5*) ;;
+	  *\ \(GNU\ Binutils\)\ 2.[[2-9]]*) ;;
+	  *\ \(GNU\ Binutils\)\ [[3-9]]*) ;;
+	  *)
+	    lt_use_gnu_ld_interface=yes
+	    ;;
+	esac
+	;;
+      *)
+	lt_use_gnu_ld_interface=yes
+	;;
+    esac
+  fi
+
+  if test "$lt_use_gnu_ld_interface" = yes; then
+    # If archive_cmds runs LD, not CC, wlarc should be empty
+    wlarc='${wl}'
+
+    # Set some defaults for GNU ld with shared library support. These
+    # are reset later if shared libraries are not supported. Putting them
+    # here allows them to be overridden if necessary.
+    runpath_var=LD_RUN_PATH
+    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+    # ancient GNU ld didn't support --whole-archive et. al.
+    if $LD --help 2>&1 | $GREP 'no-whole-archive' > /dev/null; then
+      _LT_TAGVAR(whole_archive_flag_spec, $1)="$wlarc"'--whole-archive$convenience '"$wlarc"'--no-whole-archive'
+    else
+      _LT_TAGVAR(whole_archive_flag_spec, $1)=
+    fi
+    supports_anon_versioning=no
+    case `$LD -v 2>&1` in
+      *GNU\ gold*) supports_anon_versioning=yes ;;
+      *\ [[01]].* | *\ 2.[[0-9]].* | *\ 2.10.*) ;; # catch versions < 2.11
+      *\ 2.11.93.0.2\ *) supports_anon_versioning=yes ;; # RH7.3 ...
+      *\ 2.11.92.0.12\ *) supports_anon_versioning=yes ;; # Mandrake 8.2 ...
+      *\ 2.11.*) ;; # other 2.11 versions
+      *) supports_anon_versioning=yes ;;
+    esac
+
+    # See if GNU ld supports shared libraries.
+    case $host_os in
+    aix[[3-9]]*)
+      # On AIX/PPC, the GNU linker is very broken
+      if test "$host_cpu" != ia64; then
+	_LT_TAGVAR(ld_shlibs, $1)=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: the GNU linker, at least up to release 2.19, is reported
+*** to be unable to reliably create shared libraries on AIX.
+*** Therefore, libtool is disabling shared libraries support.  If you
+*** really care for shared libraries, you may want to install binutils
+*** 2.20 or above, or modify your PATH so that a non-GNU linker is found.
+*** You will then need to restart the configuration process.
+
+_LT_EOF
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+            _LT_TAGVAR(archive_expsym_cmds, $1)=''
+        ;;
+      m68k)
+            _LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/a2ixlibrary.data~$ECHO "#define NAME $libname" > $output_objdir/a2ixlibrary.data~$ECHO "#define LIBRARY_ID 1" >> $output_objdir/a2ixlibrary.data~$ECHO "#define VERSION $major" >> $output_objdir/a2ixlibrary.data~$ECHO "#define REVISION $revision" >> $output_objdir/a2ixlibrary.data~$AR $AR_FLAGS $lib $libobjs~$RANLIB $lib~(cd $output_objdir && a2ixlibrary -32)'
+            _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+            _LT_TAGVAR(hardcode_minus_L, $1)=yes
+        ;;
+      esac
+      ;;
+
+    beos*)
+      if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	_LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	# Joseph Beckenbach <jrb3@best.com> says some releases of gcc
+	# support --undefined.  This deserves some investigation.  FIXME
+	_LT_TAGVAR(archive_cmds, $1)='$CC -nostart $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+      else
+	_LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+
+    cygwin* | mingw* | pw32* | cegcc*)
+      # _LT_TAGVAR(hardcode_libdir_flag_spec, $1) is actually meaningless,
+      # as there is no search path for DLLs.
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-all-symbols'
+      _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+      _LT_TAGVAR(always_export_symbols, $1)=no
+      _LT_TAGVAR(enable_shared_with_static_runtimes, $1)=yes
+      _LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED -e '\''/^[[BCDGRS]][[ ]]/s/.*[[ ]]\([[^ ]]*\)/\1 DATA/;s/^.*[[ ]]__nm__\([[^ ]]*\)[[ ]][[^ ]]*/\1 DATA/;/^I[[ ]]/d;/^[[AITW]][[ ]]/s/.* //'\'' | sort | uniq > $export_symbols'
+      _LT_TAGVAR(exclude_expsyms, $1)=['[_]+GLOBAL_OFFSET_TABLE_|[_]+GLOBAL__[FID]_.*|[_]+head_[A-Za-z0-9_]+_dll|[A-Za-z0-9_]+_dll_iname']
+
+      if $LD --help 2>&1 | $GREP 'auto-import' > /dev/null; then
+        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+	# If the export-symbols file already is a .def file (1st line
+	# is EXPORTS), use it as is; otherwise, prepend...
+	_LT_TAGVAR(archive_expsym_cmds, $1)='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	  cp $export_symbols $output_objdir/$soname.def;
+	else
+	  echo EXPORTS > $output_objdir/$soname.def;
+	  cat $export_symbols >> $output_objdir/$soname.def;
+	fi~
+	$CC -shared $output_objdir/$soname.def $libobjs $deplibs $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+      else
+	_LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+
+    haiku*)
+      _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+      _LT_TAGVAR(link_all_deplibs, $1)=yes
+      ;;
+
+    interix[[3-9]]*)
+      _LT_TAGVAR(hardcode_direct, $1)=no
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+      # Hack: On Interix 3.x, we cannot compile PIC because of a broken gcc.
+      # Instead, shared libraries are loaded at an image base (0x10000000 by
+      # default) and relocated if they conflict, which is a slow very memory
+      # consuming and fragmenting process.  To avoid this, we pick a random,
+      # 256 KiB-aligned image base between 0x50000000 and 0x6FFC0000 at link
+      # time.  Moving up from 0x10000000 also allows more sbrk(2) space.
+      _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+      _LT_TAGVAR(archive_expsym_cmds, $1)='sed "s,^,_," $export_symbols >$output_objdir/$soname.expsym~$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--retain-symbols-file,$output_objdir/$soname.expsym ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+      ;;
+
+    gnu* | linux* | tpf* | k*bsd*-gnu | kopensolaris*-gnu)
+      tmp_diet=no
+      if test "$host_os" = linux-dietlibc; then
+	case $cc_basename in
+	  diet\ *) tmp_diet=yes;;	# linux-dietlibc with static linking (!diet-dyn)
+	esac
+      fi
+      if $LD --help 2>&1 | $EGREP ': supported targets:.* elf' > /dev/null \
+	 && test "$tmp_diet" = no
+      then
+	tmp_addflag=' $pic_flag'
+	tmp_sharedflag='-shared'
+	case $cc_basename,$host_cpu in
+        pgcc*)				# Portland Group C compiler
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  tmp_addflag=' $pic_flag'
+	  ;;
+	pgf77* | pgf90* | pgf95* | pgfortran*)
+					# Portland Group f77 and f90 compilers
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  tmp_addflag=' $pic_flag -Mnomain' ;;
+	ecc*,ia64* | icc*,ia64*)	# Intel C compiler on ia64
+	  tmp_addflag=' -i_dynamic' ;;
+	efc*,ia64* | ifort*,ia64*)	# Intel Fortran compiler on ia64
+	  tmp_addflag=' -i_dynamic -nofor_main' ;;
+	ifc* | ifort*)			# Intel Fortran compiler
+	  tmp_addflag=' -nofor_main' ;;
+	lf95*)				# Lahey Fortran 8.1
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)=
+	  tmp_sharedflag='--shared' ;;
+	xl[[cC]]* | bgxl[[cC]]* | mpixl[[cC]]*) # IBM XL C 8.0 on PPC (deal with xlf below)
+	  tmp_sharedflag='-qmkshrobj'
+	  tmp_addflag= ;;
+	nvcc*)	# Cuda Compiler Driver 2.2
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  _LT_TAGVAR(compiler_needs_object, $1)=yes
+	  ;;
+	esac
+	case `$CC -V 2>&1 | sed 5q` in
+	*Sun\ C*)			# Sun C 5.9
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`new_convenience=; for conv in $convenience\"\"; do test -z \"$conv\" || new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	  _LT_TAGVAR(compiler_needs_object, $1)=yes
+	  tmp_sharedflag='-G' ;;
+	*Sun\ F*)			# Sun Fortran 8.3
+	  tmp_sharedflag='-G' ;;
+	esac
+	_LT_TAGVAR(archive_cmds, $1)='$CC '"$tmp_sharedflag""$tmp_addflag"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+
+        if test "x$supports_anon_versioning" = xyes; then
+          _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $output_objdir/$libname.ver~
+	    cat $export_symbols | sed -e "s/\(.*\)/\1;/" >> $output_objdir/$libname.ver~
+	    echo "local: *; };" >> $output_objdir/$libname.ver~
+	    $CC '"$tmp_sharedflag""$tmp_addflag"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-version-script ${wl}$output_objdir/$libname.ver -o $lib'
+        fi
+
+	case $cc_basename in
+	xlf* | bgf* | bgxlf* | mpixlf*)
+	  # IBM XL Fortran 10.1 on PPC cannot create shared libs itself
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='--whole-archive$convenience --no-whole-archive'
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -shared $libobjs $deplibs $linker_flags -soname $soname -o $lib'
+	  if test "x$supports_anon_versioning" = xyes; then
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $output_objdir/$libname.ver~
+	      cat $export_symbols | sed -e "s/\(.*\)/\1;/" >> $output_objdir/$libname.ver~
+	      echo "local: *; };" >> $output_objdir/$libname.ver~
+	      $LD -shared $libobjs $deplibs $linker_flags -soname $soname -version-script $output_objdir/$libname.ver -o $lib'
+	  fi
+	  ;;
+	esac
+      else
+        _LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+
+    netbsd* | netbsdelf*-gnu)
+      if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+	_LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable $libobjs $deplibs $linker_flags -o $lib'
+	wlarc=
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      fi
+      ;;
+
+    solaris*)
+      if $LD -v 2>&1 | $GREP 'BFD 2\.8' > /dev/null; then
+	_LT_TAGVAR(ld_shlibs, $1)=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: The releases 2.8.* of the GNU linker cannot reliably
+*** create shared libraries on Solaris systems.  Therefore, libtool
+*** is disabling shared libraries support.  We urge you to upgrade GNU
+*** binutils to release 2.9.1 or newer.  Another option is to modify
+*** your PATH or compiler configuration so that the native linker is
+*** used, and then restart.
+
+_LT_EOF
+      elif $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      else
+	_LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+
+    sysv5* | sco3.2v5* | sco5v6* | unixware* | OpenUNIX*)
+      case `$LD -v 2>&1` in
+        *\ [[01]].* | *\ 2.[[0-9]].* | *\ 2.1[[0-5]].*)
+	_LT_TAGVAR(ld_shlibs, $1)=no
+	cat <<_LT_EOF 1>&2
+
+*** Warning: Releases of the GNU linker prior to 2.16.91.0.3 can not
+*** reliably create shared libraries on SCO systems.  Therefore, libtool
+*** is disabling shared libraries support.  We urge you to upgrade GNU
+*** binutils to release 2.16.91.0.3 or newer.  Another option is to modify
+*** your PATH or compiler configuration so that the native linker is
+*** used, and then restart.
+
+_LT_EOF
+	;;
+	*)
+	  # For security reasons, it is highly recommended that you always
+	  # use absolute paths for naming shared libraries, and exclude the
+	  # DT_RUNPATH tag from executables and libraries.  But doing so
+	  # requires that you compile everything twice, which is a pain.
+	  if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+	  else
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	  fi
+	;;
+      esac
+      ;;
+
+    sunos4*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -assert pure-text -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+      wlarc=
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    *)
+      if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+      else
+	_LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+    esac
+
+    if test "$_LT_TAGVAR(ld_shlibs, $1)" = no; then
+      runpath_var=
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)=
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)=
+      _LT_TAGVAR(whole_archive_flag_spec, $1)=
+    fi
+  else
+    # PORTME fill in a description of your system's linker (not GNU ld)
+    case $host_os in
+    aix3*)
+      _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+      _LT_TAGVAR(always_export_symbols, $1)=yes
+      _LT_TAGVAR(archive_expsym_cmds, $1)='$LD -o $output_objdir/$soname $libobjs $deplibs $linker_flags -bE:$export_symbols -T512 -H512 -bM:SRE~$AR $AR_FLAGS $lib $output_objdir/$soname'
+      # Note: this linker hardcodes the directories in LIBPATH if there
+      # are no directories specified by -L.
+      _LT_TAGVAR(hardcode_minus_L, $1)=yes
+      if test "$GCC" = yes && test -z "$lt_prog_compiler_static"; then
+	# Neither direct hardcoding nor static linking is supported with a
+	# broken collect2.
+	_LT_TAGVAR(hardcode_direct, $1)=unsupported
+      fi
+      ;;
+
+    aix[[4-9]]*)
+      if test "$host_cpu" = ia64; then
+	# On IA64, the linker does run time linking by default, so we don't
+	# have to do anything special.
+	aix_use_runtimelinking=no
+	exp_sym_flag='-Bexport'
+	no_entry_flag=""
+      else
+	# If we're using GNU nm, then we don't want the "-C" option.
+	# -C means demangle to AIX nm, but means don't demangle with GNU nm
+	# Also, AIX nm treats weak defined symbols like other global
+	# defined symbols, whereas GNU nm marks them as "W".
+	if $NM -V 2>&1 | $GREP 'GNU' > /dev/null; then
+	  _LT_TAGVAR(export_symbols_cmds, $1)='$NM -Bpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B") || (\$ 2 == "W")) && ([substr](\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+	else
+	  _LT_TAGVAR(export_symbols_cmds, $1)='$NM -BCpg $libobjs $convenience | awk '\''{ if (((\$ 2 == "T") || (\$ 2 == "D") || (\$ 2 == "B")) && ([substr](\$ 3,1,1) != ".")) { print \$ 3 } }'\'' | sort -u > $export_symbols'
+	fi
+	aix_use_runtimelinking=no
+
+	# Test if we are trying to use run time linking or normal
+	# AIX style linking. If -brtl is somewhere in LDFLAGS, we
+	# need to do runtime linking.
+	case $host_os in aix4.[[23]]|aix4.[[23]].*|aix[[5-9]]*)
+	  for ld_flag in $LDFLAGS; do
+	  if (test $ld_flag = "-brtl" || test $ld_flag = "-Wl,-brtl"); then
+	    aix_use_runtimelinking=yes
+	    break
+	  fi
+	  done
+	  ;;
+	esac
+
+	exp_sym_flag='-bexport'
+	no_entry_flag='-bnoentry'
+      fi
+
+      # When large executables or shared objects are built, AIX ld can
+      # have problems creating the table of contents.  If linking a library
+      # or program results in "error TOC overflow" add -mminimal-toc to
+      # CXXFLAGS/CFLAGS for g++/gcc.  In the cases where that is not
+      # enough to fix the problem, add -Wl,-bbigtoc to LDFLAGS.
+
+      _LT_TAGVAR(archive_cmds, $1)=''
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=':'
+      _LT_TAGVAR(link_all_deplibs, $1)=yes
+      _LT_TAGVAR(file_list_spec, $1)='${wl}-f,'
+
+      if test "$GCC" = yes; then
+	case $host_os in aix4.[[012]]|aix4.[[012]].*)
+	# We only want to do this on AIX 4.2 and lower, the check
+	# below for broken collect2 doesn't work under 4.3+
+	  collect2name=`${CC} -print-prog-name=collect2`
+	  if test -f "$collect2name" &&
+	   strings "$collect2name" | $GREP resolve_lib_name >/dev/null
+	  then
+	  # We have reworked collect2
+	  :
+	  else
+	  # We have old collect2
+	  _LT_TAGVAR(hardcode_direct, $1)=unsupported
+	  # It fails to find uninstalled libraries when the uninstalled
+	  # path is not listed in the libpath.  Setting hardcode_minus_L
+	  # to unsupported forces relinking
+	  _LT_TAGVAR(hardcode_minus_L, $1)=yes
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+	  _LT_TAGVAR(hardcode_libdir_separator, $1)=
+	  fi
+	  ;;
+	esac
+	shared_flag='-shared'
+	if test "$aix_use_runtimelinking" = yes; then
+	  shared_flag="$shared_flag "'${wl}-G'
+	fi
+	_LT_TAGVAR(link_all_deplibs, $1)=no
+      else
+	# not using gcc
+	if test "$host_cpu" = ia64; then
+	# VisualAge C++, Version 5.5 for AIX 5L for IA-64, Beta 3 Release
+	# chokes on -Wl,-G. The following line is correct:
+	  shared_flag='-G'
+	else
+	  if test "$aix_use_runtimelinking" = yes; then
+	    shared_flag='${wl}-G'
+	  else
+	    shared_flag='${wl}-bM:SRE'
+	  fi
+	fi
+      fi
+
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-bexpall'
+      # It seems that -bexpall does not export symbols beginning with
+      # underscore (_), so it is better to generate a list of symbols to export.
+      _LT_TAGVAR(always_export_symbols, $1)=yes
+      if test "$aix_use_runtimelinking" = yes; then
+	# Warning - without using the other runtime loading flags (-brtl),
+	# -berok will link without error, but may produce a broken library.
+	_LT_TAGVAR(allow_undefined_flag, $1)='-berok'
+        # Determine the default libpath from the value encoded in an
+        # empty executable.
+        _LT_SYS_MODULE_PATH_AIX([$1])
+        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-blibpath:$libdir:'"$aix_libpath"
+        _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags `if test "x${allow_undefined_flag}" != "x"; then func_echo_all "${wl}${allow_undefined_flag}"; else :; fi` '"\${wl}$exp_sym_flag:\$export_symbols $shared_flag"
+      else
+	if test "$host_cpu" = ia64; then
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-R $libdir:/usr/lib:/lib'
+	  _LT_TAGVAR(allow_undefined_flag, $1)="-z nodefs"
+	  _LT_TAGVAR(archive_expsym_cmds, $1)="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags ${wl}${allow_undefined_flag} '"\${wl}$exp_sym_flag:\$export_symbols"
+	else
+	 # Determine the default libpath from the value encoded in an
+	 # empty executable.
+	 _LT_SYS_MODULE_PATH_AIX([$1])
+	 _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-blibpath:$libdir:'"$aix_libpath"
+	  # Warning - without using the other run time loading flags,
+	  # -berok will link without error, but may produce a broken library.
+	  _LT_TAGVAR(no_undefined_flag, $1)=' ${wl}-bernotok'
+	  _LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-berok'
+	  if test "$with_gnu_ld" = yes; then
+	    # We only use this code for GNU lds that support --whole-archive.
+	    _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive$convenience ${wl}--no-whole-archive'
+	  else
+	    # Exported symbols can be pulled into shared objects from archives
+	    _LT_TAGVAR(whole_archive_flag_spec, $1)='$convenience'
+	  fi
+	  _LT_TAGVAR(archive_cmds_need_lc, $1)=yes
+	  # This is similar to how AIX traditionally builds its shared libraries.
+	  _LT_TAGVAR(archive_expsym_cmds, $1)="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs ${wl}-bnoentry $compiler_flags ${wl}-bE:$export_symbols${allow_undefined_flag}~$AR $AR_FLAGS $output_objdir/$libname$release.a $output_objdir/$soname'
+	fi
+      fi
+      ;;
+
+    amigaos*)
+      case $host_cpu in
+      powerpc)
+            # see comment about AmigaOS4 .so support
+            _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+            _LT_TAGVAR(archive_expsym_cmds, $1)=''
+        ;;
+      m68k)
+            _LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/a2ixlibrary.data~$ECHO "#define NAME $libname" > $output_objdir/a2ixlibrary.data~$ECHO "#define LIBRARY_ID 1" >> $output_objdir/a2ixlibrary.data~$ECHO "#define VERSION $major" >> $output_objdir/a2ixlibrary.data~$ECHO "#define REVISION $revision" >> $output_objdir/a2ixlibrary.data~$AR $AR_FLAGS $lib $libobjs~$RANLIB $lib~(cd $output_objdir && a2ixlibrary -32)'
+            _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+            _LT_TAGVAR(hardcode_minus_L, $1)=yes
+        ;;
+      esac
+      ;;
+
+    bsdi[[45]]*)
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)=-rdynamic
+      ;;
+
+    cygwin* | mingw* | pw32* | cegcc*)
+      # When not using gcc, we currently assume that we are using
+      # Microsoft Visual C++.
+      # hardcode_libdir_flag_spec is actually meaningless, as there is
+      # no search path for DLLs.
+      case $cc_basename in
+      cl*)
+	# Native MSVC
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)=' '
+	_LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	_LT_TAGVAR(always_export_symbols, $1)=yes
+	_LT_TAGVAR(file_list_spec, $1)='@'
+	# Tell ltmain to make .lib files, not .a files.
+	libext=lib
+	# Tell ltmain to make .dll files, not .so files.
+	shrext_cmds=".dll"
+	# FIXME: Setting linknames here is a bad hack.
+	_LT_TAGVAR(archive_cmds, $1)='$CC -o $output_objdir/$soname $libobjs $compiler_flags $deplibs -Wl,-dll~linknames='
+	_LT_TAGVAR(archive_expsym_cmds, $1)='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	    sed -n -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' -e '1\\\!p' < $export_symbols > $output_objdir/$soname.exp;
+	  else
+	    sed -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' < $export_symbols > $output_objdir/$soname.exp;
+	  fi~
+	  $CC -o $tool_output_objdir$soname $libobjs $compiler_flags $deplibs "@$tool_output_objdir$soname.exp" -Wl,-DLL,-IMPLIB:"$tool_output_objdir$libname.dll.lib"~
+	  linknames='
+	# The linker will not automatically build a static lib if we build a DLL.
+	# _LT_TAGVAR(old_archive_from_new_cmds, $1)='true'
+	_LT_TAGVAR(enable_shared_with_static_runtimes, $1)=yes
+	_LT_TAGVAR(exclude_expsyms, $1)='_NULL_IMPORT_DESCRIPTOR|_IMPORT_DESCRIPTOR_.*'
+	_LT_TAGVAR(export_symbols_cmds, $1)='$NM $libobjs $convenience | $global_symbol_pipe | $SED -e '\''/^[[BCDGRS]][[ ]]/s/.*[[ ]]\([[^ ]]*\)/\1,DATA/'\'' | $SED -e '\''/^[[AITW]][[ ]]/s/.*[[ ]]//'\'' | sort | uniq > $export_symbols'
+	# Don't use ranlib
+	_LT_TAGVAR(old_postinstall_cmds, $1)='chmod 644 $oldlib'
+	_LT_TAGVAR(postlink_cmds, $1)='lt_outputfile="@OUTPUT@"~
+	  lt_tool_outputfile="@TOOL_OUTPUT@"~
+	  case $lt_outputfile in
+	    *.exe|*.EXE) ;;
+	    *)
+	      lt_outputfile="$lt_outputfile.exe"
+	      lt_tool_outputfile="$lt_tool_outputfile.exe"
+	      ;;
+	  esac~
+	  if test "$MANIFEST_TOOL" != ":" && test -f "$lt_outputfile.manifest"; then
+	    $MANIFEST_TOOL -manifest "$lt_tool_outputfile.manifest" -outputresource:"$lt_tool_outputfile" || exit 1;
+	    $RM "$lt_outputfile.manifest";
+	  fi'
+	;;
+      *)
+	# Assume MSVC wrapper
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)=' '
+	_LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	# Tell ltmain to make .lib files, not .a files.
+	libext=lib
+	# Tell ltmain to make .dll files, not .so files.
+	shrext_cmds=".dll"
+	# FIXME: Setting linknames here is a bad hack.
+	_LT_TAGVAR(archive_cmds, $1)='$CC -o $lib $libobjs $compiler_flags `func_echo_all "$deplibs" | $SED '\''s/ -lc$//'\''` -link -dll~linknames='
+	# The linker will automatically build a .lib file if we build a DLL.
+	_LT_TAGVAR(old_archive_from_new_cmds, $1)='true'
+	# FIXME: Should let the user specify the lib program.
+	_LT_TAGVAR(old_archive_cmds, $1)='lib -OUT:$oldlib$oldobjs$old_deplibs'
+	_LT_TAGVAR(enable_shared_with_static_runtimes, $1)=yes
+	;;
+      esac
+      ;;
+
+    darwin* | rhapsody*)
+      _LT_DARWIN_LINKER_FEATURES($1)
+      ;;
+
+    dgux*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    # FreeBSD 2.2.[012] allows us to include c++rt0.o to get C++ constructor
+    # support.  Future versions do this automatically, but an explicit c++rt0.o
+    # does not break anything, and helps significantly (at the cost of a little
+    # extra space).
+    freebsd2.2*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags /usr/lib/c++rt0.o'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    # Unfortunately, older versions of FreeBSD 2 do not have this feature.
+    freebsd2.*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_minus_L, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    # FreeBSD 3 and greater uses gcc -shared to do shared libraries.
+    freebsd* | dragonfly*)
+      _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    hpux9*)
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/$soname~$CC -shared $pic_flag ${wl}+b ${wl}$install_libdir -o $output_objdir/$soname $libobjs $deplibs $compiler_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/$soname~$LD -b +b $install_libdir -o $output_objdir/$soname $libobjs $deplibs $linker_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+      fi
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}+b ${wl}$libdir'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+
+      # hardcode_minus_L: Not really in the search PATH,
+      # but as the default location of the library.
+      _LT_TAGVAR(hardcode_minus_L, $1)=yes
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+      ;;
+
+    hpux10*)
+      if test "$GCC" = yes && test "$with_gnu_ld" = no; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$LD -b +h $soname +b $install_libdir -o $lib $libobjs $deplibs $linker_flags'
+      fi
+      if test "$with_gnu_ld" = no; then
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}+b ${wl}$libdir'
+	_LT_TAGVAR(hardcode_libdir_separator, $1)=:
+	_LT_TAGVAR(hardcode_direct, $1)=yes
+	_LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+	_LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+	# hardcode_minus_L: Not really in the search PATH,
+	# but as the default location of the library.
+	_LT_TAGVAR(hardcode_minus_L, $1)=yes
+      fi
+      ;;
+
+    hpux11*)
+      if test "$GCC" = yes && test "$with_gnu_ld" = no; then
+	case $host_cpu in
+	hppa*64*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared ${wl}+h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	ia64*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	esac
+      else
+	case $host_cpu in
+	hppa*64*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	ia64*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	*)
+	m4_if($1, [], [
+	  # Older versions of the 11.00 compiler do not understand -b yet
+	  # (HP92453-01 A.11.01.20 doesn't, HP92453-01 B.11.X.35175-35176.GP does)
+	  _LT_LINKER_OPTION([if $CC understands -b],
+	    _LT_TAGVAR(lt_cv_prog_compiler__b, $1), [-b],
+	    [_LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'],
+	    [_LT_TAGVAR(archive_cmds, $1)='$LD -b +h $soname +b $install_libdir -o $lib $libobjs $deplibs $linker_flags'])],
+	  [_LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $libobjs $deplibs $compiler_flags'])
+	  ;;
+	esac
+      fi
+      if test "$with_gnu_ld" = no; then
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}+b ${wl}$libdir'
+	_LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+	case $host_cpu in
+	hppa*64*|ia64*)
+	  _LT_TAGVAR(hardcode_direct, $1)=no
+	  _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	  ;;
+	*)
+	  _LT_TAGVAR(hardcode_direct, $1)=yes
+	  _LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+	  _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+
+	  # hardcode_minus_L: Not really in the search PATH,
+	  # but as the default location of the library.
+	  _LT_TAGVAR(hardcode_minus_L, $1)=yes
+	  ;;
+	esac
+      fi
+      ;;
+
+    irix5* | irix6* | nonstopux*)
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+	# Try to use the -exported_symbol ld option, if it does not
+	# work, assume that -exports_file does not work either and
+	# implicitly export all symbols.
+	# This should be the same for all languages, so no per-tag cache variable.
+	AC_CACHE_CHECK([whether the $host_os linker accepts -exported_symbol],
+	  [lt_cv_irix_exported_symbol],
+	  [save_LDFLAGS="$LDFLAGS"
+	   LDFLAGS="$LDFLAGS -shared ${wl}-exported_symbol ${wl}foo ${wl}-update_registry ${wl}/dev/null"
+	   AC_LINK_IFELSE(
+	     [AC_LANG_SOURCE(
+	        [AC_LANG_CASE([C], [[int foo (void) { return 0; }]],
+			      [C++], [[int foo (void) { return 0; }]],
+			      [Fortran 77], [[
+      subroutine foo
+      end]],
+			      [Fortran], [[
+      subroutine foo
+      end]])])],
+	      [lt_cv_irix_exported_symbol=yes],
+	      [lt_cv_irix_exported_symbol=no])
+           LDFLAGS="$save_LDFLAGS"])
+	if test "$lt_cv_irix_exported_symbol" = yes; then
+          _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations ${wl}-exports_file ${wl}$export_symbols -o $lib'
+	fi
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -exports_file $export_symbols -o $lib'
+      fi
+      _LT_TAGVAR(archive_cmds_need_lc, $1)='no'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+      _LT_TAGVAR(inherit_rpath, $1)=yes
+      _LT_TAGVAR(link_all_deplibs, $1)=yes
+      ;;
+
+    netbsd* | netbsdelf*-gnu)
+      if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+	_LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'  # a.out
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$LD -shared -o $lib $libobjs $deplibs $linker_flags'      # ELF
+      fi
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    newsos6)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    *nto* | *qnx*)
+      ;;
+
+    openbsd*)
+      if test -f /usr/libexec/ld.so; then
+	_LT_TAGVAR(hardcode_direct, $1)=yes
+	_LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	_LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+	if test -z "`echo __ELF__ | $CC -E - | $GREP __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags ${wl}-retain-symbols-file,$export_symbols'
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	  _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+	else
+	  case $host_os in
+	   openbsd[[01]].* | openbsd2.[[0-7]] | openbsd2.[[0-7]].*)
+	     _LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable -o $lib $libobjs $deplibs $linker_flags'
+	     _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+	     ;;
+	   *)
+	     _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -o $lib $libobjs $deplibs $compiler_flags'
+	     _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	     ;;
+	  esac
+	fi
+      else
+	_LT_TAGVAR(ld_shlibs, $1)=no
+      fi
+      ;;
+
+    os2*)
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+      _LT_TAGVAR(hardcode_minus_L, $1)=yes
+      _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+      _LT_TAGVAR(archive_cmds, $1)='$ECHO "LIBRARY $libname INITINSTANCE" > $output_objdir/$libname.def~$ECHO "DESCRIPTION \"$libname\"" >> $output_objdir/$libname.def~echo DATA >> $output_objdir/$libname.def~echo " SINGLE NONSHARED" >> $output_objdir/$libname.def~echo EXPORTS >> $output_objdir/$libname.def~emxexp $libobjs >> $output_objdir/$libname.def~$CC -Zdll -Zcrtdll -o $lib $libobjs $deplibs $compiler_flags $output_objdir/$libname.def'
+      _LT_TAGVAR(old_archive_from_new_cmds, $1)='emximp -o $output_objdir/$libname.a $output_objdir/$libname.def'
+      ;;
+
+    osf3*)
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-expect_unresolved ${wl}\*'
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+      else
+	_LT_TAGVAR(allow_undefined_flag, $1)=' -expect_unresolved \*'
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+      fi
+      _LT_TAGVAR(archive_cmds_need_lc, $1)='no'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+      ;;
+
+    osf4* | osf5*)	# as osf3* with the addition of -msym flag
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-expect_unresolved ${wl}\*'
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $pic_flag $libobjs $deplibs $compiler_flags ${wl}-msym ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+      else
+	_LT_TAGVAR(allow_undefined_flag, $1)=' -expect_unresolved \*'
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $libobjs $deplibs $compiler_flags -msym -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='for i in `cat $export_symbols`; do printf "%s %s\\n" -exported_symbol "\$i" >> $lib.exp; done; printf "%s\\n" "-hidden">> $lib.exp~
+	$CC -shared${allow_undefined_flag} ${wl}-input ${wl}$lib.exp $compiler_flags $libobjs $deplibs -soname $soname `test -n "$verstring" && $ECHO "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib~$RM $lib.exp'
+
+	# Both c and cxx compiler support -rpath directly
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-rpath $libdir'
+      fi
+      _LT_TAGVAR(archive_cmds_need_lc, $1)='no'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+      ;;
+
+    solaris*)
+      _LT_TAGVAR(no_undefined_flag, $1)=' -z defs'
+      if test "$GCC" = yes; then
+	wlarc='${wl}'
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag ${wl}-z ${wl}text ${wl}-h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $CC -shared $pic_flag ${wl}-z ${wl}text ${wl}-M ${wl}$lib.exp ${wl}-h ${wl}$soname -o $lib $libobjs $deplibs $compiler_flags~$RM $lib.exp'
+      else
+	case `$CC -V 2>&1` in
+	*"Compilers 5.0"*)
+	  wlarc=''
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -G${allow_undefined_flag} -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $LD -G${allow_undefined_flag} -M $lib.exp -h $soname -o $lib $libobjs $deplibs $linker_flags~$RM $lib.exp'
+	  ;;
+	*)
+	  wlarc='${wl}'
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -G${allow_undefined_flag} -h $soname -o $lib $libobjs $deplibs $compiler_flags'
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	  $CC -G${allow_undefined_flag} -M $lib.exp -h $soname -o $lib $libobjs $deplibs $compiler_flags~$RM $lib.exp'
+	  ;;
+	esac
+      fi
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      case $host_os in
+      solaris2.[[0-5]] | solaris2.[[0-5]].*) ;;
+      *)
+	# The compiler driver will combine and reorder linker options,
+	# but understands `-z linker_flag'.  GCC discards it without `$wl',
+	# but is careful enough not to reorder.
+	# Supported since Solaris 2.6 (maybe 2.5.1?)
+	if test "$GCC" = yes; then
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}-z ${wl}allextract$convenience ${wl}-z ${wl}defaultextract'
+	else
+	  _LT_TAGVAR(whole_archive_flag_spec, $1)='-z allextract$convenience -z defaultextract'
+	fi
+	;;
+      esac
+      _LT_TAGVAR(link_all_deplibs, $1)=yes
+      ;;
+
+    sunos4*)
+      if test "x$host_vendor" = xsequent; then
+	# Use $CC to link under sequent, because it throws in some extra .o
+	# files that make .init and .fini sections work.
+	_LT_TAGVAR(archive_cmds, $1)='$CC -G ${wl}-h $soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$LD -assert pure-text -Bstatic -o $lib $libobjs $deplibs $linker_flags'
+      fi
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+      _LT_TAGVAR(hardcode_direct, $1)=yes
+      _LT_TAGVAR(hardcode_minus_L, $1)=yes
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    sysv4)
+      case $host_vendor in
+	sni)
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  _LT_TAGVAR(hardcode_direct, $1)=yes # is this really true???
+	;;
+	siemens)
+	  ## LD is ld it makes a PLAMLIB
+	  ## CC just makes a GrossModule.
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -G -o $lib $libobjs $deplibs $linker_flags'
+	  _LT_TAGVAR(reload_cmds, $1)='$CC -r -o $output$reload_objs'
+	  _LT_TAGVAR(hardcode_direct, $1)=no
+        ;;
+	motorola)
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	  _LT_TAGVAR(hardcode_direct, $1)=no #Motorola manual says yes, but my tests say they lie
+	;;
+      esac
+      runpath_var='LD_RUN_PATH'
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    sysv4.3*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='-Bexport'
+      ;;
+
+    sysv4*MP*)
+      if test -d /usr/nec; then
+	_LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+	_LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	runpath_var=LD_RUN_PATH
+	hardcode_runpath_var=yes
+	_LT_TAGVAR(ld_shlibs, $1)=yes
+      fi
+      ;;
+
+    sysv4*uw2* | sysv5OpenUNIX* | sysv5UnixWare7.[[01]].[[10]]* | unixware7* | sco3.2v5.0.[[024]]*)
+      _LT_TAGVAR(no_undefined_flag, $1)='${wl}-z,text'
+      _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      runpath_var='LD_RUN_PATH'
+
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      fi
+      ;;
+
+    sysv5* | sco3.2v5* | sco5v6*)
+      # Note: We can NOT use -z defs as we might desire, because we do not
+      # link with -lc, and that would cause any symbols used from libc to
+      # always be unresolved, which means just about no library would
+      # ever link correctly.  If we're not using GNU ld we use -z text
+      # though, which does catch some bad symbols but isn't as heavy-handed
+      # as -z defs.
+      _LT_TAGVAR(no_undefined_flag, $1)='${wl}-z,text'
+      _LT_TAGVAR(allow_undefined_flag, $1)='${wl}-z,nodefs'
+      _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-R,$libdir'
+      _LT_TAGVAR(hardcode_libdir_separator, $1)=':'
+      _LT_TAGVAR(link_all_deplibs, $1)=yes
+      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-Bexport'
+      runpath_var='LD_RUN_PATH'
+
+      if test "$GCC" = yes; then
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      else
+	_LT_TAGVAR(archive_cmds, $1)='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+      fi
+      ;;
+
+    uts4*)
+      _LT_TAGVAR(archive_cmds, $1)='$LD -G -h $soname -o $lib $libobjs $deplibs $linker_flags'
+      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      ;;
+
+    *)
+      _LT_TAGVAR(ld_shlibs, $1)=no
+      ;;
+    esac
+
+    if test x$host_vendor = xsni; then
+      case $host in
+      sysv4 | sysv4.2uw2* | sysv4.3* | sysv5*)
+	_LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-Blargedynsym'
+	;;
+      esac
+    fi
+  fi
+])
+AC_MSG_RESULT([$_LT_TAGVAR(ld_shlibs, $1)])
+test "$_LT_TAGVAR(ld_shlibs, $1)" = no && can_build_shared=no
+
+_LT_TAGVAR(with_gnu_ld, $1)=$with_gnu_ld
+
+_LT_DECL([], [libext], [0], [Old archive suffix (normally "a")])dnl
+_LT_DECL([], [shrext_cmds], [1], [Shared library suffix (normally ".so")])dnl
+_LT_DECL([], [extract_expsyms_cmds], [2],
+    [The commands to extract the exported symbol list from a shared archive])
+
+#
+# Do we need to explicitly link libc?
+#
+case "x$_LT_TAGVAR(archive_cmds_need_lc, $1)" in
+x|xyes)
+  # Assume -lc should be added
+  _LT_TAGVAR(archive_cmds_need_lc, $1)=yes
+
+  if test "$enable_shared" = yes && test "$GCC" = yes; then
+    case $_LT_TAGVAR(archive_cmds, $1) in
+    *'~'*)
+      # FIXME: we may have to deal with multi-command sequences.
+      ;;
+    '$CC '*)
+      # Test whether the compiler implicitly links with -lc since on some
+      # systems, -lgcc has to come before -lc. If gcc already passes -lc
+      # to ld, don't add -lc before -lgcc.
+      AC_CACHE_CHECK([whether -lc should be explicitly linked in],
+	[lt_cv_]_LT_TAGVAR(archive_cmds_need_lc, $1),
+	[$RM conftest*
+	echo "$lt_simple_compile_test_code" > conftest.$ac_ext
+
+	if AC_TRY_EVAL(ac_compile) 2>conftest.err; then
+	  soname=conftest
+	  lib=conftest
+	  libobjs=conftest.$ac_objext
+	  deplibs=
+	  wl=$_LT_TAGVAR(lt_prog_compiler_wl, $1)
+	  pic_flag=$_LT_TAGVAR(lt_prog_compiler_pic, $1)
+	  compiler_flags=-v
+	  linker_flags=-v
+	  verstring=
+	  output_objdir=.
+	  libname=conftest
+	  lt_save_allow_undefined_flag=$_LT_TAGVAR(allow_undefined_flag, $1)
+	  _LT_TAGVAR(allow_undefined_flag, $1)=
+	  if AC_TRY_EVAL(_LT_TAGVAR(archive_cmds, $1) 2\>\&1 \| $GREP \" -lc \" \>/dev/null 2\>\&1)
+	  then
+	    lt_cv_[]_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+	  else
+	    lt_cv_[]_LT_TAGVAR(archive_cmds_need_lc, $1)=yes
+	  fi
+	  _LT_TAGVAR(allow_undefined_flag, $1)=$lt_save_allow_undefined_flag
+	else
+	  cat conftest.err 1>&5
+	fi
+	$RM conftest*
+	])
+      _LT_TAGVAR(archive_cmds_need_lc, $1)=$lt_cv_[]_LT_TAGVAR(archive_cmds_need_lc, $1)
+      ;;
+    esac
+  fi
+  ;;
+esac
+
+_LT_TAGDECL([build_libtool_need_lc], [archive_cmds_need_lc], [0],
+    [Whether or not to add -lc for building shared libraries])
+_LT_TAGDECL([allow_libtool_libs_with_static_runtimes],
+    [enable_shared_with_static_runtimes], [0],
+    [Whether or not to disallow shared libs when runtime libs are static])
+_LT_TAGDECL([], [export_dynamic_flag_spec], [1],
+    [Compiler flag to allow reflexive dlopens])
+_LT_TAGDECL([], [whole_archive_flag_spec], [1],
+    [Compiler flag to generate shared objects directly from archives])
+_LT_TAGDECL([], [compiler_needs_object], [1],
+    [Whether the compiler copes with passing no objects directly])
+_LT_TAGDECL([], [old_archive_from_new_cmds], [2],
+    [Create an old-style archive from a shared archive])
+_LT_TAGDECL([], [old_archive_from_expsyms_cmds], [2],
+    [Create a temporary old-style archive to link instead of a shared archive])
+_LT_TAGDECL([], [archive_cmds], [2], [Commands used to build a shared archive])
+_LT_TAGDECL([], [archive_expsym_cmds], [2])
+_LT_TAGDECL([], [module_cmds], [2],
+    [Commands used to build a loadable module if different from building
+    a shared archive.])
+_LT_TAGDECL([], [module_expsym_cmds], [2])
+_LT_TAGDECL([], [with_gnu_ld], [1],
+    [Whether we are building with GNU ld or not])
+_LT_TAGDECL([], [allow_undefined_flag], [1],
+    [Flag that allows shared libraries with undefined symbols to be built])
+_LT_TAGDECL([], [no_undefined_flag], [1],
+    [Flag that enforces no undefined symbols])
+_LT_TAGDECL([], [hardcode_libdir_flag_spec], [1],
+    [Flag to hardcode $libdir into a binary during linking.
+    This must work even if $libdir does not exist])
+_LT_TAGDECL([], [hardcode_libdir_separator], [1],
+    [Whether we need a single "-rpath" flag with a separated argument])
+_LT_TAGDECL([], [hardcode_direct], [0],
+    [Set to "yes" if using DIR/libNAME${shared_ext} during linking hardcodes
+    DIR into the resulting binary])
+_LT_TAGDECL([], [hardcode_direct_absolute], [0],
+    [Set to "yes" if using DIR/libNAME${shared_ext} during linking hardcodes
+    DIR into the resulting binary and the resulting library dependency is
+    "absolute", i.e impossible to change by setting ${shlibpath_var} if the
+    library is relocated])
+_LT_TAGDECL([], [hardcode_minus_L], [0],
+    [Set to "yes" if using the -LDIR flag during linking hardcodes DIR
+    into the resulting binary])
+_LT_TAGDECL([], [hardcode_shlibpath_var], [0],
+    [Set to "yes" if using SHLIBPATH_VAR=DIR during linking hardcodes DIR
+    into the resulting binary])
+_LT_TAGDECL([], [hardcode_automatic], [0],
+    [Set to "yes" if building a shared library automatically hardcodes DIR
+    into the library and all subsequent libraries and executables linked
+    against it])
+_LT_TAGDECL([], [inherit_rpath], [0],
+    [Set to yes if linker adds runtime paths of dependent libraries
+    to runtime path list])
+_LT_TAGDECL([], [link_all_deplibs], [0],
+    [Whether libtool must link a program against all its dependency libraries])
+_LT_TAGDECL([], [always_export_symbols], [0],
+    [Set to "yes" if exported symbols are required])
+_LT_TAGDECL([], [export_symbols_cmds], [2],
+    [The commands to list exported symbols])
+_LT_TAGDECL([], [exclude_expsyms], [1],
+    [Symbols that should not be listed in the preloaded symbols])
+_LT_TAGDECL([], [include_expsyms], [1],
+    [Symbols that must always be exported])
+_LT_TAGDECL([], [prelink_cmds], [2],
+    [Commands necessary for linking programs (against libraries) with templates])
+_LT_TAGDECL([], [postlink_cmds], [2],
+    [Commands necessary for finishing linking programs])
+_LT_TAGDECL([], [file_list_spec], [1],
+    [Specify filename containing input files])
+dnl FIXME: Not yet implemented
+dnl _LT_TAGDECL([], [thread_safe_flag_spec], [1],
+dnl    [Compiler flag to generate thread safe objects])
+])# _LT_LINKER_SHLIBS
+
+
+# _LT_LANG_C_CONFIG([TAG])
+# ------------------------
+# Ensure that the configuration variables for a C compiler are suitably
+# defined.  These variables are subsequently used by _LT_CONFIG to write
+# the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_C_CONFIG],
+[m4_require([_LT_DECL_EGREP])dnl
+lt_save_CC="$CC"
+AC_LANG_PUSH(C)
+
+# Source file extension for C test sources.
+ac_ext=c
+
+# Object file extension for compiled C test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# Code to be used in simple compile tests
+lt_simple_compile_test_code="int some_variable = 0;"
+
+# Code to be used in simple link tests
+lt_simple_link_test_code='int main(){return(0);}'
+
+_LT_TAG_COMPILER
+# Save the default compiler, since it gets overwritten when the other
+# tags are being tested, and _LT_TAGVAR(compiler, []) is a NOP.
+compiler_DEFAULT=$CC
+
+# save warnings/boilerplate of simple test code
+_LT_COMPILER_BOILERPLATE
+_LT_LINKER_BOILERPLATE
+
+## CAVEAT EMPTOR:
+## There is no encapsulation within the following macros, do not change
+## the running order or otherwise move them around unless you know exactly
+## what you are doing...
+if test -n "$compiler"; then
+  _LT_COMPILER_NO_RTTI($1)
+  _LT_COMPILER_PIC($1)
+  _LT_COMPILER_C_O($1)
+  _LT_COMPILER_FILE_LOCKS($1)
+  _LT_LINKER_SHLIBS($1)
+  _LT_SYS_DYNAMIC_LINKER($1)
+  _LT_LINKER_HARDCODE_LIBPATH($1)
+  LT_SYS_DLOPEN_SELF
+  _LT_CMD_STRIPLIB
+
+  # Report which library types will actually be built
+  AC_MSG_CHECKING([if libtool supports shared libraries])
+  AC_MSG_RESULT([$can_build_shared])
+
+  AC_MSG_CHECKING([whether to build shared libraries])
+  test "$can_build_shared" = "no" && enable_shared=no
+
+  # On AIX, shared libraries and static libraries use the same namespace, and
+  # are all built from PIC.
+  case $host_os in
+  aix3*)
+    test "$enable_shared" = yes && enable_static=no
+    if test -n "$RANLIB"; then
+      archive_cmds="$archive_cmds~\$RANLIB \$lib"
+      postinstall_cmds='$RANLIB $lib'
+    fi
+    ;;
+
+  aix[[4-9]]*)
+    if test "$host_cpu" != ia64 && test "$aix_use_runtimelinking" = no ; then
+      test "$enable_shared" = yes && enable_static=no
+    fi
+    ;;
+  esac
+  AC_MSG_RESULT([$enable_shared])
+
+  AC_MSG_CHECKING([whether to build static libraries])
+  # Make sure either enable_shared or enable_static is yes.
+  test "$enable_shared" = yes || enable_static=yes
+  AC_MSG_RESULT([$enable_static])
+
+  _LT_CONFIG($1)
+fi
+AC_LANG_POP
+CC="$lt_save_CC"
+])# _LT_LANG_C_CONFIG
+
+
+# _LT_LANG_CXX_CONFIG([TAG])
+# --------------------------
+# Ensure that the configuration variables for a C++ compiler are suitably
+# defined.  These variables are subsequently used by _LT_CONFIG to write
+# the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_CXX_CONFIG],
+[m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+m4_require([_LT_DECL_EGREP])dnl
+m4_require([_LT_PATH_MANIFEST_TOOL])dnl
+if test -n "$CXX" && ( test "X$CXX" != "Xno" &&
+    ( (test "X$CXX" = "Xg++" && `g++ -v >/dev/null 2>&1` ) ||
+    (test "X$CXX" != "Xg++"))) ; then
+  AC_PROG_CXXCPP
+else
+  _lt_caught_CXX_error=yes
+fi
+
+AC_LANG_PUSH(C++)
+_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+_LT_TAGVAR(allow_undefined_flag, $1)=
+_LT_TAGVAR(always_export_symbols, $1)=no
+_LT_TAGVAR(archive_expsym_cmds, $1)=
+_LT_TAGVAR(compiler_needs_object, $1)=no
+_LT_TAGVAR(export_dynamic_flag_spec, $1)=
+_LT_TAGVAR(hardcode_direct, $1)=no
+_LT_TAGVAR(hardcode_direct_absolute, $1)=no
+_LT_TAGVAR(hardcode_libdir_flag_spec, $1)=
+_LT_TAGVAR(hardcode_libdir_separator, $1)=
+_LT_TAGVAR(hardcode_minus_L, $1)=no
+_LT_TAGVAR(hardcode_shlibpath_var, $1)=unsupported
+_LT_TAGVAR(hardcode_automatic, $1)=no
+_LT_TAGVAR(inherit_rpath, $1)=no
+_LT_TAGVAR(module_cmds, $1)=
+_LT_TAGVAR(module_expsym_cmds, $1)=
+_LT_TAGVAR(link_all_deplibs, $1)=unknown
+_LT_TAGVAR(old_archive_cmds, $1)=$old_archive_cmds
+_LT_TAGVAR(reload_flag, $1)=$reload_flag
+_LT_TAGVAR(reload_cmds, $1)=$reload_cmds
+_LT_TAGVAR(no_undefined_flag, $1)=
+_LT_TAGVAR(whole_archive_flag_spec, $1)=
+_LT_TAGVAR(enable_shared_with_static_runtimes, $1)=no
+
+# Source file extension for C++ test sources.
+ac_ext=cpp
+
+# Object file extension for compiled C++ test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# No sense in running all these tests if we already determined that
+# the CXX compiler isn't working.  Some variables (like enable_shared)
+# are currently assumed to apply to all compilers on this platform,
+# and will be corrupted by setting them based on a non-working compiler.
+if test "$_lt_caught_CXX_error" != yes; then
+  # Code to be used in simple compile tests
+  lt_simple_compile_test_code="int some_variable = 0;"
+
+  # Code to be used in simple link tests
+  lt_simple_link_test_code='int main(int, char *[[]]) { return(0); }'
+
+  # ltmain only uses $CC for tagged configurations so make sure $CC is set.
+  _LT_TAG_COMPILER
+
+  # save warnings/boilerplate of simple test code
+  _LT_COMPILER_BOILERPLATE
+  _LT_LINKER_BOILERPLATE
+
+  # Allow CC to be a program name with arguments.
+  lt_save_CC=$CC
+  lt_save_CFLAGS=$CFLAGS
+  lt_save_LD=$LD
+  lt_save_GCC=$GCC
+  GCC=$GXX
+  lt_save_with_gnu_ld=$with_gnu_ld
+  lt_save_path_LD=$lt_cv_path_LD
+  if test -n "${lt_cv_prog_gnu_ldcxx+set}"; then
+    lt_cv_prog_gnu_ld=$lt_cv_prog_gnu_ldcxx
+  else
+    $as_unset lt_cv_prog_gnu_ld
+  fi
+  if test -n "${lt_cv_path_LDCXX+set}"; then
+    lt_cv_path_LD=$lt_cv_path_LDCXX
+  else
+    $as_unset lt_cv_path_LD
+  fi
+  test -z "${LDCXX+set}" || LD=$LDCXX
+  CC=${CXX-"c++"}
+  CFLAGS=$CXXFLAGS
+  compiler=$CC
+  _LT_TAGVAR(compiler, $1)=$CC
+  _LT_CC_BASENAME([$compiler])
+
+  if test -n "$compiler"; then
+    # We don't want -fno-exception when compiling C++ code, so set the
+    # no_builtin_flag separately
+    if test "$GXX" = yes; then
+      _LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)=' -fno-builtin'
+    else
+      _LT_TAGVAR(lt_prog_compiler_no_builtin_flag, $1)=
+    fi
+
+    if test "$GXX" = yes; then
+      # Set up default GNU C++ configuration
+
+      LT_PATH_LD
+
+      # Check if GNU C++ uses GNU ld as the underlying linker, since the
+      # archiving commands below assume that GNU ld is being used.
+      if test "$with_gnu_ld" = yes; then
+        _LT_TAGVAR(archive_cmds, $1)='$CC $pic_flag -shared -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname -o $lib'
+        _LT_TAGVAR(archive_expsym_cmds, $1)='$CC $pic_flag -shared -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+
+        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+        _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+
+        # If archive_cmds runs LD, not CC, wlarc should be empty
+        # XXX I think wlarc can be eliminated in ltcf-cxx, but I need to
+        #     investigate it a little bit more. (MM)
+        wlarc='${wl}'
+
+        # ancient GNU ld didn't support --whole-archive et. al.
+        if eval "`$CC -print-prog-name=ld` --help 2>&1" |
+	  $GREP 'no-whole-archive' > /dev/null; then
+          _LT_TAGVAR(whole_archive_flag_spec, $1)="$wlarc"'--whole-archive$convenience '"$wlarc"'--no-whole-archive'
+        else
+          _LT_TAGVAR(whole_archive_flag_spec, $1)=
+        fi
+      else
+        with_gnu_ld=no
+        wlarc=
+
+        # A generic and very simple default shared library creation
+        # command for GNU C++ for the case where it uses the native
+        # linker, instead of GNU ld.  If possible, this setting should
+        # overridden to take advantage of the native linker features on
+        # the platform it is being used on.
+        _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -o $lib'
+      fi
+
+      # Commands to make compiler produce verbose output that lists
+      # what "hidden" libraries, object files and flags are used when
+      # linking a shared library.
+      output_verbose_link_cmd='$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP -v "^Configured with:" | $GREP "\-L"'
+
+    else
+      GXX=no
+      with_gnu_ld=no
+      wlarc=
+    fi
+
+    # PORTME: fill in a description of your system's C++ link characteristics
+    AC_MSG_CHECKING([whether the $compiler linker ($LD) supports shared libraries])
+    _LT_TAGVAR(ld_shlibs, $1)=yes
+    case $host_os in
+      aix3*)
+        # FIXME: insert proper C++ library support
+        _LT_TAGVAR(ld_shlibs, $1)=no
+        ;;
+      aix[[4-9]]*)
+        if test "$host_cpu" = ia64; then
+          # On IA64, the linker does run time linking by default, so we don't
+          # have to do anything special.
+          aix_use_runtimelinking=no
+          exp_sym_flag='-Bexport'
+          no_entry_flag=""
+        else
+          aix_use_runtimelinking=no
+
+          # Test if we are trying to use run time linking or normal
+          # AIX style linking. If -brtl is somewhere in LDFLAGS, we
+          # need to do runtime linking.
+          case $host_os in aix4.[[23]]|aix4.[[23]].*|aix[[5-9]]*)
+	    for ld_flag in $LDFLAGS; do
+	      case $ld_flag in
+	      *-brtl*)
+	        aix_use_runtimelinking=yes
+	        break
+	        ;;
+	      esac
+	    done
+	    ;;
+          esac
+
+          exp_sym_flag='-bexport'
+          no_entry_flag='-bnoentry'
+        fi
+
+        # When large executables or shared objects are built, AIX ld can
+        # have problems creating the table of contents.  If linking a library
+        # or program results in "error TOC overflow" add -mminimal-toc to
+        # CXXFLAGS/CFLAGS for g++/gcc.  In the cases where that is not
+        # enough to fix the problem, add -Wl,-bbigtoc to LDFLAGS.
+
+        _LT_TAGVAR(archive_cmds, $1)=''
+        _LT_TAGVAR(hardcode_direct, $1)=yes
+        _LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+        _LT_TAGVAR(hardcode_libdir_separator, $1)=':'
+        _LT_TAGVAR(link_all_deplibs, $1)=yes
+        _LT_TAGVAR(file_list_spec, $1)='${wl}-f,'
+
+        if test "$GXX" = yes; then
+          case $host_os in aix4.[[012]]|aix4.[[012]].*)
+          # We only want to do this on AIX 4.2 and lower, the check
+          # below for broken collect2 doesn't work under 4.3+
+	  collect2name=`${CC} -print-prog-name=collect2`
+	  if test -f "$collect2name" &&
+	     strings "$collect2name" | $GREP resolve_lib_name >/dev/null
+	  then
+	    # We have reworked collect2
+	    :
+	  else
+	    # We have old collect2
+	    _LT_TAGVAR(hardcode_direct, $1)=unsupported
+	    # It fails to find uninstalled libraries when the uninstalled
+	    # path is not listed in the libpath.  Setting hardcode_minus_L
+	    # to unsupported forces relinking
+	    _LT_TAGVAR(hardcode_minus_L, $1)=yes
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+	    _LT_TAGVAR(hardcode_libdir_separator, $1)=
+	  fi
+          esac
+          shared_flag='-shared'
+	  if test "$aix_use_runtimelinking" = yes; then
+	    shared_flag="$shared_flag "'${wl}-G'
+	  fi
+        else
+          # not using gcc
+          if test "$host_cpu" = ia64; then
+	  # VisualAge C++, Version 5.5 for AIX 5L for IA-64, Beta 3 Release
+	  # chokes on -Wl,-G. The following line is correct:
+	  shared_flag='-G'
+          else
+	    if test "$aix_use_runtimelinking" = yes; then
+	      shared_flag='${wl}-G'
+	    else
+	      shared_flag='${wl}-bM:SRE'
+	    fi
+          fi
+        fi
+
+        _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-bexpall'
+        # It seems that -bexpall does not export symbols beginning with
+        # underscore (_), so it is better to generate a list of symbols to
+	# export.
+        _LT_TAGVAR(always_export_symbols, $1)=yes
+        if test "$aix_use_runtimelinking" = yes; then
+          # Warning - without using the other runtime loading flags (-brtl),
+          # -berok will link without error, but may produce a broken library.
+          _LT_TAGVAR(allow_undefined_flag, $1)='-berok'
+          # Determine the default libpath from the value encoded in an empty
+          # executable.
+          _LT_SYS_MODULE_PATH_AIX([$1])
+          _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-blibpath:$libdir:'"$aix_libpath"
+
+          _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags `if test "x${allow_undefined_flag}" != "x"; then func_echo_all "${wl}${allow_undefined_flag}"; else :; fi` '"\${wl}$exp_sym_flag:\$export_symbols $shared_flag"
+        else
+          if test "$host_cpu" = ia64; then
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-R $libdir:/usr/lib:/lib'
+	    _LT_TAGVAR(allow_undefined_flag, $1)="-z nodefs"
+	    _LT_TAGVAR(archive_expsym_cmds, $1)="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs '"\${wl}$no_entry_flag"' $compiler_flags ${wl}${allow_undefined_flag} '"\${wl}$exp_sym_flag:\$export_symbols"
+          else
+	    # Determine the default libpath from the value encoded in an
+	    # empty executable.
+	    _LT_SYS_MODULE_PATH_AIX([$1])
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-blibpath:$libdir:'"$aix_libpath"
+	    # Warning - without using the other run time loading flags,
+	    # -berok will link without error, but may produce a broken library.
+	    _LT_TAGVAR(no_undefined_flag, $1)=' ${wl}-bernotok'
+	    _LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-berok'
+	    if test "$with_gnu_ld" = yes; then
+	      # We only use this code for GNU lds that support --whole-archive.
+	      _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive$convenience ${wl}--no-whole-archive'
+	    else
+	      # Exported symbols can be pulled into shared objects from archives
+	      _LT_TAGVAR(whole_archive_flag_spec, $1)='$convenience'
+	    fi
+	    _LT_TAGVAR(archive_cmds_need_lc, $1)=yes
+	    # This is similar to how AIX traditionally builds its shared
+	    # libraries.
+	    _LT_TAGVAR(archive_expsym_cmds, $1)="\$CC $shared_flag"' -o $output_objdir/$soname $libobjs $deplibs ${wl}-bnoentry $compiler_flags ${wl}-bE:$export_symbols${allow_undefined_flag}~$AR $AR_FLAGS $output_objdir/$libname$release.a $output_objdir/$soname'
+          fi
+        fi
+        ;;
+
+      beos*)
+	if $LD --help 2>&1 | $GREP ': supported targets:.* elf' > /dev/null; then
+	  _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	  # Joseph Beckenbach <jrb3@best.com> says some releases of gcc
+	  # support --undefined.  This deserves some investigation.  FIXME
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -nostart $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	else
+	  _LT_TAGVAR(ld_shlibs, $1)=no
+	fi
+	;;
+
+      chorus*)
+        case $cc_basename in
+          *)
+	  # FIXME: insert proper C++ library support
+	  _LT_TAGVAR(ld_shlibs, $1)=no
+	  ;;
+        esac
+        ;;
+
+      cygwin* | mingw* | pw32* | cegcc*)
+	case $GXX,$cc_basename in
+	,cl* | no,cl*)
+	  # Native MSVC
+	  # hardcode_libdir_flag_spec is actually meaningless, as there is
+	  # no search path for DLLs.
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)=' '
+	  _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	  _LT_TAGVAR(always_export_symbols, $1)=yes
+	  _LT_TAGVAR(file_list_spec, $1)='@'
+	  # Tell ltmain to make .lib files, not .a files.
+	  libext=lib
+	  # Tell ltmain to make .dll files, not .so files.
+	  shrext_cmds=".dll"
+	  # FIXME: Setting linknames here is a bad hack.
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -o $output_objdir/$soname $libobjs $compiler_flags $deplibs -Wl,-dll~linknames='
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	      $SED -n -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' -e '1\\\!p' < $export_symbols > $output_objdir/$soname.exp;
+	    else
+	      $SED -e 's/\\\\\\\(.*\\\\\\\)/-link\\\ -EXPORT:\\\\\\\1/' < $export_symbols > $output_objdir/$soname.exp;
+	    fi~
+	    $CC -o $tool_output_objdir$soname $libobjs $compiler_flags $deplibs "@$tool_output_objdir$soname.exp" -Wl,-DLL,-IMPLIB:"$tool_output_objdir$libname.dll.lib"~
+	    linknames='
+	  # The linker will not automatically build a static lib if we build a DLL.
+	  # _LT_TAGVAR(old_archive_from_new_cmds, $1)='true'
+	  _LT_TAGVAR(enable_shared_with_static_runtimes, $1)=yes
+	  # Don't use ranlib
+	  _LT_TAGVAR(old_postinstall_cmds, $1)='chmod 644 $oldlib'
+	  _LT_TAGVAR(postlink_cmds, $1)='lt_outputfile="@OUTPUT@"~
+	    lt_tool_outputfile="@TOOL_OUTPUT@"~
+	    case $lt_outputfile in
+	      *.exe|*.EXE) ;;
+	      *)
+		lt_outputfile="$lt_outputfile.exe"
+		lt_tool_outputfile="$lt_tool_outputfile.exe"
+		;;
+	    esac~
+	    func_to_tool_file "$lt_outputfile"~
+	    if test "$MANIFEST_TOOL" != ":" && test -f "$lt_outputfile.manifest"; then
+	      $MANIFEST_TOOL -manifest "$lt_tool_outputfile.manifest" -outputresource:"$lt_tool_outputfile" || exit 1;
+	      $RM "$lt_outputfile.manifest";
+	    fi'
+	  ;;
+	*)
+	  # g++
+	  # _LT_TAGVAR(hardcode_libdir_flag_spec, $1) is actually meaningless,
+	  # as there is no search path for DLLs.
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-L$libdir'
+	  _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-all-symbols'
+	  _LT_TAGVAR(allow_undefined_flag, $1)=unsupported
+	  _LT_TAGVAR(always_export_symbols, $1)=no
+	  _LT_TAGVAR(enable_shared_with_static_runtimes, $1)=yes
+
+	  if $LD --help 2>&1 | $GREP 'auto-import' > /dev/null; then
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+	    # If the export-symbols file already is a .def file (1st line
+	    # is EXPORTS), use it as is; otherwise, prepend...
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='if test "x`$SED 1q $export_symbols`" = xEXPORTS; then
+	      cp $export_symbols $output_objdir/$soname.def;
+	    else
+	      echo EXPORTS > $output_objdir/$soname.def;
+	      cat $export_symbols >> $output_objdir/$soname.def;
+	    fi~
+	    $CC -shared -nostdlib $output_objdir/$soname.def $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -o $output_objdir/$soname ${wl}--enable-auto-image-base -Xlinker --out-implib -Xlinker $lib'
+	  else
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	  fi
+	  ;;
+	esac
+	;;
+      darwin* | rhapsody*)
+        _LT_DARWIN_LINKER_FEATURES($1)
+	;;
+
+      dgux*)
+        case $cc_basename in
+          ec++*)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          ghcx*)
+	    # Green Hills C++ Compiler
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          *)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+        esac
+        ;;
+
+      freebsd2.*)
+        # C++ shared libraries reported to be fairly broken before
+	# switch to ELF
+        _LT_TAGVAR(ld_shlibs, $1)=no
+        ;;
+
+      freebsd-elf*)
+        _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+        ;;
+
+      freebsd* | dragonfly*)
+        # FreeBSD 3 and later use GNU C++ and GNU ld with standard ELF
+        # conventions
+        _LT_TAGVAR(ld_shlibs, $1)=yes
+        ;;
+
+      haiku*)
+        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+        _LT_TAGVAR(link_all_deplibs, $1)=yes
+        ;;
+
+      hpux9*)
+        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}+b ${wl}$libdir'
+        _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+        _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+        _LT_TAGVAR(hardcode_direct, $1)=yes
+        _LT_TAGVAR(hardcode_minus_L, $1)=yes # Not in the search PATH,
+				             # but as the default
+				             # location of the library.
+
+        case $cc_basename in
+          CC*)
+            # FIXME: insert proper C++ library support
+            _LT_TAGVAR(ld_shlibs, $1)=no
+            ;;
+          aCC*)
+            _LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/$soname~$CC -b ${wl}+b ${wl}$install_libdir -o $output_objdir/$soname $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+            # Commands to make compiler produce verbose output that lists
+            # what "hidden" libraries, object files and flags are used when
+            # linking a shared library.
+            #
+            # There doesn't appear to be a way to prevent this compiler from
+            # explicitly linking system object files so we need to strip them
+            # from the output so that they don't get included in the library
+            # dependencies.
+            output_verbose_link_cmd='templist=`($CC -b $CFLAGS -v conftest.$objext 2>&1) | $EGREP "\-L"`; list=""; for z in $templist; do case $z in conftest.$objext) list="$list $z";; *.$objext);; *) list="$list $z";;esac; done; func_echo_all "$list"'
+            ;;
+          *)
+            if test "$GXX" = yes; then
+              _LT_TAGVAR(archive_cmds, $1)='$RM $output_objdir/$soname~$CC -shared -nostdlib $pic_flag ${wl}+b ${wl}$install_libdir -o $output_objdir/$soname $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags~test $output_objdir/$soname = $lib || mv $output_objdir/$soname $lib'
+            else
+              # FIXME: insert proper C++ library support
+              _LT_TAGVAR(ld_shlibs, $1)=no
+            fi
+            ;;
+        esac
+        ;;
+
+      hpux10*|hpux11*)
+        if test $with_gnu_ld = no; then
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}+b ${wl}$libdir'
+	  _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+          case $host_cpu in
+            hppa*64*|ia64*)
+              ;;
+            *)
+	      _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+              ;;
+          esac
+        fi
+        case $host_cpu in
+          hppa*64*|ia64*)
+            _LT_TAGVAR(hardcode_direct, $1)=no
+            _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+            ;;
+          *)
+            _LT_TAGVAR(hardcode_direct, $1)=yes
+            _LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+            _LT_TAGVAR(hardcode_minus_L, $1)=yes # Not in the search PATH,
+					         # but as the default
+					         # location of the library.
+            ;;
+        esac
+
+        case $cc_basename in
+          CC*)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          aCC*)
+	    case $host_cpu in
+	      hppa*64*)
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	        ;;
+	      ia64*)
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	        ;;
+	      *)
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -b ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	        ;;
+	    esac
+	    # Commands to make compiler produce verbose output that lists
+	    # what "hidden" libraries, object files and flags are used when
+	    # linking a shared library.
+	    #
+	    # There doesn't appear to be a way to prevent this compiler from
+	    # explicitly linking system object files so we need to strip them
+	    # from the output so that they don't get included in the library
+	    # dependencies.
+	    output_verbose_link_cmd='templist=`($CC -b $CFLAGS -v conftest.$objext 2>&1) | $GREP "\-L"`; list=""; for z in $templist; do case $z in conftest.$objext) list="$list $z";; *.$objext);; *) list="$list $z";;esac; done; func_echo_all "$list"'
+	    ;;
+          *)
+	    if test "$GXX" = yes; then
+	      if test $with_gnu_ld = no; then
+	        case $host_cpu in
+	          hppa*64*)
+	            _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib -fPIC ${wl}+h ${wl}$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	            ;;
+	          ia64*)
+	            _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib $pic_flag ${wl}+h ${wl}$soname ${wl}+nodefaultrpath -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	            ;;
+	          *)
+	            _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib $pic_flag ${wl}+h ${wl}$soname ${wl}+b ${wl}$install_libdir -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	            ;;
+	        esac
+	      fi
+	    else
+	      # FIXME: insert proper C++ library support
+	      _LT_TAGVAR(ld_shlibs, $1)=no
+	    fi
+	    ;;
+        esac
+        ;;
+
+      interix[[3-9]]*)
+	_LT_TAGVAR(hardcode_direct, $1)=no
+	_LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	_LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+	# Hack: On Interix 3.x, we cannot compile PIC because of a broken gcc.
+	# Instead, shared libraries are loaded at an image base (0x10000000 by
+	# default) and relocated if they conflict, which is a slow very memory
+	# consuming and fragmenting process.  To avoid this, we pick a random,
+	# 256 KiB-aligned image base between 0x50000000 and 0x6FFC0000 at link
+	# time.  Moving up from 0x10000000 also allows more sbrk(2) space.
+	_LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+	_LT_TAGVAR(archive_expsym_cmds, $1)='sed "s,^,_," $export_symbols >$output_objdir/$soname.expsym~$CC -shared $pic_flag $libobjs $deplibs $compiler_flags ${wl}-h,$soname ${wl}--retain-symbols-file,$output_objdir/$soname.expsym ${wl}--image-base,`expr ${RANDOM-$$} % 4096 / 2 \* 262144 + 1342177280` -o $lib'
+	;;
+      irix5* | irix6*)
+        case $cc_basename in
+          CC*)
+	    # SGI C++
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared -all -multigot $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+
+	    # Archives containing C++ object files must be created using
+	    # "CC -ar", where "CC" is the IRIX C++ compiler.  This is
+	    # necessary to make sure instantiated templates are included
+	    # in the archive.
+	    _LT_TAGVAR(old_archive_cmds, $1)='$CC -ar -WR,-u -o $oldlib $oldobjs'
+	    ;;
+          *)
+	    if test "$GXX" = yes; then
+	      if test "$with_gnu_ld" = no; then
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+	      else
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -nostdlib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` -o $lib'
+	      fi
+	    fi
+	    _LT_TAGVAR(link_all_deplibs, $1)=yes
+	    ;;
+        esac
+        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+        _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+        _LT_TAGVAR(inherit_rpath, $1)=yes
+        ;;
+
+      linux* | k*bsd*-gnu | kopensolaris*-gnu | gnu*)
+        case $cc_basename in
+          KCC*)
+	    # Kuck and Associates, Inc. (KAI) C++ Compiler
+
+	    # KCC will only create a shared library if the output file
+	    # ends with ".so" (or ".sl" for HP-UX), so rename the library
+	    # to its proper name (with version) after linking.
+	    _LT_TAGVAR(archive_cmds, $1)='tempext=`echo $shared_ext | $SED -e '\''s/\([[^()0-9A-Za-z{}]]\)/\\\\\1/g'\''`; templib=`echo $lib | $SED -e "s/\${tempext}\..*/.so/"`; $CC $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags --soname $soname -o \$templib; mv \$templib $lib'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='tempext=`echo $shared_ext | $SED -e '\''s/\([[^()0-9A-Za-z{}]]\)/\\\\\1/g'\''`; templib=`echo $lib | $SED -e "s/\${tempext}\..*/.so/"`; $CC $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags --soname $soname -o \$templib ${wl}-retain-symbols-file,$export_symbols; mv \$templib $lib'
+	    # Commands to make compiler produce verbose output that lists
+	    # what "hidden" libraries, object files and flags are used when
+	    # linking a shared library.
+	    #
+	    # There doesn't appear to be a way to prevent this compiler from
+	    # explicitly linking system object files so we need to strip them
+	    # from the output so that they don't get included in the library
+	    # dependencies.
+	    output_verbose_link_cmd='templist=`$CC $CFLAGS -v conftest.$objext -o libconftest$shared_ext 2>&1 | $GREP "ld"`; rm -f libconftest$shared_ext; list=""; for z in $templist; do case $z in conftest.$objext) list="$list $z";; *.$objext);; *) list="$list $z";;esac; done; func_echo_all "$list"'
+
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+
+	    # Archives containing C++ object files must be created using
+	    # "CC -Bstatic", where "CC" is the KAI C++ compiler.
+	    _LT_TAGVAR(old_archive_cmds, $1)='$CC -Bstatic -o $oldlib $oldobjs'
+	    ;;
+	  icpc* | ecpc* )
+	    # Intel C++
+	    with_gnu_ld=yes
+	    # version 8.0 and above of icpc choke on multiply defined symbols
+	    # if we add $predep_objects and $postdep_objects, however 7.1 and
+	    # earlier do not add the objects themselves.
+	    case `$CC -V 2>&1` in
+	      *"Version 7."*)
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname -o $lib'
+		_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+		;;
+	      *)  # Version 8.0 or newer
+	        tmp_idyn=
+	        case $host_cpu in
+		  ia64*) tmp_idyn=' -i_dynamic';;
+		esac
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared'"$tmp_idyn"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+		_LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared'"$tmp_idyn"' $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-retain-symbols-file $wl$export_symbols -o $lib'
+		;;
+	    esac
+	    _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+	    _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive$convenience ${wl}--no-whole-archive'
+	    ;;
+          pgCC* | pgcpp*)
+            # Portland Group C++ compiler
+	    case `$CC -V` in
+	    *pgCC\ [[1-5]].* | *pgcpp\ [[1-5]].*)
+	      _LT_TAGVAR(prelink_cmds, $1)='tpldir=Template.dir~
+		rm -rf $tpldir~
+		$CC --prelink_objects --instantiation_dir $tpldir $objs $libobjs $compile_deplibs~
+		compile_command="$compile_command `find $tpldir -name \*.o | sort | $NL2SP`"'
+	      _LT_TAGVAR(old_archive_cmds, $1)='tpldir=Template.dir~
+		rm -rf $tpldir~
+		$CC --prelink_objects --instantiation_dir $tpldir $oldobjs$old_deplibs~
+		$AR $AR_FLAGS $oldlib$oldobjs$old_deplibs `find $tpldir -name \*.o | sort | $NL2SP`~
+		$RANLIB $oldlib'
+	      _LT_TAGVAR(archive_cmds, $1)='tpldir=Template.dir~
+		rm -rf $tpldir~
+		$CC --prelink_objects --instantiation_dir $tpldir $predep_objects $libobjs $deplibs $convenience $postdep_objects~
+		$CC -shared $pic_flag $predep_objects $libobjs $deplibs `find $tpldir -name \*.o | sort | $NL2SP` $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname -o $lib'
+	      _LT_TAGVAR(archive_expsym_cmds, $1)='tpldir=Template.dir~
+		rm -rf $tpldir~
+		$CC --prelink_objects --instantiation_dir $tpldir $predep_objects $libobjs $deplibs $convenience $postdep_objects~
+		$CC -shared $pic_flag $predep_objects $libobjs $deplibs `find $tpldir -name \*.o | sort | $NL2SP` $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname ${wl}-retain-symbols-file ${wl}$export_symbols -o $lib'
+	      ;;
+	    *) # Version 6 and above use weak symbols
+	      _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname -o $lib'
+	      _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname ${wl}-retain-symbols-file ${wl}$export_symbols -o $lib'
+	      ;;
+	    esac
+
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}--rpath ${wl}$libdir'
+	    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+	    _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`for conv in $convenience\"\"; do test  -n \"$conv\" && new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+            ;;
+	  cxx*)
+	    # Compaq C++
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $wl$soname  -o $lib ${wl}-retain-symbols-file $wl$export_symbols'
+
+	    runpath_var=LD_RUN_PATH
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-rpath $libdir'
+	    _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+	    # Commands to make compiler produce verbose output that lists
+	    # what "hidden" libraries, object files and flags are used when
+	    # linking a shared library.
+	    #
+	    # There doesn't appear to be a way to prevent this compiler from
+	    # explicitly linking system object files so we need to strip them
+	    # from the output so that they don't get included in the library
+	    # dependencies.
+	    output_verbose_link_cmd='templist=`$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP "ld"`; templist=`func_echo_all "$templist" | $SED "s/\(^.*ld.*\)\( .*ld .*$\)/\1/"`; list=""; for z in $templist; do case $z in conftest.$objext) list="$list $z";; *.$objext);; *) list="$list $z";;esac; done; func_echo_all "X$list" | $Xsed'
+	    ;;
+	  xl* | mpixl* | bgxl*)
+	    # IBM XL 8.0 on PPC, with GNU ld
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+	    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}--export-dynamic'
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -qmkshrobj $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname -o $lib'
+	    if test "x$supports_anon_versioning" = xyes; then
+	      _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $output_objdir/$libname.ver~
+		cat $export_symbols | sed -e "s/\(.*\)/\1;/" >> $output_objdir/$libname.ver~
+		echo "local: *; };" >> $output_objdir/$libname.ver~
+		$CC -qmkshrobj $libobjs $deplibs $compiler_flags ${wl}-soname $wl$soname ${wl}-version-script ${wl}$output_objdir/$libname.ver -o $lib'
+	    fi
+	    ;;
+	  *)
+	    case `$CC -V 2>&1 | sed 5q` in
+	    *Sun\ C*)
+	      # Sun C++ 5.9
+	      _LT_TAGVAR(no_undefined_flag, $1)=' -zdefs'
+	      _LT_TAGVAR(archive_cmds, $1)='$CC -G${allow_undefined_flag} -h$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	      _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -G${allow_undefined_flag} -h$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-retain-symbols-file ${wl}$export_symbols'
+	      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+	      _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}--whole-archive`new_convenience=; for conv in $convenience\"\"; do test -z \"$conv\" || new_convenience=\"$new_convenience,$conv\"; done; func_echo_all \"$new_convenience\"` ${wl}--no-whole-archive'
+	      _LT_TAGVAR(compiler_needs_object, $1)=yes
+
+	      # Not sure whether something based on
+	      # $CC $CFLAGS -v conftest.$objext -o libconftest$shared_ext 2>&1
+	      # would be better.
+	      output_verbose_link_cmd='func_echo_all'
+
+	      # Archives containing C++ object files must be created using
+	      # "CC -xar", where "CC" is the Sun C++ compiler.  This is
+	      # necessary to make sure instantiated templates are included
+	      # in the archive.
+	      _LT_TAGVAR(old_archive_cmds, $1)='$CC -xar -o $oldlib $oldobjs'
+	      ;;
+	    esac
+	    ;;
+	esac
+	;;
+
+      lynxos*)
+        # FIXME: insert proper C++ library support
+	_LT_TAGVAR(ld_shlibs, $1)=no
+	;;
+
+      m88k*)
+        # FIXME: insert proper C++ library support
+        _LT_TAGVAR(ld_shlibs, $1)=no
+	;;
+
+      mvs*)
+        case $cc_basename in
+          cxx*)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+	  *)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+	esac
+	;;
+
+      netbsd*)
+        if echo __ELF__ | $CC -E - | $GREP __ELF__ >/dev/null; then
+	  _LT_TAGVAR(archive_cmds, $1)='$LD -Bshareable  -o $lib $predep_objects $libobjs $deplibs $postdep_objects $linker_flags'
+	  wlarc=
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+	  _LT_TAGVAR(hardcode_direct, $1)=yes
+	  _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	fi
+	# Workaround some broken pre-1.5 toolchains
+	output_verbose_link_cmd='$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP conftest.$objext | $SED -e "s:-lgcc -lc -lgcc::"'
+	;;
+
+      *nto* | *qnx*)
+        _LT_TAGVAR(ld_shlibs, $1)=yes
+	;;
+
+      openbsd2*)
+        # C++ shared libraries are fairly broken
+	_LT_TAGVAR(ld_shlibs, $1)=no
+	;;
+
+      openbsd*)
+	if test -f /usr/libexec/ld.so; then
+	  _LT_TAGVAR(hardcode_direct, $1)=yes
+	  _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	  _LT_TAGVAR(hardcode_direct_absolute, $1)=yes
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -o $lib'
+	  _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	  if test -z "`echo __ELF__ | $CC -E - | grep __ELF__`" || test "$host_os-$host_cpu" = "openbsd2.8-powerpc"; then
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared $pic_flag $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-retain-symbols-file,$export_symbols -o $lib'
+	    _LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-E'
+	    _LT_TAGVAR(whole_archive_flag_spec, $1)="$wlarc"'--whole-archive$convenience '"$wlarc"'--no-whole-archive'
+	  fi
+	  output_verbose_link_cmd=func_echo_all
+	else
+	  _LT_TAGVAR(ld_shlibs, $1)=no
+	fi
+	;;
+
+      osf3* | osf4* | osf5*)
+        case $cc_basename in
+          KCC*)
+	    # Kuck and Associates, Inc. (KAI) C++ Compiler
+
+	    # KCC will only create a shared library if the output file
+	    # ends with ".so" (or ".sl" for HP-UX), so rename the library
+	    # to its proper name (with version) after linking.
+	    _LT_TAGVAR(archive_cmds, $1)='tempext=`echo $shared_ext | $SED -e '\''s/\([[^()0-9A-Za-z{}]]\)/\\\\\1/g'\''`; templib=`echo "$lib" | $SED -e "s/\${tempext}\..*/.so/"`; $CC $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags --soname $soname -o \$templib; mv \$templib $lib'
+
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath,$libdir'
+	    _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+	    # Archives containing C++ object files must be created using
+	    # the KAI C++ compiler.
+	    case $host in
+	      osf3*) _LT_TAGVAR(old_archive_cmds, $1)='$CC -Bstatic -o $oldlib $oldobjs' ;;
+	      *) _LT_TAGVAR(old_archive_cmds, $1)='$CC -o $oldlib $oldobjs' ;;
+	    esac
+	    ;;
+          RCC*)
+	    # Rational C++ 2.4.1
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          cxx*)
+	    case $host in
+	      osf3*)
+	        _LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-expect_unresolved ${wl}\*'
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname $soname `test -n "$verstring" && func_echo_all "${wl}-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+		;;
+	      *)
+	        _LT_TAGVAR(allow_undefined_flag, $1)=' -expect_unresolved \*'
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared${allow_undefined_flag} $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -msym -soname $soname `test -n "$verstring" && func_echo_all "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib'
+	        _LT_TAGVAR(archive_expsym_cmds, $1)='for i in `cat $export_symbols`; do printf "%s %s\\n" -exported_symbol "\$i" >> $lib.exp; done~
+	          echo "-hidden">> $lib.exp~
+	          $CC -shared$allow_undefined_flag $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags -msym -soname $soname ${wl}-input ${wl}$lib.exp  `test -n "$verstring" && $ECHO "-set_version $verstring"` -update_registry ${output_objdir}/so_locations -o $lib~
+	          $RM $lib.exp'
+	        _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-rpath $libdir'
+		;;
+	    esac
+
+	    _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+	    # Commands to make compiler produce verbose output that lists
+	    # what "hidden" libraries, object files and flags are used when
+	    # linking a shared library.
+	    #
+	    # There doesn't appear to be a way to prevent this compiler from
+	    # explicitly linking system object files so we need to strip them
+	    # from the output so that they don't get included in the library
+	    # dependencies.
+	    output_verbose_link_cmd='templist=`$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP "ld" | $GREP -v "ld:"`; templist=`func_echo_all "$templist" | $SED "s/\(^.*ld.*\)\( .*ld.*$\)/\1/"`; list=""; for z in $templist; do case $z in conftest.$objext) list="$list $z";; *.$objext);; *) list="$list $z";;esac; done; func_echo_all "$list"'
+	    ;;
+	  *)
+	    if test "$GXX" = yes && test "$with_gnu_ld" = no; then
+	      _LT_TAGVAR(allow_undefined_flag, $1)=' ${wl}-expect_unresolved ${wl}\*'
+	      case $host in
+	        osf3*)
+	          _LT_TAGVAR(archive_cmds, $1)='$CC -shared -nostdlib ${allow_undefined_flag} $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+		  ;;
+	        *)
+	          _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -nostdlib ${allow_undefined_flag} $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-msym ${wl}-soname ${wl}$soname `test -n "$verstring" && func_echo_all "${wl}-set_version ${wl}$verstring"` ${wl}-update_registry ${wl}${output_objdir}/so_locations -o $lib'
+		  ;;
+	      esac
+
+	      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-rpath ${wl}$libdir'
+	      _LT_TAGVAR(hardcode_libdir_separator, $1)=:
+
+	      # Commands to make compiler produce verbose output that lists
+	      # what "hidden" libraries, object files and flags are used when
+	      # linking a shared library.
+	      output_verbose_link_cmd='$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP -v "^Configured with:" | $GREP "\-L"'
+
+	    else
+	      # FIXME: insert proper C++ library support
+	      _LT_TAGVAR(ld_shlibs, $1)=no
+	    fi
+	    ;;
+        esac
+        ;;
+
+      psos*)
+        # FIXME: insert proper C++ library support
+        _LT_TAGVAR(ld_shlibs, $1)=no
+        ;;
+
+      sunos4*)
+        case $cc_basename in
+          CC*)
+	    # Sun C++ 4.x
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          lcc*)
+	    # Lucid
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          *)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+        esac
+        ;;
+
+      solaris*)
+        case $cc_basename in
+          CC* | sunCC*)
+	    # Sun C++ 4.2, 5.x and Centerline C++
+            _LT_TAGVAR(archive_cmds_need_lc,$1)=yes
+	    _LT_TAGVAR(no_undefined_flag, $1)=' -zdefs'
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -G${allow_undefined_flag}  -h$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+	      $CC -G${allow_undefined_flag} ${wl}-M ${wl}$lib.exp -h$soname -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags~$RM $lib.exp'
+
+	    _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='-R$libdir'
+	    _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	    case $host_os in
+	      solaris2.[[0-5]] | solaris2.[[0-5]].*) ;;
+	      *)
+		# The compiler driver will combine and reorder linker options,
+		# but understands `-z linker_flag'.
+	        # Supported since Solaris 2.6 (maybe 2.5.1?)
+		_LT_TAGVAR(whole_archive_flag_spec, $1)='-z allextract$convenience -z defaultextract'
+	        ;;
+	    esac
+	    _LT_TAGVAR(link_all_deplibs, $1)=yes
+
+	    output_verbose_link_cmd='func_echo_all'
+
+	    # Archives containing C++ object files must be created using
+	    # "CC -xar", where "CC" is the Sun C++ compiler.  This is
+	    # necessary to make sure instantiated templates are included
+	    # in the archive.
+	    _LT_TAGVAR(old_archive_cmds, $1)='$CC -xar -o $oldlib $oldobjs'
+	    ;;
+          gcx*)
+	    # Green Hills C++ Compiler
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-h $wl$soname -o $lib'
+
+	    # The C++ compiler must be used to create the archive.
+	    _LT_TAGVAR(old_archive_cmds, $1)='$CC $LDFLAGS -archive -o $oldlib $oldobjs'
+	    ;;
+          *)
+	    # GNU C++ compiler with Solaris linker
+	    if test "$GXX" = yes && test "$with_gnu_ld" = no; then
+	      _LT_TAGVAR(no_undefined_flag, $1)=' ${wl}-z ${wl}defs'
+	      if $CC --version | $GREP -v '^2\.7' > /dev/null; then
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -shared $pic_flag -nostdlib $LDFLAGS $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-h $wl$soname -o $lib'
+	        _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+		  $CC -shared $pic_flag -nostdlib ${wl}-M $wl$lib.exp -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags~$RM $lib.exp'
+
+	        # Commands to make compiler produce verbose output that lists
+	        # what "hidden" libraries, object files and flags are used when
+	        # linking a shared library.
+	        output_verbose_link_cmd='$CC -shared $CFLAGS -v conftest.$objext 2>&1 | $GREP -v "^Configured with:" | $GREP "\-L"'
+	      else
+	        # g++ 2.7 appears to require `-G' NOT `-shared' on this
+	        # platform.
+	        _LT_TAGVAR(archive_cmds, $1)='$CC -G -nostdlib $LDFLAGS $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags ${wl}-h $wl$soname -o $lib'
+	        _LT_TAGVAR(archive_expsym_cmds, $1)='echo "{ global:" > $lib.exp~cat $export_symbols | $SED -e "s/\(.*\)/\1;/" >> $lib.exp~echo "local: *; };" >> $lib.exp~
+		  $CC -G -nostdlib ${wl}-M $wl$lib.exp -o $lib $predep_objects $libobjs $deplibs $postdep_objects $compiler_flags~$RM $lib.exp'
+
+	        # Commands to make compiler produce verbose output that lists
+	        # what "hidden" libraries, object files and flags are used when
+	        # linking a shared library.
+	        output_verbose_link_cmd='$CC -G $CFLAGS -v conftest.$objext 2>&1 | $GREP -v "^Configured with:" | $GREP "\-L"'
+	      fi
+
+	      _LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-R $wl$libdir'
+	      case $host_os in
+		solaris2.[[0-5]] | solaris2.[[0-5]].*) ;;
+		*)
+		  _LT_TAGVAR(whole_archive_flag_spec, $1)='${wl}-z ${wl}allextract$convenience ${wl}-z ${wl}defaultextract'
+		  ;;
+	      esac
+	    fi
+	    ;;
+        esac
+        ;;
+
+    sysv4*uw2* | sysv5OpenUNIX* | sysv5UnixWare7.[[01]].[[10]]* | unixware7* | sco3.2v5.0.[[024]]*)
+      _LT_TAGVAR(no_undefined_flag, $1)='${wl}-z,text'
+      _LT_TAGVAR(archive_cmds_need_lc, $1)=no
+      _LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+      runpath_var='LD_RUN_PATH'
+
+      case $cc_basename in
+        CC*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+	*)
+	  _LT_TAGVAR(archive_cmds, $1)='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	  ;;
+      esac
+      ;;
+
+      sysv5* | sco3.2v5* | sco5v6*)
+	# Note: We can NOT use -z defs as we might desire, because we do not
+	# link with -lc, and that would cause any symbols used from libc to
+	# always be unresolved, which means just about no library would
+	# ever link correctly.  If we're not using GNU ld we use -z text
+	# though, which does catch some bad symbols but isn't as heavy-handed
+	# as -z defs.
+	_LT_TAGVAR(no_undefined_flag, $1)='${wl}-z,text'
+	_LT_TAGVAR(allow_undefined_flag, $1)='${wl}-z,nodefs'
+	_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+	_LT_TAGVAR(hardcode_shlibpath_var, $1)=no
+	_LT_TAGVAR(hardcode_libdir_flag_spec, $1)='${wl}-R,$libdir'
+	_LT_TAGVAR(hardcode_libdir_separator, $1)=':'
+	_LT_TAGVAR(link_all_deplibs, $1)=yes
+	_LT_TAGVAR(export_dynamic_flag_spec, $1)='${wl}-Bexport'
+	runpath_var='LD_RUN_PATH'
+
+	case $cc_basename in
+          CC*)
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -G ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -G ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	    _LT_TAGVAR(old_archive_cmds, $1)='$CC -Tprelink_objects $oldobjs~
+	      '"$_LT_TAGVAR(old_archive_cmds, $1)"
+	    _LT_TAGVAR(reload_cmds, $1)='$CC -Tprelink_objects $reload_objs~
+	      '"$_LT_TAGVAR(reload_cmds, $1)"
+	    ;;
+	  *)
+	    _LT_TAGVAR(archive_cmds, $1)='$CC -shared ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	    _LT_TAGVAR(archive_expsym_cmds, $1)='$CC -shared ${wl}-Bexport:$export_symbols ${wl}-h,$soname -o $lib $libobjs $deplibs $compiler_flags'
+	    ;;
+	esac
+      ;;
+
+      tandem*)
+        case $cc_basename in
+          NCC*)
+	    # NonStop-UX NCC 3.20
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+          *)
+	    # FIXME: insert proper C++ library support
+	    _LT_TAGVAR(ld_shlibs, $1)=no
+	    ;;
+        esac
+        ;;
+
+      vxworks*)
+        # FIXME: insert proper C++ library support
+        _LT_TAGVAR(ld_shlibs, $1)=no
+        ;;
+
+      *)
+        # FIXME: insert proper C++ library support
+        _LT_TAGVAR(ld_shlibs, $1)=no
+        ;;
+    esac
+
+    AC_MSG_RESULT([$_LT_TAGVAR(ld_shlibs, $1)])
+    test "$_LT_TAGVAR(ld_shlibs, $1)" = no && can_build_shared=no
+
+    _LT_TAGVAR(GCC, $1)="$GXX"
+    _LT_TAGVAR(LD, $1)="$LD"
+
+    ## CAVEAT EMPTOR:
+    ## There is no encapsulation within the following macros, do not change
+    ## the running order or otherwise move them around unless you know exactly
+    ## what you are doing...
+    _LT_SYS_HIDDEN_LIBDEPS($1)
+    _LT_COMPILER_PIC($1)
+    _LT_COMPILER_C_O($1)
+    _LT_COMPILER_FILE_LOCKS($1)
+    _LT_LINKER_SHLIBS($1)
+    _LT_SYS_DYNAMIC_LINKER($1)
+    _LT_LINKER_HARDCODE_LIBPATH($1)
+
+    _LT_CONFIG($1)
+  fi # test -n "$compiler"
+
+  CC=$lt_save_CC
+  CFLAGS=$lt_save_CFLAGS
+  LDCXX=$LD
+  LD=$lt_save_LD
+  GCC=$lt_save_GCC
+  with_gnu_ld=$lt_save_with_gnu_ld
+  lt_cv_path_LDCXX=$lt_cv_path_LD
+  lt_cv_path_LD=$lt_save_path_LD
+  lt_cv_prog_gnu_ldcxx=$lt_cv_prog_gnu_ld
+  lt_cv_prog_gnu_ld=$lt_save_with_gnu_ld
+fi # test "$_lt_caught_CXX_error" != yes
+
+AC_LANG_POP
+])# _LT_LANG_CXX_CONFIG
+
+
+# _LT_FUNC_STRIPNAME_CNF
+# ----------------------
+# func_stripname_cnf prefix suffix name
+# strip PREFIX and SUFFIX off of NAME.
+# PREFIX and SUFFIX must not contain globbing or regex special
+# characters, hashes, percent signs, but SUFFIX may contain a leading
+# dot (in which case that matches only a dot).
+#
+# This function is identical to the (non-XSI) version of func_stripname,
+# except this one can be used by m4 code that may be executed by configure,
+# rather than the libtool script.
+m4_defun([_LT_FUNC_STRIPNAME_CNF],[dnl
+AC_REQUIRE([_LT_DECL_SED])
+AC_REQUIRE([_LT_PROG_ECHO_BACKSLASH])
+func_stripname_cnf ()
+{
+  case ${2} in
+  .*) func_stripname_result=`$ECHO "${3}" | $SED "s%^${1}%%; s%\\\\${2}\$%%"`;;
+  *)  func_stripname_result=`$ECHO "${3}" | $SED "s%^${1}%%; s%${2}\$%%"`;;
+  esac
+} # func_stripname_cnf
+])# _LT_FUNC_STRIPNAME_CNF
+
+# _LT_SYS_HIDDEN_LIBDEPS([TAGNAME])
+# ---------------------------------
+# Figure out "hidden" library dependencies from verbose
+# compiler output when linking a shared library.
+# Parse the compiler output and extract the necessary
+# objects, libraries and library flags.
+m4_defun([_LT_SYS_HIDDEN_LIBDEPS],
+[m4_require([_LT_FILEUTILS_DEFAULTS])dnl
+AC_REQUIRE([_LT_FUNC_STRIPNAME_CNF])dnl
+# Dependencies to place before and after the object being linked:
+_LT_TAGVAR(predep_objects, $1)=
+_LT_TAGVAR(postdep_objects, $1)=
+_LT_TAGVAR(predeps, $1)=
+_LT_TAGVAR(postdeps, $1)=
+_LT_TAGVAR(compiler_lib_search_path, $1)=
+
+dnl we can't use the lt_simple_compile_test_code here,
+dnl because it contains code intended for an executable,
+dnl not a library.  It's possible we should let each
+dnl tag define a new lt_????_link_test_code variable,
+dnl but it's only used here...
+m4_if([$1], [], [cat > conftest.$ac_ext <<_LT_EOF
+int a;
+void foo (void) { a = 0; }
+_LT_EOF
+], [$1], [CXX], [cat > conftest.$ac_ext <<_LT_EOF
+class Foo
+{
+public:
+  Foo (void) { a = 0; }
+private:
+  int a;
+};
+_LT_EOF
+], [$1], [F77], [cat > conftest.$ac_ext <<_LT_EOF
+      subroutine foo
+      implicit none
+      integer*4 a
+      a=0
+      return
+      end
+_LT_EOF
+], [$1], [FC], [cat > conftest.$ac_ext <<_LT_EOF
+      subroutine foo
+      implicit none
+      integer a
+      a=0
+      return
+      end
+_LT_EOF
+], [$1], [GCJ], [cat > conftest.$ac_ext <<_LT_EOF
+public class foo {
+  private int a;
+  public void bar (void) {
+    a = 0;
+  }
+};
+_LT_EOF
+], [$1], [GO], [cat > conftest.$ac_ext <<_LT_EOF
+package foo
+func foo() {
+}
+_LT_EOF
+])
+
+_lt_libdeps_save_CFLAGS=$CFLAGS
+case "$CC $CFLAGS " in #(
+*\ -flto*\ *) CFLAGS="$CFLAGS -fno-lto" ;;
+*\ -fwhopr*\ *) CFLAGS="$CFLAGS -fno-whopr" ;;
+*\ -fuse-linker-plugin*\ *) CFLAGS="$CFLAGS -fno-use-linker-plugin" ;;
+esac
+
+dnl Parse the compiler output and extract the necessary
+dnl objects, libraries and library flags.
+if AC_TRY_EVAL(ac_compile); then
+  # Parse the compiler output and extract the necessary
+  # objects, libraries and library flags.
+
+  # Sentinel used to keep track of whether or not we are before
+  # the conftest object file.
+  pre_test_object_deps_done=no
+
+  for p in `eval "$output_verbose_link_cmd"`; do
+    case ${prev}${p} in
+
+    -L* | -R* | -l*)
+       # Some compilers place space between "-{L,R}" and the path.
+       # Remove the space.
+       if test $p = "-L" ||
+          test $p = "-R"; then
+	 prev=$p
+	 continue
+       fi
+
+       # Expand the sysroot to ease extracting the directories later.
+       if test -z "$prev"; then
+         case $p in
+         -L*) func_stripname_cnf '-L' '' "$p"; prev=-L; p=$func_stripname_result ;;
+         -R*) func_stripname_cnf '-R' '' "$p"; prev=-R; p=$func_stripname_result ;;
+         -l*) func_stripname_cnf '-l' '' "$p"; prev=-l; p=$func_stripname_result ;;
+         esac
+       fi
+       case $p in
+       =*) func_stripname_cnf '=' '' "$p"; p=$lt_sysroot$func_stripname_result ;;
+       esac
+       if test "$pre_test_object_deps_done" = no; then
+	 case ${prev} in
+	 -L | -R)
+	   # Internal compiler library paths should come after those
+	   # provided the user.  The postdeps already come after the
+	   # user supplied libs so there is no need to process them.
+	   if test -z "$_LT_TAGVAR(compiler_lib_search_path, $1)"; then
+	     _LT_TAGVAR(compiler_lib_search_path, $1)="${prev}${p}"
+	   else
+	     _LT_TAGVAR(compiler_lib_search_path, $1)="${_LT_TAGVAR(compiler_lib_search_path, $1)} ${prev}${p}"
+	   fi
+	   ;;
+	 # The "-l" case would never come before the object being
+	 # linked, so don't bother handling this case.
+	 esac
+       else
+	 if test -z "$_LT_TAGVAR(postdeps, $1)"; then
+	   _LT_TAGVAR(postdeps, $1)="${prev}${p}"
+	 else
+	   _LT_TAGVAR(postdeps, $1)="${_LT_TAGVAR(postdeps, $1)} ${prev}${p}"
+	 fi
+       fi
+       prev=
+       ;;
+
+    *.lto.$objext) ;; # Ignore GCC LTO objects
+    *.$objext)
+       # This assumes that the test object file only shows up
+       # once in the compiler output.
+       if test "$p" = "conftest.$objext"; then
+	 pre_test_object_deps_done=yes
+	 continue
+       fi
+
+       if test "$pre_test_object_deps_done" = no; then
+	 if test -z "$_LT_TAGVAR(predep_objects, $1)"; then
+	   _LT_TAGVAR(predep_objects, $1)="$p"
+	 else
+	   _LT_TAGVAR(predep_objects, $1)="$_LT_TAGVAR(predep_objects, $1) $p"
+	 fi
+       else
+	 if test -z "$_LT_TAGVAR(postdep_objects, $1)"; then
+	   _LT_TAGVAR(postdep_objects, $1)="$p"
+	 else
+	   _LT_TAGVAR(postdep_objects, $1)="$_LT_TAGVAR(postdep_objects, $1) $p"
+	 fi
+       fi
+       ;;
+
+    *) ;; # Ignore the rest.
+
+    esac
+  done
+
+  # Clean up.
+  rm -f a.out a.exe
+else
+  echo "libtool.m4: error: problem compiling $1 test program"
+fi
+
+$RM -f confest.$objext
+CFLAGS=$_lt_libdeps_save_CFLAGS
+
+# PORTME: override above test on systems where it is broken
+m4_if([$1], [CXX],
+[case $host_os in
+interix[[3-9]]*)
+  # Interix 3.5 installs completely hosed .la files for C++, so rather than
+  # hack all around it, let's just trust "g++" to DTRT.
+  _LT_TAGVAR(predep_objects,$1)=
+  _LT_TAGVAR(postdep_objects,$1)=
+  _LT_TAGVAR(postdeps,$1)=
+  ;;
+
+linux*)
+  case `$CC -V 2>&1 | sed 5q` in
+  *Sun\ C*)
+    # Sun C++ 5.9
+
+    # The more standards-conforming stlport4 library is
+    # incompatible with the Cstd library. Avoid specifying
+    # it if it's in CXXFLAGS. Ignore libCrun as
+    # -library=stlport4 depends on it.
+    case " $CXX $CXXFLAGS " in
+    *" -library=stlport4 "*)
+      solaris_use_stlport4=yes
+      ;;
+    esac
+
+    if test "$solaris_use_stlport4" != yes; then
+      _LT_TAGVAR(postdeps,$1)='-library=Cstd -library=Crun'
+    fi
+    ;;
+  esac
+  ;;
+
+solaris*)
+  case $cc_basename in
+  CC* | sunCC*)
+    # The more standards-conforming stlport4 library is
+    # incompatible with the Cstd library. Avoid specifying
+    # it if it's in CXXFLAGS. Ignore libCrun as
+    # -library=stlport4 depends on it.
+    case " $CXX $CXXFLAGS " in
+    *" -library=stlport4 "*)
+      solaris_use_stlport4=yes
+      ;;
+    esac
+
+    # Adding this requires a known-good setup of shared libraries for
+    # Sun compiler versions before 5.6, else PIC objects from an old
+    # archive will be linked into the output, leading to subtle bugs.
+    if test "$solaris_use_stlport4" != yes; then
+      _LT_TAGVAR(postdeps,$1)='-library=Cstd -library=Crun'
+    fi
+    ;;
+  esac
+  ;;
+esac
+])
+
+case " $_LT_TAGVAR(postdeps, $1) " in
+*" -lc "*) _LT_TAGVAR(archive_cmds_need_lc, $1)=no ;;
+esac
+ _LT_TAGVAR(compiler_lib_search_dirs, $1)=
+if test -n "${_LT_TAGVAR(compiler_lib_search_path, $1)}"; then
+ _LT_TAGVAR(compiler_lib_search_dirs, $1)=`echo " ${_LT_TAGVAR(compiler_lib_search_path, $1)}" | ${SED} -e 's! -L! !g' -e 's!^ !!'`
+fi
+_LT_TAGDECL([], [compiler_lib_search_dirs], [1],
+    [The directories searched by this compiler when creating a shared library])
+_LT_TAGDECL([], [predep_objects], [1],
+    [Dependencies to place before and after the objects being linked to
+    create a shared library])
+_LT_TAGDECL([], [postdep_objects], [1])
+_LT_TAGDECL([], [predeps], [1])
+_LT_TAGDECL([], [postdeps], [1])
+_LT_TAGDECL([], [compiler_lib_search_path], [1],
+    [The library search path used internally by the compiler when linking
+    a shared library])
+])# _LT_SYS_HIDDEN_LIBDEPS
+
+
+# _LT_LANG_F77_CONFIG([TAG])
+# --------------------------
+# Ensure that the configuration variables for a Fortran 77 compiler are
+# suitably defined.  These variables are subsequently used by _LT_CONFIG
+# to write the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_F77_CONFIG],
+[AC_LANG_PUSH(Fortran 77)
+if test -z "$F77" || test "X$F77" = "Xno"; then
+  _lt_disable_F77=yes
+fi
+
+_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+_LT_TAGVAR(allow_undefined_flag, $1)=
+_LT_TAGVAR(always_export_symbols, $1)=no
+_LT_TAGVAR(archive_expsym_cmds, $1)=
+_LT_TAGVAR(export_dynamic_flag_spec, $1)=
+_LT_TAGVAR(hardcode_direct, $1)=no
+_LT_TAGVAR(hardcode_direct_absolute, $1)=no
+_LT_TAGVAR(hardcode_libdir_flag_spec, $1)=
+_LT_TAGVAR(hardcode_libdir_separator, $1)=
+_LT_TAGVAR(hardcode_minus_L, $1)=no
+_LT_TAGVAR(hardcode_automatic, $1)=no
+_LT_TAGVAR(inherit_rpath, $1)=no
+_LT_TAGVAR(module_cmds, $1)=
+_LT_TAGVAR(module_expsym_cmds, $1)=
+_LT_TAGVAR(link_all_deplibs, $1)=unknown
+_LT_TAGVAR(old_archive_cmds, $1)=$old_archive_cmds
+_LT_TAGVAR(reload_flag, $1)=$reload_flag
+_LT_TAGVAR(reload_cmds, $1)=$reload_cmds
+_LT_TAGVAR(no_undefined_flag, $1)=
+_LT_TAGVAR(whole_archive_flag_spec, $1)=
+_LT_TAGVAR(enable_shared_with_static_runtimes, $1)=no
+
+# Source file extension for f77 test sources.
+ac_ext=f
+
+# Object file extension for compiled f77 test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# No sense in running all these tests if we already determined that
+# the F77 compiler isn't working.  Some variables (like enable_shared)
+# are currently assumed to apply to all compilers on this platform,
+# and will be corrupted by setting them based on a non-working compiler.
+if test "$_lt_disable_F77" != yes; then
+  # Code to be used in simple compile tests
+  lt_simple_compile_test_code="\
+      subroutine t
+      return
+      end
+"
+
+  # Code to be used in simple link tests
+  lt_simple_link_test_code="\
+      program t
+      end
+"
+
+  # ltmain only uses $CC for tagged configurations so make sure $CC is set.
+  _LT_TAG_COMPILER
+
+  # save warnings/boilerplate of simple test code
+  _LT_COMPILER_BOILERPLATE
+  _LT_LINKER_BOILERPLATE
+
+  # Allow CC to be a program name with arguments.
+  lt_save_CC="$CC"
+  lt_save_GCC=$GCC
+  lt_save_CFLAGS=$CFLAGS
+  CC=${F77-"f77"}
+  CFLAGS=$FFLAGS
+  compiler=$CC
+  _LT_TAGVAR(compiler, $1)=$CC
+  _LT_CC_BASENAME([$compiler])
+  GCC=$G77
+  if test -n "$compiler"; then
+    AC_MSG_CHECKING([if libtool supports shared libraries])
+    AC_MSG_RESULT([$can_build_shared])
+
+    AC_MSG_CHECKING([whether to build shared libraries])
+    test "$can_build_shared" = "no" && enable_shared=no
+
+    # On AIX, shared libraries and static libraries use the same namespace, and
+    # are all built from PIC.
+    case $host_os in
+      aix3*)
+        test "$enable_shared" = yes && enable_static=no
+        if test -n "$RANLIB"; then
+          archive_cmds="$archive_cmds~\$RANLIB \$lib"
+          postinstall_cmds='$RANLIB $lib'
+        fi
+        ;;
+      aix[[4-9]]*)
+	if test "$host_cpu" != ia64 && test "$aix_use_runtimelinking" = no ; then
+	  test "$enable_shared" = yes && enable_static=no
+	fi
+        ;;
+    esac
+    AC_MSG_RESULT([$enable_shared])
+
+    AC_MSG_CHECKING([whether to build static libraries])
+    # Make sure either enable_shared or enable_static is yes.
+    test "$enable_shared" = yes || enable_static=yes
+    AC_MSG_RESULT([$enable_static])
+
+    _LT_TAGVAR(GCC, $1)="$G77"
+    _LT_TAGVAR(LD, $1)="$LD"
+
+    ## CAVEAT EMPTOR:
+    ## There is no encapsulation within the following macros, do not change
+    ## the running order or otherwise move them around unless you know exactly
+    ## what you are doing...
+    _LT_COMPILER_PIC($1)
+    _LT_COMPILER_C_O($1)
+    _LT_COMPILER_FILE_LOCKS($1)
+    _LT_LINKER_SHLIBS($1)
+    _LT_SYS_DYNAMIC_LINKER($1)
+    _LT_LINKER_HARDCODE_LIBPATH($1)
+
+    _LT_CONFIG($1)
+  fi # test -n "$compiler"
+
+  GCC=$lt_save_GCC
+  CC="$lt_save_CC"
+  CFLAGS="$lt_save_CFLAGS"
+fi # test "$_lt_disable_F77" != yes
+
+AC_LANG_POP
+])# _LT_LANG_F77_CONFIG
+
+
+# _LT_LANG_FC_CONFIG([TAG])
+# -------------------------
+# Ensure that the configuration variables for a Fortran compiler are
+# suitably defined.  These variables are subsequently used by _LT_CONFIG
+# to write the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_FC_CONFIG],
+[AC_LANG_PUSH(Fortran)
+
+if test -z "$FC" || test "X$FC" = "Xno"; then
+  _lt_disable_FC=yes
+fi
+
+_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+_LT_TAGVAR(allow_undefined_flag, $1)=
+_LT_TAGVAR(always_export_symbols, $1)=no
+_LT_TAGVAR(archive_expsym_cmds, $1)=
+_LT_TAGVAR(export_dynamic_flag_spec, $1)=
+_LT_TAGVAR(hardcode_direct, $1)=no
+_LT_TAGVAR(hardcode_direct_absolute, $1)=no
+_LT_TAGVAR(hardcode_libdir_flag_spec, $1)=
+_LT_TAGVAR(hardcode_libdir_separator, $1)=
+_LT_TAGVAR(hardcode_minus_L, $1)=no
+_LT_TAGVAR(hardcode_automatic, $1)=no
+_LT_TAGVAR(inherit_rpath, $1)=no
+_LT_TAGVAR(module_cmds, $1)=
+_LT_TAGVAR(module_expsym_cmds, $1)=
+_LT_TAGVAR(link_all_deplibs, $1)=unknown
+_LT_TAGVAR(old_archive_cmds, $1)=$old_archive_cmds
+_LT_TAGVAR(reload_flag, $1)=$reload_flag
+_LT_TAGVAR(reload_cmds, $1)=$reload_cmds
+_LT_TAGVAR(no_undefined_flag, $1)=
+_LT_TAGVAR(whole_archive_flag_spec, $1)=
+_LT_TAGVAR(enable_shared_with_static_runtimes, $1)=no
+
+# Source file extension for fc test sources.
+ac_ext=${ac_fc_srcext-f}
+
+# Object file extension for compiled fc test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# No sense in running all these tests if we already determined that
+# the FC compiler isn't working.  Some variables (like enable_shared)
+# are currently assumed to apply to all compilers on this platform,
+# and will be corrupted by setting them based on a non-working compiler.
+if test "$_lt_disable_FC" != yes; then
+  # Code to be used in simple compile tests
+  lt_simple_compile_test_code="\
+      subroutine t
+      return
+      end
+"
+
+  # Code to be used in simple link tests
+  lt_simple_link_test_code="\
+      program t
+      end
+"
+
+  # ltmain only uses $CC for tagged configurations so make sure $CC is set.
+  _LT_TAG_COMPILER
+
+  # save warnings/boilerplate of simple test code
+  _LT_COMPILER_BOILERPLATE
+  _LT_LINKER_BOILERPLATE
+
+  # Allow CC to be a program name with arguments.
+  lt_save_CC="$CC"
+  lt_save_GCC=$GCC
+  lt_save_CFLAGS=$CFLAGS
+  CC=${FC-"f95"}
+  CFLAGS=$FCFLAGS
+  compiler=$CC
+  GCC=$ac_cv_fc_compiler_gnu
+
+  _LT_TAGVAR(compiler, $1)=$CC
+  _LT_CC_BASENAME([$compiler])
+
+  if test -n "$compiler"; then
+    AC_MSG_CHECKING([if libtool supports shared libraries])
+    AC_MSG_RESULT([$can_build_shared])
+
+    AC_MSG_CHECKING([whether to build shared libraries])
+    test "$can_build_shared" = "no" && enable_shared=no
+
+    # On AIX, shared libraries and static libraries use the same namespace, and
+    # are all built from PIC.
+    case $host_os in
+      aix3*)
+        test "$enable_shared" = yes && enable_static=no
+        if test -n "$RANLIB"; then
+          archive_cmds="$archive_cmds~\$RANLIB \$lib"
+          postinstall_cmds='$RANLIB $lib'
+        fi
+        ;;
+      aix[[4-9]]*)
+	if test "$host_cpu" != ia64 && test "$aix_use_runtimelinking" = no ; then
+	  test "$enable_shared" = yes && enable_static=no
+	fi
+        ;;
+    esac
+    AC_MSG_RESULT([$enable_shared])
+
+    AC_MSG_CHECKING([whether to build static libraries])
+    # Make sure either enable_shared or enable_static is yes.
+    test "$enable_shared" = yes || enable_static=yes
+    AC_MSG_RESULT([$enable_static])
+
+    _LT_TAGVAR(GCC, $1)="$ac_cv_fc_compiler_gnu"
+    _LT_TAGVAR(LD, $1)="$LD"
+
+    ## CAVEAT EMPTOR:
+    ## There is no encapsulation within the following macros, do not change
+    ## the running order or otherwise move them around unless you know exactly
+    ## what you are doing...
+    _LT_SYS_HIDDEN_LIBDEPS($1)
+    _LT_COMPILER_PIC($1)
+    _LT_COMPILER_C_O($1)
+    _LT_COMPILER_FILE_LOCKS($1)
+    _LT_LINKER_SHLIBS($1)
+    _LT_SYS_DYNAMIC_LINKER($1)
+    _LT_LINKER_HARDCODE_LIBPATH($1)
+
+    _LT_CONFIG($1)
+  fi # test -n "$compiler"
+
+  GCC=$lt_save_GCC
+  CC=$lt_save_CC
+  CFLAGS=$lt_save_CFLAGS
+fi # test "$_lt_disable_FC" != yes
+
+AC_LANG_POP
+])# _LT_LANG_FC_CONFIG
+
+
+# _LT_LANG_GCJ_CONFIG([TAG])
+# --------------------------
+# Ensure that the configuration variables for the GNU Java Compiler compiler
+# are suitably defined.  These variables are subsequently used by _LT_CONFIG
+# to write the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_GCJ_CONFIG],
+[AC_REQUIRE([LT_PROG_GCJ])dnl
+AC_LANG_SAVE
+
+# Source file extension for Java test sources.
+ac_ext=java
+
+# Object file extension for compiled Java test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# Code to be used in simple compile tests
+lt_simple_compile_test_code="class foo {}"
+
+# Code to be used in simple link tests
+lt_simple_link_test_code='public class conftest { public static void main(String[[]] argv) {}; }'
+
+# ltmain only uses $CC for tagged configurations so make sure $CC is set.
+_LT_TAG_COMPILER
+
+# save warnings/boilerplate of simple test code
+_LT_COMPILER_BOILERPLATE
+_LT_LINKER_BOILERPLATE
+
+# Allow CC to be a program name with arguments.
+lt_save_CC=$CC
+lt_save_CFLAGS=$CFLAGS
+lt_save_GCC=$GCC
+GCC=yes
+CC=${GCJ-"gcj"}
+CFLAGS=$GCJFLAGS
+compiler=$CC
+_LT_TAGVAR(compiler, $1)=$CC
+_LT_TAGVAR(LD, $1)="$LD"
+_LT_CC_BASENAME([$compiler])
+
+# GCJ did not exist at the time GCC didn't implicitly link libc in.
+_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+
+_LT_TAGVAR(old_archive_cmds, $1)=$old_archive_cmds
+_LT_TAGVAR(reload_flag, $1)=$reload_flag
+_LT_TAGVAR(reload_cmds, $1)=$reload_cmds
+
+## CAVEAT EMPTOR:
+## There is no encapsulation within the following macros, do not change
+## the running order or otherwise move them around unless you know exactly
+## what you are doing...
+if test -n "$compiler"; then
+  _LT_COMPILER_NO_RTTI($1)
+  _LT_COMPILER_PIC($1)
+  _LT_COMPILER_C_O($1)
+  _LT_COMPILER_FILE_LOCKS($1)
+  _LT_LINKER_SHLIBS($1)
+  _LT_LINKER_HARDCODE_LIBPATH($1)
+
+  _LT_CONFIG($1)
+fi
+
+AC_LANG_RESTORE
+
+GCC=$lt_save_GCC
+CC=$lt_save_CC
+CFLAGS=$lt_save_CFLAGS
+])# _LT_LANG_GCJ_CONFIG
+
+
+# _LT_LANG_GO_CONFIG([TAG])
+# --------------------------
+# Ensure that the configuration variables for the GNU Go compiler
+# are suitably defined.  These variables are subsequently used by _LT_CONFIG
+# to write the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_GO_CONFIG],
+[AC_REQUIRE([LT_PROG_GO])dnl
+AC_LANG_SAVE
+
+# Source file extension for Go test sources.
+ac_ext=go
+
+# Object file extension for compiled Go test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# Code to be used in simple compile tests
+lt_simple_compile_test_code="package main; func main() { }"
+
+# Code to be used in simple link tests
+lt_simple_link_test_code='package main; func main() { }'
+
+# ltmain only uses $CC for tagged configurations so make sure $CC is set.
+_LT_TAG_COMPILER
+
+# save warnings/boilerplate of simple test code
+_LT_COMPILER_BOILERPLATE
+_LT_LINKER_BOILERPLATE
+
+# Allow CC to be a program name with arguments.
+lt_save_CC=$CC
+lt_save_CFLAGS=$CFLAGS
+lt_save_GCC=$GCC
+GCC=yes
+CC=${GOC-"gccgo"}
+CFLAGS=$GOFLAGS
+compiler=$CC
+_LT_TAGVAR(compiler, $1)=$CC
+_LT_TAGVAR(LD, $1)="$LD"
+_LT_CC_BASENAME([$compiler])
+
+# Go did not exist at the time GCC didn't implicitly link libc in.
+_LT_TAGVAR(archive_cmds_need_lc, $1)=no
+
+_LT_TAGVAR(old_archive_cmds, $1)=$old_archive_cmds
+_LT_TAGVAR(reload_flag, $1)=$reload_flag
+_LT_TAGVAR(reload_cmds, $1)=$reload_cmds
+
+## CAVEAT EMPTOR:
+## There is no encapsulation within the following macros, do not change
+## the running order or otherwise move them around unless you know exactly
+## what you are doing...
+if test -n "$compiler"; then
+  _LT_COMPILER_NO_RTTI($1)
+  _LT_COMPILER_PIC($1)
+  _LT_COMPILER_C_O($1)
+  _LT_COMPILER_FILE_LOCKS($1)
+  _LT_LINKER_SHLIBS($1)
+  _LT_LINKER_HARDCODE_LIBPATH($1)
+
+  _LT_CONFIG($1)
+fi
+
+AC_LANG_RESTORE
+
+GCC=$lt_save_GCC
+CC=$lt_save_CC
+CFLAGS=$lt_save_CFLAGS
+])# _LT_LANG_GO_CONFIG
+
+
+# _LT_LANG_RC_CONFIG([TAG])
+# -------------------------
+# Ensure that the configuration variables for the Windows resource compiler
+# are suitably defined.  These variables are subsequently used by _LT_CONFIG
+# to write the compiler configuration to `libtool'.
+m4_defun([_LT_LANG_RC_CONFIG],
+[AC_REQUIRE([LT_PROG_RC])dnl
+AC_LANG_SAVE
+
+# Source file extension for RC test sources.
+ac_ext=rc
+
+# Object file extension for compiled RC test sources.
+objext=o
+_LT_TAGVAR(objext, $1)=$objext
+
+# Code to be used in simple compile tests
+lt_simple_compile_test_code='sample MENU { MENUITEM "&Soup", 100, CHECKED }'
+
+# Code to be used in simple link tests
+lt_simple_link_test_code="$lt_simple_compile_test_code"
+
+# ltmain only uses $CC for tagged configurations so make sure $CC is set.
+_LT_TAG_COMPILER
+
+# save warnings/boilerplate of simple test code
+_LT_COMPILER_BOILERPLATE
+_LT_LINKER_BOILERPLATE
+
+# Allow CC to be a program name with arguments.
+lt_save_CC="$CC"
+lt_save_CFLAGS=$CFLAGS
+lt_save_GCC=$GCC
+GCC=
+CC=${RC-"windres"}
+CFLAGS=
+compiler=$CC
+_LT_TAGVAR(compiler, $1)=$CC
+_LT_CC_BASENAME([$compiler])
+_LT_TAGVAR(lt_cv_prog_compiler_c_o, $1)=yes
+
+if test -n "$compiler"; then
+  :
+  _LT_CONFIG($1)
+fi
+
+GCC=$lt_save_GCC
+AC_LANG_RESTORE
+CC=$lt_save_CC
+CFLAGS=$lt_save_CFLAGS
+])# _LT_LANG_RC_CONFIG
+
+
+# LT_PROG_GCJ
+# -----------
+AC_DEFUN([LT_PROG_GCJ],
+[m4_ifdef([AC_PROG_GCJ], [AC_PROG_GCJ],
+  [m4_ifdef([A][M_PROG_GCJ], [A][M_PROG_GCJ],
+    [AC_CHECK_TOOL(GCJ, gcj,)
+      test "x${GCJFLAGS+set}" = xset || GCJFLAGS="-g -O2"
+      AC_SUBST(GCJFLAGS)])])[]dnl
+])
+
+# Old name:
+AU_ALIAS([LT_AC_PROG_GCJ], [LT_PROG_GCJ])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([LT_AC_PROG_GCJ], [])
+
+
+# LT_PROG_GO
+# ----------
+AC_DEFUN([LT_PROG_GO],
+[AC_CHECK_TOOL(GOC, gccgo,)
+])
+
+
+# LT_PROG_RC
+# ----------
+AC_DEFUN([LT_PROG_RC],
+[AC_CHECK_TOOL(RC, windres,)
+])
+
+# Old name:
+AU_ALIAS([LT_AC_PROG_RC], [LT_PROG_RC])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([LT_AC_PROG_RC], [])
+
+
+# _LT_DECL_EGREP
+# --------------
+# If we don't have a new enough Autoconf to choose the best grep
+# available, choose the one first in the user's PATH.
+m4_defun([_LT_DECL_EGREP],
+[AC_REQUIRE([AC_PROG_EGREP])dnl
+AC_REQUIRE([AC_PROG_FGREP])dnl
+test -z "$GREP" && GREP=grep
+_LT_DECL([], [GREP], [1], [A grep program that handles long lines])
+_LT_DECL([], [EGREP], [1], [An ERE matcher])
+_LT_DECL([], [FGREP], [1], [A literal string matcher])
+dnl Non-bleeding-edge autoconf doesn't subst GREP, so do it here too
+AC_SUBST([GREP])
+])
+
+
+# _LT_DECL_OBJDUMP
+# --------------
+# If we don't have a new enough Autoconf to choose the best objdump
+# available, choose the one first in the user's PATH.
+m4_defun([_LT_DECL_OBJDUMP],
+[AC_CHECK_TOOL(OBJDUMP, objdump, false)
+test -z "$OBJDUMP" && OBJDUMP=objdump
+_LT_DECL([], [OBJDUMP], [1], [An object symbol dumper])
+AC_SUBST([OBJDUMP])
+])
+
+# _LT_DECL_DLLTOOL
+# ----------------
+# Ensure DLLTOOL variable is set.
+m4_defun([_LT_DECL_DLLTOOL],
+[AC_CHECK_TOOL(DLLTOOL, dlltool, false)
+test -z "$DLLTOOL" && DLLTOOL=dlltool
+_LT_DECL([], [DLLTOOL], [1], [DLL creation program])
+AC_SUBST([DLLTOOL])
+])
+
+# _LT_DECL_SED
+# ------------
+# Check for a fully-functional sed program, that truncates
+# as few characters as possible.  Prefer GNU sed if found.
+m4_defun([_LT_DECL_SED],
+[AC_PROG_SED
+test -z "$SED" && SED=sed
+Xsed="$SED -e 1s/^X//"
+_LT_DECL([], [SED], [1], [A sed program that does not truncate output])
+_LT_DECL([], [Xsed], ["\$SED -e 1s/^X//"],
+    [Sed that helps us avoid accidentally triggering echo(1) options like -n])
+])# _LT_DECL_SED
+
+m4_ifndef([AC_PROG_SED], [
+############################################################
+# NOTE: This macro has been submitted for inclusion into   #
+#  GNU Autoconf as AC_PROG_SED.  When it is available in   #
+#  a released version of Autoconf we should remove this    #
+#  macro and use it instead.                               #
+############################################################
+
+m4_defun([AC_PROG_SED],
+[AC_MSG_CHECKING([for a sed that does not truncate output])
+AC_CACHE_VAL(lt_cv_path_SED,
+[# Loop through the user's path and test for sed and gsed.
+# Then use that list of sed's as ones to test for truncation.
+as_save_IFS=$IFS; IFS=$PATH_SEPARATOR
+for as_dir in $PATH
+do
+  IFS=$as_save_IFS
+  test -z "$as_dir" && as_dir=.
+  for lt_ac_prog in sed gsed; do
+    for ac_exec_ext in '' $ac_executable_extensions; do
+      if $as_executable_p "$as_dir/$lt_ac_prog$ac_exec_ext"; then
+        lt_ac_sed_list="$lt_ac_sed_list $as_dir/$lt_ac_prog$ac_exec_ext"
+      fi
+    done
+  done
+done
+IFS=$as_save_IFS
+lt_ac_max=0
+lt_ac_count=0
+# Add /usr/xpg4/bin/sed as it is typically found on Solaris
+# along with /bin/sed that truncates output.
+for lt_ac_sed in $lt_ac_sed_list /usr/xpg4/bin/sed; do
+  test ! -f $lt_ac_sed && continue
+  cat /dev/null > conftest.in
+  lt_ac_count=0
+  echo $ECHO_N "0123456789$ECHO_C" >conftest.in
+  # Check for GNU sed and select it if it is found.
+  if "$lt_ac_sed" --version 2>&1 < /dev/null | grep 'GNU' > /dev/null; then
+    lt_cv_path_SED=$lt_ac_sed
+    break
+  fi
+  while true; do
+    cat conftest.in conftest.in >conftest.tmp
+    mv conftest.tmp conftest.in
+    cp conftest.in conftest.nl
+    echo >>conftest.nl
+    $lt_ac_sed -e 's/a$//' < conftest.nl >conftest.out || break
+    cmp -s conftest.out conftest.nl || break
+    # 10000 chars as input seems more than enough
+    test $lt_ac_count -gt 10 && break
+    lt_ac_count=`expr $lt_ac_count + 1`
+    if test $lt_ac_count -gt $lt_ac_max; then
+      lt_ac_max=$lt_ac_count
+      lt_cv_path_SED=$lt_ac_sed
+    fi
+  done
+done
+])
+SED=$lt_cv_path_SED
+AC_SUBST([SED])
+AC_MSG_RESULT([$SED])
+])#AC_PROG_SED
+])#m4_ifndef
+
+# Old name:
+AU_ALIAS([LT_AC_PROG_SED], [AC_PROG_SED])
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([LT_AC_PROG_SED], [])
+
+
+# _LT_CHECK_SHELL_FEATURES
+# ------------------------
+# Find out whether the shell is Bourne or XSI compatible,
+# or has some other useful features.
+m4_defun([_LT_CHECK_SHELL_FEATURES],
+[AC_MSG_CHECKING([whether the shell understands some XSI constructs])
+# Try some XSI features
+xsi_shell=no
+( _lt_dummy="a/b/c"
+  test "${_lt_dummy##*/},${_lt_dummy%/*},${_lt_dummy#??}"${_lt_dummy%"$_lt_dummy"}, \
+      = c,a/b,b/c, \
+    && eval 'test $(( 1 + 1 )) -eq 2 \
+    && test "${#_lt_dummy}" -eq 5' ) >/dev/null 2>&1 \
+  && xsi_shell=yes
+AC_MSG_RESULT([$xsi_shell])
+_LT_CONFIG_LIBTOOL_INIT([xsi_shell='$xsi_shell'])
+
+AC_MSG_CHECKING([whether the shell understands "+="])
+lt_shell_append=no
+( foo=bar; set foo baz; eval "$[1]+=\$[2]" && test "$foo" = barbaz ) \
+    >/dev/null 2>&1 \
+  && lt_shell_append=yes
+AC_MSG_RESULT([$lt_shell_append])
+_LT_CONFIG_LIBTOOL_INIT([lt_shell_append='$lt_shell_append'])
+
+if ( (MAIL=60; unset MAIL) || exit) >/dev/null 2>&1; then
+  lt_unset=unset
+else
+  lt_unset=false
+fi
+_LT_DECL([], [lt_unset], [0], [whether the shell understands "unset"])dnl
+
+# test EBCDIC or ASCII
+case `echo X|tr X '\101'` in
+ A) # ASCII based system
+    # \n is not interpreted correctly by Solaris 8 /usr/ucb/tr
+  lt_SP2NL='tr \040 \012'
+  lt_NL2SP='tr \015\012 \040\040'
+  ;;
+ *) # EBCDIC based system
+  lt_SP2NL='tr \100 \n'
+  lt_NL2SP='tr \r\n \100\100'
+  ;;
+esac
+_LT_DECL([SP2NL], [lt_SP2NL], [1], [turn spaces into newlines])dnl
+_LT_DECL([NL2SP], [lt_NL2SP], [1], [turn newlines into spaces])dnl
+])# _LT_CHECK_SHELL_FEATURES
+
+
+# _LT_PROG_FUNCTION_REPLACE (FUNCNAME, REPLACEMENT-BODY)
+# ------------------------------------------------------
+# In `$cfgfile', look for function FUNCNAME delimited by `^FUNCNAME ()$' and
+# '^} FUNCNAME ', and replace its body with REPLACEMENT-BODY.
+m4_defun([_LT_PROG_FUNCTION_REPLACE],
+[dnl {
+sed -e '/^$1 ()$/,/^} # $1 /c\
+$1 ()\
+{\
+m4_bpatsubsts([$2], [$], [\\], [^\([	 ]\)], [\\\1])
+} # Extended-shell $1 implementation' "$cfgfile" > $cfgfile.tmp \
+  && mv -f "$cfgfile.tmp" "$cfgfile" \
+    || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+test 0 -eq $? || _lt_function_replace_fail=:
+])
+
+
+# _LT_PROG_REPLACE_SHELLFNS
+# -------------------------
+# Replace existing portable implementations of several shell functions with
+# equivalent extended shell implementations where those features are available..
+m4_defun([_LT_PROG_REPLACE_SHELLFNS],
+[if test x"$xsi_shell" = xyes; then
+  _LT_PROG_FUNCTION_REPLACE([func_dirname], [dnl
+    case ${1} in
+      */*) func_dirname_result="${1%/*}${2}" ;;
+      *  ) func_dirname_result="${3}" ;;
+    esac])
+
+  _LT_PROG_FUNCTION_REPLACE([func_basename], [dnl
+    func_basename_result="${1##*/}"])
+
+  _LT_PROG_FUNCTION_REPLACE([func_dirname_and_basename], [dnl
+    case ${1} in
+      */*) func_dirname_result="${1%/*}${2}" ;;
+      *  ) func_dirname_result="${3}" ;;
+    esac
+    func_basename_result="${1##*/}"])
+
+  _LT_PROG_FUNCTION_REPLACE([func_stripname], [dnl
+    # pdksh 5.2.14 does not do ${X%$Y} correctly if both X and Y are
+    # positional parameters, so assign one to ordinary parameter first.
+    func_stripname_result=${3}
+    func_stripname_result=${func_stripname_result#"${1}"}
+    func_stripname_result=${func_stripname_result%"${2}"}])
+
+  _LT_PROG_FUNCTION_REPLACE([func_split_long_opt], [dnl
+    func_split_long_opt_name=${1%%=*}
+    func_split_long_opt_arg=${1#*=}])
+
+  _LT_PROG_FUNCTION_REPLACE([func_split_short_opt], [dnl
+    func_split_short_opt_arg=${1#??}
+    func_split_short_opt_name=${1%"$func_split_short_opt_arg"}])
+
+  _LT_PROG_FUNCTION_REPLACE([func_lo2o], [dnl
+    case ${1} in
+      *.lo) func_lo2o_result=${1%.lo}.${objext} ;;
+      *)    func_lo2o_result=${1} ;;
+    esac])
+
+  _LT_PROG_FUNCTION_REPLACE([func_xform], [    func_xform_result=${1%.*}.lo])
+
+  _LT_PROG_FUNCTION_REPLACE([func_arith], [    func_arith_result=$(( $[*] ))])
+
+  _LT_PROG_FUNCTION_REPLACE([func_len], [    func_len_result=${#1}])
+fi
+
+if test x"$lt_shell_append" = xyes; then
+  _LT_PROG_FUNCTION_REPLACE([func_append], [    eval "${1}+=\\${2}"])
+
+  _LT_PROG_FUNCTION_REPLACE([func_append_quoted], [dnl
+    func_quote_for_eval "${2}"
+dnl m4 expansion turns \\\\ into \\, and then the shell eval turns that into \
+    eval "${1}+=\\\\ \\$func_quote_for_eval_result"])
+
+  # Save a `func_append' function call where possible by direct use of '+='
+  sed -e 's%func_append \([[a-zA-Z_]]\{1,\}\) "%\1+="%g' $cfgfile > $cfgfile.tmp \
+    && mv -f "$cfgfile.tmp" "$cfgfile" \
+      || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+  test 0 -eq $? || _lt_function_replace_fail=:
+else
+  # Save a `func_append' function call even when '+=' is not available
+  sed -e 's%func_append \([[a-zA-Z_]]\{1,\}\) "%\1="$\1%g' $cfgfile > $cfgfile.tmp \
+    && mv -f "$cfgfile.tmp" "$cfgfile" \
+      || (rm -f "$cfgfile" && cp "$cfgfile.tmp" "$cfgfile" && rm -f "$cfgfile.tmp")
+  test 0 -eq $? || _lt_function_replace_fail=:
+fi
+
+if test x"$_lt_function_replace_fail" = x":"; then
+  AC_MSG_WARN([Unable to substitute extended shell functions in $ofile])
+fi
+])
+
+# _LT_PATH_CONVERSION_FUNCTIONS
+# -----------------------------
+# Determine which file name conversion functions should be used by
+# func_to_host_file (and, implicitly, by func_to_host_path).  These are needed
+# for certain cross-compile configurations and native mingw.
+m4_defun([_LT_PATH_CONVERSION_FUNCTIONS],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+AC_REQUIRE([AC_CANONICAL_BUILD])dnl
+AC_MSG_CHECKING([how to convert $build file names to $host format])
+AC_CACHE_VAL(lt_cv_to_host_file_cmd,
+[case $host in
+  *-*-mingw* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_host_file_cmd=func_convert_file_msys_to_w32
+        ;;
+      *-*-cygwin* )
+        lt_cv_to_host_file_cmd=func_convert_file_cygwin_to_w32
+        ;;
+      * ) # otherwise, assume *nix
+        lt_cv_to_host_file_cmd=func_convert_file_nix_to_w32
+        ;;
+    esac
+    ;;
+  *-*-cygwin* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_host_file_cmd=func_convert_file_msys_to_cygwin
+        ;;
+      *-*-cygwin* )
+        lt_cv_to_host_file_cmd=func_convert_file_noop
+        ;;
+      * ) # otherwise, assume *nix
+        lt_cv_to_host_file_cmd=func_convert_file_nix_to_cygwin
+        ;;
+    esac
+    ;;
+  * ) # unhandled hosts (and "normal" native builds)
+    lt_cv_to_host_file_cmd=func_convert_file_noop
+    ;;
+esac
+])
+to_host_file_cmd=$lt_cv_to_host_file_cmd
+AC_MSG_RESULT([$lt_cv_to_host_file_cmd])
+_LT_DECL([to_host_file_cmd], [lt_cv_to_host_file_cmd],
+         [0], [convert $build file names to $host format])dnl
+
+AC_MSG_CHECKING([how to convert $build file names to toolchain format])
+AC_CACHE_VAL(lt_cv_to_tool_file_cmd,
+[#assume ordinary cross tools, or native build.
+lt_cv_to_tool_file_cmd=func_convert_file_noop
+case $host in
+  *-*-mingw* )
+    case $build in
+      *-*-mingw* ) # actually msys
+        lt_cv_to_tool_file_cmd=func_convert_file_msys_to_w32
+        ;;
+    esac
+    ;;
+esac
+])
+to_tool_file_cmd=$lt_cv_to_tool_file_cmd
+AC_MSG_RESULT([$lt_cv_to_tool_file_cmd])
+_LT_DECL([to_tool_file_cmd], [lt_cv_to_tool_file_cmd],
+         [0], [convert $build files to toolchain format])dnl
+])# _LT_PATH_CONVERSION_FUNCTIONS
diff --git a/m4/ltoptions.m4 b/m4/ltoptions.m4
new file mode 100644
index 0000000..5d9acd8
--- /dev/null
+++ b/m4/ltoptions.m4
@@ -0,0 +1,384 @@
+# Helper functions for option handling.                    -*- Autoconf -*-
+#
+#   Copyright (C) 2004, 2005, 2007, 2008, 2009 Free Software Foundation,
+#   Inc.
+#   Written by Gary V. Vaughan, 2004
+#
+# This file is free software; the Free Software Foundation gives
+# unlimited permission to copy and/or distribute it, with or without
+# modifications, as long as this notice is preserved.
+
+# serial 7 ltoptions.m4
+
+# This is to help aclocal find these macros, as it can't see m4_define.
+AC_DEFUN([LTOPTIONS_VERSION], [m4_if([1])])
+
+
+# _LT_MANGLE_OPTION(MACRO-NAME, OPTION-NAME)
+# ------------------------------------------
+m4_define([_LT_MANGLE_OPTION],
+[[_LT_OPTION_]m4_bpatsubst($1__$2, [[^a-zA-Z0-9_]], [_])])
+
+
+# _LT_SET_OPTION(MACRO-NAME, OPTION-NAME)
+# ---------------------------------------
+# Set option OPTION-NAME for macro MACRO-NAME, and if there is a
+# matching handler defined, dispatch to it.  Other OPTION-NAMEs are
+# saved as a flag.
+m4_define([_LT_SET_OPTION],
+[m4_define(_LT_MANGLE_OPTION([$1], [$2]))dnl
+m4_ifdef(_LT_MANGLE_DEFUN([$1], [$2]),
+        _LT_MANGLE_DEFUN([$1], [$2]),
+    [m4_warning([Unknown $1 option `$2'])])[]dnl
+])
+
+
+# _LT_IF_OPTION(MACRO-NAME, OPTION-NAME, IF-SET, [IF-NOT-SET])
+# ------------------------------------------------------------
+# Execute IF-SET if OPTION is set, IF-NOT-SET otherwise.
+m4_define([_LT_IF_OPTION],
+[m4_ifdef(_LT_MANGLE_OPTION([$1], [$2]), [$3], [$4])])
+
+
+# _LT_UNLESS_OPTIONS(MACRO-NAME, OPTION-LIST, IF-NOT-SET)
+# -------------------------------------------------------
+# Execute IF-NOT-SET unless all options in OPTION-LIST for MACRO-NAME
+# are set.
+m4_define([_LT_UNLESS_OPTIONS],
+[m4_foreach([_LT_Option], m4_split(m4_normalize([$2])),
+	    [m4_ifdef(_LT_MANGLE_OPTION([$1], _LT_Option),
+		      [m4_define([$0_found])])])[]dnl
+m4_ifdef([$0_found], [m4_undefine([$0_found])], [$3
+])[]dnl
+])
+
+
+# _LT_SET_OPTIONS(MACRO-NAME, OPTION-LIST)
+# ----------------------------------------
+# OPTION-LIST is a space-separated list of Libtool options associated
+# with MACRO-NAME.  If any OPTION has a matching handler declared with
+# LT_OPTION_DEFINE, dispatch to that macro; otherwise complain about
+# the unknown option and exit.
+m4_defun([_LT_SET_OPTIONS],
+[# Set options
+m4_foreach([_LT_Option], m4_split(m4_normalize([$2])),
+    [_LT_SET_OPTION([$1], _LT_Option)])
+
+m4_if([$1],[LT_INIT],[
+  dnl
+  dnl Simply set some default values (i.e off) if boolean options were not
+  dnl specified:
+  _LT_UNLESS_OPTIONS([LT_INIT], [dlopen], [enable_dlopen=no
+  ])
+  _LT_UNLESS_OPTIONS([LT_INIT], [win32-dll], [enable_win32_dll=no
+  ])
+  dnl
+  dnl If no reference was made to various pairs of opposing options, then
+  dnl we run the default mode handler for the pair.  For example, if neither
+  dnl `shared' nor `disable-shared' was passed, we enable building of shared
+  dnl archives by default:
+  _LT_UNLESS_OPTIONS([LT_INIT], [shared disable-shared], [_LT_ENABLE_SHARED])
+  _LT_UNLESS_OPTIONS([LT_INIT], [static disable-static], [_LT_ENABLE_STATIC])
+  _LT_UNLESS_OPTIONS([LT_INIT], [pic-only no-pic], [_LT_WITH_PIC])
+  _LT_UNLESS_OPTIONS([LT_INIT], [fast-install disable-fast-install],
+  		   [_LT_ENABLE_FAST_INSTALL])
+  ])
+])# _LT_SET_OPTIONS
+
+
+## --------------------------------- ##
+## Macros to handle LT_INIT options. ##
+## --------------------------------- ##
+
+# _LT_MANGLE_DEFUN(MACRO-NAME, OPTION-NAME)
+# -----------------------------------------
+m4_define([_LT_MANGLE_DEFUN],
+[[_LT_OPTION_DEFUN_]m4_bpatsubst(m4_toupper([$1__$2]), [[^A-Z0-9_]], [_])])
+
+
+# LT_OPTION_DEFINE(MACRO-NAME, OPTION-NAME, CODE)
+# -----------------------------------------------
+m4_define([LT_OPTION_DEFINE],
+[m4_define(_LT_MANGLE_DEFUN([$1], [$2]), [$3])[]dnl
+])# LT_OPTION_DEFINE
+
+
+# dlopen
+# ------
+LT_OPTION_DEFINE([LT_INIT], [dlopen], [enable_dlopen=yes
+])
+
+AU_DEFUN([AC_LIBTOOL_DLOPEN],
+[_LT_SET_OPTION([LT_INIT], [dlopen])
+AC_DIAGNOSE([obsolete],
+[$0: Remove this warning and the call to _LT_SET_OPTION when you
+put the `dlopen' option into LT_INIT's first parameter.])
+])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_DLOPEN], [])
+
+
+# win32-dll
+# ---------
+# Declare package support for building win32 dll's.
+LT_OPTION_DEFINE([LT_INIT], [win32-dll],
+[enable_win32_dll=yes
+
+case $host in
+*-*-cygwin* | *-*-mingw* | *-*-pw32* | *-*-cegcc*)
+  AC_CHECK_TOOL(AS, as, false)
+  AC_CHECK_TOOL(DLLTOOL, dlltool, false)
+  AC_CHECK_TOOL(OBJDUMP, objdump, false)
+  ;;
+esac
+
+test -z "$AS" && AS=as
+_LT_DECL([], [AS],      [1], [Assembler program])dnl
+
+test -z "$DLLTOOL" && DLLTOOL=dlltool
+_LT_DECL([], [DLLTOOL], [1], [DLL creation program])dnl
+
+test -z "$OBJDUMP" && OBJDUMP=objdump
+_LT_DECL([], [OBJDUMP], [1], [Object dumper program])dnl
+])# win32-dll
+
+AU_DEFUN([AC_LIBTOOL_WIN32_DLL],
+[AC_REQUIRE([AC_CANONICAL_HOST])dnl
+_LT_SET_OPTION([LT_INIT], [win32-dll])
+AC_DIAGNOSE([obsolete],
+[$0: Remove this warning and the call to _LT_SET_OPTION when you
+put the `win32-dll' option into LT_INIT's first parameter.])
+])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_WIN32_DLL], [])
+
+
+# _LT_ENABLE_SHARED([DEFAULT])
+# ----------------------------
+# implement the --enable-shared flag, and supports the `shared' and
+# `disable-shared' LT_INIT options.
+# DEFAULT is either `yes' or `no'.  If omitted, it defaults to `yes'.
+m4_define([_LT_ENABLE_SHARED],
+[m4_define([_LT_ENABLE_SHARED_DEFAULT], [m4_if($1, no, no, yes)])dnl
+AC_ARG_ENABLE([shared],
+    [AS_HELP_STRING([--enable-shared@<:@=PKGS@:>@],
+	[build shared libraries @<:@default=]_LT_ENABLE_SHARED_DEFAULT[@:>@])],
+    [p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_shared=yes ;;
+    no) enable_shared=no ;;
+    *)
+      enable_shared=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_shared=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac],
+    [enable_shared=]_LT_ENABLE_SHARED_DEFAULT)
+
+    _LT_DECL([build_libtool_libs], [enable_shared], [0],
+	[Whether or not to build shared libraries])
+])# _LT_ENABLE_SHARED
+
+LT_OPTION_DEFINE([LT_INIT], [shared], [_LT_ENABLE_SHARED([yes])])
+LT_OPTION_DEFINE([LT_INIT], [disable-shared], [_LT_ENABLE_SHARED([no])])
+
+# Old names:
+AC_DEFUN([AC_ENABLE_SHARED],
+[_LT_SET_OPTION([LT_INIT], m4_if([$1], [no], [disable-])[shared])
+])
+
+AC_DEFUN([AC_DISABLE_SHARED],
+[_LT_SET_OPTION([LT_INIT], [disable-shared])
+])
+
+AU_DEFUN([AM_ENABLE_SHARED], [AC_ENABLE_SHARED($@)])
+AU_DEFUN([AM_DISABLE_SHARED], [AC_DISABLE_SHARED($@)])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AM_ENABLE_SHARED], [])
+dnl AC_DEFUN([AM_DISABLE_SHARED], [])
+
+
+
+# _LT_ENABLE_STATIC([DEFAULT])
+# ----------------------------
+# implement the --enable-static flag, and support the `static' and
+# `disable-static' LT_INIT options.
+# DEFAULT is either `yes' or `no'.  If omitted, it defaults to `yes'.
+m4_define([_LT_ENABLE_STATIC],
+[m4_define([_LT_ENABLE_STATIC_DEFAULT], [m4_if($1, no, no, yes)])dnl
+AC_ARG_ENABLE([static],
+    [AS_HELP_STRING([--enable-static@<:@=PKGS@:>@],
+	[build static libraries @<:@default=]_LT_ENABLE_STATIC_DEFAULT[@:>@])],
+    [p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_static=yes ;;
+    no) enable_static=no ;;
+    *)
+     enable_static=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_static=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac],
+    [enable_static=]_LT_ENABLE_STATIC_DEFAULT)
+
+    _LT_DECL([build_old_libs], [enable_static], [0],
+	[Whether or not to build static libraries])
+])# _LT_ENABLE_STATIC
+
+LT_OPTION_DEFINE([LT_INIT], [static], [_LT_ENABLE_STATIC([yes])])
+LT_OPTION_DEFINE([LT_INIT], [disable-static], [_LT_ENABLE_STATIC([no])])
+
+# Old names:
+AC_DEFUN([AC_ENABLE_STATIC],
+[_LT_SET_OPTION([LT_INIT], m4_if([$1], [no], [disable-])[static])
+])
+
+AC_DEFUN([AC_DISABLE_STATIC],
+[_LT_SET_OPTION([LT_INIT], [disable-static])
+])
+
+AU_DEFUN([AM_ENABLE_STATIC], [AC_ENABLE_STATIC($@)])
+AU_DEFUN([AM_DISABLE_STATIC], [AC_DISABLE_STATIC($@)])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AM_ENABLE_STATIC], [])
+dnl AC_DEFUN([AM_DISABLE_STATIC], [])
+
+
+
+# _LT_ENABLE_FAST_INSTALL([DEFAULT])
+# ----------------------------------
+# implement the --enable-fast-install flag, and support the `fast-install'
+# and `disable-fast-install' LT_INIT options.
+# DEFAULT is either `yes' or `no'.  If omitted, it defaults to `yes'.
+m4_define([_LT_ENABLE_FAST_INSTALL],
+[m4_define([_LT_ENABLE_FAST_INSTALL_DEFAULT], [m4_if($1, no, no, yes)])dnl
+AC_ARG_ENABLE([fast-install],
+    [AS_HELP_STRING([--enable-fast-install@<:@=PKGS@:>@],
+    [optimize for fast installation @<:@default=]_LT_ENABLE_FAST_INSTALL_DEFAULT[@:>@])],
+    [p=${PACKAGE-default}
+    case $enableval in
+    yes) enable_fast_install=yes ;;
+    no) enable_fast_install=no ;;
+    *)
+      enable_fast_install=no
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for pkg in $enableval; do
+	IFS="$lt_save_ifs"
+	if test "X$pkg" = "X$p"; then
+	  enable_fast_install=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac],
+    [enable_fast_install=]_LT_ENABLE_FAST_INSTALL_DEFAULT)
+
+_LT_DECL([fast_install], [enable_fast_install], [0],
+	 [Whether or not to optimize for fast installation])dnl
+])# _LT_ENABLE_FAST_INSTALL
+
+LT_OPTION_DEFINE([LT_INIT], [fast-install], [_LT_ENABLE_FAST_INSTALL([yes])])
+LT_OPTION_DEFINE([LT_INIT], [disable-fast-install], [_LT_ENABLE_FAST_INSTALL([no])])
+
+# Old names:
+AU_DEFUN([AC_ENABLE_FAST_INSTALL],
+[_LT_SET_OPTION([LT_INIT], m4_if([$1], [no], [disable-])[fast-install])
+AC_DIAGNOSE([obsolete],
+[$0: Remove this warning and the call to _LT_SET_OPTION when you put
+the `fast-install' option into LT_INIT's first parameter.])
+])
+
+AU_DEFUN([AC_DISABLE_FAST_INSTALL],
+[_LT_SET_OPTION([LT_INIT], [disable-fast-install])
+AC_DIAGNOSE([obsolete],
+[$0: Remove this warning and the call to _LT_SET_OPTION when you put
+the `disable-fast-install' option into LT_INIT's first parameter.])
+])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_ENABLE_FAST_INSTALL], [])
+dnl AC_DEFUN([AM_DISABLE_FAST_INSTALL], [])
+
+
+# _LT_WITH_PIC([MODE])
+# --------------------
+# implement the --with-pic flag, and support the `pic-only' and `no-pic'
+# LT_INIT options.
+# MODE is either `yes' or `no'.  If omitted, it defaults to `both'.
+m4_define([_LT_WITH_PIC],
+[AC_ARG_WITH([pic],
+    [AS_HELP_STRING([--with-pic@<:@=PKGS@:>@],
+	[try to use only PIC/non-PIC objects @<:@default=use both@:>@])],
+    [lt_p=${PACKAGE-default}
+    case $withval in
+    yes|no) pic_mode=$withval ;;
+    *)
+      pic_mode=default
+      # Look at the argument we got.  We use all the common list separators.
+      lt_save_ifs="$IFS"; IFS="${IFS}$PATH_SEPARATOR,"
+      for lt_pkg in $withval; do
+	IFS="$lt_save_ifs"
+	if test "X$lt_pkg" = "X$lt_p"; then
+	  pic_mode=yes
+	fi
+      done
+      IFS="$lt_save_ifs"
+      ;;
+    esac],
+    [pic_mode=default])
+
+test -z "$pic_mode" && pic_mode=m4_default([$1], [default])
+
+_LT_DECL([], [pic_mode], [0], [What type of objects to build])dnl
+])# _LT_WITH_PIC
+
+LT_OPTION_DEFINE([LT_INIT], [pic-only], [_LT_WITH_PIC([yes])])
+LT_OPTION_DEFINE([LT_INIT], [no-pic], [_LT_WITH_PIC([no])])
+
+# Old name:
+AU_DEFUN([AC_LIBTOOL_PICMODE],
+[_LT_SET_OPTION([LT_INIT], [pic-only])
+AC_DIAGNOSE([obsolete],
+[$0: Remove this warning and the call to _LT_SET_OPTION when you
+put the `pic-only' option into LT_INIT's first parameter.])
+])
+
+dnl aclocal-1.4 backwards compatibility:
+dnl AC_DEFUN([AC_LIBTOOL_PICMODE], [])
+
+## ----------------- ##
+## LTDL_INIT Options ##
+## ----------------- ##
+
+m4_define([_LTDL_MODE], [])
+LT_OPTION_DEFINE([LTDL_INIT], [nonrecursive],
+		 [m4_define([_LTDL_MODE], [nonrecursive])])
+LT_OPTION_DEFINE([LTDL_INIT], [recursive],
+		 [m4_define([_LTDL_MODE], [recursive])])
+LT_OPTION_DEFINE([LTDL_INIT], [subproject],
+		 [m4_define([_LTDL_MODE], [subproject])])
+
+m4_define([_LTDL_TYPE], [])
+LT_OPTION_DEFINE([LTDL_INIT], [installable],
+		 [m4_define([_LTDL_TYPE], [installable])])
+LT_OPTION_DEFINE([LTDL_INIT], [convenience],
+		 [m4_define([_LTDL_TYPE], [convenience])])
diff --git a/m4/ltsugar.m4 b/m4/ltsugar.m4
new file mode 100644
index 0000000..9000a05
--- /dev/null
+++ b/m4/ltsugar.m4
@@ -0,0 +1,123 @@
+# ltsugar.m4 -- libtool m4 base layer.                         -*-Autoconf-*-
+#
+# Copyright (C) 2004, 2005, 2007, 2008 Free Software Foundation, Inc.
+# Written by Gary V. Vaughan, 2004
+#
+# This file is free software; the Free Software Foundation gives
+# unlimited permission to copy and/or distribute it, with or without
+# modifications, as long as this notice is preserved.
+
+# serial 6 ltsugar.m4
+
+# This is to help aclocal find these macros, as it can't see m4_define.
+AC_DEFUN([LTSUGAR_VERSION], [m4_if([0.1])])
+
+
+# lt_join(SEP, ARG1, [ARG2...])
+# -----------------------------
+# Produce ARG1SEPARG2...SEPARGn, omitting [] arguments and their
+# associated separator.
+# Needed until we can rely on m4_join from Autoconf 2.62, since all earlier
+# versions in m4sugar had bugs.
+m4_define([lt_join],
+[m4_if([$#], [1], [],
+       [$#], [2], [[$2]],
+       [m4_if([$2], [], [], [[$2]_])$0([$1], m4_shift(m4_shift($@)))])])
+m4_define([_lt_join],
+[m4_if([$#$2], [2], [],
+       [m4_if([$2], [], [], [[$1$2]])$0([$1], m4_shift(m4_shift($@)))])])
+
+
+# lt_car(LIST)
+# lt_cdr(LIST)
+# ------------
+# Manipulate m4 lists.
+# These macros are necessary as long as will still need to support
+# Autoconf-2.59 which quotes differently.
+m4_define([lt_car], [[$1]])
+m4_define([lt_cdr],
+[m4_if([$#], 0, [m4_fatal([$0: cannot be called without arguments])],
+       [$#], 1, [],
+       [m4_dquote(m4_shift($@))])])
+m4_define([lt_unquote], $1)
+
+
+# lt_append(MACRO-NAME, STRING, [SEPARATOR])
+# ------------------------------------------
+# Redefine MACRO-NAME to hold its former content plus `SEPARATOR'`STRING'.
+# Note that neither SEPARATOR nor STRING are expanded; they are appended
+# to MACRO-NAME as is (leaving the expansion for when MACRO-NAME is invoked).
+# No SEPARATOR is output if MACRO-NAME was previously undefined (different
+# than defined and empty).
+#
+# This macro is needed until we can rely on Autoconf 2.62, since earlier
+# versions of m4sugar mistakenly expanded SEPARATOR but not STRING.
+m4_define([lt_append],
+[m4_define([$1],
+	   m4_ifdef([$1], [m4_defn([$1])[$3]])[$2])])
+
+
+
+# lt_combine(SEP, PREFIX-LIST, INFIX, SUFFIX1, [SUFFIX2...])
+# ----------------------------------------------------------
+# Produce a SEP delimited list of all paired combinations of elements of
+# PREFIX-LIST with SUFFIX1 through SUFFIXn.  Each element of the list
+# has the form PREFIXmINFIXSUFFIXn.
+# Needed until we can rely on m4_combine added in Autoconf 2.62.
+m4_define([lt_combine],
+[m4_if(m4_eval([$# > 3]), [1],
+       [m4_pushdef([_Lt_sep], [m4_define([_Lt_sep], m4_defn([lt_car]))])]]dnl
+[[m4_foreach([_Lt_prefix], [$2],
+	     [m4_foreach([_Lt_suffix],
+		]m4_dquote(m4_dquote(m4_shift(m4_shift(m4_shift($@)))))[,
+	[_Lt_sep([$1])[]m4_defn([_Lt_prefix])[$3]m4_defn([_Lt_suffix])])])])])
+
+
+# lt_if_append_uniq(MACRO-NAME, VARNAME, [SEPARATOR], [UNIQ], [NOT-UNIQ])
+# -----------------------------------------------------------------------
+# Iff MACRO-NAME does not yet contain VARNAME, then append it (delimited
+# by SEPARATOR if supplied) and expand UNIQ, else NOT-UNIQ.
+m4_define([lt_if_append_uniq],
+[m4_ifdef([$1],
+	  [m4_if(m4_index([$3]m4_defn([$1])[$3], [$3$2$3]), [-1],
+		 [lt_append([$1], [$2], [$3])$4],
+		 [$5])],
+	  [lt_append([$1], [$2], [$3])$4])])
+
+
+# lt_dict_add(DICT, KEY, VALUE)
+# -----------------------------
+m4_define([lt_dict_add],
+[m4_define([$1($2)], [$3])])
+
+
+# lt_dict_add_subkey(DICT, KEY, SUBKEY, VALUE)
+# --------------------------------------------
+m4_define([lt_dict_add_subkey],
+[m4_define([$1($2:$3)], [$4])])
+
+
+# lt_dict_fetch(DICT, KEY, [SUBKEY])
+# ----------------------------------
+m4_define([lt_dict_fetch],
+[m4_ifval([$3],
+	m4_ifdef([$1($2:$3)], [m4_defn([$1($2:$3)])]),
+    m4_ifdef([$1($2)], [m4_defn([$1($2)])]))])
+
+
+# lt_if_dict_fetch(DICT, KEY, [SUBKEY], VALUE, IF-TRUE, [IF-FALSE])
+# -----------------------------------------------------------------
+m4_define([lt_if_dict_fetch],
+[m4_if(lt_dict_fetch([$1], [$2], [$3]), [$4],
+	[$5],
+    [$6])])
+
+
+# lt_dict_filter(DICT, [SUBKEY], VALUE, [SEPARATOR], KEY, [...])
+# --------------------------------------------------------------
+m4_define([lt_dict_filter],
+[m4_if([$5], [], [],
+  [lt_join(m4_quote(m4_default([$4], [[, ]])),
+           lt_unquote(m4_split(m4_normalize(m4_foreach(_Lt_key, lt_car([m4_shiftn(4, $@)]),
+		      [lt_if_dict_fetch([$1], _Lt_key, [$2], [$3], [_Lt_key ])])))))])[]dnl
+])
diff --git a/m4/ltversion.m4 b/m4/ltversion.m4
new file mode 100644
index 0000000..07a8602
--- /dev/null
+++ b/m4/ltversion.m4
@@ -0,0 +1,23 @@
+# ltversion.m4 -- version numbers			-*- Autoconf -*-
+#
+#   Copyright (C) 2004 Free Software Foundation, Inc.
+#   Written by Scott James Remnant, 2004
+#
+# This file is free software; the Free Software Foundation gives
+# unlimited permission to copy and/or distribute it, with or without
+# modifications, as long as this notice is preserved.
+
+# @configure_input@
+
+# serial 3337 ltversion.m4
+# This file is part of GNU Libtool
+
+m4_define([LT_PACKAGE_VERSION], [2.4.2])
+m4_define([LT_PACKAGE_REVISION], [1.3337])
+
+AC_DEFUN([LTVERSION_VERSION],
+[macro_version='2.4.2'
+macro_revision='1.3337'
+_LT_DECL(, macro_version, 0, [Which release of libtool.m4 was used?])
+_LT_DECL(, macro_revision, 0)
+])
diff --git a/m4/lt~obsolete.m4 b/m4/lt~obsolete.m4
new file mode 100644
index 0000000..c573da9
--- /dev/null
+++ b/m4/lt~obsolete.m4
@@ -0,0 +1,98 @@
+# lt~obsolete.m4 -- aclocal satisfying obsolete definitions.    -*-Autoconf-*-
+#
+#   Copyright (C) 2004, 2005, 2007, 2009 Free Software Foundation, Inc.
+#   Written by Scott James Remnant, 2004.
+#
+# This file is free software; the Free Software Foundation gives
+# unlimited permission to copy and/or distribute it, with or without
+# modifications, as long as this notice is preserved.
+
+# serial 5 lt~obsolete.m4
+
+# These exist entirely to fool aclocal when bootstrapping libtool.
+#
+# In the past libtool.m4 has provided macros via AC_DEFUN (or AU_DEFUN)
+# which have later been changed to m4_define as they aren't part of the
+# exported API, or moved to Autoconf or Automake where they belong.
+#
+# The trouble is, aclocal is a bit thick.  It'll see the old AC_DEFUN
+# in /usr/share/aclocal/libtool.m4 and remember it, then when it sees us
+# using a macro with the same name in our local m4/libtool.m4 it'll
+# pull the old libtool.m4 in (it doesn't see our shiny new m4_define
+# and doesn't know about Autoconf macros at all.)
+#
+# So we provide this file, which has a silly filename so it's always
+# included after everything else.  This provides aclocal with the
+# AC_DEFUNs it wants, but when m4 processes it, it doesn't do anything
+# because those macros already exist, or will be overwritten later.
+# We use AC_DEFUN over AU_DEFUN for compatibility with aclocal-1.6. 
+#
+# Anytime we withdraw an AC_DEFUN or AU_DEFUN, remember to add it here.
+# Yes, that means every name once taken will need to remain here until
+# we give up compatibility with versions before 1.7, at which point
+# we need to keep only those names which we still refer to.
+
+# This is to help aclocal find these macros, as it can't see m4_define.
+AC_DEFUN([LTOBSOLETE_VERSION], [m4_if([1])])
+
+m4_ifndef([AC_LIBTOOL_LINKER_OPTION],	[AC_DEFUN([AC_LIBTOOL_LINKER_OPTION])])
+m4_ifndef([AC_PROG_EGREP],		[AC_DEFUN([AC_PROG_EGREP])])
+m4_ifndef([_LT_AC_PROG_ECHO_BACKSLASH],	[AC_DEFUN([_LT_AC_PROG_ECHO_BACKSLASH])])
+m4_ifndef([_LT_AC_SHELL_INIT],		[AC_DEFUN([_LT_AC_SHELL_INIT])])
+m4_ifndef([_LT_AC_SYS_LIBPATH_AIX],	[AC_DEFUN([_LT_AC_SYS_LIBPATH_AIX])])
+m4_ifndef([_LT_PROG_LTMAIN],		[AC_DEFUN([_LT_PROG_LTMAIN])])
+m4_ifndef([_LT_AC_TAGVAR],		[AC_DEFUN([_LT_AC_TAGVAR])])
+m4_ifndef([AC_LTDL_ENABLE_INSTALL],	[AC_DEFUN([AC_LTDL_ENABLE_INSTALL])])
+m4_ifndef([AC_LTDL_PREOPEN],		[AC_DEFUN([AC_LTDL_PREOPEN])])
+m4_ifndef([_LT_AC_SYS_COMPILER],	[AC_DEFUN([_LT_AC_SYS_COMPILER])])
+m4_ifndef([_LT_AC_LOCK],		[AC_DEFUN([_LT_AC_LOCK])])
+m4_ifndef([AC_LIBTOOL_SYS_OLD_ARCHIVE],	[AC_DEFUN([AC_LIBTOOL_SYS_OLD_ARCHIVE])])
+m4_ifndef([_LT_AC_TRY_DLOPEN_SELF],	[AC_DEFUN([_LT_AC_TRY_DLOPEN_SELF])])
+m4_ifndef([AC_LIBTOOL_PROG_CC_C_O],	[AC_DEFUN([AC_LIBTOOL_PROG_CC_C_O])])
+m4_ifndef([AC_LIBTOOL_SYS_HARD_LINK_LOCKS], [AC_DEFUN([AC_LIBTOOL_SYS_HARD_LINK_LOCKS])])
+m4_ifndef([AC_LIBTOOL_OBJDIR],		[AC_DEFUN([AC_LIBTOOL_OBJDIR])])
+m4_ifndef([AC_LTDL_OBJDIR],		[AC_DEFUN([AC_LTDL_OBJDIR])])
+m4_ifndef([AC_LIBTOOL_PROG_LD_HARDCODE_LIBPATH], [AC_DEFUN([AC_LIBTOOL_PROG_LD_HARDCODE_LIBPATH])])
+m4_ifndef([AC_LIBTOOL_SYS_LIB_STRIP],	[AC_DEFUN([AC_LIBTOOL_SYS_LIB_STRIP])])
+m4_ifndef([AC_PATH_MAGIC],		[AC_DEFUN([AC_PATH_MAGIC])])
+m4_ifndef([AC_PROG_LD_GNU],		[AC_DEFUN([AC_PROG_LD_GNU])])
+m4_ifndef([AC_PROG_LD_RELOAD_FLAG],	[AC_DEFUN([AC_PROG_LD_RELOAD_FLAG])])
+m4_ifndef([AC_DEPLIBS_CHECK_METHOD],	[AC_DEFUN([AC_DEPLIBS_CHECK_METHOD])])
+m4_ifndef([AC_LIBTOOL_PROG_COMPILER_NO_RTTI], [AC_DEFUN([AC_LIBTOOL_PROG_COMPILER_NO_RTTI])])
+m4_ifndef([AC_LIBTOOL_SYS_GLOBAL_SYMBOL_PIPE], [AC_DEFUN([AC_LIBTOOL_SYS_GLOBAL_SYMBOL_PIPE])])
+m4_ifndef([AC_LIBTOOL_PROG_COMPILER_PIC], [AC_DEFUN([AC_LIBTOOL_PROG_COMPILER_PIC])])
+m4_ifndef([AC_LIBTOOL_PROG_LD_SHLIBS],	[AC_DEFUN([AC_LIBTOOL_PROG_LD_SHLIBS])])
+m4_ifndef([AC_LIBTOOL_POSTDEP_PREDEP],	[AC_DEFUN([AC_LIBTOOL_POSTDEP_PREDEP])])
+m4_ifndef([LT_AC_PROG_EGREP],		[AC_DEFUN([LT_AC_PROG_EGREP])])
+m4_ifndef([LT_AC_PROG_SED],		[AC_DEFUN([LT_AC_PROG_SED])])
+m4_ifndef([_LT_CC_BASENAME],		[AC_DEFUN([_LT_CC_BASENAME])])
+m4_ifndef([_LT_COMPILER_BOILERPLATE],	[AC_DEFUN([_LT_COMPILER_BOILERPLATE])])
+m4_ifndef([_LT_LINKER_BOILERPLATE],	[AC_DEFUN([_LT_LINKER_BOILERPLATE])])
+m4_ifndef([_AC_PROG_LIBTOOL],		[AC_DEFUN([_AC_PROG_LIBTOOL])])
+m4_ifndef([AC_LIBTOOL_SETUP],		[AC_DEFUN([AC_LIBTOOL_SETUP])])
+m4_ifndef([_LT_AC_CHECK_DLFCN],		[AC_DEFUN([_LT_AC_CHECK_DLFCN])])
+m4_ifndef([AC_LIBTOOL_SYS_DYNAMIC_LINKER],	[AC_DEFUN([AC_LIBTOOL_SYS_DYNAMIC_LINKER])])
+m4_ifndef([_LT_AC_TAGCONFIG],		[AC_DEFUN([_LT_AC_TAGCONFIG])])
+m4_ifndef([AC_DISABLE_FAST_INSTALL],	[AC_DEFUN([AC_DISABLE_FAST_INSTALL])])
+m4_ifndef([_LT_AC_LANG_CXX],		[AC_DEFUN([_LT_AC_LANG_CXX])])
+m4_ifndef([_LT_AC_LANG_F77],		[AC_DEFUN([_LT_AC_LANG_F77])])
+m4_ifndef([_LT_AC_LANG_GCJ],		[AC_DEFUN([_LT_AC_LANG_GCJ])])
+m4_ifndef([AC_LIBTOOL_LANG_C_CONFIG],	[AC_DEFUN([AC_LIBTOOL_LANG_C_CONFIG])])
+m4_ifndef([_LT_AC_LANG_C_CONFIG],	[AC_DEFUN([_LT_AC_LANG_C_CONFIG])])
+m4_ifndef([AC_LIBTOOL_LANG_CXX_CONFIG],	[AC_DEFUN([AC_LIBTOOL_LANG_CXX_CONFIG])])
+m4_ifndef([_LT_AC_LANG_CXX_CONFIG],	[AC_DEFUN([_LT_AC_LANG_CXX_CONFIG])])
+m4_ifndef([AC_LIBTOOL_LANG_F77_CONFIG],	[AC_DEFUN([AC_LIBTOOL_LANG_F77_CONFIG])])
+m4_ifndef([_LT_AC_LANG_F77_CONFIG],	[AC_DEFUN([_LT_AC_LANG_F77_CONFIG])])
+m4_ifndef([AC_LIBTOOL_LANG_GCJ_CONFIG],	[AC_DEFUN([AC_LIBTOOL_LANG_GCJ_CONFIG])])
+m4_ifndef([_LT_AC_LANG_GCJ_CONFIG],	[AC_DEFUN([_LT_AC_LANG_GCJ_CONFIG])])
+m4_ifndef([AC_LIBTOOL_LANG_RC_CONFIG],	[AC_DEFUN([AC_LIBTOOL_LANG_RC_CONFIG])])
+m4_ifndef([_LT_AC_LANG_RC_CONFIG],	[AC_DEFUN([_LT_AC_LANG_RC_CONFIG])])
+m4_ifndef([AC_LIBTOOL_CONFIG],		[AC_DEFUN([AC_LIBTOOL_CONFIG])])
+m4_ifndef([_LT_AC_FILE_LTDLL_C],	[AC_DEFUN([_LT_AC_FILE_LTDLL_C])])
+m4_ifndef([_LT_REQUIRED_DARWIN_CHECKS],	[AC_DEFUN([_LT_REQUIRED_DARWIN_CHECKS])])
+m4_ifndef([_LT_AC_PROG_CXXCPP],		[AC_DEFUN([_LT_AC_PROG_CXXCPP])])
+m4_ifndef([_LT_PREPARE_SED_QUOTE_VARS],	[AC_DEFUN([_LT_PREPARE_SED_QUOTE_VARS])])
+m4_ifndef([_LT_PROG_ECHO_BACKSLASH],	[AC_DEFUN([_LT_PROG_ECHO_BACKSLASH])])
+m4_ifndef([_LT_PROG_F77],		[AC_DEFUN([_LT_PROG_F77])])
+m4_ifndef([_LT_PROG_FC],		[AC_DEFUN([_LT_PROG_FC])])
+m4_ifndef([_LT_PROG_CXX],		[AC_DEFUN([_LT_PROG_CXX])])
diff --git a/src/Makefile.am b/src/Makefile.am
new file mode 100644
index 0000000..3d43dbe
--- /dev/null
+++ b/src/Makefile.am
@@ -0,0 +1,111 @@
+## Process this file with automake to produce Makefile.in
+
+# File lists
+common_headers = common.h prototypes.h version.h
+common_sources = tls.c str.c file.c client.c log.c options.c protocol.c
+common_sources += network.c resolver.c ssl.c ctx.c verify.c sthreads.c
+common_sources += fd.c dhparam.c cron.c stunnel.c
+unix_sources = pty.c libwrap.c ui_unix.c
+shared_sources = env.c
+win32_gui_sources = ui_win_gui.c resources.h resources.rc
+win32_gui_sources += stunnel.ico active.ico error.ico idle.ico
+win32_cli_sources = ui_win_cli.c
+
+# Unix executables
+bin_PROGRAMS = stunnel
+stunnel_SOURCES = $(common_headers) $(common_sources) $(unix_sources)
+bin_SCRIPTS = stunnel3
+
+EXTRA_DIST = stunnel3.in
+CLEANFILES = stunnel3
+
+# Unix shared library
+pkglib_LTLIBRARIES = libstunnel.la
+libstunnel_la_SOURCES = $(shared_sources)
+libstunnel_la_LDFLAGS = -avoid-version
+
+# Red Hat "by design" bug #82369
+stunnel_CPPFLAGS = -I/usr/kerberos/include
+
+# Additional preprocesor definitions
+stunnel_CPPFLAGS += -I$(SSLDIR)/include
+stunnel_CPPFLAGS += -DLIBDIR='"$(pkglibdir)"'
+stunnel_CPPFLAGS += -DCONFDIR='"$(sysconfdir)/stunnel"'
+
+# Generate a new set of DH parameters for each version
+dhparam.c: version.h
+	echo '#include "common.h"' >dhparam.c
+	echo '#ifndef OPENSSL_NO_DH' >>dhparam.c
+	echo '#define DN_new DH_new' >>dhparam.c
+	openssl dhparam -noout -C 2048 >>dhparam.c
+	echo '#endif /* OPENSSL_NO_DH */' >>dhparam.c
+
+# SSL library
+stunnel_LDFLAGS = -L$(SSLDIR)/lib64 -L$(SSLDIR)/lib -lssl -lcrypto
+
+# Win32 executables
+
+if AUTHOR_TESTS
+# Just check if the programs can be built, don't perform any actual tests
+check_PROGRAMS = stunnel.exe tstunnel.exe
+endif
+stunnel_exe_SOURCES = $(common_headers) $(common_sources) $(win32_gui_sources)
+tstunnel_exe_SOURCES = $(common_headers) $(common_sources) $(win32_cli_sources)
+
+# Remaining files to be included
+# EXTRA_PROGRAMS = stunnel.exe tstunnel.exe
+# EXTRA_DIST += $(win32_gui_sources) $(win32_cli_sources)
+EXTRA_DIST += make.bat makece.bat makew32.bat
+EXTRA_DIST += mingw.mak evc.mak vc.mak os2.mak
+
+# win32_ssl_dir = /usr/src/openssl-0.9.8u-fips
+# win32_cppflags = -I$(win32_ssl_dir)/inc32
+win32_ssl_dir = /usr/src/openssl-1.0.2d-i686
+win32_cppflags = -I$(win32_ssl_dir)/include
+win32_cflags = -mthreads -fstack-protector -O2
+win32_cflags += -Wall -Wextra -Wpedantic -Wformat=2 -Wconversion -Wno-long-long
+win32_cflags += -D_FORTIFY_SOURCE=2 -DUNICODE -D_UNICODE
+win32_ldflags = -mthreads -fstack-protector -s
+
+win32_common_libs = -lws2_32
+win32_ssl_libs = -L$(win32_ssl_dir) -lcrypto -lssl
+win32_gui_libs = $(win32_common_libs) -lgdi32 -lpsapi $(win32_ssl_libs)
+win32_cli_libs = $(win32_common_libs) $(win32_ssl_libs)
+
+win32_common_objs = tls.obj str.obj file.obj client.obj log.obj options.obj
+win32_common_objs += protocol.obj network.obj resolver.obj ssl.obj ctx.obj
+win32_common_objs += verify.obj sthreads.obj fd.obj dhparam.obj cron.obj
+win32_common_objs += stunnel.obj
+win32_gui_objs = ui_win_gui.obj resources.obj
+win32_cli_objs = ui_win_cli.obj
+
+win32_prefix = i686-w64-mingw32-
+win32_cc = $(win32_prefix)gcc
+win32_windres = $(win32_prefix)windres
+
+MOSTLYCLEANFILES = $(win32_common_objs) $(win32_gui_objs) $(win32_cli_objs)
+CLEANFILES += stunnel.exe tstunnel.exe
+
+# dist-hook: stunnel.exe tstunnel.exe
+
+# SUFFIXES = .c .rc .obj
+
+stunnel.exe: $(win32_common_objs) $(win32_gui_objs)
+	$(win32_cc) -mwindows $(win32_ldflags) -o stunnel.exe $(win32_common_objs) $(win32_gui_objs) $(win32_gui_libs)
+
+tstunnel.exe: $(win32_common_objs) $(win32_cli_objs)
+	$(win32_cc) $(win32_ldflags) -o tstunnel.exe $(win32_common_objs) $(win32_cli_objs) $(win32_cli_libs)
+
+%.obj: %.c $(common_headers)
+	$(win32_cc) -c $(win32_cppflags) $(win32_cflags) -o $@ $<
+
+resources.obj: resources.rc resources.h version.h
+	$(win32_windres) --include-dir $(srcdir) $< $@
+
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g'
+
+stunnel3: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel3: $(srcdir)/stunnel3.in
diff --git a/src/Makefile.in b/src/Makefile.in
new file mode 100644
index 0000000..a987fad
--- /dev/null
+++ b/src/Makefile.in
@@ -0,0 +1,1219 @@
+# Makefile.in generated by automake 1.14.1 from Makefile.am.
+# @configure_input@
+
+# Copyright (C) 1994-2013 Free Software Foundation, Inc.
+
+# This Makefile.in is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+@SET_MAKE@
+
+
+
+VPATH = @srcdir@
+am__is_gnu_make = test -n '$(MAKEFILE_LIST)' && test -n '$(MAKELEVEL)'
+am__make_running_with_option = \
+  case $${target_option-} in \
+      ?) ;; \
+      *) echo "am__make_running_with_option: internal error: invalid" \
+              "target option '$${target_option-}' specified" >&2; \
+         exit 1;; \
+  esac; \
+  has_opt=no; \
+  sane_makeflags=$$MAKEFLAGS; \
+  if $(am__is_gnu_make); then \
+    sane_makeflags=$$MFLAGS; \
+  else \
+    case $$MAKEFLAGS in \
+      *\\[\ \	]*) \
+        bs=\\; \
+        sane_makeflags=`printf '%s\n' "$$MAKEFLAGS" \
+          | sed "s/$$bs$$bs[$$bs $$bs	]*//g"`;; \
+    esac; \
+  fi; \
+  skip_next=no; \
+  strip_trailopt () \
+  { \
+    flg=`printf '%s\n' "$$flg" | sed "s/$$1.*$$//"`; \
+  }; \
+  for flg in $$sane_makeflags; do \
+    test $$skip_next = yes && { skip_next=no; continue; }; \
+    case $$flg in \
+      *=*|--*) continue;; \
+        -*I) strip_trailopt 'I'; skip_next=yes;; \
+      -*I?*) strip_trailopt 'I';; \
+        -*O) strip_trailopt 'O'; skip_next=yes;; \
+      -*O?*) strip_trailopt 'O';; \
+        -*l) strip_trailopt 'l'; skip_next=yes;; \
+      -*l?*) strip_trailopt 'l';; \
+      -[dEDm]) skip_next=yes;; \
+      -[JT]) skip_next=yes;; \
+    esac; \
+    case $$flg in \
+      *$$target_option*) has_opt=yes; break;; \
+    esac; \
+  done; \
+  test $$has_opt = yes
+am__make_dryrun = (target_option=n; $(am__make_running_with_option))
+am__make_keepgoing = (target_option=k; $(am__make_running_with_option))
+pkgdatadir = $(datadir)/@PACKAGE@
+pkgincludedir = $(includedir)/@PACKAGE@
+pkglibdir = $(libdir)/@PACKAGE@
+pkglibexecdir = $(libexecdir)/@PACKAGE@
+am__cd = CDPATH="$${ZSH_VERSION+.}$(PATH_SEPARATOR)" && cd
+install_sh_DATA = $(install_sh) -c -m 644
+install_sh_PROGRAM = $(install_sh) -c
+install_sh_SCRIPT = $(install_sh) -c
+INSTALL_HEADER = $(INSTALL_DATA)
+transform = $(program_transform_name)
+NORMAL_INSTALL = :
+PRE_INSTALL = :
+POST_INSTALL = :
+NORMAL_UNINSTALL = :
+PRE_UNINSTALL = :
+POST_UNINSTALL = :
+build_triplet = @build@
+host_triplet = @host@
+bin_PROGRAMS = stunnel$(EXEEXT)
+@AUTHOR_TESTS_TRUE@check_PROGRAMS = stunnel.exe$(EXEEXT) \
+@AUTHOR_TESTS_TRUE@	tstunnel.exe$(EXEEXT)
+subdir = src
+DIST_COMMON = $(srcdir)/Makefile.in $(srcdir)/Makefile.am \
+	$(srcdir)/config.h.in $(top_srcdir)/auto/depcomp
+ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
+am__aclocal_m4_deps = $(top_srcdir)/m4/ax_append_compile_flags.m4 \
+	$(top_srcdir)/m4/ax_append_flag.m4 \
+	$(top_srcdir)/m4/ax_append_link_flags.m4 \
+	$(top_srcdir)/m4/ax_check_compile_flag.m4 \
+	$(top_srcdir)/m4/ax_check_link_flag.m4 \
+	$(top_srcdir)/m4/ax_pthread.m4 \
+	$(top_srcdir)/m4/ax_require_defined.m4 \
+	$(top_srcdir)/m4/libtool.m4 $(top_srcdir)/m4/ltoptions.m4 \
+	$(top_srcdir)/m4/ltsugar.m4 $(top_srcdir)/m4/ltversion.m4 \
+	$(top_srcdir)/m4/lt~obsolete.m4 $(top_srcdir)/configure.ac
+am__configure_deps = $(am__aclocal_m4_deps) $(CONFIGURE_DEPENDENCIES) \
+	$(ACLOCAL_M4)
+mkinstalldirs = $(install_sh) -d
+CONFIG_HEADER = config.h
+CONFIG_CLEAN_FILES =
+CONFIG_CLEAN_VPATH_FILES =
+am__vpath_adj_setup = srcdirstrip=`echo "$(srcdir)" | sed 's|.|.|g'`;
+am__vpath_adj = case $$p in \
+    $(srcdir)/*) f=`echo "$$p" | sed "s|^$$srcdirstrip/||"`;; \
+    *) f=$$p;; \
+  esac;
+am__strip_dir = f=`echo $$p | sed -e 's|^.*/||'`;
+am__install_max = 40
+am__nobase_strip_setup = \
+  srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*|]/\\\\&/g'`
+am__nobase_strip = \
+  for p in $$list; do echo "$$p"; done | sed -e "s|$$srcdirstrip/||"
+am__nobase_list = $(am__nobase_strip_setup); \
+  for p in $$list; do echo "$$p $$p"; done | \
+  sed "s| $$srcdirstrip/| |;"' / .*\//!s/ .*/ ./; s,\( .*\)/[^/]*$$,\1,' | \
+  $(AWK) 'BEGIN { files["."] = "" } { files[$$2] = files[$$2] " " $$1; \
+    if (++n[$$2] == $(am__install_max)) \
+      { print $$2, files[$$2]; n[$$2] = 0; files[$$2] = "" } } \
+    END { for (dir in files) print dir, files[dir] }'
+am__base_list = \
+  sed '$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;s/\n/ /g' | \
+  sed '$$!N;$$!N;$$!N;$$!N;s/\n/ /g'
+am__uninstall_files_from_dir = { \
+  test -z "$$files" \
+    || { test ! -d "$$dir" && test ! -f "$$dir" && test ! -r "$$dir"; } \
+    || { echo " ( cd '$$dir' && rm -f" $$files ")"; \
+         $(am__cd) "$$dir" && rm -f $$files; }; \
+  }
+am__installdirs = "$(DESTDIR)$(pkglibdir)" "$(DESTDIR)$(bindir)" \
+	"$(DESTDIR)$(bindir)"
+LTLIBRARIES = $(pkglib_LTLIBRARIES)
+libstunnel_la_LIBADD =
+am__objects_1 = env.lo
+am_libstunnel_la_OBJECTS = $(am__objects_1)
+libstunnel_la_OBJECTS = $(am_libstunnel_la_OBJECTS)
+AM_V_lt = $(am__v_lt_@AM_V@)
+am__v_lt_ = $(am__v_lt_@AM_DEFAULT_V@)
+am__v_lt_0 = --silent
+am__v_lt_1 = 
+libstunnel_la_LINK = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=link $(CCLD) $(AM_CFLAGS) $(CFLAGS) \
+	$(libstunnel_la_LDFLAGS) $(LDFLAGS) -o $@
+PROGRAMS = $(bin_PROGRAMS)
+am__objects_2 =
+am__objects_3 = stunnel-tls.$(OBJEXT) stunnel-str.$(OBJEXT) \
+	stunnel-file.$(OBJEXT) stunnel-client.$(OBJEXT) \
+	stunnel-log.$(OBJEXT) stunnel-options.$(OBJEXT) \
+	stunnel-protocol.$(OBJEXT) stunnel-network.$(OBJEXT) \
+	stunnel-resolver.$(OBJEXT) stunnel-ssl.$(OBJEXT) \
+	stunnel-ctx.$(OBJEXT) stunnel-verify.$(OBJEXT) \
+	stunnel-sthreads.$(OBJEXT) stunnel-fd.$(OBJEXT) \
+	stunnel-dhparam.$(OBJEXT) stunnel-cron.$(OBJEXT) \
+	stunnel-stunnel.$(OBJEXT)
+am__objects_4 = stunnel-pty.$(OBJEXT) stunnel-libwrap.$(OBJEXT) \
+	stunnel-ui_unix.$(OBJEXT)
+am_stunnel_OBJECTS = $(am__objects_2) $(am__objects_3) \
+	$(am__objects_4)
+stunnel_OBJECTS = $(am_stunnel_OBJECTS)
+stunnel_LDADD = $(LDADD)
+stunnel_LINK = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=link $(CCLD) $(AM_CFLAGS) $(CFLAGS) \
+	$(stunnel_LDFLAGS) $(LDFLAGS) -o $@
+am__objects_5 = tls.$(OBJEXT) str.$(OBJEXT) file.$(OBJEXT) \
+	client.$(OBJEXT) log.$(OBJEXT) options.$(OBJEXT) \
+	protocol.$(OBJEXT) network.$(OBJEXT) resolver.$(OBJEXT) \
+	ssl.$(OBJEXT) ctx.$(OBJEXT) verify.$(OBJEXT) \
+	sthreads.$(OBJEXT) fd.$(OBJEXT) dhparam.$(OBJEXT) \
+	cron.$(OBJEXT) stunnel.$(OBJEXT)
+am__objects_6 = ui_win_gui.$(OBJEXT)
+am_stunnel_exe_OBJECTS = $(am__objects_2) $(am__objects_5) \
+	$(am__objects_6)
+stunnel_exe_OBJECTS = $(am_stunnel_exe_OBJECTS)
+stunnel_exe_LDADD = $(LDADD)
+am__objects_7 = ui_win_cli.$(OBJEXT)
+am_tstunnel_exe_OBJECTS = $(am__objects_2) $(am__objects_5) \
+	$(am__objects_7)
+tstunnel_exe_OBJECTS = $(am_tstunnel_exe_OBJECTS)
+tstunnel_exe_LDADD = $(LDADD)
+SCRIPTS = $(bin_SCRIPTS)
+AM_V_P = $(am__v_P_@AM_V@)
+am__v_P_ = $(am__v_P_@AM_DEFAULT_V@)
+am__v_P_0 = false
+am__v_P_1 = :
+AM_V_GEN = $(am__v_GEN_@AM_V@)
+am__v_GEN_ = $(am__v_GEN_@AM_DEFAULT_V@)
+am__v_GEN_0 = @echo "  GEN     " $@;
+am__v_GEN_1 = 
+AM_V_at = $(am__v_at_@AM_V@)
+am__v_at_ = $(am__v_at_@AM_DEFAULT_V@)
+am__v_at_0 = @
+am__v_at_1 = 
+DEFAULT_INCLUDES = -I.@am__isrc@
+depcomp = $(SHELL) $(top_srcdir)/auto/depcomp
+am__depfiles_maybe = depfiles
+am__mv = mv -f
+COMPILE = $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(AM_CPPFLAGS) \
+	$(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS)
+LTCOMPILE = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) \
+	$(DEFAULT_INCLUDES) $(INCLUDES) $(AM_CPPFLAGS) $(CPPFLAGS) \
+	$(AM_CFLAGS) $(CFLAGS)
+AM_V_CC = $(am__v_CC_@AM_V@)
+am__v_CC_ = $(am__v_CC_@AM_DEFAULT_V@)
+am__v_CC_0 = @echo "  CC      " $@;
+am__v_CC_1 = 
+CCLD = $(CC)
+LINK = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=link $(CCLD) $(AM_CFLAGS) $(CFLAGS) \
+	$(AM_LDFLAGS) $(LDFLAGS) -o $@
+AM_V_CCLD = $(am__v_CCLD_@AM_V@)
+am__v_CCLD_ = $(am__v_CCLD_@AM_DEFAULT_V@)
+am__v_CCLD_0 = @echo "  CCLD    " $@;
+am__v_CCLD_1 = 
+SOURCES = $(libstunnel_la_SOURCES) $(stunnel_SOURCES) \
+	$(stunnel_exe_SOURCES) $(tstunnel_exe_SOURCES)
+DIST_SOURCES = $(libstunnel_la_SOURCES) $(stunnel_SOURCES) \
+	$(stunnel_exe_SOURCES) $(tstunnel_exe_SOURCES)
+am__can_run_installinfo = \
+  case $$AM_UPDATE_INFO_DIR in \
+    n|no|NO) false;; \
+    *) (install-info --version) >/dev/null 2>&1;; \
+  esac
+am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) \
+	$(LISP)config.h.in
+# Read a list of newline-separated strings from the standard input,
+# and print each of them once, without duplicates.  Input order is
+# *not* preserved.
+am__uniquify_input = $(AWK) '\
+  BEGIN { nonempty = 0; } \
+  { items[$$0] = 1; nonempty = 1; } \
+  END { if (nonempty) { for (i in items) print i; }; } \
+'
+# Make sure the list of sources is unique.  This is necessary because,
+# e.g., the same source file might be shared among _SOURCES variables
+# for different programs/libraries.
+am__define_uniq_tagged_files = \
+  list='$(am__tagged_files)'; \
+  unique=`for i in $$list; do \
+    if test -f "$$i"; then echo $$i; else echo $(srcdir)/$$i; fi; \
+  done | $(am__uniquify_input)`
+ETAGS = etags
+CTAGS = ctags
+DISTFILES = $(DIST_COMMON) $(DIST_SOURCES) $(TEXINFOS) $(EXTRA_DIST)
+ACLOCAL = @ACLOCAL@
+AMTAR = @AMTAR@
+AM_DEFAULT_VERBOSITY = @AM_DEFAULT_VERBOSITY@
+AR = @AR@
+AUTOCONF = @AUTOCONF@
+AUTOHEADER = @AUTOHEADER@
+AUTOMAKE = @AUTOMAKE@
+AWK = @AWK@
+CC = @CC@
+CCDEPMODE = @CCDEPMODE@
+CFLAGS = @CFLAGS@
+CPP = @CPP@
+CPPFLAGS = @CPPFLAGS@
+CYGPATH_W = @CYGPATH_W@
+DEFAULT_GROUP = @DEFAULT_GROUP@
+DEFS = @DEFS@
+DEPDIR = @DEPDIR@
+DLLTOOL = @DLLTOOL@
+DSYMUTIL = @DSYMUTIL@
+DUMPBIN = @DUMPBIN@
+ECHO_C = @ECHO_C@
+ECHO_N = @ECHO_N@
+ECHO_T = @ECHO_T@
+EGREP = @EGREP@
+EXEEXT = @EXEEXT@
+FGREP = @FGREP@
+GREP = @GREP@
+INSTALL = @INSTALL@
+INSTALL_DATA = @INSTALL_DATA@
+INSTALL_PROGRAM = @INSTALL_PROGRAM@
+INSTALL_SCRIPT = @INSTALL_SCRIPT@
+INSTALL_STRIP_PROGRAM = @INSTALL_STRIP_PROGRAM@
+LD = @LD@
+LDFLAGS = @LDFLAGS@
+LIBOBJS = @LIBOBJS@
+LIBS = @LIBS@
+LIBTOOL = @LIBTOOL@
+LIBTOOL_DEPS = @LIBTOOL_DEPS@
+LIPO = @LIPO@
+LN_S = @LN_S@
+LTLIBOBJS = @LTLIBOBJS@
+MAKEINFO = @MAKEINFO@
+MANIFEST_TOOL = @MANIFEST_TOOL@
+MKDIR_P = @MKDIR_P@
+NM = @NM@
+NMEDIT = @NMEDIT@
+OBJDUMP = @OBJDUMP@
+OBJEXT = @OBJEXT@
+OTOOL = @OTOOL@
+OTOOL64 = @OTOOL64@
+PACKAGE = @PACKAGE@
+PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
+PACKAGE_NAME = @PACKAGE_NAME@
+PACKAGE_STRING = @PACKAGE_STRING@
+PACKAGE_TARNAME = @PACKAGE_TARNAME@
+PACKAGE_URL = @PACKAGE_URL@
+PACKAGE_VERSION = @PACKAGE_VERSION@
+PATH_SEPARATOR = @PATH_SEPARATOR@
+PTHREAD_CC = @PTHREAD_CC@
+PTHREAD_CFLAGS = @PTHREAD_CFLAGS@
+PTHREAD_LIBS = @PTHREAD_LIBS@
+RANDOM_FILE = @RANDOM_FILE@
+RANLIB = @RANLIB@
+SED = @SED@
+SET_MAKE = @SET_MAKE@
+SHELL = @SHELL@
+SSLDIR = @SSLDIR@
+STRIP = @STRIP@
+VERSION = @VERSION@
+abs_builddir = @abs_builddir@
+abs_srcdir = @abs_srcdir@
+abs_top_builddir = @abs_top_builddir@
+abs_top_srcdir = @abs_top_srcdir@
+ac_ct_AR = @ac_ct_AR@
+ac_ct_CC = @ac_ct_CC@
+ac_ct_DUMPBIN = @ac_ct_DUMPBIN@
+am__include = @am__include@
+am__leading_dot = @am__leading_dot@
+am__quote = @am__quote@
+am__tar = @am__tar@
+am__untar = @am__untar@
+ax_pthread_config = @ax_pthread_config@
+bindir = @bindir@
+build = @build@
+build_alias = @build_alias@
+build_cpu = @build_cpu@
+build_os = @build_os@
+build_vendor = @build_vendor@
+builddir = @builddir@
+datadir = @datadir@
+datarootdir = @datarootdir@
+docdir = @docdir@
+dvidir = @dvidir@
+exec_prefix = @exec_prefix@
+host = @host@
+host_alias = @host_alias@
+host_cpu = @host_cpu@
+host_os = @host_os@
+host_vendor = @host_vendor@
+htmldir = @htmldir@
+includedir = @includedir@
+infodir = @infodir@
+install_sh = @install_sh@
+libdir = @libdir@
+libexecdir = @libexecdir@
+localedir = @localedir@
+localstatedir = @localstatedir@
+mandir = @mandir@
+mkdir_p = @mkdir_p@
+oldincludedir = @oldincludedir@
+pdfdir = @pdfdir@
+prefix = @prefix@
+program_transform_name = @program_transform_name@
+psdir = @psdir@
+sbindir = @sbindir@
+sharedstatedir = @sharedstatedir@
+srcdir = @srcdir@
+sysconfdir = @sysconfdir@
+target_alias = @target_alias@
+top_build_prefix = @top_build_prefix@
+top_builddir = @top_builddir@
+top_srcdir = @top_srcdir@
+
+# File lists
+common_headers = common.h prototypes.h version.h
+common_sources = tls.c str.c file.c client.c log.c options.c \
+	protocol.c network.c resolver.c ssl.c ctx.c verify.c \
+	sthreads.c fd.c dhparam.c cron.c stunnel.c
+unix_sources = pty.c libwrap.c ui_unix.c
+shared_sources = env.c
+win32_gui_sources = ui_win_gui.c resources.h resources.rc stunnel.ico \
+	active.ico error.ico idle.ico
+win32_cli_sources = ui_win_cli.c
+stunnel_SOURCES = $(common_headers) $(common_sources) $(unix_sources)
+bin_SCRIPTS = stunnel3
+
+# Remaining files to be included
+# EXTRA_PROGRAMS = stunnel.exe tstunnel.exe
+# EXTRA_DIST += $(win32_gui_sources) $(win32_cli_sources)
+EXTRA_DIST = stunnel3.in make.bat makece.bat makew32.bat mingw.mak \
+	evc.mak vc.mak os2.mak
+CLEANFILES = stunnel3 stunnel.exe tstunnel.exe
+
+# Unix shared library
+pkglib_LTLIBRARIES = libstunnel.la
+libstunnel_la_SOURCES = $(shared_sources)
+libstunnel_la_LDFLAGS = -avoid-version
+
+# Red Hat "by design" bug #82369
+
+# Additional preprocesor definitions
+stunnel_CPPFLAGS = -I/usr/kerberos/include -I$(SSLDIR)/include \
+	-DLIBDIR='"$(pkglibdir)"' -DCONFDIR='"$(sysconfdir)/stunnel"'
+
+# SSL library
+stunnel_LDFLAGS = -L$(SSLDIR)/lib64 -L$(SSLDIR)/lib -lssl -lcrypto
+stunnel_exe_SOURCES = $(common_headers) $(common_sources) $(win32_gui_sources)
+tstunnel_exe_SOURCES = $(common_headers) $(common_sources) $(win32_cli_sources)
+
+# win32_ssl_dir = /usr/src/openssl-0.9.8u-fips
+# win32_cppflags = -I$(win32_ssl_dir)/inc32
+win32_ssl_dir = /usr/src/openssl-1.0.2d-i686
+win32_cppflags = -I$(win32_ssl_dir)/include
+win32_cflags = -mthreads -fstack-protector -O2 -Wall -Wextra \
+	-Wpedantic -Wformat=2 -Wconversion -Wno-long-long \
+	-D_FORTIFY_SOURCE=2 -DUNICODE -D_UNICODE
+win32_ldflags = -mthreads -fstack-protector -s
+win32_common_libs = -lws2_32
+win32_ssl_libs = -L$(win32_ssl_dir) -lcrypto -lssl
+win32_gui_libs = $(win32_common_libs) -lgdi32 -lpsapi $(win32_ssl_libs)
+win32_cli_libs = $(win32_common_libs) $(win32_ssl_libs)
+win32_common_objs = tls.obj str.obj file.obj client.obj log.obj \
+	options.obj protocol.obj network.obj resolver.obj ssl.obj \
+	ctx.obj verify.obj sthreads.obj fd.obj dhparam.obj cron.obj \
+	stunnel.obj
+win32_gui_objs = ui_win_gui.obj resources.obj
+win32_cli_objs = ui_win_cli.obj
+win32_prefix = i686-w64-mingw32-
+win32_cc = $(win32_prefix)gcc
+win32_windres = $(win32_prefix)windres
+MOSTLYCLEANFILES = $(win32_common_objs) $(win32_gui_objs) $(win32_cli_objs)
+edit = sed \
+	-e 's|@bindir[@]|$(bindir)|g'
+
+all: config.h
+	$(MAKE) $(AM_MAKEFLAGS) all-am
+
+.SUFFIXES:
+.SUFFIXES: .c .lo .o .obj
+$(srcdir)/Makefile.in:  $(srcdir)/Makefile.am  $(am__configure_deps)
+	@for dep in $?; do \
+	  case '$(am__configure_deps)' in \
+	    *$$dep*) \
+	      ( cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh ) \
+	        && { if test -f $@; then exit 0; else break; fi; }; \
+	      exit 1;; \
+	  esac; \
+	done; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu src/Makefile'; \
+	$(am__cd) $(top_srcdir) && \
+	  $(AUTOMAKE) --gnu src/Makefile
+.PRECIOUS: Makefile
+Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
+	@case '$?' in \
+	  *config.status*) \
+	    cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh;; \
+	  *) \
+	    echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe)'; \
+	    cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe);; \
+	esac;
+
+$(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+
+$(top_srcdir)/configure:  $(am__configure_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(ACLOCAL_M4):  $(am__aclocal_m4_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(am__aclocal_m4_deps):
+
+config.h: stamp-h1
+	@test -f $@ || rm -f stamp-h1
+	@test -f $@ || $(MAKE) $(AM_MAKEFLAGS) stamp-h1
+
+stamp-h1: $(srcdir)/config.h.in $(top_builddir)/config.status
+	@rm -f stamp-h1
+	cd $(top_builddir) && $(SHELL) ./config.status src/config.h
+$(srcdir)/config.h.in:  $(am__configure_deps) 
+	($(am__cd) $(top_srcdir) && $(AUTOHEADER))
+	rm -f stamp-h1
+	touch $@
+
+distclean-hdr:
+	-rm -f config.h stamp-h1
+
+install-pkglibLTLIBRARIES: $(pkglib_LTLIBRARIES)
+	@$(NORMAL_INSTALL)
+	@list='$(pkglib_LTLIBRARIES)'; test -n "$(pkglibdir)" || list=; \
+	list2=; for p in $$list; do \
+	  if test -f $$p; then \
+	    list2="$$list2 $$p"; \
+	  else :; fi; \
+	done; \
+	test -z "$$list2" || { \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(pkglibdir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(pkglibdir)" || exit 1; \
+	  echo " $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=install $(INSTALL) $(INSTALL_STRIP_FLAG) $$list2 '$(DESTDIR)$(pkglibdir)'"; \
+	  $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=install $(INSTALL) $(INSTALL_STRIP_FLAG) $$list2 "$(DESTDIR)$(pkglibdir)"; \
+	}
+
+uninstall-pkglibLTLIBRARIES:
+	@$(NORMAL_UNINSTALL)
+	@list='$(pkglib_LTLIBRARIES)'; test -n "$(pkglibdir)" || list=; \
+	for p in $$list; do \
+	  $(am__strip_dir) \
+	  echo " $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=uninstall rm -f '$(DESTDIR)$(pkglibdir)/$$f'"; \
+	  $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=uninstall rm -f "$(DESTDIR)$(pkglibdir)/$$f"; \
+	done
+
+clean-pkglibLTLIBRARIES:
+	-test -z "$(pkglib_LTLIBRARIES)" || rm -f $(pkglib_LTLIBRARIES)
+	@list='$(pkglib_LTLIBRARIES)'; \
+	locs=`for p in $$list; do echo $$p; done | \
+	      sed 's|^[^/]*$$|.|; s|/[^/]*$$||; s|$$|/so_locations|' | \
+	      sort -u`; \
+	test -z "$$locs" || { \
+	  echo rm -f $${locs}; \
+	  rm -f $${locs}; \
+	}
+
+libstunnel.la: $(libstunnel_la_OBJECTS) $(libstunnel_la_DEPENDENCIES) $(EXTRA_libstunnel_la_DEPENDENCIES) 
+	$(AM_V_CCLD)$(libstunnel_la_LINK) -rpath $(pkglibdir) $(libstunnel_la_OBJECTS) $(libstunnel_la_LIBADD) $(LIBS)
+install-binPROGRAMS: $(bin_PROGRAMS)
+	@$(NORMAL_INSTALL)
+	@list='$(bin_PROGRAMS)'; test -n "$(bindir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(bindir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(bindir)" || exit 1; \
+	fi; \
+	for p in $$list; do echo "$$p $$p"; done | \
+	sed 's/$(EXEEXT)$$//' | \
+	while read p p1; do if test -f $$p \
+	 || test -f $$p1 \
+	  ; then echo "$$p"; echo "$$p"; else :; fi; \
+	done | \
+	sed -e 'p;s,.*/,,;n;h' \
+	    -e 's|.*|.|' \
+	    -e 'p;x;s,.*/,,;s/$(EXEEXT)$$//;$(transform);s/$$/$(EXEEXT)/' | \
+	sed 'N;N;N;s,\n, ,g' | \
+	$(AWK) 'BEGIN { files["."] = ""; dirs["."] = 1 } \
+	  { d=$$3; if (dirs[d] != 1) { print "d", d; dirs[d] = 1 } \
+	    if ($$2 == $$4) files[d] = files[d] " " $$1; \
+	    else { print "f", $$3 "/" $$4, $$1; } } \
+	  END { for (d in files) print "f", d, files[d] }' | \
+	while read type dir files; do \
+	    if test "$$dir" = .; then dir=; else dir=/$$dir; fi; \
+	    test -z "$$files" || { \
+	    echo " $(INSTALL_PROGRAM_ENV) $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=install $(INSTALL_PROGRAM) $$files '$(DESTDIR)$(bindir)$$dir'"; \
+	    $(INSTALL_PROGRAM_ENV) $(LIBTOOL) $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=install $(INSTALL_PROGRAM) $$files "$(DESTDIR)$(bindir)$$dir" || exit $$?; \
+	    } \
+	; done
+
+uninstall-binPROGRAMS:
+	@$(NORMAL_UNINSTALL)
+	@list='$(bin_PROGRAMS)'; test -n "$(bindir)" || list=; \
+	files=`for p in $$list; do echo "$$p"; done | \
+	  sed -e 'h;s,^.*/,,;s/$(EXEEXT)$$//;$(transform)' \
+	      -e 's/$$/$(EXEEXT)/' \
+	`; \
+	test -n "$$list" || exit 0; \
+	echo " ( cd '$(DESTDIR)$(bindir)' && rm -f" $$files ")"; \
+	cd "$(DESTDIR)$(bindir)" && rm -f $$files
+
+clean-binPROGRAMS:
+	@list='$(bin_PROGRAMS)'; test -n "$$list" || exit 0; \
+	echo " rm -f" $$list; \
+	rm -f $$list || exit $$?; \
+	test -n "$(EXEEXT)" || exit 0; \
+	list=`for p in $$list; do echo "$$p"; done | sed 's/$(EXEEXT)$$//'`; \
+	echo " rm -f" $$list; \
+	rm -f $$list
+
+clean-checkPROGRAMS:
+	@list='$(check_PROGRAMS)'; test -n "$$list" || exit 0; \
+	echo " rm -f" $$list; \
+	rm -f $$list || exit $$?; \
+	test -n "$(EXEEXT)" || exit 0; \
+	list=`for p in $$list; do echo "$$p"; done | sed 's/$(EXEEXT)$$//'`; \
+	echo " rm -f" $$list; \
+	rm -f $$list
+
+stunnel$(EXEEXT): $(stunnel_OBJECTS) $(stunnel_DEPENDENCIES) $(EXTRA_stunnel_DEPENDENCIES) 
+	@rm -f stunnel$(EXEEXT)
+	$(AM_V_CCLD)$(stunnel_LINK) $(stunnel_OBJECTS) $(stunnel_LDADD) $(LIBS)
+install-binSCRIPTS: $(bin_SCRIPTS)
+	@$(NORMAL_INSTALL)
+	@list='$(bin_SCRIPTS)'; test -n "$(bindir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(bindir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(bindir)" || exit 1; \
+	fi; \
+	for p in $$list; do \
+	  if test -f "$$p"; then d=; else d="$(srcdir)/"; fi; \
+	  if test -f "$$d$$p"; then echo "$$d$$p"; echo "$$p"; else :; fi; \
+	done | \
+	sed -e 'p;s,.*/,,;n' \
+	    -e 'h;s|.*|.|' \
+	    -e 'p;x;s,.*/,,;$(transform)' | sed 'N;N;N;s,\n, ,g' | \
+	$(AWK) 'BEGIN { files["."] = ""; dirs["."] = 1; } \
+	  { d=$$3; if (dirs[d] != 1) { print "d", d; dirs[d] = 1 } \
+	    if ($$2 == $$4) { files[d] = files[d] " " $$1; \
+	      if (++n[d] == $(am__install_max)) { \
+		print "f", d, files[d]; n[d] = 0; files[d] = "" } } \
+	    else { print "f", d "/" $$4, $$1 } } \
+	  END { for (d in files) print "f", d, files[d] }' | \
+	while read type dir files; do \
+	     if test "$$dir" = .; then dir=; else dir=/$$dir; fi; \
+	     test -z "$$files" || { \
+	       echo " $(INSTALL_SCRIPT) $$files '$(DESTDIR)$(bindir)$$dir'"; \
+	       $(INSTALL_SCRIPT) $$files "$(DESTDIR)$(bindir)$$dir" || exit $$?; \
+	     } \
+	; done
+
+uninstall-binSCRIPTS:
+	@$(NORMAL_UNINSTALL)
+	@list='$(bin_SCRIPTS)'; test -n "$(bindir)" || exit 0; \
+	files=`for p in $$list; do echo "$$p"; done | \
+	       sed -e 's,.*/,,;$(transform)'`; \
+	dir='$(DESTDIR)$(bindir)'; $(am__uninstall_files_from_dir)
+
+mostlyclean-compile:
+	-rm -f *.$(OBJEXT)
+
+distclean-compile:
+	-rm -f *.tab.c
+
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/client.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/cron.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/ctx.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/dhparam.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/env.Plo@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/fd.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/file.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/log.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/network.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/options.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/protocol.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/resolver.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/ssl.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/sthreads.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/str.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-client.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-cron.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-ctx.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-dhparam.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-fd.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-file.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-libwrap.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-log.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-network.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-options.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-protocol.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-pty.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-resolver.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-ssl.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-sthreads.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-str.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-stunnel.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-tls.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-ui_unix.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel-verify.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/stunnel.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/tls.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/ui_win_cli.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/ui_win_gui.Po@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/verify.Po@am__quote@
+
+.c.o:
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ $<
+
+.c.obj:
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ `$(CYGPATH_W) '$<'`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'`
+
+.c.lo:
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(LTCOMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Plo
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(LTCOMPILE) -c -o $@ $<
+
+stunnel-tls.o: tls.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-tls.o -MD -MP -MF $(DEPDIR)/stunnel-tls.Tpo -c -o stunnel-tls.o `test -f 'tls.c' || echo '$(srcdir)/'`tls.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-tls.Tpo $(DEPDIR)/stunnel-tls.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='tls.c' object='stunnel-tls.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-tls.o `test -f 'tls.c' || echo '$(srcdir)/'`tls.c
+
+stunnel-tls.obj: tls.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-tls.obj -MD -MP -MF $(DEPDIR)/stunnel-tls.Tpo -c -o stunnel-tls.obj `if test -f 'tls.c'; then $(CYGPATH_W) 'tls.c'; else $(CYGPATH_W) '$(srcdir)/tls.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-tls.Tpo $(DEPDIR)/stunnel-tls.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='tls.c' object='stunnel-tls.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-tls.obj `if test -f 'tls.c'; then $(CYGPATH_W) 'tls.c'; else $(CYGPATH_W) '$(srcdir)/tls.c'; fi`
+
+stunnel-str.o: str.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-str.o -MD -MP -MF $(DEPDIR)/stunnel-str.Tpo -c -o stunnel-str.o `test -f 'str.c' || echo '$(srcdir)/'`str.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-str.Tpo $(DEPDIR)/stunnel-str.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='str.c' object='stunnel-str.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-str.o `test -f 'str.c' || echo '$(srcdir)/'`str.c
+
+stunnel-str.obj: str.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-str.obj -MD -MP -MF $(DEPDIR)/stunnel-str.Tpo -c -o stunnel-str.obj `if test -f 'str.c'; then $(CYGPATH_W) 'str.c'; else $(CYGPATH_W) '$(srcdir)/str.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-str.Tpo $(DEPDIR)/stunnel-str.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='str.c' object='stunnel-str.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-str.obj `if test -f 'str.c'; then $(CYGPATH_W) 'str.c'; else $(CYGPATH_W) '$(srcdir)/str.c'; fi`
+
+stunnel-file.o: file.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-file.o -MD -MP -MF $(DEPDIR)/stunnel-file.Tpo -c -o stunnel-file.o `test -f 'file.c' || echo '$(srcdir)/'`file.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-file.Tpo $(DEPDIR)/stunnel-file.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='file.c' object='stunnel-file.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-file.o `test -f 'file.c' || echo '$(srcdir)/'`file.c
+
+stunnel-file.obj: file.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-file.obj -MD -MP -MF $(DEPDIR)/stunnel-file.Tpo -c -o stunnel-file.obj `if test -f 'file.c'; then $(CYGPATH_W) 'file.c'; else $(CYGPATH_W) '$(srcdir)/file.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-file.Tpo $(DEPDIR)/stunnel-file.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='file.c' object='stunnel-file.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-file.obj `if test -f 'file.c'; then $(CYGPATH_W) 'file.c'; else $(CYGPATH_W) '$(srcdir)/file.c'; fi`
+
+stunnel-client.o: client.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-client.o -MD -MP -MF $(DEPDIR)/stunnel-client.Tpo -c -o stunnel-client.o `test -f 'client.c' || echo '$(srcdir)/'`client.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-client.Tpo $(DEPDIR)/stunnel-client.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='client.c' object='stunnel-client.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-client.o `test -f 'client.c' || echo '$(srcdir)/'`client.c
+
+stunnel-client.obj: client.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-client.obj -MD -MP -MF $(DEPDIR)/stunnel-client.Tpo -c -o stunnel-client.obj `if test -f 'client.c'; then $(CYGPATH_W) 'client.c'; else $(CYGPATH_W) '$(srcdir)/client.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-client.Tpo $(DEPDIR)/stunnel-client.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='client.c' object='stunnel-client.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-client.obj `if test -f 'client.c'; then $(CYGPATH_W) 'client.c'; else $(CYGPATH_W) '$(srcdir)/client.c'; fi`
+
+stunnel-log.o: log.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-log.o -MD -MP -MF $(DEPDIR)/stunnel-log.Tpo -c -o stunnel-log.o `test -f 'log.c' || echo '$(srcdir)/'`log.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-log.Tpo $(DEPDIR)/stunnel-log.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='log.c' object='stunnel-log.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-log.o `test -f 'log.c' || echo '$(srcdir)/'`log.c
+
+stunnel-log.obj: log.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-log.obj -MD -MP -MF $(DEPDIR)/stunnel-log.Tpo -c -o stunnel-log.obj `if test -f 'log.c'; then $(CYGPATH_W) 'log.c'; else $(CYGPATH_W) '$(srcdir)/log.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-log.Tpo $(DEPDIR)/stunnel-log.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='log.c' object='stunnel-log.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-log.obj `if test -f 'log.c'; then $(CYGPATH_W) 'log.c'; else $(CYGPATH_W) '$(srcdir)/log.c'; fi`
+
+stunnel-options.o: options.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-options.o -MD -MP -MF $(DEPDIR)/stunnel-options.Tpo -c -o stunnel-options.o `test -f 'options.c' || echo '$(srcdir)/'`options.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-options.Tpo $(DEPDIR)/stunnel-options.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='options.c' object='stunnel-options.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-options.o `test -f 'options.c' || echo '$(srcdir)/'`options.c
+
+stunnel-options.obj: options.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-options.obj -MD -MP -MF $(DEPDIR)/stunnel-options.Tpo -c -o stunnel-options.obj `if test -f 'options.c'; then $(CYGPATH_W) 'options.c'; else $(CYGPATH_W) '$(srcdir)/options.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-options.Tpo $(DEPDIR)/stunnel-options.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='options.c' object='stunnel-options.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-options.obj `if test -f 'options.c'; then $(CYGPATH_W) 'options.c'; else $(CYGPATH_W) '$(srcdir)/options.c'; fi`
+
+stunnel-protocol.o: protocol.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-protocol.o -MD -MP -MF $(DEPDIR)/stunnel-protocol.Tpo -c -o stunnel-protocol.o `test -f 'protocol.c' || echo '$(srcdir)/'`protocol.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-protocol.Tpo $(DEPDIR)/stunnel-protocol.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='protocol.c' object='stunnel-protocol.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-protocol.o `test -f 'protocol.c' || echo '$(srcdir)/'`protocol.c
+
+stunnel-protocol.obj: protocol.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-protocol.obj -MD -MP -MF $(DEPDIR)/stunnel-protocol.Tpo -c -o stunnel-protocol.obj `if test -f 'protocol.c'; then $(CYGPATH_W) 'protocol.c'; else $(CYGPATH_W) '$(srcdir)/protocol.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-protocol.Tpo $(DEPDIR)/stunnel-protocol.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='protocol.c' object='stunnel-protocol.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-protocol.obj `if test -f 'protocol.c'; then $(CYGPATH_W) 'protocol.c'; else $(CYGPATH_W) '$(srcdir)/protocol.c'; fi`
+
+stunnel-network.o: network.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-network.o -MD -MP -MF $(DEPDIR)/stunnel-network.Tpo -c -o stunnel-network.o `test -f 'network.c' || echo '$(srcdir)/'`network.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-network.Tpo $(DEPDIR)/stunnel-network.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='network.c' object='stunnel-network.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-network.o `test -f 'network.c' || echo '$(srcdir)/'`network.c
+
+stunnel-network.obj: network.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-network.obj -MD -MP -MF $(DEPDIR)/stunnel-network.Tpo -c -o stunnel-network.obj `if test -f 'network.c'; then $(CYGPATH_W) 'network.c'; else $(CYGPATH_W) '$(srcdir)/network.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-network.Tpo $(DEPDIR)/stunnel-network.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='network.c' object='stunnel-network.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-network.obj `if test -f 'network.c'; then $(CYGPATH_W) 'network.c'; else $(CYGPATH_W) '$(srcdir)/network.c'; fi`
+
+stunnel-resolver.o: resolver.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-resolver.o -MD -MP -MF $(DEPDIR)/stunnel-resolver.Tpo -c -o stunnel-resolver.o `test -f 'resolver.c' || echo '$(srcdir)/'`resolver.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-resolver.Tpo $(DEPDIR)/stunnel-resolver.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='resolver.c' object='stunnel-resolver.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-resolver.o `test -f 'resolver.c' || echo '$(srcdir)/'`resolver.c
+
+stunnel-resolver.obj: resolver.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-resolver.obj -MD -MP -MF $(DEPDIR)/stunnel-resolver.Tpo -c -o stunnel-resolver.obj `if test -f 'resolver.c'; then $(CYGPATH_W) 'resolver.c'; else $(CYGPATH_W) '$(srcdir)/resolver.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-resolver.Tpo $(DEPDIR)/stunnel-resolver.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='resolver.c' object='stunnel-resolver.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-resolver.obj `if test -f 'resolver.c'; then $(CYGPATH_W) 'resolver.c'; else $(CYGPATH_W) '$(srcdir)/resolver.c'; fi`
+
+stunnel-ssl.o: ssl.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ssl.o -MD -MP -MF $(DEPDIR)/stunnel-ssl.Tpo -c -o stunnel-ssl.o `test -f 'ssl.c' || echo '$(srcdir)/'`ssl.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ssl.Tpo $(DEPDIR)/stunnel-ssl.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ssl.c' object='stunnel-ssl.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ssl.o `test -f 'ssl.c' || echo '$(srcdir)/'`ssl.c
+
+stunnel-ssl.obj: ssl.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ssl.obj -MD -MP -MF $(DEPDIR)/stunnel-ssl.Tpo -c -o stunnel-ssl.obj `if test -f 'ssl.c'; then $(CYGPATH_W) 'ssl.c'; else $(CYGPATH_W) '$(srcdir)/ssl.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ssl.Tpo $(DEPDIR)/stunnel-ssl.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ssl.c' object='stunnel-ssl.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ssl.obj `if test -f 'ssl.c'; then $(CYGPATH_W) 'ssl.c'; else $(CYGPATH_W) '$(srcdir)/ssl.c'; fi`
+
+stunnel-ctx.o: ctx.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ctx.o -MD -MP -MF $(DEPDIR)/stunnel-ctx.Tpo -c -o stunnel-ctx.o `test -f 'ctx.c' || echo '$(srcdir)/'`ctx.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ctx.Tpo $(DEPDIR)/stunnel-ctx.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ctx.c' object='stunnel-ctx.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ctx.o `test -f 'ctx.c' || echo '$(srcdir)/'`ctx.c
+
+stunnel-ctx.obj: ctx.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ctx.obj -MD -MP -MF $(DEPDIR)/stunnel-ctx.Tpo -c -o stunnel-ctx.obj `if test -f 'ctx.c'; then $(CYGPATH_W) 'ctx.c'; else $(CYGPATH_W) '$(srcdir)/ctx.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ctx.Tpo $(DEPDIR)/stunnel-ctx.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ctx.c' object='stunnel-ctx.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ctx.obj `if test -f 'ctx.c'; then $(CYGPATH_W) 'ctx.c'; else $(CYGPATH_W) '$(srcdir)/ctx.c'; fi`
+
+stunnel-verify.o: verify.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-verify.o -MD -MP -MF $(DEPDIR)/stunnel-verify.Tpo -c -o stunnel-verify.o `test -f 'verify.c' || echo '$(srcdir)/'`verify.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-verify.Tpo $(DEPDIR)/stunnel-verify.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='verify.c' object='stunnel-verify.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-verify.o `test -f 'verify.c' || echo '$(srcdir)/'`verify.c
+
+stunnel-verify.obj: verify.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-verify.obj -MD -MP -MF $(DEPDIR)/stunnel-verify.Tpo -c -o stunnel-verify.obj `if test -f 'verify.c'; then $(CYGPATH_W) 'verify.c'; else $(CYGPATH_W) '$(srcdir)/verify.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-verify.Tpo $(DEPDIR)/stunnel-verify.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='verify.c' object='stunnel-verify.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-verify.obj `if test -f 'verify.c'; then $(CYGPATH_W) 'verify.c'; else $(CYGPATH_W) '$(srcdir)/verify.c'; fi`
+
+stunnel-sthreads.o: sthreads.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-sthreads.o -MD -MP -MF $(DEPDIR)/stunnel-sthreads.Tpo -c -o stunnel-sthreads.o `test -f 'sthreads.c' || echo '$(srcdir)/'`sthreads.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-sthreads.Tpo $(DEPDIR)/stunnel-sthreads.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='sthreads.c' object='stunnel-sthreads.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-sthreads.o `test -f 'sthreads.c' || echo '$(srcdir)/'`sthreads.c
+
+stunnel-sthreads.obj: sthreads.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-sthreads.obj -MD -MP -MF $(DEPDIR)/stunnel-sthreads.Tpo -c -o stunnel-sthreads.obj `if test -f 'sthreads.c'; then $(CYGPATH_W) 'sthreads.c'; else $(CYGPATH_W) '$(srcdir)/sthreads.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-sthreads.Tpo $(DEPDIR)/stunnel-sthreads.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='sthreads.c' object='stunnel-sthreads.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-sthreads.obj `if test -f 'sthreads.c'; then $(CYGPATH_W) 'sthreads.c'; else $(CYGPATH_W) '$(srcdir)/sthreads.c'; fi`
+
+stunnel-fd.o: fd.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-fd.o -MD -MP -MF $(DEPDIR)/stunnel-fd.Tpo -c -o stunnel-fd.o `test -f 'fd.c' || echo '$(srcdir)/'`fd.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-fd.Tpo $(DEPDIR)/stunnel-fd.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='fd.c' object='stunnel-fd.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-fd.o `test -f 'fd.c' || echo '$(srcdir)/'`fd.c
+
+stunnel-fd.obj: fd.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-fd.obj -MD -MP -MF $(DEPDIR)/stunnel-fd.Tpo -c -o stunnel-fd.obj `if test -f 'fd.c'; then $(CYGPATH_W) 'fd.c'; else $(CYGPATH_W) '$(srcdir)/fd.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-fd.Tpo $(DEPDIR)/stunnel-fd.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='fd.c' object='stunnel-fd.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-fd.obj `if test -f 'fd.c'; then $(CYGPATH_W) 'fd.c'; else $(CYGPATH_W) '$(srcdir)/fd.c'; fi`
+
+stunnel-dhparam.o: dhparam.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-dhparam.o -MD -MP -MF $(DEPDIR)/stunnel-dhparam.Tpo -c -o stunnel-dhparam.o `test -f 'dhparam.c' || echo '$(srcdir)/'`dhparam.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-dhparam.Tpo $(DEPDIR)/stunnel-dhparam.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='dhparam.c' object='stunnel-dhparam.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-dhparam.o `test -f 'dhparam.c' || echo '$(srcdir)/'`dhparam.c
+
+stunnel-dhparam.obj: dhparam.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-dhparam.obj -MD -MP -MF $(DEPDIR)/stunnel-dhparam.Tpo -c -o stunnel-dhparam.obj `if test -f 'dhparam.c'; then $(CYGPATH_W) 'dhparam.c'; else $(CYGPATH_W) '$(srcdir)/dhparam.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-dhparam.Tpo $(DEPDIR)/stunnel-dhparam.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='dhparam.c' object='stunnel-dhparam.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-dhparam.obj `if test -f 'dhparam.c'; then $(CYGPATH_W) 'dhparam.c'; else $(CYGPATH_W) '$(srcdir)/dhparam.c'; fi`
+
+stunnel-cron.o: cron.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-cron.o -MD -MP -MF $(DEPDIR)/stunnel-cron.Tpo -c -o stunnel-cron.o `test -f 'cron.c' || echo '$(srcdir)/'`cron.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-cron.Tpo $(DEPDIR)/stunnel-cron.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='cron.c' object='stunnel-cron.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-cron.o `test -f 'cron.c' || echo '$(srcdir)/'`cron.c
+
+stunnel-cron.obj: cron.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-cron.obj -MD -MP -MF $(DEPDIR)/stunnel-cron.Tpo -c -o stunnel-cron.obj `if test -f 'cron.c'; then $(CYGPATH_W) 'cron.c'; else $(CYGPATH_W) '$(srcdir)/cron.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-cron.Tpo $(DEPDIR)/stunnel-cron.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='cron.c' object='stunnel-cron.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-cron.obj `if test -f 'cron.c'; then $(CYGPATH_W) 'cron.c'; else $(CYGPATH_W) '$(srcdir)/cron.c'; fi`
+
+stunnel-stunnel.o: stunnel.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-stunnel.o -MD -MP -MF $(DEPDIR)/stunnel-stunnel.Tpo -c -o stunnel-stunnel.o `test -f 'stunnel.c' || echo '$(srcdir)/'`stunnel.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-stunnel.Tpo $(DEPDIR)/stunnel-stunnel.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='stunnel.c' object='stunnel-stunnel.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-stunnel.o `test -f 'stunnel.c' || echo '$(srcdir)/'`stunnel.c
+
+stunnel-stunnel.obj: stunnel.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-stunnel.obj -MD -MP -MF $(DEPDIR)/stunnel-stunnel.Tpo -c -o stunnel-stunnel.obj `if test -f 'stunnel.c'; then $(CYGPATH_W) 'stunnel.c'; else $(CYGPATH_W) '$(srcdir)/stunnel.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-stunnel.Tpo $(DEPDIR)/stunnel-stunnel.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='stunnel.c' object='stunnel-stunnel.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-stunnel.obj `if test -f 'stunnel.c'; then $(CYGPATH_W) 'stunnel.c'; else $(CYGPATH_W) '$(srcdir)/stunnel.c'; fi`
+
+stunnel-pty.o: pty.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-pty.o -MD -MP -MF $(DEPDIR)/stunnel-pty.Tpo -c -o stunnel-pty.o `test -f 'pty.c' || echo '$(srcdir)/'`pty.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-pty.Tpo $(DEPDIR)/stunnel-pty.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='pty.c' object='stunnel-pty.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-pty.o `test -f 'pty.c' || echo '$(srcdir)/'`pty.c
+
+stunnel-pty.obj: pty.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-pty.obj -MD -MP -MF $(DEPDIR)/stunnel-pty.Tpo -c -o stunnel-pty.obj `if test -f 'pty.c'; then $(CYGPATH_W) 'pty.c'; else $(CYGPATH_W) '$(srcdir)/pty.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-pty.Tpo $(DEPDIR)/stunnel-pty.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='pty.c' object='stunnel-pty.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-pty.obj `if test -f 'pty.c'; then $(CYGPATH_W) 'pty.c'; else $(CYGPATH_W) '$(srcdir)/pty.c'; fi`
+
+stunnel-libwrap.o: libwrap.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-libwrap.o -MD -MP -MF $(DEPDIR)/stunnel-libwrap.Tpo -c -o stunnel-libwrap.o `test -f 'libwrap.c' || echo '$(srcdir)/'`libwrap.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-libwrap.Tpo $(DEPDIR)/stunnel-libwrap.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='libwrap.c' object='stunnel-libwrap.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-libwrap.o `test -f 'libwrap.c' || echo '$(srcdir)/'`libwrap.c
+
+stunnel-libwrap.obj: libwrap.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-libwrap.obj -MD -MP -MF $(DEPDIR)/stunnel-libwrap.Tpo -c -o stunnel-libwrap.obj `if test -f 'libwrap.c'; then $(CYGPATH_W) 'libwrap.c'; else $(CYGPATH_W) '$(srcdir)/libwrap.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-libwrap.Tpo $(DEPDIR)/stunnel-libwrap.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='libwrap.c' object='stunnel-libwrap.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-libwrap.obj `if test -f 'libwrap.c'; then $(CYGPATH_W) 'libwrap.c'; else $(CYGPATH_W) '$(srcdir)/libwrap.c'; fi`
+
+stunnel-ui_unix.o: ui_unix.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ui_unix.o -MD -MP -MF $(DEPDIR)/stunnel-ui_unix.Tpo -c -o stunnel-ui_unix.o `test -f 'ui_unix.c' || echo '$(srcdir)/'`ui_unix.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ui_unix.Tpo $(DEPDIR)/stunnel-ui_unix.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ui_unix.c' object='stunnel-ui_unix.o' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ui_unix.o `test -f 'ui_unix.c' || echo '$(srcdir)/'`ui_unix.c
+
+stunnel-ui_unix.obj: ui_unix.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT stunnel-ui_unix.obj -MD -MP -MF $(DEPDIR)/stunnel-ui_unix.Tpo -c -o stunnel-ui_unix.obj `if test -f 'ui_unix.c'; then $(CYGPATH_W) 'ui_unix.c'; else $(CYGPATH_W) '$(srcdir)/ui_unix.c'; fi`
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/stunnel-ui_unix.Tpo $(DEPDIR)/stunnel-ui_unix.Po
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='ui_unix.c' object='stunnel-ui_unix.obj' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(stunnel_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o stunnel-ui_unix.obj `if test -f 'ui_unix.c'; then $(CYGPATH_W) 'ui_unix.c'; else $(CYGPATH_W) '$(srcdir)/ui_unix.c'; fi`
+
+mostlyclean-libtool:
+	-rm -f *.lo
+
+clean-libtool:
+	-rm -rf .libs _libs
+
+ID: $(am__tagged_files)
+	$(am__define_uniq_tagged_files); mkid -fID $$unique
+tags: tags-am
+TAGS: tags
+
+tags-am: $(TAGS_DEPENDENCIES) $(am__tagged_files)
+	set x; \
+	here=`pwd`; \
+	$(am__define_uniq_tagged_files); \
+	shift; \
+	if test -z "$(ETAGS_ARGS)$$*$$unique"; then :; else \
+	  test -n "$$unique" || unique=$$empty_fix; \
+	  if test $$# -gt 0; then \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      "$$@" $$unique; \
+	  else \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      $$unique; \
+	  fi; \
+	fi
+ctags: ctags-am
+
+CTAGS: ctags
+ctags-am: $(TAGS_DEPENDENCIES) $(am__tagged_files)
+	$(am__define_uniq_tagged_files); \
+	test -z "$(CTAGS_ARGS)$$unique" \
+	  || $(CTAGS) $(CTAGSFLAGS) $(AM_CTAGSFLAGS) $(CTAGS_ARGS) \
+	     $$unique
+
+GTAGS:
+	here=`$(am__cd) $(top_builddir) && pwd` \
+	  && $(am__cd) $(top_srcdir) \
+	  && gtags -i $(GTAGS_ARGS) "$$here"
+cscopelist: cscopelist-am
+
+cscopelist-am: $(am__tagged_files)
+	list='$(am__tagged_files)'; \
+	case "$(srcdir)" in \
+	  [\\/]* | ?:[\\/]*) sdir="$(srcdir)" ;; \
+	  *) sdir=$(subdir)/$(srcdir) ;; \
+	esac; \
+	for i in $$list; do \
+	  if test -f "$$i"; then \
+	    echo "$(subdir)/$$i"; \
+	  else \
+	    echo "$$sdir/$$i"; \
+	  fi; \
+	done >> $(top_builddir)/cscope.files
+
+distclean-tags:
+	-rm -f TAGS ID GTAGS GRTAGS GSYMS GPATH tags
+
+distdir: $(DISTFILES)
+	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	list='$(DISTFILES)'; \
+	  dist_files=`for file in $$list; do echo $$file; done | \
+	  sed -e "s|^$$srcdirstrip/||;t" \
+	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
+	case $$dist_files in \
+	  */*) $(MKDIR_P) `echo "$$dist_files" | \
+			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sort -u` ;; \
+	esac; \
+	for file in $$dist_files; do \
+	  if test -f $$file || test -d $$file; then d=.; else d=$(srcdir); fi; \
+	  if test -d $$d/$$file; then \
+	    dir=`echo "/$$file" | sed -e 's,/[^/]*$$,,'`; \
+	    if test -d "$(distdir)/$$file"; then \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    if test -d $(srcdir)/$$file && test $$d != $(srcdir); then \
+	      cp -fpR $(srcdir)/$$file "$(distdir)$$dir" || exit 1; \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    cp -fpR $$d/$$file "$(distdir)$$dir" || exit 1; \
+	  else \
+	    test -f "$(distdir)/$$file" \
+	    || cp -p $$d/$$file "$(distdir)/$$file" \
+	    || exit 1; \
+	  fi; \
+	done
+check-am: all-am
+	$(MAKE) $(AM_MAKEFLAGS) $(check_PROGRAMS)
+check: check-am
+all-am: Makefile $(LTLIBRARIES) $(PROGRAMS) $(SCRIPTS) config.h
+installdirs:
+	for dir in "$(DESTDIR)$(pkglibdir)" "$(DESTDIR)$(bindir)" "$(DESTDIR)$(bindir)"; do \
+	  test -z "$$dir" || $(MKDIR_P) "$$dir"; \
+	done
+install: install-am
+install-exec: install-exec-am
+install-data: install-data-am
+uninstall: uninstall-am
+
+install-am: all-am
+	@$(MAKE) $(AM_MAKEFLAGS) install-exec-am install-data-am
+
+installcheck: installcheck-am
+install-strip:
+	if test -z '$(STRIP)'; then \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	      install; \
+	else \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	    "INSTALL_PROGRAM_ENV=STRIPPROG='$(STRIP)'" install; \
+	fi
+mostlyclean-generic:
+	-test -z "$(MOSTLYCLEANFILES)" || rm -f $(MOSTLYCLEANFILES)
+
+clean-generic:
+	-test -z "$(CLEANFILES)" || rm -f $(CLEANFILES)
+
+distclean-generic:
+	-test -z "$(CONFIG_CLEAN_FILES)" || rm -f $(CONFIG_CLEAN_FILES)
+	-test . = "$(srcdir)" || test -z "$(CONFIG_CLEAN_VPATH_FILES)" || rm -f $(CONFIG_CLEAN_VPATH_FILES)
+
+maintainer-clean-generic:
+	@echo "This command is intended for maintainers to use"
+	@echo "it deletes files that may require special tools to rebuild."
+clean: clean-am
+
+clean-am: clean-binPROGRAMS clean-checkPROGRAMS clean-generic \
+	clean-libtool clean-pkglibLTLIBRARIES mostlyclean-am
+
+distclean: distclean-am
+	-rm -rf ./$(DEPDIR)
+	-rm -f Makefile
+distclean-am: clean-am distclean-compile distclean-generic \
+	distclean-hdr distclean-tags
+
+dvi: dvi-am
+
+dvi-am:
+
+html: html-am
+
+html-am:
+
+info: info-am
+
+info-am:
+
+install-data-am:
+
+install-dvi: install-dvi-am
+
+install-dvi-am:
+
+install-exec-am: install-binPROGRAMS install-binSCRIPTS \
+	install-pkglibLTLIBRARIES
+
+install-html: install-html-am
+
+install-html-am:
+
+install-info: install-info-am
+
+install-info-am:
+
+install-man:
+
+install-pdf: install-pdf-am
+
+install-pdf-am:
+
+install-ps: install-ps-am
+
+install-ps-am:
+
+installcheck-am:
+
+maintainer-clean: maintainer-clean-am
+	-rm -rf ./$(DEPDIR)
+	-rm -f Makefile
+maintainer-clean-am: distclean-am maintainer-clean-generic
+
+mostlyclean: mostlyclean-am
+
+mostlyclean-am: mostlyclean-compile mostlyclean-generic \
+	mostlyclean-libtool
+
+pdf: pdf-am
+
+pdf-am:
+
+ps: ps-am
+
+ps-am:
+
+uninstall-am: uninstall-binPROGRAMS uninstall-binSCRIPTS \
+	uninstall-pkglibLTLIBRARIES
+
+.MAKE: all check-am install-am install-strip
+
+.PHONY: CTAGS GTAGS TAGS all all-am check check-am clean \
+	clean-binPROGRAMS clean-checkPROGRAMS clean-generic \
+	clean-libtool clean-pkglibLTLIBRARIES cscopelist-am ctags \
+	ctags-am distclean distclean-compile distclean-generic \
+	distclean-hdr distclean-libtool distclean-tags distdir dvi \
+	dvi-am html html-am info info-am install install-am \
+	install-binPROGRAMS install-binSCRIPTS install-data \
+	install-data-am install-dvi install-dvi-am install-exec \
+	install-exec-am install-html install-html-am install-info \
+	install-info-am install-man install-pdf install-pdf-am \
+	install-pkglibLTLIBRARIES install-ps install-ps-am \
+	install-strip installcheck installcheck-am installdirs \
+	maintainer-clean maintainer-clean-generic mostlyclean \
+	mostlyclean-compile mostlyclean-generic mostlyclean-libtool \
+	pdf pdf-am ps ps-am tags tags-am uninstall uninstall-am \
+	uninstall-binPROGRAMS uninstall-binSCRIPTS \
+	uninstall-pkglibLTLIBRARIES
+
+
+# Generate a new set of DH parameters for each version
+dhparam.c: version.h
+	echo '#include "common.h"' >dhparam.c
+	echo '#ifndef OPENSSL_NO_DH' >>dhparam.c
+	echo '#define DN_new DH_new' >>dhparam.c
+	openssl dhparam -noout -C 2048 >>dhparam.c
+	echo '#endif /* OPENSSL_NO_DH */' >>dhparam.c
+
+# dist-hook: stunnel.exe tstunnel.exe
+
+# SUFFIXES = .c .rc .obj
+
+stunnel.exe: $(win32_common_objs) $(win32_gui_objs)
+	$(win32_cc) -mwindows $(win32_ldflags) -o stunnel.exe $(win32_common_objs) $(win32_gui_objs) $(win32_gui_libs)
+
+tstunnel.exe: $(win32_common_objs) $(win32_cli_objs)
+	$(win32_cc) $(win32_ldflags) -o tstunnel.exe $(win32_common_objs) $(win32_cli_objs) $(win32_cli_libs)
+
+%.obj: %.c $(common_headers)
+	$(win32_cc) -c $(win32_cppflags) $(win32_cflags) -o $@ $<
+
+resources.obj: resources.rc resources.h version.h
+	$(win32_windres) --include-dir $(srcdir) $< $@
+
+stunnel3: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel3: $(srcdir)/stunnel3.in
+
+# Tell versions [3.59,3.63) of GNU make to not export all variables.
+# Otherwise a system limit (for SysV at least) may be exceeded.
+.NOEXPORT:
diff --git a/src/active.ico b/src/active.ico
new file mode 100644
index 0000000..e9dfefb
--- /dev/null
+++ b/src/active.ico
Binary files differ
diff --git a/src/client.c b/src/client.c
new file mode 100644
index 0000000..dd73d94
--- /dev/null
+++ b/src/client.c
@@ -0,0 +1,1433 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifndef SHUT_RD
+#define SHUT_RD 0
+#endif
+#ifndef SHUT_WR
+#define SHUT_WR 1
+#endif
+#ifndef SHUT_RDWR
+#define SHUT_RDWR 2
+#endif
+
+NOEXPORT void client_try(CLI *);
+NOEXPORT void client_run(CLI *);
+NOEXPORT void local_start(CLI *);
+NOEXPORT void remote_start(CLI *);
+NOEXPORT void ssl_start(CLI *);
+NOEXPORT void new_chain(CLI *);
+NOEXPORT void transfer(CLI *);
+NOEXPORT int parse_socket_error(CLI *, const char *);
+
+NOEXPORT void print_cipher(CLI *);
+NOEXPORT void auth_user(CLI *, char *);
+NOEXPORT SOCKET connect_local(CLI *);
+NOEXPORT SOCKET connect_remote(CLI *);
+NOEXPORT void connect_cache(SSL_SESSION *, SOCKADDR_UNION *);
+NOEXPORT unsigned connect_index(CLI *);
+NOEXPORT void setup_connect_addr(CLI *);
+NOEXPORT void local_bind(CLI *c);
+NOEXPORT void print_bound_address(CLI *);
+NOEXPORT void reset(SOCKET, char *);
+
+/* allocate local data structure for the new thread */
+CLI *alloc_client_session(SERVICE_OPTIONS *opt, SOCKET rfd, SOCKET wfd) {
+    CLI *c;
+
+    c=str_alloc_detached(sizeof(CLI));
+    c->opt=opt;
+    c->local_rfd.fd=rfd;
+    c->local_wfd.fd=wfd;
+    c->redirect=REDIRECT_OFF;
+    return c;
+}
+
+void *client_thread(void *arg) {
+    CLI *c=arg;
+
+    c->tls=NULL; /* do not reuse */
+    tls_alloc(c, NULL, NULL);
+#ifdef DEBUG_STACK_SIZE
+    stack_info(1); /* initialize */
+#endif
+    client_main(c);
+#ifdef DEBUG_STACK_SIZE
+    stack_info(0); /* display computed value */
+#endif
+    str_stats(); /* client thread allocation tracking */
+    tls_cleanup();
+    /* s_log() is not allowed after tls_cleanup() */
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+    _endthread();
+#endif
+#ifdef USE_UCONTEXT
+    s_poll_wait(NULL, 0, 0); /* wait on poll() */
+#endif
+    return NULL;
+}
+
+void client_main(CLI *c) {
+    s_log(LOG_DEBUG, "Service [%s] started", c->opt->servname);
+    if(c->opt->exec_name && c->opt->connect_addr.names) {
+            /* exec+connect options specified together
+             * -> spawn a local program instead of stdio */
+        for(;;) {
+            SERVICE_OPTIONS *opt=c->opt;
+            memset(c, 0, sizeof(CLI)); /* connect_local needs clean c */
+            c->opt=opt;
+            if(!setjmp(c->err))
+                c->local_rfd.fd=c->local_wfd.fd=connect_local(c);
+            else
+                break;
+            client_run(c);
+            if(!c->opt->option.retry)
+                break;
+            sleep(1); /* FIXME: not a good idea in ucontext threading */
+            s_poll_free(c->fds);
+            c->fds=NULL;
+            str_stats(); /* client thread allocation tracking */
+            /* c allocation is detached, so it is safe to call str_stats() */
+            if(service_options.next) /* no tls_cleanup() in inetd mode */
+                tls_cleanup();
+        }
+    } else
+        client_run(c);
+    str_free(c);
+}
+
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-Wformat"
+#pragma GCC diagnostic ignored "-Wformat-extra-args"
+#endif /* __GNUC__ */
+NOEXPORT void client_run(CLI *c) {
+    int err, rst;
+#ifndef USE_FORK
+    long num_clients_copy;
+#endif
+
+#ifndef USE_FORK
+    enter_critical_section(CRIT_CLIENTS);
+    ui_clients(++num_clients);
+    leave_critical_section(CRIT_CLIENTS);
+#endif
+
+        /* initialize the client context */
+    c->remote_fd.fd=INVALID_SOCKET;
+    c->fd=INVALID_SOCKET;
+    c->ssl=NULL;
+    c->sock_bytes=c->ssl_bytes=0;
+    if(c->opt->option.client) {
+        c->sock_rfd=&(c->local_rfd);
+        c->sock_wfd=&(c->local_wfd);
+        c->ssl_rfd=c->ssl_wfd=&(c->remote_fd);
+    } else {
+        c->sock_rfd=c->sock_wfd=&(c->remote_fd);
+        c->ssl_rfd=&(c->local_rfd);
+        c->ssl_wfd=&(c->local_wfd);
+    }
+    c->fds=s_poll_alloc();
+    addrlist_clear(&c->connect_addr, 0);
+
+        /* try to process the request */
+    err=setjmp(c->err);
+    if(!err)
+        client_try(c);
+    rst=err==1 && c->opt->option.reset;
+    s_log(LOG_NOTICE,
+        "Connection %s: %llu byte(s) sent to SSL, %llu byte(s) sent to socket",
+        rst ? "reset" : "closed",
+        (unsigned long long)c->ssl_bytes, (unsigned long long)c->sock_bytes);
+
+        /* cleanup temporary (e.g. IDENT) socket */
+    if(c->fd!=INVALID_SOCKET)
+        closesocket(c->fd);
+    c->fd=INVALID_SOCKET;
+
+        /* cleanup the SSL context */
+    if(c->ssl) { /* SSL initialized */
+        SSL_set_shutdown(c->ssl, SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+        SSL_free(c->ssl);
+        c->ssl=NULL;
+#if OPENSSL_VERSION_NUMBER>=0x10000000L
+        ERR_remove_thread_state(NULL);
+#else /* OpenSSL version < 1.0.0 */
+        ERR_remove_state(0);
+#endif /* OpenSSL version >= 1.0.0 */
+    }
+
+        /* cleanup the remote socket */
+    if(c->remote_fd.fd!=INVALID_SOCKET) { /* remote socket initialized */
+        if(rst && c->remote_fd.is_socket) /* reset */
+            reset(c->remote_fd.fd, "linger (remote)");
+        closesocket(c->remote_fd.fd);
+        s_log(LOG_DEBUG, "Remote socket (FD=%d) closed", c->remote_fd.fd);
+        c->remote_fd.fd=INVALID_SOCKET;
+    }
+
+        /* cleanup the local socket */
+    if(c->local_rfd.fd!=INVALID_SOCKET) { /* local socket initialized */
+        if(c->local_rfd.fd==c->local_wfd.fd) {
+            if(rst && c->local_rfd.is_socket)
+                reset(c->local_rfd.fd, "linger (local)");
+            closesocket(c->local_rfd.fd);
+            s_log(LOG_DEBUG, "Local socket (FD=%d) closed", c->local_rfd.fd);
+        } else { /* stdin/stdout */
+            if(rst && c->local_rfd.is_socket)
+                reset(c->local_rfd.fd, "linger (local_rfd)");
+            if(rst && c->local_wfd.is_socket)
+                reset(c->local_wfd.fd, "linger (local_wfd)");
+        }
+        c->local_rfd.fd=c->local_wfd.fd=INVALID_SOCKET;
+    }
+
+#ifdef USE_FORK
+    /* display child return code if it managed to arrive on time */
+    /* otherwise it will be retrieved by the init process and ignored */
+    if(c->opt->exec_name) /* 'exec' specified */
+        child_status(); /* null SIGCHLD handler was used */
+    s_log(LOG_DEBUG, "Service [%s] finished", c->opt->servname);
+#else
+    enter_critical_section(CRIT_CLIENTS);
+    ui_clients(--num_clients);
+    num_clients_copy=num_clients; /* to move s_log() away from CRIT_CLIENTS */
+    leave_critical_section(CRIT_CLIENTS);
+    s_log(LOG_DEBUG, "Service [%s] finished (%ld left)",
+        c->opt->servname, num_clients_copy);
+#endif
+
+        /* free the client context */
+    str_free(c->connect_addr.addr);
+    s_poll_free(c->fds);
+    c->fds=NULL;
+}
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+
+NOEXPORT void client_try(CLI *c) {
+    local_start(c);
+    protocol(c, c->opt, PROTOCOL_EARLY);
+    if(c->opt->option.connect_before_ssl) {
+        remote_start(c);
+        protocol(c, c->opt, PROTOCOL_MIDDLE);
+        ssl_start(c);
+    } else {
+        ssl_start(c);
+        protocol(c, c->opt, PROTOCOL_MIDDLE);
+        remote_start(c);
+    }
+    protocol(c, c->opt, PROTOCOL_LATE);
+    transfer(c);
+}
+
+NOEXPORT void local_start(CLI *c) {
+    SOCKADDR_UNION addr;
+    socklen_t addr_len;
+    char *accepted_address;
+
+    /* check if local_rfd is a socket and get peer address */
+    addr_len=sizeof(SOCKADDR_UNION);
+    c->local_rfd.is_socket=!getpeername(c->local_rfd.fd, &addr.sa, &addr_len);
+    if(c->local_rfd.is_socket) {
+        memcpy(&c->peer_addr.sa, &addr.sa, (size_t)addr_len);
+        c->peer_addr_len=addr_len;
+        if(set_socket_options(c->local_rfd.fd, 1))
+            s_log(LOG_WARNING, "Failed to set local socket options");
+    } else {
+        if(get_last_socket_error()!=S_ENOTSOCK) {
+            sockerror("getpeerbyname (local_rfd)");
+            longjmp(c->err, 1);
+        }
+    }
+
+    /* check if local_wfd is a socket and get peer address */
+    if(c->local_rfd.fd==c->local_wfd.fd) {
+        c->local_wfd.is_socket=c->local_rfd.is_socket;
+    } else {
+        addr_len=sizeof(SOCKADDR_UNION);
+        c->local_wfd.is_socket=!getpeername(c->local_wfd.fd, &addr.sa, &addr_len);
+        if(c->local_wfd.is_socket) {
+            if(!c->local_rfd.is_socket) { /* already retrieved */
+                memcpy(&c->peer_addr.sa, &addr.sa, (size_t)addr_len);
+                c->peer_addr_len=addr_len;
+            }
+            if(set_socket_options(c->local_wfd.fd, 1))
+                s_log(LOG_WARNING, "Failed to set local socket options");
+        } else {
+            if(get_last_socket_error()!=S_ENOTSOCK) {
+                sockerror("getpeerbyname (local_wfd)");
+                longjmp(c->err, 1);
+            }
+        }
+    }
+
+    /* neither of local descriptors is a socket */
+    if(!c->local_rfd.is_socket && !c->local_wfd.is_socket) {
+#ifndef USE_WIN32
+        if(c->opt->option.transparent_src) {
+            s_log(LOG_ERR, "Transparent source needs a socket");
+            longjmp(c->err, 1);
+        }
+#endif
+        s_log(LOG_NOTICE, "Service [%s] accepted connection", c->opt->servname);
+        return;
+    }
+
+    /* authenticate based on retrieved IP address of the client */
+    accepted_address=s_ntop(&c->peer_addr, c->peer_addr_len);
+#ifdef USE_LIBWRAP
+    libwrap_auth(c, accepted_address);
+#endif /* USE_LIBWRAP */
+    auth_user(c, accepted_address);
+    s_log(LOG_NOTICE, "Service [%s] accepted connection from %s",
+        c->opt->servname, accepted_address);
+    str_free(accepted_address);
+}
+
+NOEXPORT void remote_start(CLI *c) {
+    /* where to bind connecting socket */
+    if(c->opt->option.local) /* outgoing interface */
+        c->bind_addr=&c->opt->source_addr;
+#ifndef USE_WIN32
+    else if(c->opt->option.transparent_src)
+        c->bind_addr=&c->peer_addr;
+#endif
+    else
+        c->bind_addr=NULL; /* don't bind */
+
+    /* setup c->remote_fd, now */
+    if(c->opt->exec_name && !c->opt->connect_addr.names)
+        c->remote_fd.fd=connect_local(c); /* not for exec+connect targets */
+    else
+        c->remote_fd.fd=connect_remote(c);
+
+    c->remote_fd.is_socket=1; /* always! */
+    s_log(LOG_DEBUG, "Remote socket (FD=%d) initialized", c->remote_fd.fd);
+    if(set_socket_options(c->remote_fd.fd, 2))
+        s_log(LOG_WARNING, "Failed to set remote socket options");
+}
+
+NOEXPORT void ssl_start(CLI *c) {
+    int i, err;
+    SSL_SESSION *old_session;
+    int unsafe_openssl;
+    X509 *peer_cert;
+
+    c->ssl=SSL_new(c->opt->ctx);
+    if(!c->ssl) {
+        sslerror("SSL_new");
+        longjmp(c->err, 1);
+    }
+    SSL_set_ex_data(c->ssl, index_cli, c); /* for callbacks */
+    if(c->opt->option.client) {
+#ifndef OPENSSL_NO_TLSEXT
+        if(c->opt->sni) {
+            s_log(LOG_INFO, "SNI: sending servername: %s", c->opt->sni);
+            if(!SSL_set_tlsext_host_name(c->ssl, c->opt->sni)) {
+                sslerror("SSL_set_tlsext_host_name");
+                longjmp(c->err, 1);
+            }
+        }
+#endif
+        if(c->opt->session) {
+            enter_critical_section(CRIT_SESSION);
+            SSL_set_session(c->ssl, c->opt->session);
+            leave_critical_section(CRIT_SESSION);
+        }
+        SSL_set_fd(c->ssl, (int)c->remote_fd.fd);
+        SSL_set_connect_state(c->ssl);
+    } else { /* SSL server */
+        if(c->local_rfd.fd==c->local_wfd.fd)
+            SSL_set_fd(c->ssl, (int)c->local_rfd.fd);
+        else {
+           /* does it make sense to have SSL on STDIN/STDOUT? */
+            SSL_set_rfd(c->ssl, (int)c->local_rfd.fd);
+            SSL_set_wfd(c->ssl, (int)c->local_wfd.fd);
+        }
+        SSL_set_accept_state(c->ssl);
+    }
+
+    unsafe_openssl=SSLeay()<0x0090810fL ||
+        (SSLeay()>=0x10000000L && SSLeay()<0x1000002fL);
+    while(1) {
+        /* critical section for OpenSSL version < 0.9.8p or 1.x.x < 1.0.0b *
+         * this critical section is a crude workaround for CVE-2010-3864   *
+         * see http://www.securityfocus.com/bid/44884 for details          *
+         * alternative solution is to disable internal session caching     *
+         * NOTE: this critical section also covers callbacks (e.g. OCSP)   */
+        if(unsafe_openssl)
+            enter_critical_section(CRIT_SSL);
+
+        if(c->opt->option.client)
+            i=SSL_connect(c->ssl);
+        else
+            i=SSL_accept(c->ssl);
+
+        if(unsafe_openssl)
+            leave_critical_section(CRIT_SSL);
+
+        err=SSL_get_error(c->ssl, i);
+        if(err==SSL_ERROR_NONE)
+            break; /* ok -> done */
+        if(err==SSL_ERROR_WANT_READ || err==SSL_ERROR_WANT_WRITE) {
+            s_poll_init(c->fds);
+            s_poll_add(c->fds, c->ssl_rfd->fd,
+                err==SSL_ERROR_WANT_READ,
+                err==SSL_ERROR_WANT_WRITE);
+            switch(s_poll_wait(c->fds, c->opt->timeout_busy, 0)) {
+            case -1:
+                sockerror("ssl_start: s_poll_wait");
+                longjmp(c->err, 1);
+            case 0:
+                s_log(LOG_INFO, "ssl_start: s_poll_wait:"
+                    " TIMEOUTbusy exceeded: sending reset");
+                longjmp(c->err, 1);
+            case 1:
+                break; /* OK */
+            default:
+                s_log(LOG_ERR, "ssl_start: s_poll_wait: unknown result");
+                longjmp(c->err, 1);
+            }
+            continue; /* ok -> retry */
+        }
+        if(err==SSL_ERROR_SYSCALL) {
+            switch(get_last_socket_error()) {
+            case S_EINTR:
+            case S_EWOULDBLOCK:
+#if S_EAGAIN!=S_EWOULDBLOCK
+            case S_EAGAIN:
+#endif
+                continue;
+            }
+        }
+        if(c->opt->option.client)
+            sslerror("SSL_connect");
+        else
+            sslerror("SSL_accept");
+        longjmp(c->err, 1);
+    }
+    s_log(LOG_INFO, "SSL %s: %s",
+        c->opt->option.client ? "connected" : "accepted",
+        SSL_session_reused(c->ssl) ?
+            "previous session reused" : "new session negotiated");
+    if(SSL_session_reused(c->ssl)) {
+        c->redirect=(uintptr_t)SSL_SESSION_get_ex_data(SSL_get_session(c->ssl),
+            index_redirect);
+        if(c->opt->redirect_addr.names && !c->redirect) {
+            s_log(LOG_ERR, "No application data found in the reused session");
+            longjmp(c->err, 1);
+        }
+    } else { /* a new session was negotiated */
+        new_chain(c);
+        peer_cert=SSL_get_peer_certificate(c->ssl);
+        if(peer_cert) /* c->redirect was set by the callback */
+            X509_free(peer_cert);
+        else if(c->opt->redirect_addr.names)
+            c->redirect=REDIRECT_ON;
+        SSL_SESSION_set_ex_data(SSL_get_session(c->ssl),
+            index_redirect, (void *)c->redirect);
+        if(c->opt->option.client) {
+            enter_critical_section(CRIT_SESSION);
+            old_session=c->opt->session;
+            c->opt->session=SSL_get1_session(c->ssl); /* store it */
+            leave_critical_section(CRIT_SESSION);
+            if(old_session)
+                SSL_SESSION_free(old_session); /* release the old one */
+        } else { /* SSL server */
+            SSL_CTX_add_session(c->opt->ctx, SSL_get_session(c->ssl));
+        }
+        print_cipher(c);
+    }
+}
+
+NOEXPORT void new_chain(CLI *c) {
+    BIO *bio;
+    int i, len;
+    X509 *peer_cert;
+    STACK_OF(X509) *sk;
+    char *chain;
+
+    if(c->opt->chain) /* already cached */
+        return; /* this race condition is safe to ignore */
+    bio=BIO_new(BIO_s_mem());
+    if(!bio)
+        return;
+    sk=SSL_get_peer_cert_chain(c->ssl);
+    for(i=0; sk && i<sk_X509_num(sk); i++) {
+        peer_cert=sk_X509_value(sk, i);
+        PEM_write_bio_X509(bio, peer_cert);
+    }
+    if(!sk || !c->opt->option.client) {
+        peer_cert=SSL_get_peer_certificate(c->ssl);
+        if(peer_cert) {
+            PEM_write_bio_X509(bio, peer_cert);
+            X509_free(peer_cert);
+        }
+    }
+    len=BIO_pending(bio);
+    if(len<=0) {
+        s_log(LOG_INFO, "No peer certificate received");
+        BIO_free(bio);
+        return;
+    }
+    /* prevent automatic deallocation of the cached value */
+    chain=str_alloc_detached((size_t)len+1);
+    len=BIO_read(bio, chain, len);
+    if(len<0) {
+        s_log(LOG_ERR, "BIO_read failed");
+        BIO_free(bio);
+        str_free(chain);
+        return;
+    }
+    chain[len]='\0';
+    BIO_free(bio);
+    c->opt->chain=chain; /* this race condition is safe to ignore */
+    ui_new_chain(c->opt->section_number);
+    s_log(LOG_DEBUG, "Peer certificate was cached (%d bytes)", len);
+}
+
+/****************************** transfer data */
+NOEXPORT void transfer(CLI *c) {
+    int watchdog=0; /* a counter to detect an infinite loop */
+    ssize_t num;
+    int err;
+    /* logical channels (not file descriptors!) open for read or write */
+    int sock_open_rd=1, sock_open_wr=1;
+    /* awaited conditions on SSL file descriptors */
+    int shutdown_wants_read=0, shutdown_wants_write=0;
+    int read_wants_read=0, read_wants_write=0;
+    int write_wants_read=0, write_wants_write=0;
+    /* actual conditions on file descriptors */
+    int sock_can_rd, sock_can_wr, ssl_can_rd, ssl_can_wr;
+#ifdef USE_WIN32
+    unsigned long bytes;
+#else
+    int bytes;
+#endif
+
+    c->sock_ptr=c->ssl_ptr=0;
+
+    do { /* main loop of client data transfer */
+        /****************************** initialize *_wants_* */
+        read_wants_read|=!(SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN)
+            && c->ssl_ptr<BUFFSIZE && !read_wants_write;
+        write_wants_write|=!(SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN)
+            && c->sock_ptr && !write_wants_read;
+
+        /****************************** setup c->fds structure */
+        s_poll_init(c->fds); /* initialize the structure */
+        /* for plain socket open data strem = open file descriptor */
+        /* make sure to add each open socket to receive exceptions! */
+        if(sock_open_rd) /* only poll if the read file descriptor is open */
+            s_poll_add(c->fds, c->sock_rfd->fd, c->sock_ptr<BUFFSIZE, 0);
+        if(sock_open_wr) /* only poll if the write file descriptor is open */
+            s_poll_add(c->fds, c->sock_wfd->fd, 0, c->ssl_ptr>0);
+        /* poll SSL file descriptors unless SSL shutdown was completed */
+        if(SSL_get_shutdown(c->ssl)!=
+                (SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN)) {
+            s_poll_add(c->fds, c->ssl_rfd->fd,
+                read_wants_read || write_wants_read || shutdown_wants_read, 0);
+            s_poll_add(c->fds, c->ssl_wfd->fd, 0,
+                read_wants_write || write_wants_write || shutdown_wants_write);
+        }
+
+        /****************************** wait for an event */
+        err=s_poll_wait(c->fds,
+            (sock_open_rd && /* both peers open */
+                !(SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN)) ||
+            c->ssl_ptr /* data buffered to write to socket */ ||
+            c->sock_ptr /* data buffered to write to SSL */ ?
+            c->opt->timeout_idle : c->opt->timeout_close, 0);
+        switch(err) {
+        case -1:
+            sockerror("transfer: s_poll_wait");
+            longjmp(c->err, 1);
+        case 0: /* timeout */
+            if((sock_open_rd &&
+                    !(SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN)) ||
+                    c->ssl_ptr || c->sock_ptr) {
+                s_log(LOG_INFO, "transfer: s_poll_wait:"
+                    " TIMEOUTidle exceeded: sending reset");
+                longjmp(c->err, 1);
+            } else { /* already closing connection */
+                s_log(LOG_ERR, "transfer: s_poll_wait:"
+                    " TIMEOUTclose exceeded: closing");
+                return; /* OK */
+            }
+        }
+
+        /****************************** retrieve results from c->fds */
+        sock_can_rd=s_poll_canread(c->fds, c->sock_rfd->fd);
+        sock_can_wr=s_poll_canwrite(c->fds, c->sock_wfd->fd);
+        ssl_can_rd=s_poll_canread(c->fds, c->ssl_rfd->fd);
+        ssl_can_wr=s_poll_canwrite(c->fds, c->ssl_wfd->fd);
+
+        /****************************** checks for internal failures */
+        /* please report any internal errors to stunnel-users mailing list */
+        if(!(sock_can_rd || sock_can_wr || ssl_can_rd || ssl_can_wr)) {
+            s_log(LOG_ERR, "INTERNAL ERROR: "
+                "s_poll_wait returned %d, but no descriptor is ready", err);
+            s_poll_dump(c->fds, LOG_ERR);
+            longjmp(c->err, 1);
+        }
+
+        if(c->reneg_state==RENEG_DETECTED && !c->opt->option.renegotiation) {
+            s_log(LOG_ERR, "Aborting due to renegotiation request");
+            longjmp(c->err, 1);
+        }
+
+        /****************************** send SSL close_notify alert */
+        if(shutdown_wants_read || shutdown_wants_write) {
+            num=SSL_shutdown(c->ssl); /* send close_notify alert */
+            if(num<0) /* -1 - not completed */
+                err=SSL_get_error(c->ssl, (int)num);
+            else /* 0 or 1 - success */
+                err=SSL_ERROR_NONE;
+            switch(err) {
+            case SSL_ERROR_NONE: /* the shutdown was successfully completed */
+                s_log(LOG_INFO, "SSL_shutdown successfully sent close_notify alert");
+                shutdown_wants_read=shutdown_wants_write=0;
+                break;
+            case SSL_ERROR_SYSCALL: /* socket error */
+                if(parse_socket_error(c, "SSL_shutdown"))
+                    break; /* a non-critical error: retry */
+                SSL_set_shutdown(c->ssl, SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+                shutdown_wants_read=shutdown_wants_write=0;
+                break;
+            case SSL_ERROR_WANT_WRITE:
+                s_log(LOG_DEBUG, "SSL_shutdown returned WANT_WRITE: retrying");
+                shutdown_wants_read=0;
+                shutdown_wants_write=1;
+                break;
+            case SSL_ERROR_WANT_READ:
+                s_log(LOG_DEBUG, "SSL_shutdown returned WANT_READ: retrying");
+                shutdown_wants_read=1;
+                shutdown_wants_write=0;
+                break;
+            case SSL_ERROR_SSL: /* SSL error */
+                sslerror("SSL_shutdown");
+                longjmp(c->err, 1);
+            default:
+                s_log(LOG_ERR, "SSL_shutdown/SSL_get_error returned %d", err);
+                longjmp(c->err, 1);
+            }
+        }
+
+        /****************************** write to socket */
+        if(sock_open_wr && sock_can_wr) {
+            num=writesocket(c->sock_wfd->fd, c->ssl_buff, c->ssl_ptr);
+            switch(num) {
+            case -1: /* error */
+                if(parse_socket_error(c, "writesocket"))
+                    break; /* a non-critical error: retry */
+                sock_open_rd=sock_open_wr=0;
+                break;
+            default:
+                memmove(c->ssl_buff, c->ssl_buff+num, c->ssl_ptr-(size_t)num);
+                c->ssl_ptr-=(size_t)num;
+                memset(c->ssl_buff+c->ssl_ptr, 0, (size_t)num); /* paranoia */
+                c->sock_bytes+=(size_t)num;
+                watchdog=0; /* reset watchdog */
+            }
+        }
+
+        /****************************** read from socket */
+        if(sock_open_rd && sock_can_rd) {
+            num=readsocket(c->sock_rfd->fd,
+                c->sock_buff+c->sock_ptr, BUFFSIZE-c->sock_ptr);
+            switch(num) {
+            case -1:
+                if(parse_socket_error(c, "readsocket"))
+                    break; /* a non-critical error: retry */
+                sock_open_rd=sock_open_wr=0;
+                break;
+            case 0: /* close */
+                s_log(LOG_INFO, "Read socket closed (readsocket)");
+                sock_open_rd=0;
+                break;
+            default:
+                c->sock_ptr+=(size_t)num;
+                watchdog=0; /* reset watchdog */
+            }
+        }
+
+        /****************************** update *_wants_* based on new *_ptr */
+        /* this update is also required for SSL_pending() to be used */
+        read_wants_read|=!(SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN)
+            && c->ssl_ptr<BUFFSIZE && !read_wants_write;
+        write_wants_write|=!(SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN)
+            && c->sock_ptr && !write_wants_read;
+
+        /****************************** write to SSL */
+        if((write_wants_read && ssl_can_rd) ||
+                (write_wants_write && ssl_can_wr)) {
+            write_wants_read=0;
+            write_wants_write=0;
+            num=SSL_write(c->ssl, c->sock_buff, (int)(c->sock_ptr));
+            switch(err=SSL_get_error(c->ssl, (int)num)) {
+            case SSL_ERROR_NONE:
+                if(num==0)
+                    s_log(LOG_DEBUG, "SSL_write returned 0");
+                memmove(c->sock_buff, c->sock_buff+num,
+                    c->sock_ptr-(size_t)num);
+                c->sock_ptr-=(size_t)num;
+                memset(c->sock_buff+c->sock_ptr, 0, (size_t)num); /* paranoia */
+                c->ssl_bytes+=(size_t)num;
+                watchdog=0; /* reset watchdog */
+                break;
+            case SSL_ERROR_WANT_WRITE: /* buffered data? */
+                s_log(LOG_DEBUG, "SSL_write returned WANT_WRITE: retrying");
+                write_wants_write=1;
+                break;
+            case SSL_ERROR_WANT_READ:
+                s_log(LOG_DEBUG, "SSL_write returned WANT_READ: retrying");
+                write_wants_read=1;
+                break;
+            case SSL_ERROR_WANT_X509_LOOKUP:
+                s_log(LOG_DEBUG,
+                    "SSL_write returned WANT_X509_LOOKUP: retrying");
+                break;
+            case SSL_ERROR_SYSCALL: /* socket error */
+                if(num && parse_socket_error(c, "SSL_write"))
+                    break; /* a non-critical error: retry */
+                /* EOF -> buggy (e.g. Microsoft) peer:
+                 * SSL socket closed without close_notify alert */
+                if(c->sock_ptr) { /* TODO: what about buffered data? */
+                    s_log(LOG_ERR,
+                        "SSL socket closed (SSL_write) with %ld unsent byte(s)",
+                        c->sock_ptr);
+                    longjmp(c->err, 1); /* reset the socket */
+                }
+                s_log(LOG_INFO, "SSL socket closed (SSL_write)");
+                SSL_set_shutdown(c->ssl, SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+                break;
+            case SSL_ERROR_ZERO_RETURN: /* close_notify alert received */
+                s_log(LOG_INFO, "SSL closed (SSL_write)");
+                if(SSL_version(c->ssl)==SSL2_VERSION)
+                    SSL_set_shutdown(c->ssl, SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+                break;
+            case SSL_ERROR_SSL:
+                sslerror("SSL_write");
+                longjmp(c->err, 1);
+            default:
+                s_log(LOG_ERR, "SSL_write/SSL_get_error returned %d", err);
+                longjmp(c->err, 1);
+            }
+        }
+
+        /****************************** read from SSL */
+        if((read_wants_read && (ssl_can_rd || SSL_pending(c->ssl))) ||
+                /* it may be possible to read some pending data after
+                 * writesocket() above made some room in c->ssl_buff */
+                (read_wants_write && ssl_can_wr)) {
+            read_wants_read=0;
+            read_wants_write=0;
+            num=SSL_read(c->ssl, c->ssl_buff+c->ssl_ptr, (int)(BUFFSIZE-c->ssl_ptr));
+            switch(err=SSL_get_error(c->ssl, (int)num)) {
+            case SSL_ERROR_NONE:
+                if(num==0)
+                    s_log(LOG_DEBUG, "SSL_read returned 0");
+                c->ssl_ptr+=(size_t)num;
+                watchdog=0; /* reset watchdog */
+                break;
+            case SSL_ERROR_WANT_WRITE:
+                s_log(LOG_DEBUG, "SSL_read returned WANT_WRITE: retrying");
+                read_wants_write=1;
+                break;
+            case SSL_ERROR_WANT_READ: /* happens quite often */
+#if 0
+                s_log(LOG_DEBUG, "SSL_read returned WANT_READ: retrying");
+#endif
+                read_wants_read=1;
+                break;
+            case SSL_ERROR_WANT_X509_LOOKUP:
+                s_log(LOG_DEBUG,
+                    "SSL_read returned WANT_X509_LOOKUP: retrying");
+                break;
+            case SSL_ERROR_SYSCALL:
+                if(num && parse_socket_error(c, "SSL_read"))
+                    break; /* a non-critical error: retry */
+                /* EOF -> buggy (e.g. Microsoft) peer:
+                 * SSL socket closed without close_notify alert */
+                if(c->sock_ptr || write_wants_write) {
+                    s_log(LOG_ERR,
+                        "SSL socket closed (SSL_read) with %ld unsent byte(s)",
+                        c->sock_ptr);
+                    longjmp(c->err, 1); /* reset the socket */
+                }
+                s_log(LOG_INFO, "SSL socket closed (SSL_read)");
+                SSL_set_shutdown(c->ssl,
+                    SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+                break;
+            case SSL_ERROR_ZERO_RETURN: /* close_notify alert received */
+                s_log(LOG_INFO, "SSL closed (SSL_read)");
+                if(SSL_version(c->ssl)==SSL2_VERSION)
+                    SSL_set_shutdown(c->ssl,
+                        SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+                break;
+            case SSL_ERROR_SSL:
+                sslerror("SSL_read");
+                longjmp(c->err, 1);
+            default:
+                s_log(LOG_ERR, "SSL_read/SSL_get_error returned %d", err);
+                longjmp(c->err, 1);
+            }
+        }
+
+        /****************************** check for hangup conditions */
+        /* http://marc.info/?l=linux-man&m=128002066306087 */
+        /* readsocket() must be the last sock_rfd operation before FIONREAD */
+        if(sock_open_rd && s_poll_rdhup(c->fds, c->sock_rfd->fd) &&
+                (ioctlsocket(c->sock_rfd->fd, FIONREAD, &bytes) || !bytes)) {
+            s_log(LOG_INFO, "Read socket closed (read hangup)");
+            sock_open_rd=0;
+        }
+        if(sock_open_wr && s_poll_hup(c->fds, c->sock_wfd->fd)) {
+            if(c->ssl_ptr) {
+                s_log(LOG_ERR,
+                    "Write socket closed (write hangup) with %ld unsent byte(s)",
+                    c->ssl_ptr);
+                longjmp(c->err, 1); /* reset the socket */
+            }
+            s_log(LOG_INFO, "Write socket closed (write hangup)");
+            sock_open_wr=0;
+        }
+        /* SSL_read() must be the last ssl_rfd operation before FIONREAD */
+        if(!(SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN) &&
+                s_poll_rdhup(c->fds, c->ssl_rfd->fd) &&
+                (ioctlsocket(c->ssl_rfd->fd, FIONREAD, &bytes) || !bytes)) {
+            /* hangup -> buggy (e.g. Microsoft) peer:
+             * SSL socket closed without close_notify alert */
+            s_log(LOG_INFO, "SSL socket closed (read hangup)");
+            SSL_set_shutdown(c->ssl,
+                SSL_get_shutdown(c->ssl)|SSL_RECEIVED_SHUTDOWN);
+        }
+        if(!(SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN) &&
+                s_poll_hup(c->fds, c->ssl_wfd->fd)) {
+            if(c->sock_ptr || write_wants_write) {
+                s_log(LOG_ERR,
+                    "SSL socket closed (write hangup) with %ld unsent byte(s)",
+                    c->sock_ptr);
+                longjmp(c->err, 1); /* reset the socket */
+            }
+            s_log(LOG_INFO, "SSL socket closed (write hangup)");
+            SSL_set_shutdown(c->ssl,
+                SSL_get_shutdown(c->ssl)|SSL_SENT_SHUTDOWN);
+        }
+
+        /****************************** check write shutdown conditions */
+        if(sock_open_wr && SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN &&
+                !c->ssl_ptr) {
+            sock_open_wr=0; /* no further write allowed */
+            if(!c->sock_wfd->is_socket) {
+                s_log(LOG_DEBUG, "Closing the file descriptor");
+                sock_open_rd=0; /* file descriptor is ready to be closed */
+            } else if(!shutdown(c->sock_wfd->fd, SHUT_WR)) { /* send TCP FIN */
+                s_log(LOG_DEBUG, "Sent socket write shutdown");
+            } else {
+                s_log(LOG_DEBUG, "Failed to send socket write shutdown");
+                sock_open_rd=0; /* file descriptor is ready to be closed */
+            }
+        }
+        if(!(SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN) && !sock_open_rd &&
+                !c->sock_ptr && !write_wants_write) {
+            if(SSL_version(c->ssl)!=SSL2_VERSION) {
+                s_log(LOG_DEBUG, "Sending close_notify alert");
+                shutdown_wants_write=1;
+            } else { /* no alerts in SSLv2, including the close_notify alert */
+                s_log(LOG_DEBUG, "Closing SSLv2 socket");
+                if(c->ssl_rfd->is_socket)
+                    shutdown(c->ssl_rfd->fd, SHUT_RD); /* notify the kernel */
+                if(c->ssl_wfd->is_socket)
+                    shutdown(c->ssl_wfd->fd, SHUT_WR); /* send TCP FIN */
+                /* notify the OpenSSL library */
+                SSL_set_shutdown(c->ssl, SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
+            }
+        }
+
+        /****************************** check watchdog */
+        if(++watchdog>100) { /* loop executes without transferring any data */
+            s_log(LOG_ERR,
+                "transfer() loop executes not transferring any data");
+            s_log(LOG_ERR,
+                "please report the problem to Michal.Trojnara@mirt.net");
+            stunnel_info(LOG_ERR);
+            s_log(LOG_ERR, "protocol=%s, SSL_pending=%d",
+                SSL_get_version(c->ssl), SSL_pending(c->ssl));
+            s_log(LOG_ERR, "sock_open_rd=%s, sock_open_wr=%s",
+                sock_open_rd ? "Y" : "n", sock_open_wr ? "Y" : "n");
+            s_log(LOG_ERR, "SSL_RECEIVED_SHUTDOWN=%s, SSL_SENT_SHUTDOWN=%s",
+                SSL_get_shutdown(c->ssl)&SSL_RECEIVED_SHUTDOWN ? "Y" : "n",
+                SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN ? "Y" : "n");
+            s_log(LOG_ERR, "sock_can_rd=%s, sock_can_wr=%s",
+                sock_can_rd ? "Y" : "n", sock_can_wr ? "Y" : "n");
+            s_log(LOG_ERR, "ssl_can_rd=%s, ssl_can_wr=%s",
+                ssl_can_rd ? "Y" : "n", ssl_can_wr ? "Y" : "n");
+            s_log(LOG_ERR, "read_wants_read=%s, read_wants_write=%s",
+                read_wants_read ? "Y" : "n", read_wants_write ? "Y" : "n");
+            s_log(LOG_ERR, "write_wants_read=%s, write_wants_write=%s",
+                write_wants_read ? "Y" : "n", write_wants_write ? "Y" : "n");
+            s_log(LOG_ERR, "shutdown_wants_read=%s, shutdown_wants_write=%s",
+                shutdown_wants_read ? "Y" : "n",
+                shutdown_wants_write ? "Y" : "n");
+            s_log(LOG_ERR, "socket input buffer: %ld byte(s), "
+                "ssl input buffer: %ld byte(s)", c->sock_ptr, c->ssl_ptr);
+            longjmp(c->err, 1);
+        }
+
+    } while(sock_open_wr || !(SSL_get_shutdown(c->ssl)&SSL_SENT_SHUTDOWN) ||
+        shutdown_wants_read || shutdown_wants_write);
+}
+
+    /* returns 0 on close and 1 on non-critical errors */
+NOEXPORT int parse_socket_error(CLI *c, const char *text) {
+    switch(get_last_socket_error()) {
+        /* http://tangentsoft.net/wskfaq/articles/bsd-compatibility.html */
+    case 0: /* close on read, or close on write on WIN32 */
+#ifndef USE_WIN32
+    case EPIPE: /* close on write on Unix */
+#endif
+    case S_ECONNABORTED:
+        s_log(LOG_INFO, "%s: Socket is closed", text);
+        return 0;
+    case S_EINTR:
+        s_log(LOG_DEBUG, "%s: Interrupted by a signal: retrying", text);
+        return 1;
+    case S_EWOULDBLOCK:
+        s_log(LOG_NOTICE, "%s: Would block: retrying", text);
+        sleep(1); /* Microsoft bug KB177346 */
+        return 1;
+#if S_EAGAIN!=S_EWOULDBLOCK
+    case S_EAGAIN:
+        s_log(LOG_DEBUG,
+            "%s: Temporary lack of resources: retrying", text);
+        return 1;
+#endif
+#ifdef USE_WIN32
+    case S_ECONNRESET:
+        /* dying "exec" processes on Win32 cause reset instead of close */
+        if(c->opt->exec_name) {
+            s_log(LOG_INFO, "%s: Socket is closed (exec)", text);
+            return 0;
+        }
+#endif
+    default:
+        sockerror(text);
+        longjmp(c->err, 1);
+        return -1; /* some C compilers require a return value */
+    }
+}
+
+NOEXPORT void print_cipher(CLI *c) { /* print negotiated cipher */
+    SSL_CIPHER *cipher;
+#ifndef OPENSSL_NO_COMP
+    const COMP_METHOD *compression, *expansion;
+#endif
+
+    if(c->opt->log_level<LOG_INFO) /* performance optimization */
+        return;
+    cipher=(SSL_CIPHER *)SSL_get_current_cipher(c->ssl);
+    s_log(LOG_INFO, "Negotiated %s ciphersuite %s (%d-bit encryption)",
+        SSL_get_version(c->ssl), SSL_CIPHER_get_name(cipher),
+        SSL_CIPHER_get_bits(cipher, NULL));
+
+#ifndef OPENSSL_NO_COMP
+    compression=SSL_get_current_compression(c->ssl);
+    expansion=SSL_get_current_expansion(c->ssl);
+    s_log(compression||expansion ? LOG_INFO : LOG_DEBUG,
+        "Compression: %s, expansion: %s",
+        compression ? SSL_COMP_get_name(compression) : "null",
+        expansion ? SSL_COMP_get_name(expansion) : "null");
+#endif
+}
+
+NOEXPORT void auth_user(CLI *c, char *accepted_address) {
+#ifndef _WIN32_WCE
+    struct servent *s_ent;    /* structure for getservbyname */
+#endif
+    SOCKADDR_UNION ident;     /* IDENT socket name */
+    char *line, *type, *system, *user;
+
+    if(!c->opt->username)
+        return; /* -u option not specified */
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    if(c->peer_addr.sa.sa_family==AF_UNIX) {
+        s_log(LOG_INFO, "IDENT not supported on Unix sockets");
+        return;
+    }
+#endif
+    c->fd=s_socket(c->peer_addr.sa.sa_family, SOCK_STREAM,
+        0, 1, "socket (auth_user)");
+    if(c->fd==INVALID_SOCKET)
+        longjmp(c->err, 1);
+    memcpy(&ident, &c->peer_addr, (size_t)c->peer_addr_len);
+#ifndef _WIN32_WCE
+    s_ent=getservbyname("auth", "tcp");
+    if(s_ent) {
+        ident.in.sin_port=(u_short)s_ent->s_port;
+    } else
+#endif
+    {
+        s_log(LOG_WARNING, "Unknown service 'auth': using default 113");
+        ident.in.sin_port=htons(113);
+    }
+    if(s_connect(c, &ident, addr_len(&ident)))
+        longjmp(c->err, 1);
+    s_log(LOG_DEBUG, "IDENT server connected");
+    fd_printf(c, c->fd, "%u , %u",
+        ntohs(c->peer_addr.in.sin_port),
+        ntohs(c->opt->local_addr.in.sin_port));
+    line=fd_getline(c, c->fd);
+    closesocket(c->fd);
+    c->fd=INVALID_SOCKET; /* avoid double close on cleanup */
+    type=strchr(line, ':');
+    if(!type) {
+        s_log(LOG_ERR, "Malformed IDENT response");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    *type++='\0';
+    system=strchr(type, ':');
+    if(!system) {
+        s_log(LOG_ERR, "Malformed IDENT response");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    *system++='\0';
+    if(strcmp(type, " USERID ")) {
+        s_log(LOG_ERR, "Incorrect INETD response type");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    user=strchr(system, ':');
+    if(!user) {
+        s_log(LOG_ERR, "Malformed IDENT response");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    *user++='\0';
+    while(*user==' ') /* skip leading spaces */
+        ++user;
+    if(strcmp(user, c->opt->username)) {
+        s_log(LOG_WARNING, "Connection from %s REFUSED by IDENT (user \"%s\")",
+            accepted_address, user);
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    s_log(LOG_INFO, "IDENT authentication passed");
+    str_free(line);
+}
+
+#if defined(_WIN32_WCE) || defined(__vms)
+
+NOEXPORT int connect_local(CLI *c) { /* spawn local process */
+    s_log(LOG_ERR, "Local mode is not supported on this platform");
+    longjmp(c->err, 1);
+    return -1; /* some C compilers require a return value */
+}
+
+#elif defined(USE_WIN32)
+
+NOEXPORT SOCKET connect_local(CLI *c) { /* spawn local process */
+    SOCKET fd[2];
+    STARTUPINFO si;
+    PROCESS_INFORMATION pi;
+    LPTSTR name, args;
+
+    if(make_sockets(fd))
+        longjmp(c->err, 1);
+    memset(&si, 0, sizeof si);
+    si.cb=sizeof si;
+    si.dwFlags=STARTF_USESHOWWINDOW|STARTF_USESTDHANDLES;
+    si.wShowWindow=SW_HIDE;
+    si.hStdInput=si.hStdOutput=si.hStdError=(HANDLE)fd[1];
+    memset(&pi, 0, sizeof pi);
+
+    name=str2tstr(c->opt->exec_name);
+    args=str2tstr(c->opt->exec_args);
+    CreateProcess(name, args, NULL, NULL, TRUE, 0, NULL, NULL, &si, &pi);
+    str_free(name);
+    str_free(args);
+
+    closesocket(fd[1]);
+    CloseHandle(pi.hProcess);
+    CloseHandle(pi.hThread);
+    return fd[0];
+}
+
+#else /* standard Unix version */
+
+NOEXPORT SOCKET connect_local(CLI *c) { /* spawn local process */
+    char *name, host[40], port[6];
+    int fd[2], pid;
+    X509 *peer_cert;
+#ifdef HAVE_PTHREAD_SIGMASK
+    sigset_t newmask;
+#endif
+
+    if(c->opt->option.pty) {
+        char tty[64];
+
+        if(pty_allocate(fd, fd+1, tty))
+            longjmp(c->err, 1);
+        s_log(LOG_DEBUG, "TTY=%s allocated", tty);
+    } else
+        if(make_sockets(fd))
+            longjmp(c->err, 1);
+
+    pid=fork();
+    c->pid=(unsigned long)pid;
+    switch(pid) {
+    case -1:    /* error */
+        closesocket(fd[0]);
+        closesocket(fd[1]);
+        ioerror("fork");
+        longjmp(c->err, 1);
+    case  0:    /* child */
+        tls_alloc(NULL, c->tls, NULL); /* reuse thread-local storage */
+        closesocket(fd[0]);
+        set_nonblock(fd[1], 0); /* switch back to blocking mode */
+        /* dup2() does not copy FD_CLOEXEC flag */
+        dup2(fd[1], 0);
+        dup2(fd[1], 1);
+        if(!global_options.option.foreground)
+            dup2(fd[1], 2);
+        closesocket(fd[1]); /* not really needed due to FD_CLOEXEC */
+
+        if(!getnameinfo(&c->peer_addr.sa, c->peer_addr_len,
+                host, 40, port, 6, NI_NUMERICHOST|NI_NUMERICSERV)) {
+            /* just don't set these variables if getnameinfo() fails */
+            putenv(str_printf("REMOTE_HOST=%s", host));
+            putenv(str_printf("REMOTE_PORT=%s", port));
+            if(c->opt->option.transparent_src) {
+#ifndef LIBDIR
+#define LIBDIR "."
+#endif
+#ifdef MACH64
+                putenv("LD_PRELOAD_32=" LIBDIR "/libstunnel.so");
+                putenv("LD_PRELOAD_64=" LIBDIR "/" MACH64 "/libstunnel.so");
+#elif __osf /* for Tru64 _RLD_LIST is used instead */
+                putenv("_RLD_LIST=" LIBDIR "/libstunnel.so:DEFAULT");
+#else
+                putenv("LD_PRELOAD=" LIBDIR "/libstunnel.so");
+#endif
+            }
+        }
+
+        if(c->ssl) {
+            peer_cert=SSL_get_peer_certificate(c->ssl);
+            if(peer_cert) {
+                name=X509_NAME2text(X509_get_subject_name(peer_cert));
+                putenv(str_printf("SSL_CLIENT_DN=%s", name));
+                name=X509_NAME2text(X509_get_issuer_name(peer_cert));
+                putenv(str_printf("SSL_CLIENT_I_DN=%s", name));
+                X509_free(peer_cert);
+            }
+        }
+#ifdef HAVE_PTHREAD_SIGMASK
+        sigemptyset(&newmask);
+        sigprocmask(SIG_SETMASK, &newmask, NULL);
+#endif
+        signal(SIGCHLD, SIG_DFL);
+        signal(SIGHUP, SIG_DFL);
+        signal(SIGUSR1, SIG_DFL);
+        signal(SIGPIPE, SIG_DFL);
+        signal(SIGTERM, SIG_DFL);
+        signal(SIGQUIT, SIG_DFL);
+        signal(SIGINT, SIG_DFL);
+        execvp(c->opt->exec_name, c->opt->exec_args);
+        ioerror(c->opt->exec_name); /* execvp failed */
+        _exit(1);
+    default: /* parent */
+        s_log(LOG_INFO, "Local mode child started (PID=%lu)", c->pid);
+        closesocket(fd[1]);
+        return fd[0];
+    }
+}
+
+#endif /* not USE_WIN32 or __vms */
+
+/* connect remote host */
+NOEXPORT SOCKET connect_remote(CLI *c) {
+    SOCKET fd;
+    unsigned ind_start, ind_try, ind_cur;
+
+    setup_connect_addr(c);
+    switch(c->connect_addr.num) {
+    case 0:
+        s_log(LOG_ERR, "No remote host resolved");
+        longjmp(c->err, 1);
+    case 1:
+        ind_start=0;
+        break;
+    default:
+        ind_start=connect_index(c);
+    }
+
+    /* try to connect each host from the list */
+    for(ind_try=0; ind_try<c->connect_addr.num; ind_try++) {
+        ind_cur=(ind_start+ind_try)%c->connect_addr.num;
+        c->fd=s_socket(c->connect_addr.addr[ind_cur].sa.sa_family,
+            SOCK_STREAM, 0, 1, "remote socket");
+        if(c->fd==INVALID_SOCKET)
+            longjmp(c->err, 1);
+
+        local_bind(c); /* explicit local bind or transparent proxy */
+
+        if(s_connect(c, &c->connect_addr.addr[ind_cur],
+                addr_len(&c->connect_addr.addr[ind_cur]))) {
+            closesocket(c->fd);
+            c->fd=INVALID_SOCKET;
+            continue; /* next IP */
+        }
+        if(c->ssl)
+            connect_cache(SSL_get_session(c->ssl),
+                &c->connect_addr.addr[ind_cur]);
+        print_bound_address(c);
+        fd=c->fd;
+        c->fd=INVALID_SOCKET;
+        return fd; /* success! */
+    }
+    longjmp(c->err, 1);
+    return INVALID_SOCKET; /* some C compilers require a return value */
+}
+
+NOEXPORT void connect_cache(SSL_SESSION *sess, SOCKADDR_UNION *cur_addr) {
+    SOCKADDR_UNION *old_addr, *new_addr;
+    socklen_t len;
+    char *addr_txt;
+
+    /* make a copy of the address, so it may work with delayed resolver */
+    len=addr_len(cur_addr);
+    new_addr=str_alloc_detached((size_t)len);
+    memcpy(new_addr, cur_addr, (size_t)len);
+
+    addr_txt=s_ntop(cur_addr, len);
+    s_log(LOG_INFO, "persistence: %s cached", addr_txt);
+    str_free(addr_txt);
+
+    enter_critical_section(CRIT_ADDR);
+    old_addr=SSL_SESSION_get_ex_data(sess, index_addr);
+    SSL_SESSION_set_ex_data(sess, index_addr, new_addr);
+    leave_critical_section(CRIT_ADDR);
+    str_free(old_addr); /* NULL pointers are ignored */
+}
+
+NOEXPORT unsigned connect_index(CLI *c) {
+    unsigned i;
+    SOCKADDR_UNION addr, *ptr;
+    socklen_t len;
+    char *addr_txt;
+
+    if(c->ssl && SSL_session_reused(c->ssl)) {
+        enter_critical_section(CRIT_ADDR);
+        ptr=SSL_SESSION_get_ex_data(SSL_get_session(c->ssl), index_addr);
+        if(ptr) {
+            len=addr_len(ptr);
+            memcpy(&addr, ptr, (size_t)len);
+            leave_critical_section(CRIT_ADDR);
+            /* address was copied, ptr itself is no longer valid */
+            for(i=0; i<c->connect_addr.num; ++i) {
+                if(addr_len(&c->connect_addr.addr[i])==len &&
+                        !memcmp(&c->connect_addr.addr[i],
+                            &addr, (size_t)len)) {
+                    addr_txt=s_ntop(&addr, len);
+                    s_log(LOG_INFO, "persistence: %s reused", addr_txt);
+                    str_free(addr_txt);
+                    return i;
+                }
+            }
+            addr_txt=s_ntop(&addr, len);
+            s_log(LOG_INFO, "persistence: %s not available", addr_txt);
+            str_free(addr_txt);
+        } else {
+            leave_critical_section(CRIT_ADDR);
+            s_log(LOG_NOTICE, "persistence: No cached address found");
+        }
+    }
+
+    if(c->opt->failover==FAILOVER_RR) {
+        /* the race condition here can be safely ignored */
+        i=*c->connect_addr.rr_ptr;
+        *c->connect_addr.rr_ptr=(i+1)%c->connect_addr.num;
+        s_log(LOG_INFO, "failover: round-robin, starting at entry #%d", i);
+    } else {
+        i=0;
+        s_log(LOG_INFO, "failover: priority, starting at entry #0");
+    }
+    return i;
+}
+
+NOEXPORT void setup_connect_addr(CLI *c) {
+#ifdef SO_ORIGINAL_DST
+    socklen_t addrlen=sizeof(SOCKADDR_UNION);
+#endif /* SO_ORIGINAL_DST */
+
+    /* process "redirect" first */
+    if(c->redirect==REDIRECT_ON) {
+        s_log(LOG_NOTICE, "Redirecting connection");
+        /* c->connect_addr.addr may be allocated in protocol negotiations */
+        str_free(c->connect_addr.addr);
+        addrlist_dup(&c->connect_addr, &c->opt->redirect_addr);
+        return;
+    }
+
+    /* check if the address was already set in protocol negotiations */
+    /* used by the following protocols: CONNECT, SOCKS */
+    if(c->connect_addr.num)
+        return;
+
+    /* transparent destination */
+#ifdef SO_ORIGINAL_DST
+    if(c->opt->option.transparent_dst) {
+        c->connect_addr.num=1;
+        c->connect_addr.addr=str_alloc(sizeof(SOCKADDR_UNION));
+        if(getsockopt(c->local_rfd.fd, SOL_IP, SO_ORIGINAL_DST,
+                c->connect_addr.addr, &addrlen)) {
+            sockerror("setsockopt SO_ORIGINAL_DST");
+            longjmp(c->err, 1);
+        }
+        return;
+    }
+#endif /* SO_ORIGINAL_DST */
+
+    /* default "connect" target */
+    addrlist_dup(&c->connect_addr, &c->opt->connect_addr);
+}
+
+NOEXPORT void local_bind(CLI *c) {
+#ifndef USE_WIN32
+    int on;
+
+    on=1;
+#endif
+    if(!c->bind_addr)
+        return;
+#if defined(USE_WIN32)
+    /* do nothing */
+#elif defined(__linux__)
+    /* non-local bind on Linux */
+    if(c->opt->option.transparent_src) {
+        if(setsockopt(c->fd, SOL_IP, IP_TRANSPARENT, &on, sizeof on)) {
+            sockerror("setsockopt IP_TRANSPARENT");
+            if(setsockopt(c->fd, SOL_IP, IP_FREEBIND, &on, sizeof on))
+                sockerror("setsockopt IP_FREEBIND");
+            else
+                s_log(LOG_INFO, "IP_FREEBIND socket option set");
+        } else
+            s_log(LOG_INFO, "IP_TRANSPARENT socket option set");
+        /* ignore the error to retain Linux 2.2 compatibility */
+        /* the error will be handled by bind(), anyway */
+    }
+#elif defined(IP_BINDANY) && defined(IPV6_BINDANY)
+    /* non-local bind on FreeBSD */
+    if(c->opt->option.transparent_src) {
+        if(c->bind_addr->sa.sa_family==AF_INET) { /* IPv4 */
+            if(setsockopt(c->fd, IPPROTO_IP, IP_BINDANY, &on, sizeof on)) {
+                sockerror("setsockopt IP_BINDANY");
+                longjmp(c->err, 1);
+            }
+        } else { /* IPv6 */
+            if(setsockopt(c->fd, IPPROTO_IPV6, IPV6_BINDANY, &on, sizeof on)) {
+                sockerror("setsockopt IPV6_BINDANY");
+                longjmp(c->err, 1);
+            }
+        }
+    }
+#else
+    /* unsupported platform */
+    if(c->opt->option.transparent_src) {
+        s_log(LOG_ERR, "Transparent proxy in remote mode is not supported"
+            " on this platform");
+        longjmp(c->err, 1);
+    }
+#endif
+
+    if(ntohs(c->bind_addr->in.sin_port)>=1024) { /* security check */
+        /* this is currently only possible with transparent_src */
+        if(!bind(c->fd, &c->bind_addr->sa, addr_len(c->bind_addr))) {
+            s_log(LOG_INFO, "local_bind succeeded on the original port");
+            return; /* success */
+        }
+        if(get_last_socket_error()!=S_EADDRINUSE) {
+            sockerror("local_bind (original port)");
+            longjmp(c->err, 1);
+        }
+    }
+
+    c->bind_addr->in.sin_port=htons(0); /* retry with ephemeral port */
+    if(!bind(c->fd, &c->bind_addr->sa, addr_len(c->bind_addr))) {
+        s_log(LOG_INFO, "local_bind succeeded on an ephemeral port");
+        return; /* success */
+    }
+    sockerror("local_bind (ephemeral port)");
+    longjmp(c->err, 1);
+}
+
+NOEXPORT void print_bound_address(CLI *c) {
+    char *txt;
+    SOCKADDR_UNION addr;
+    socklen_t addrlen=sizeof addr;
+
+    if(c->opt->log_level<LOG_NOTICE) /* performance optimization */
+        return;
+    memset(&addr, 0, (size_t)addrlen);
+    if(getsockname(c->fd, (struct sockaddr *)&addr, &addrlen)) {
+        sockerror("getsockname");
+        return;
+    }
+    txt=s_ntop(&addr, addrlen);
+    s_log(LOG_NOTICE,"Service [%s] connected remote server from %s",
+        c->opt->servname, txt);
+    str_free(txt);
+}
+
+NOEXPORT void reset(SOCKET fd, char *txt) { /* set lingering on a socket */
+    struct linger l;
+
+    l.l_onoff=1;
+    l.l_linger=0;
+    if(setsockopt(fd, SOL_SOCKET, SO_LINGER, (void *)&l, sizeof l))
+        log_error(LOG_DEBUG, get_last_socket_error(), txt);
+}
+
+/* end of client.c */
diff --git a/src/common.h b/src/common.h
new file mode 100644
index 0000000..f47c98d
--- /dev/null
+++ b/src/common.h
@@ -0,0 +1,517 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ * 
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ * 
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ * 
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ * 
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ * 
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#ifndef COMMON_H
+#define COMMON_H
+
+#include "version.h"
+
+/**************************************** common constants */
+
+#define LIBWRAP_CLIENTS 5
+
+/* CPU stack size */
+#define DEFAULT_STACK_SIZE 65536
+/* #define DEBUG_STACK_SIZE */
+
+/* I/O buffer size: 18432 (0x4800) is the maximum size of SSL record payload */
+#define BUFFSIZE 18432
+
+/* how many bytes of random input to read from files for PRNG */
+/* OpenSSL likes at least 128 bits, so 64 bytes seems plenty. */
+#define RANDOM_BYTES 64
+
+/* for FormatGuard */
+/* #define __NO_FORMATGUARD_ */
+
+/* additional diagnostic messages */
+/* #define DEBUG_FD_ALLOC */
+
+#ifdef DEBUG_INFO
+#define NOEXPORT
+#else
+#define NOEXPORT static
+#endif
+
+/**************************************** platform */
+
+#ifdef _WIN32
+#define USE_WIN32
+#endif
+
+#ifdef _WIN32_WCE
+#define USE_WIN32
+typedef int                 socklen_t;
+#endif
+
+#ifdef USE_WIN32
+typedef signed   char       int8_t;
+typedef signed   short      int16_t;
+typedef signed   int        int32_t;
+typedef signed   long long  int64_t;
+typedef unsigned char       uint8_t;
+typedef unsigned short      uint16_t;
+typedef unsigned int        uint32_t;
+typedef unsigned long long  uint64_t;
+#ifndef __MINGW32__
+#ifdef  _WIN64
+typedef __int64             ssize_t;
+#else
+typedef int                 ssize_t;
+#endif
+#endif
+#define USE_IPv6
+#define _CRT_SECURE_NO_DEPRECATE
+#define _CRT_NONSTDC_NO_DEPRECATE
+#define _CRT_NON_CONFORMING_SWPRINTFS
+#define HAVE_OSSL_ENGINE_H
+#define HAVE_OSSL_OCSP_H
+/* prevent including wincrypt.h, as it defines its own OCSP_RESPONSE */
+#define __WINCRYPT_H__
+#define S_EADDRINUSE  WSAEADDRINUSE
+/* winsock does not define WSAEAGAIN */
+/* in most (but not all!) BSD implementations EAGAIN==EWOULDBLOCK */
+#define S_EAGAIN        WSAEWOULDBLOCK
+#define S_ECONNRESET    WSAECONNRESET
+#define S_EINPROGRESS   WSAEINPROGRESS
+#define S_EINTR         WSAEINTR
+#define S_EINVAL        WSAEINVAL
+#define S_EISCONN       WSAEISCONN
+#define S_EMFILE        WSAEMFILE
+/* winsock does not define WSAENFILE */
+#define S_ENOBUFS       WSAENOBUFS
+/* winsock does not define WSAENOMEM */
+#define S_ENOPROTOOPT   WSAENOPROTOOPT
+#define S_ENOTSOCK      WSAENOTSOCK
+#define S_EOPNOTSUPP    WSAEOPNOTSUPP
+#define S_EWOULDBLOCK   WSAEWOULDBLOCK
+#define S_ECONNABORTED  WSAECONNABORTED
+#else /* USE_WIN32 */
+#define S_EADDRINUSE    EADDRINUSE
+#define S_EAGAIN        EAGAIN
+#define S_ECONNRESET    ECONNRESET
+#define S_EINPROGRESS   EINPROGRESS
+#define S_EINTR         EINTR
+#define S_EINVAL        EINVAL
+#define S_EISCONN       EISCONN
+#define S_EMFILE        EMFILE
+#ifdef ENFILE
+#define S_ENFILE        ENFILE
+#endif
+#ifdef ENOBUFS
+#define S_ENOBUFS       ENOBUFS
+#endif
+#ifdef ENOMEM
+#define S_ENOMEM        ENOMEM
+#endif
+#define S_ENOPROTOOPT   ENOPROTOOPT
+#define S_ENOTSOCK      ENOTSOCK
+#define S_EOPNOTSUPP    EOPNOTSUPP
+#define S_EWOULDBLOCK   EWOULDBLOCK
+#define S_ECONNABORTED  ECONNABORTED
+#endif /* USE_WIN32 */
+
+/**************************************** generic headers */
+
+#ifdef __vms
+#include <starlet.h>
+#endif /* __vms */
+
+/* for nsr-tandem-nsk architecture */
+#ifdef __TANDEM
+#include <floss.h>
+#endif
+
+/* threads model */
+#ifdef USE_UCONTEXT
+#define __MAKECONTEXT_V2_SOURCE
+#include <ucontext.h>
+#endif
+
+#ifdef USE_PTHREAD
+#ifndef THREADS
+#define THREADS
+#endif
+#ifndef _REENTRANT
+/* _REENTRANT is required for thread-safe errno on Solaris */
+#define _REENTRANT
+#endif
+#ifndef _THREAD_SAFE
+#define _THREAD_SAFE
+#endif
+#include <pthread.h>
+#endif
+
+/* systemd */
+#ifdef USE_SYSTEMD
+#include <systemd/sd-daemon.h>
+#endif
+
+#ifdef HAVE_STDINT_H
+#include <stdint.h>
+#endif
+
+#ifdef HAVE_INTTYPES_H
+#include <inttypes.h>
+#endif
+
+/* must be included before sys/stat.h for Ultrix */
+/* must be included before sys/socket.h for OpenBSD */
+#include <sys/types.h>   /* u_short, u_long */
+/* general headers */
+#include <stdio.h>
+/* must be included before sys/stat.h for Ultrix */
+#ifndef _WIN32_WCE
+#include <errno.h>
+#endif
+#include <stdlib.h>
+#include <stdarg.h>      /* va_ */
+#include <string.h>
+#include <ctype.h>       /* isalnum */
+#include <time.h>
+#include <sys/stat.h>    /* stat */
+#include <setjmp.h>
+#include <fcntl.h>
+
+/**************************************** WIN32 headers */
+
+#ifdef USE_WIN32
+
+#define HAVE_STRUCT_ADDRINFO
+#define HAVE_SNPRINTF
+#define snprintf                    _snprintf
+#define HAVE_VSNPRINTF
+#define vsnprintf                   _vsnprintf
+#define strcasecmp                  _stricmp
+#define strncasecmp                 _strnicmp
+#define sleep(c)                    Sleep(1000*(c))
+
+#define get_last_socket_error()     WSAGetLastError()
+#define set_last_socket_error(e)    WSASetLastError(e)
+#define get_last_error()            GetLastError()
+#define set_last_error(e)           SetLastError(e)
+#define readsocket(s,b,n)           recv((s),(b),(int)(n),0)
+#define writesocket(s,b,n)          send((s),(b),(int)(n),0)
+
+/* #define Win32_Winsock */
+#define __USE_W32_SOCKETS
+
+/* Winsock2 header for IPv6 definitions */
+#include <winsock2.h>
+#include <ws2tcpip.h>
+
+#include <windows.h>
+
+#include <process.h>     /* _beginthread */
+#include <shlobj.h>      /* SHGetFolderPath */
+#include <tchar.h>
+
+#include "resources.h"
+
+/**************************************** non-WIN32 headers */
+
+#else /* USE_WIN32 */
+
+#ifdef __INNOTEK_LIBC__
+#define socklen_t                   __socklen_t
+#define strcasecmp                  stricmp
+#define strncasecmp                 strnicmp
+#define NI_NUMERICHOST              1
+#define NI_NUMERICSERV              2
+#define get_last_socket_error()     sock_errno()
+#define set_last_socket_error(e)    ()
+#define get_last_error()            errno
+#define set_last_error(e)           (errno=(e))
+#define readsocket(s,b,n)           recv((s),(b),(n),0)
+#define writesocket(s,b,n)          send((s),(b),(n),0)
+#define closesocket(s)              close(s)
+#define ioctlsocket(a,b,c)          so_ioctl((a),(b),(c))
+#else
+#define get_last_socket_error()     errno
+#define set_last_socket_error(e)    (errno=(e))
+#define get_last_error()            errno
+#define set_last_error(e)           (errno=(e))
+#define readsocket(s,b,n)           read((s),(b),(n))
+#define writesocket(s,b,n)          write((s),(b),(n))
+#define closesocket(s)              close(s)
+#define ioctlsocket(a,b,c)          ioctl((a),(b),(c))
+#endif
+
+typedef int SOCKET;
+#define INVALID_SOCKET (-1)
+
+    /* OpenVMS compatibility */
+#ifdef __vms
+#define LIBDIR "__NA__"
+#ifdef __alpha
+#define HOST "alpha-openvms"
+#else
+#define HOST "vax-openvms"
+#endif
+#include <inet.h>
+#include <unistd.h>
+#else   /* __vms */
+#include <syslog.h>
+#endif  /* __vms */
+
+    /* Unix-specific headers */
+#include <signal.h>         /* signal */
+#include <sys/wait.h>       /* wait */
+#ifdef HAVE_SYS_RESOURCE_H
+#include <sys/resource.h>   /* getrlimit */
+#endif
+#ifdef HAVE_UNISTD_H
+#include <unistd.h>         /* getpid, fork, execvp, exit */
+#endif
+#ifdef HAVE_STROPTS_H
+#include <stropts.h>
+#endif
+#ifdef HAVE_MALLOC_H
+#include <malloc.h>         /* mallopt */
+#endif
+#ifdef HAVE_SYS_SELECT_H
+#include <sys/select.h>     /* for aix */
+#endif
+#include <dirent.h>
+
+#if defined(HAVE_POLL) && !defined(BROKEN_POLL)
+#ifdef HAVE_POLL_H
+#include <poll.h>
+#define USE_POLL
+#else /* HAVE_POLL_H */
+#ifdef HAVE_SYS_POLL_H
+#include <sys/poll.h>
+#define USE_POLL
+#endif /* HAVE_SYS_POLL_H */
+#endif /* HAVE_POLL_H */
+#endif /* HAVE_POLL && !BROKEN_POLL */
+
+#ifdef HAVE_SYS_FILIO_H
+#include <sys/filio.h>   /* for FIONBIO */
+#endif
+#include <pwd.h>
+#ifdef HAVE_GRP_H
+#include <grp.h>
+#endif
+#ifdef __BEOS__
+#include <posix/grp.h>
+#endif
+
+#ifdef HAVE_SYS_UIO_H
+#include <sys/uio.h>    /* struct iovec */
+#endif /* HAVE_SYS_UIO_H */
+
+/* BSD sockets */
+#include <netinet/in.h>  /* struct sockaddr_in */
+#include <sys/socket.h>  /* getpeername */
+#include <arpa/inet.h>   /* inet_ntoa */
+#include <sys/time.h>    /* select */
+#include <sys/ioctl.h>   /* ioctl */
+#ifdef HAVE_SYS_UN_H
+#include <sys/un.h>
+#endif
+#include <netinet/tcp.h>
+#include <netdb.h>
+#ifndef INADDR_ANY
+#define INADDR_ANY       (u32)0x00000000
+#endif
+#ifndef INADDR_LOOPBACK
+#define INADDR_LOOPBACK  (u32)0x7F000001
+#endif
+
+#if defined(HAVE_WAITPID)
+/* for SYSV systems */
+#define wait_for_pid(a, b, c) waitpid((a), (b), (c))
+#define HAVE_WAIT_FOR_PID 1
+#elif defined(HAVE_WAIT4)
+/* for BSD systems */
+#define wait_for_pid(a, b, c) wait4((a), (b), (c), NULL)
+#define HAVE_WAIT_FOR_PID 1
+#endif
+
+/* SunOS 4 */
+#if defined(sun) && !defined(__svr4__) && !defined(__SVR4)
+#define atexit(a) on_exit((a), NULL)
+extern int sys_nerr;
+extern char *sys_errlist[];
+#define strerror(num) ((num)==0 ? "No error" : \
+    ((num)>=sys_nerr ? "Unknown error" : sys_errlist[num]))
+#endif /* SunOS 4 */
+
+/* AIX does not have SOL_TCP defined */
+#ifndef SOL_TCP
+#define SOL_TCP SOL_SOCKET
+#endif /* SOL_TCP */
+
+/* Linux */
+#ifdef __linux__
+#ifndef IP_FREEBIND
+/* kernel headers without IP_FREEBIND definition */
+#define IP_FREEBIND 15
+#endif /* IP_FREEBIND */
+#ifndef IP_TRANSPARENT
+/* kernel headers without IP_TRANSPARENT definition */
+#define IP_TRANSPARENT 19
+#endif /* IP_TRANSPARENT */
+#ifdef HAVE_LINUX_NETFILTER_IPV4_H
+#include <limits.h>
+#include <linux/types.h>
+#include <linux/netfilter_ipv4.h>
+#endif /* HAVE_LINUX_NETFILTER_IPV4_H */
+#endif /* __linux__ */
+#ifdef HAVE_SYS_SYSCALL_H
+#include <sys/syscall.h> /* SYS_gettid */
+#endif
+#ifdef HAVE_LINUX_SCHED_H
+#include <linux/sched.h> /* SCHED_BATCH */
+#endif
+
+#endif /* USE_WIN32 */
+
+#ifndef S_ISREG
+#define S_ISREG(m) (((m)&S_IFMT)==S_IFREG)
+#endif
+
+/**************************************** OpenSSL headers */
+
+#define OPENSSL_THREAD_DEFINES
+#include <openssl/opensslconf.h>
+/* opensslv.h requires prior opensslconf.h to include -fips in version string */
+#include <openssl/opensslv.h>
+
+#if OPENSSL_VERSION_NUMBER<0x0090700fL
+#error OpenSSL 0.9.7 or later is required
+#endif /* OpenSSL older than 0.9.7 */
+
+#if defined(USE_PTHREAD) && !defined(OPENSSL_THREADS)
+#error OpenSSL library compiled without thread support
+#endif /* !OPENSSL_THREADS && USE_PTHREAD */
+
+#if OPENSSL_VERSION_NUMBER<0x0090800fL
+#define OPENSSL_NO_ECDH
+#define OPENSSL_NO_COMP
+#endif /* OpenSSL older than 0.9.8 */
+
+/* non-blocking OCSP API is not available before OpenSSL 0.9.8h */
+#if OPENSSL_VERSION_NUMBER<0x00908080L
+#ifndef OPENSSL_NO_OCSP
+#define OPENSSL_NO_OCSP
+#endif /* !defined(OPENSSL_NO_OCSP) */
+#endif /* OpenSSL older than 0.9.8h */
+
+#if OPENSSL_VERSION_NUMBER<0x10000000L
+#define OPENSSL_NO_TLSEXT
+#define OPENSSL_NO_PSK
+#endif /* OpenSSL older than 1.0.0 */
+
+#if OPENSSL_VERSION_NUMBER<0x10001000L || defined(OPENSSL_NO_TLS1)
+#define OPENSSL_NO_TLS1_1
+#define OPENSSL_NO_TLS1_2
+#endif /* OpenSSL older than 1.0.1 || defined(OPENSSL_NO_TLS1) */
+
+#if OPENSSL_VERSION_NUMBER>=0x10100000L
+#ifndef OPENSSL_NO_SSL2
+#define OPENSSL_NO_SSL2
+#endif /* !defined(OPENSSL_NO_SSL2) */
+#endif /* OpenSSL 1.1.0 or newer */
+
+#if !defined(HAVE_OSSL_ENGINE_H) && !defined(OPENSSL_NO_ENGINE)
+#define OPENSSL_NO_ENGINE
+#endif /* !defined(HAVE_OSSL_ENGINE_H) && !defined(OPENSSL_NO_ENGINE) */
+
+#if !defined(HAVE_OSSL_OCSP_H) && !defined(OPENSSL_NO_OCSP)
+#define OPENSSL_NO_OCSP
+#endif /* !defined(HAVE_OSSL_OCSP_H) && !defined(OPENSSL_NO_OCSP) */
+
+#if defined(USE_WIN32) && defined(OPENSSL_FIPS)
+#define USE_FIPS
+#endif
+
+#include <openssl/lhash.h>
+#include <openssl/ssl.h>
+#include <openssl/ssl23.h>
+#include <openssl/ui.h>
+#include <openssl/err.h>
+#include <openssl/crypto.h> /* for CRYPTO_* and SSLeay_version */
+#include <openssl/rand.h>
+#include <openssl/bn.h>
+#ifndef OPENSSL_NO_MD4
+#include <openssl/md4.h>
+#endif /* !defined(OPENSSL_NO_MD4) */
+#include <openssl/des.h>
+#ifndef OPENSSL_NO_DH
+#include <openssl/dh.h>
+#endif /* !defined(OPENSSL_NO_DH) */
+#ifndef OPENSSL_NO_ENGINE
+#include <openssl/engine.h>
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+#ifndef OPENSSL_NO_OCSP
+#include <openssl/ocsp.h>
+#endif /* !defined(OPENSSL_NO_OCSP) */
+#ifndef OPENSSL_NO_COMP
+/* not defined in public headers before OpenSSL 0.9.8 */
+STACK_OF(SSL_COMP) *SSL_COMP_get_compression_methods(void);
+#endif /* !defined(OPENSSL_NO_COMP) */
+
+/**************************************** other defines */
+
+/* always use IPv4 defaults! */
+#define DEFAULT_LOOPBACK "127.0.0.1"
+#define DEFAULT_ANY "0.0.0.0"
+#if 0
+#define DEFAULT_LOOPBACK "::1"
+#define DEFAULT_ANY "::"
+#endif
+
+#if defined (USE_WIN32) || defined (__vms)
+#define LOG_EMERG       0
+#define LOG_ALERT       1
+#define LOG_CRIT        2
+#define LOG_ERR         3
+#define LOG_WARNING     4
+#define LOG_NOTICE      5
+#define LOG_INFO        6
+#define LOG_DEBUG       7
+#endif /* defined (USE_WIN32) || defined (__vms) */
+
+#ifndef offsetof
+#define offsetof(T, F) ((unsigned)((char *)&((T *)0L)->F - (char *)0L))
+#endif
+
+#endif /* defined COMMON_H */
+
+/* end of common.h */
diff --git a/src/config.h.in b/src/config.h.in
new file mode 100644
index 0000000..1d5443e
--- /dev/null
+++ b/src/config.h.in
@@ -0,0 +1,335 @@
+/* src/config.h.in.  Generated from configure.ac by autoheader.  */
+
+/* Define to 1 if you have a broken 'poll' implementation. */
+#undef BROKEN_POLL
+
+/* Entropy Gathering Daemon socket path */
+#undef EGD_SOCKET
+
+/* Define to 1 if you have the `accept4' function. */
+#undef HAVE_ACCEPT4
+
+/* Define to 1 if you have the `chroot' function. */
+#undef HAVE_CHROOT
+
+/* Define to 1 if you have the `daemon' function. */
+#undef HAVE_DAEMON
+
+/* Define to 1 if you have '/dev/ptmx' device. */
+#undef HAVE_DEV_PTMX
+
+/* Define to 1 if you have '/dev/ptc' device. */
+#undef HAVE_DEV_PTS_AND_PTC
+
+/* Define to 1 if you have the <dlfcn.h> header file. */
+#undef HAVE_DLFCN_H
+
+/* Define to 1 if you have the `endhostent' function. */
+#undef HAVE_ENDHOSTENT
+
+/* Define to 1 if you have the `FIPS_mode_set' function. */
+#undef HAVE_FIPS_MODE_SET
+
+/* Define to 1 if you have 'getaddrinfo' function. */
+#undef HAVE_GETADDRINFO
+
+/* Define to 1 if you have the `getcontext' function. */
+#undef HAVE_GETCONTEXT
+
+/* Define to 1 if you have the `gethostbyname2' function. */
+#undef HAVE_GETHOSTBYNAME2
+
+/* Define to 1 if you have the `getnameinfo' function. */
+#undef HAVE_GETNAMEINFO
+
+/* Define to 1 if you have the `getrlimit' function. */
+#undef HAVE_GETRLIMIT
+
+/* Define to 1 if you have the <grp.h> header file. */
+#undef HAVE_GRP_H
+
+/* Define to 1 if you have the <inttypes.h> header file. */
+#undef HAVE_INTTYPES_H
+
+/* Define to 1 if you have the <libutil.h> header file. */
+#undef HAVE_LIBUTIL_H
+
+/* Define to 1 if you have the <linux/netfilter_ipv4.h> header file. */
+#undef HAVE_LINUX_NETFILTER_IPV4_H
+
+/* Define to 1 if you have the <linux/sched.h> header file. */
+#undef HAVE_LINUX_SCHED_H
+
+/* Define to 1 if you have the `localtime_r' function. */
+#undef HAVE_LOCALTIME_R
+
+/* Define to 1 if you have the <malloc.h> header file. */
+#undef HAVE_MALLOC_H
+
+/* Define to 1 if you have the <memory.h> header file. */
+#undef HAVE_MEMORY_H
+
+/* Define to 1 if you have 'msghdr.msg_control' structure. */
+#undef HAVE_MSGHDR_MSG_CONTROL
+
+/* Define to 1 if you have the `openpty' function. */
+#undef HAVE_OPENPTY
+
+/* Define to 1 if you have <engine.h> header file. */
+#undef HAVE_OSSL_ENGINE_H
+
+/* Define to 1 if you have <ocsp.h> header file. */
+#undef HAVE_OSSL_OCSP_H
+
+/* Define to 1 if you have the `pipe2' function. */
+#undef HAVE_PIPE2
+
+/* Define to 1 if you have the `poll' function. */
+#undef HAVE_POLL
+
+/* Define to 1 if you have the <poll.h> header file. */
+#undef HAVE_POLL_H
+
+/* Define if you have POSIX threads libraries and header files. */
+#undef HAVE_PTHREAD
+
+/* Define to 1 if you have the <pthread.h> header file. */
+#undef HAVE_PTHREAD_H
+
+/* Have PTHREAD_PRIO_INHERIT. */
+#undef HAVE_PTHREAD_PRIO_INHERIT
+
+/* Define to 1 if you have the `pthread_sigmask' function. */
+#undef HAVE_PTHREAD_SIGMASK
+
+/* Define to 1 if you have the <pty.h> header file. */
+#undef HAVE_PTY_H
+
+/* Define to 1 if you have the `setgroups' function. */
+#undef HAVE_SETGROUPS
+
+/* Define to 1 if you have the `setsid' function. */
+#undef HAVE_SETSID
+
+/* Define to 1 if you have the `snprintf' function. */
+#undef HAVE_SNPRINTF
+
+/* Define to 1 if you have the <stdint.h> header file. */
+#undef HAVE_STDINT_H
+
+/* Define to 1 if you have the <stdlib.h> header file. */
+#undef HAVE_STDLIB_H
+
+/* Define to 1 if you have the <strings.h> header file. */
+#undef HAVE_STRINGS_H
+
+/* Define to 1 if you have the <string.h> header file. */
+#undef HAVE_STRING_H
+
+/* Define to 1 if you have the <stropts.h> header file. */
+#undef HAVE_STROPTS_H
+
+/* Define to 1 if the system has the type `struct addrinfo'. */
+#undef HAVE_STRUCT_ADDRINFO
+
+/* Define to 1 if `msg_control' is a member of `struct msghdr'. */
+#undef HAVE_STRUCT_MSGHDR_MSG_CONTROL
+
+/* Define to 1 if the system has the type `struct sockaddr_un'. */
+#undef HAVE_STRUCT_SOCKADDR_UN
+
+/* Define to 1 if you have the `sysconf' function. */
+#undef HAVE_SYSCONF
+
+/* Define to 1 if you have the <systemd/sd-daemon.h> header file. */
+#undef HAVE_SYSTEMD_SD_DAEMON_H
+
+/* Define to 1 if you have the <sys/filio.h> header file. */
+#undef HAVE_SYS_FILIO_H
+
+/* Define to 1 if you have the <sys/ioctl.h> header file. */
+#undef HAVE_SYS_IOCTL_H
+
+/* Define to 1 if you have the <sys/poll.h> header file. */
+#undef HAVE_SYS_POLL_H
+
+/* Define to 1 if you have the <sys/resource.h> header file. */
+#undef HAVE_SYS_RESOURCE_H
+
+/* Define to 1 if you have the <sys/select.h> header file. */
+#undef HAVE_SYS_SELECT_H
+
+/* Define to 1 if you have the <sys/socket.h> header file. */
+#undef HAVE_SYS_SOCKET_H
+
+/* Define to 1 if you have the <sys/stat.h> header file. */
+#undef HAVE_SYS_STAT_H
+
+/* Define to 1 if you have the <sys/syscall.h> header file. */
+#undef HAVE_SYS_SYSCALL_H
+
+/* Define to 1 if you have the <sys/types.h> header file. */
+#undef HAVE_SYS_TYPES_H
+
+/* Define to 1 if you have the <sys/uio.h> header file. */
+#undef HAVE_SYS_UIO_H
+
+/* Define to 1 if you have the <sys/un.h> header file. */
+#undef HAVE_SYS_UN_H
+
+/* Define to 1 if you have the <tcpd.h> header file. */
+#undef HAVE_TCPD_H
+
+/* Define to 1 if you have the <ucontext.h> header file. */
+#undef HAVE_UCONTEXT_H
+
+/* Define to 1 if you have the <unistd.h> header file. */
+#undef HAVE_UNISTD_H
+
+/* Define to 1 if you have the <util.h> header file. */
+#undef HAVE_UTIL_H
+
+/* Define to 1 if you have the `vsnprintf' function. */
+#undef HAVE_VSNPRINTF
+
+/* Define to 1 if you have the `wait4' function. */
+#undef HAVE_WAIT4
+
+/* Define to 1 if you have the `waitpid' function. */
+#undef HAVE_WAITPID
+
+/* Define to 1 if you have the `_getpty' function. */
+#undef HAVE__GETPTY
+
+/* Define to 1 if you have the `__makecontext_v2' function. */
+#undef HAVE___MAKECONTEXT_V2
+
+/* Host description */
+#undef HOST
+
+/* Define to the sub-directory in which libtool stores uninstalled libraries.
+   */
+#undef LT_OBJDIR
+
+/* Name of package */
+#undef PACKAGE
+
+/* Define to the address where bug reports for this package should be sent. */
+#undef PACKAGE_BUGREPORT
+
+/* Define to the full name of this package. */
+#undef PACKAGE_NAME
+
+/* Define to the full name and version of this package. */
+#undef PACKAGE_STRING
+
+/* Define to the one symbol short name of this package. */
+#undef PACKAGE_TARNAME
+
+/* Define to the home page for this package. */
+#undef PACKAGE_URL
+
+/* Define to the version of this package. */
+#undef PACKAGE_VERSION
+
+/* Define to necessary symbol if this constant uses a non-standard name on
+   your system. */
+#undef PTHREAD_CREATE_JOINABLE
+
+/* Random file path */
+#undef RANDOM_FILE
+
+/* SSL directory */
+#undef SSLDIR
+
+/* Define to 1 if you have the ANSI C header files. */
+#undef STDC_HEADERS
+
+/* Define to 1 to enable OpenSSL FIPS support */
+#undef USE_FIPS
+
+/* Define to 1 to select FORK mode */
+#undef USE_FORK
+
+/* Define to 1 to enable IPv6 support */
+#undef USE_IPv6
+
+/* Define to 1 to enable TCP wrappers support */
+#undef USE_LIBWRAP
+
+/* Define to 1 to select PTHREAD mode */
+#undef USE_PTHREAD
+
+/* Define to 1 to enable systemd socket activation */
+#undef USE_SYSTEMD
+
+/* Define to 1 to select UCONTEXT mode */
+#undef USE_UCONTEXT
+
+/* Version number of package */
+#undef VERSION
+
+/* Use GNU source */
+#undef _GNU_SOURCE
+
+/* Define for Solaris 2.5.1 so the uint32_t typedef from <sys/synch.h>,
+   <pthread.h>, or <semaphore.h> is not used. If the typedef were allowed, the
+   #define below would cause a syntax error. */
+#undef _UINT32_T
+
+/* Define for Solaris 2.5.1 so the uint64_t typedef from <sys/synch.h>,
+   <pthread.h>, or <semaphore.h> is not used. If the typedef were allowed, the
+   #define below would cause a syntax error. */
+#undef _UINT64_T
+
+/* Define for Solaris 2.5.1 so the uint8_t typedef from <sys/synch.h>,
+   <pthread.h>, or <semaphore.h> is not used. If the typedef were allowed, the
+   #define below would cause a syntax error. */
+#undef _UINT8_T
+
+/* Define to `int' if <sys/types.h> doesn't define. */
+#undef gid_t
+
+/* Define to the type of a signed integer type of width exactly 16 bits if
+   such a type exists and the standard includes do not define it. */
+#undef int16_t
+
+/* Define to the type of a signed integer type of width exactly 32 bits if
+   such a type exists and the standard includes do not define it. */
+#undef int32_t
+
+/* Define to the type of a signed integer type of width exactly 64 bits if
+   such a type exists and the standard includes do not define it. */
+#undef int64_t
+
+/* Define to the type of a signed integer type of width exactly 8 bits if such
+   a type exists and the standard includes do not define it. */
+#undef int8_t
+
+/* Define to `unsigned int' if <sys/types.h> does not define. */
+#undef size_t
+
+/* Type of socklen_t */
+#undef socklen_t
+
+/* Define to `int' if <sys/types.h> does not define. */
+#undef ssize_t
+
+/* Define to `int' if <sys/types.h> doesn't define. */
+#undef uid_t
+
+/* Define to the type of an unsigned integer type of width exactly 16 bits if
+   such a type exists and the standard includes do not define it. */
+#undef uint16_t
+
+/* Define to the type of an unsigned integer type of width exactly 32 bits if
+   such a type exists and the standard includes do not define it. */
+#undef uint32_t
+
+/* Define to the type of an unsigned integer type of width exactly 64 bits if
+   such a type exists and the standard includes do not define it. */
+#undef uint64_t
+
+/* Define to the type of an unsigned integer type of width exactly 8 bits if
+   such a type exists and the standard includes do not define it. */
+#undef uint8_t
diff --git a/src/cron.c b/src/cron.c
new file mode 100644
index 0000000..cba6656
--- /dev/null
+++ b/src/cron.c
@@ -0,0 +1,201 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifdef USE_PTHREAD
+NOEXPORT void *cron_thread(void *arg);
+#endif
+#ifdef USE_WIN32
+NOEXPORT void cron_thread(void *arg);
+#endif
+#if defined(USE_PTHREAD) || defined(USE_WIN32)
+NOEXPORT void cron_worker(void);
+NOEXPORT void cron_dh_param(void);
+#endif
+
+#if defined(USE_PTHREAD)
+
+int cron_init() {
+    pthread_t thread;
+    pthread_attr_t pth_attr;
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    sigset_t new_set, old_set;
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    sigfillset(&new_set);
+    pthread_sigmask(SIG_SETMASK, &new_set, &old_set); /* block signals */
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+    pthread_attr_init(&pth_attr);
+    pthread_attr_setdetachstate(&pth_attr, PTHREAD_CREATE_DETACHED);
+    if(pthread_create(&thread, &pth_attr, cron_thread, NULL))
+        ioerror("pthread_create");
+    pthread_attr_destroy(&pth_attr);
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    pthread_sigmask(SIG_SETMASK, &old_set, NULL); /* unblock signals */
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+    return 0;
+}
+
+NOEXPORT void *cron_thread(void *arg) {
+#ifdef SCHED_BATCH
+    struct sched_param param;
+#endif
+
+    (void)arg; /* skip warning about unused parameter */
+    tls_alloc(NULL, NULL, "cron");
+#ifdef SCHED_BATCH
+    param.sched_priority=0;
+    if(pthread_setschedparam(pthread_self(), SCHED_BATCH, &param))
+        ioerror("pthread_getschedparam");
+#endif
+    cron_worker();
+    return NULL; /* it should never be executed */
+}
+
+#elif defined(USE_WIN32)
+
+int cron_init() {
+    if((long)_beginthread(cron_thread, 0, NULL)==-1)
+        ioerror("_beginthread");
+    return 0;
+}
+
+NOEXPORT void cron_thread(void *arg) {
+    (void)arg; /* skip warning about unused parameter */
+    tls_alloc(NULL, NULL, "cron");
+    if(!SetThreadPriority(GetCurrentThread(), THREAD_PRIORITY_LOWEST))
+        ioerror("SetThreadPriority");
+    cron_worker();
+    _endthread(); /* it should never be executed */
+}
+
+#else /* !defined(USE_PTHREAD) && !defined(USE_WIN32) */
+
+int cron_init() {
+    /* not implemented for now */
+    return 0;
+}
+
+#endif
+
+/* run the cron job every 24 hours */
+#define CRON_PERIOD (24*60*60)
+
+#if defined(USE_PTHREAD) || defined(USE_WIN32)
+
+NOEXPORT void cron_worker(void) {
+    time_t now, then;
+    int delay;
+
+    s_log(LOG_DEBUG, "Cron started");
+    sleep(60); /* allow the other services to start with idle CPU */
+    time(&then);
+    for(;;) {
+        s_log(LOG_INFO, "Executing cron jobs");
+#ifndef OPENSSL_NO_DH
+        cron_dh_param();
+#endif /* OPENSSL_NO_DH */
+        time(&now);
+        s_log(LOG_INFO, "Cron jobs completed in %d seconds", (int)(now-then));
+        then+=CRON_PERIOD;
+        if(then>now) {
+            delay=(int)(then-now);
+        } else {
+            s_log(LOG_NOTICE, "Cron backlog cleared (possible hibernation)");
+            delay=CRON_PERIOD-(int)(now-then)%CRON_PERIOD;
+            then=now+delay;
+        }
+        s_log(LOG_DEBUG, "Waiting %d seconds", delay);
+        do { /* retry sleep() if it was interrupted by a signal */
+            sleep((unsigned)delay);
+            time(&now);
+            delay=(int)(then-now);
+        } while(delay>0);
+        s_log(LOG_INFO, "Reopening log file");
+        signal_post(SIGNAL_REOPEN_LOG);
+    }
+}
+
+#ifndef OPENSSL_NO_DH
+NOEXPORT void cron_dh_param(void) {
+    SERVICE_OPTIONS *opt;
+    DH *dh;
+
+    if(!dh_needed)
+        return;
+
+    s_log(LOG_NOTICE, "Updating DH parameters");
+#if OPENSSL_VERSION_NUMBER>=0x0090800fL
+    /* generate 2048-bit DH parameters */
+    dh=DH_new();
+    if(!dh) {
+        sslerror("DH_new");
+        return;
+    }
+    if(!DH_generate_parameters_ex(dh, 2048, 2, NULL)) {
+        DH_free(dh);
+        sslerror("DH_generate_parameters_ex");
+        return;
+    }
+#else /* OpenSSL older than 0.9.8 */
+    dh=DH_generate_parameters(2048, 2, NULL, NULL);
+    if(!dh) {
+        sslerror("DH_generate_parameters");
+        return;
+    }
+#endif
+
+    /* update global dh_params for future configuration reloads */
+    enter_critical_section(CRIT_DH); /* it only needs an rwlock here */
+    DH_free(dh_params);
+    dh_params=dh;
+    leave_critical_section(CRIT_DH);
+
+    /* set for all sections that require it */
+    for(opt=service_options.next; opt; opt=opt->next)
+        if(opt->option.dh_needed)
+            SSL_CTX_set_tmp_dh(opt->ctx, dh);
+    s_log(LOG_NOTICE, "DH parameters updated");
+}
+#endif /* OPENSSL_NO_DH */
+
+#endif /* USE_PTHREAD || USE_WIN32 */
+
+/* end of cron.c */
diff --git a/src/ctx.c b/src/ctx.c
new file mode 100644
index 0000000..c5653bc
--- /dev/null
+++ b/src/ctx.c
@@ -0,0 +1,900 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifndef OPENSSL_NO_DH
+DH *dh_params=NULL;
+int dh_needed=0;
+#endif /* OPENSSL_NO_DH */
+
+/**************************************** prototypes */
+
+/* SNI */
+#ifndef OPENSSL_NO_TLSEXT
+NOEXPORT int servername_cb(SSL *, int *, void *);
+NOEXPORT int matches_wildcard(char *, char *);
+#endif
+
+/* DH/ECDH initialization */
+#ifndef OPENSSL_NO_DH
+NOEXPORT int dh_init(SERVICE_OPTIONS *);
+NOEXPORT DH *dh_read(char *);
+#endif /* OPENSSL_NO_DH */
+#ifndef OPENSSL_NO_ECDH
+NOEXPORT int ecdh_init(SERVICE_OPTIONS *);
+#endif /* USE_ECDH */
+
+/* initialize authentication */
+NOEXPORT int auth_init(SERVICE_OPTIONS *);
+#ifndef OPENSSL_NO_PSK
+NOEXPORT unsigned psk_client_callback(SSL *, const char *,
+    char *, unsigned, unsigned char *, unsigned);
+NOEXPORT unsigned psk_server_callback(SSL *, const char *,
+    unsigned char *, unsigned);
+#endif /* !defined(OPENSSL_NO_PSK) */
+NOEXPORT int load_cert(SERVICE_OPTIONS *);
+NOEXPORT int load_key_file(SERVICE_OPTIONS *);
+#ifndef OPENSSL_NO_ENGINE
+NOEXPORT int load_key_engine(SERVICE_OPTIONS *);
+#endif
+NOEXPORT int password_cb(char *, int, int, void *);
+
+/* session cache callbacks */
+NOEXPORT int sess_new_cb(SSL *, SSL_SESSION *);
+NOEXPORT SSL_SESSION *sess_get_cb(SSL *, unsigned char *, int, int *);
+NOEXPORT void sess_remove_cb(SSL_CTX *, SSL_SESSION *);
+
+/* sessiond interface */
+NOEXPORT void cache_transfer(SSL_CTX *, const u_char, const long,
+    const u_char *, const size_t,
+    const u_char *, const size_t,
+    unsigned char **, size_t *);
+
+/* info callbacks */
+NOEXPORT void info_callback(const SSL *, int, int);
+
+NOEXPORT void sslerror_queue(void);
+NOEXPORT void sslerror_log(unsigned long, char *);
+
+/**************************************** initialize section->ctx */
+
+int context_init(SERVICE_OPTIONS *section) { /* init SSL context */
+    /* create SSL context */
+    if(section->option.client)
+        section->ctx=SSL_CTX_new(section->client_method);
+    else /* server mode */
+        section->ctx=SSL_CTX_new(section->server_method);
+    if(!section->ctx) {
+        sslerror("SSL_CTX_new");
+        return 1; /* FAILED */
+    }
+    SSL_CTX_set_ex_data(section->ctx, index_opt, section); /* for callbacks */
+
+    /* load certificate and private key to be verified by the peer server */
+#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_VERSION_NUMBER>=0x0090809fL
+    /* SSL_CTX_set_client_cert_engine() was introduced in OpenSSL 0.9.8i */
+    if(section->option.client && section->engine) {
+        if(SSL_CTX_set_client_cert_engine(section->ctx, section->engine))
+            s_log(LOG_INFO, "Client certificate engine (%s) enabled",
+                ENGINE_get_id(section->engine));
+        else /* no client certificate functionality in this engine */
+            sslerror("SSL_CTX_set_client_cert_engine"); /* ignore error */
+    }
+#endif
+    if(auth_init(section))
+        return 1; /* FAILED */
+
+    /* initialize verification of the peer server certificate */
+    if(verify_init(section))
+        return 1; /* FAILED */
+
+    /* initialize DH/ECDH server mode */
+    if(!section->option.client) {
+#ifndef OPENSSL_NO_TLSEXT
+        SSL_CTX_set_tlsext_servername_arg(section->ctx, section);
+        SSL_CTX_set_tlsext_servername_callback(section->ctx, servername_cb);
+#endif /* OPENSSL_NO_TLSEXT */
+#ifndef OPENSSL_NO_DH
+        dh_init(section); /* ignore the result (errors are not critical) */
+#endif /* OPENSSL_NO_DH */
+#ifndef OPENSSL_NO_ECDH
+        ecdh_init(section); /* ignore the result (errors are not critical) */
+#endif /* OPENSSL_NO_ECDH */
+    }
+
+    /* setup session cache */
+    if(!section->option.client) {
+        unsigned servname_len=(unsigned)strlen(section->servname);
+        if(servname_len>SSL_MAX_SSL_SESSION_ID_LENGTH)
+            servname_len=SSL_MAX_SSL_SESSION_ID_LENGTH;
+        if(!SSL_CTX_set_session_id_context(section->ctx,
+                (unsigned char *)section->servname, servname_len)) {
+            sslerror("SSL_CTX_set_session_id_context");
+            return 1; /* FAILED */
+        }
+    }
+#ifdef SSL_SESS_CACHE_NO_INTERNAL_STORE
+    /* the default cache mode is just SSL_SESS_CACHE_SERVER */
+    SSL_CTX_set_session_cache_mode(section->ctx,
+        SSL_SESS_CACHE_SERVER|SSL_SESS_CACHE_NO_INTERNAL_STORE);
+#endif
+    SSL_CTX_sess_set_cache_size(section->ctx, section->session_size);
+    SSL_CTX_set_timeout(section->ctx, section->session_timeout);
+    if(section->option.sessiond) {
+        SSL_CTX_sess_set_new_cb(section->ctx, sess_new_cb);
+        SSL_CTX_sess_set_get_cb(section->ctx, sess_get_cb);
+        SSL_CTX_sess_set_remove_cb(section->ctx, sess_remove_cb);
+    }
+
+    /* set info callback */
+    SSL_CTX_set_info_callback(section->ctx, info_callback);
+
+    /* ciphers, options, mode */
+    if(section->cipher_list)
+        if(!SSL_CTX_set_cipher_list(section->ctx, section->cipher_list)) {
+            sslerror("SSL_CTX_set_cipher_list");
+            return 1; /* FAILED */
+        }
+    SSL_CTX_set_options(section->ctx, section->ssl_options_set);
+#if OPENSSL_VERSION_NUMBER>=0x009080dfL
+    SSL_CTX_clear_options(section->ctx, section->ssl_options_clear);
+    s_log(LOG_DEBUG, "SSL options: 0x%08lX (+0x%08lX, -0x%08lX)",
+        SSL_CTX_get_options(section->ctx),
+        section->ssl_options_set, section->ssl_options_clear);
+#else /* OpenSSL older than 0.9.8m */
+    s_log(LOG_DEBUG, "SSL options: 0x%08lX (+0x%08lX)",
+        SSL_CTX_get_options(section->ctx),
+        section->ssl_options_set);
+#endif /* OpenSSL 0.9.8m or later */
+#ifdef SSL_MODE_RELEASE_BUFFERS
+    SSL_CTX_set_mode(section->ctx,
+        SSL_MODE_ENABLE_PARTIAL_WRITE |
+        SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER |
+        SSL_MODE_RELEASE_BUFFERS);
+#else
+    SSL_CTX_set_mode(section->ctx,
+        SSL_MODE_ENABLE_PARTIAL_WRITE |
+        SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER);
+#endif
+    return 0; /* OK */
+}
+
+/**************************************** SNI callback */
+
+#ifndef OPENSSL_NO_TLSEXT
+
+NOEXPORT int servername_cb(SSL *ssl, int *ad, void *arg) {
+    SERVICE_OPTIONS *section=(SERVICE_OPTIONS *)arg;
+    const char *servername=SSL_get_servername(ssl, TLSEXT_NAMETYPE_host_name);
+    SERVERNAME_LIST *list;
+    CLI *c;
+#ifdef USE_LIBWRAP
+    char *accepted_address;
+#endif /* USE_LIBWRAP */
+
+    /* leave the alert type at SSL_AD_UNRECOGNIZED_NAME */
+    (void)ad; /* skip warning about unused parameter */
+    if(!section->servername_list_head) {
+        s_log(LOG_DEBUG, "SNI: no virtual services defined");
+        return SSL_TLSEXT_ERR_OK;
+    }
+    if(!servername) {
+        s_log(LOG_NOTICE, "SNI: no servername received");
+        return SSL_TLSEXT_ERR_NOACK;
+    }
+    s_log(LOG_INFO, "SNI: requested servername: %s", servername);
+
+    for(list=section->servername_list_head; list; list=list->next)
+        if(matches_wildcard((char *)servername, list->servername)) {
+            s_log(LOG_DEBUG, "SNI: matched pattern: %s", list->servername);
+            c=SSL_get_ex_data(ssl, index_cli);
+            c->opt=list->opt;
+            SSL_set_SSL_CTX(ssl, c->opt->ctx);
+            SSL_set_verify(ssl, SSL_CTX_get_verify_mode(c->opt->ctx),
+                SSL_CTX_get_verify_callback(c->opt->ctx));
+            s_log(LOG_NOTICE, "SNI: switched to service [%s]",
+                c->opt->servname);
+#ifdef USE_LIBWRAP
+            accepted_address=s_ntop(&c->peer_addr, c->peer_addr_len);
+            libwrap_auth(c, accepted_address); /* retry on a service switch */
+            str_free(accepted_address);
+#endif /* USE_LIBWRAP */
+            return SSL_TLSEXT_ERR_OK;
+        }
+    s_log(LOG_ERR, "SNI: no pattern matched servername: %s", servername);
+    return SSL_TLSEXT_ERR_ALERT_FATAL;
+}
+/* TLSEXT callback return codes:
+ *  - SSL_TLSEXT_ERR_OK
+ *  - SSL_TLSEXT_ERR_ALERT_WARNING
+ *  - SSL_TLSEXT_ERR_ALERT_FATAL
+ *  - SSL_TLSEXT_ERR_NOACK */
+
+NOEXPORT int matches_wildcard(char *servername, char *pattern) {
+    ssize_t diff;
+
+    if(!servername || !pattern)
+        return 0;
+    if(*pattern=='*') { /* wildcard comparison */
+        diff=(ssize_t)strlen(servername)-(ssize_t)strlen(++pattern);
+        if(diff<0) /* pattern longer than servername */
+            return 0;
+        servername+=diff;
+    }
+    return !strcasecmp(servername, pattern);
+}
+
+#endif /* OPENSSL_NO_TLSEXT */
+
+/**************************************** DH initialization */
+
+#ifndef OPENSSL_NO_DH
+
+NOEXPORT int dh_init(SERVICE_OPTIONS *section) {
+    DH *dh=NULL;
+
+    s_log(LOG_DEBUG, "DH initialization");
+#ifndef OPENSSL_NO_ENGINE
+    if(!section->engine) /* cert is a file and not an identifier */
+#endif
+        dh=dh_read(section->cert);
+    if(dh) {
+        SSL_CTX_set_tmp_dh(section->ctx, dh);
+        s_log(LOG_INFO, "%d-bit DH parameters loaded", 8*DH_size(dh));
+        DH_free(dh);
+        return 0; /* OK */
+    }
+    enter_critical_section(CRIT_DH); /* it only needs an rwlock here */
+    SSL_CTX_set_tmp_dh(section->ctx, dh_params);
+    leave_critical_section(CRIT_DH);
+    dh_needed=1; /* generate temporary DH parameters in cron */
+    section->option.dh_needed=1; /* update this context */
+    s_log(LOG_INFO, "Using dynamic DH parameters");
+    return 0; /* OK */
+}
+
+NOEXPORT DH *dh_read(char *cert) {
+    DH *dh;
+    BIO *bio;
+
+    if(!cert) {
+        s_log(LOG_DEBUG, "No certificate available to load DH parameters");
+        return NULL; /* FAILED */
+    }
+    bio=BIO_new_file(cert, "r");
+    if(!bio) {
+        sslerror("BIO_new_file");
+        return NULL; /* FAILED */
+    }
+    dh=PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
+    BIO_free(bio);
+    if(!dh) {
+        while(ERR_get_error())
+            ; /* OpenSSL error queue cleanup */
+        s_log(LOG_DEBUG, "Could not load DH parameters from %s", cert);
+        return NULL; /* FAILED */
+    }
+    s_log(LOG_DEBUG, "Using DH parameters from %s", cert);
+    return dh;
+}
+
+#endif /* OPENSSL_NO_DH */
+
+/**************************************** ECDH initialization */
+
+#ifndef OPENSSL_NO_ECDH
+NOEXPORT int ecdh_init(SERVICE_OPTIONS *section) {
+    EC_KEY *ecdh;
+
+    s_log(LOG_DEBUG, "ECDH initialization");
+    ecdh=EC_KEY_new_by_curve_name(section->curve);
+    if(!ecdh) {
+        sslerror("EC_KEY_new_by_curve_name");
+        s_log(LOG_ERR, "Cannot create curve %s",
+            OBJ_nid2ln(section->curve));
+        return 1; /* FAILED */
+    }
+    SSL_CTX_set_tmp_ecdh(section->ctx, ecdh);
+    EC_KEY_free(ecdh);
+    s_log(LOG_DEBUG, "ECDH initialized with curve %s",
+        OBJ_nid2ln(section->curve));
+    return 0; /* OK */
+}
+#endif /* OPENSSL_NO_ECDH */
+
+/**************************************** initialize authentication */
+
+NOEXPORT int auth_init(SERVICE_OPTIONS *section) {
+    int result;
+
+    result=load_cert(section);
+#ifndef OPENSSL_NO_PSK
+    if(section->psk_keys) {
+        if(section->option.client)
+            SSL_CTX_set_psk_client_callback(section->ctx, psk_client_callback);
+        else
+            SSL_CTX_set_psk_server_callback(section->ctx, psk_server_callback);
+        result=0;
+    }
+#endif /* !defined(OPENSSL_NO_PSK) */
+    return result;
+}
+
+#ifndef OPENSSL_NO_PSK
+
+NOEXPORT unsigned psk_client_callback(SSL *ssl, const char *hint,
+    char *identity, unsigned max_identity_len,
+    unsigned char *psk, unsigned max_psk_len) {
+    CLI *c;
+    size_t identity_len;
+
+    (void)hint; /* skip warning about unused parameter */
+    c=SSL_get_ex_data(ssl, index_cli);
+    if(!c->opt->psk_selected) {
+        s_log(LOG_ERR, "INTERNAL ERROR: No PSK identity selected");
+        return 0;
+    }
+    /* the source seems to have its buffer large enough for
+     * the trailing null character, but the manual page says
+     * nothing about it -- lets play safe */
+    identity_len=strlen(c->opt->psk_selected->identity)+1;
+    if(identity_len>max_identity_len) {
+        s_log(LOG_ERR, "PSK identity too long (%lu>%d bytes)",
+            (long unsigned)identity_len, max_psk_len);
+        return 0;
+    }
+    if(c->opt->psk_selected->key_len>max_psk_len) {
+        s_log(LOG_ERR, "PSK too long (%lu>%d bytes)",
+            (long unsigned)c->opt->psk_selected->key_len, max_psk_len);
+        return 0;
+    }
+    strcpy(identity, c->opt->psk_selected->identity);
+    memcpy(psk, c->opt->psk_selected->key_val, c->opt->psk_selected->key_len);
+    s_log(LOG_INFO, "PSK client configured for identity \"%s\"", identity);
+    return (unsigned)(c->opt->psk_selected->key_len);
+}
+
+NOEXPORT unsigned psk_server_callback(SSL *ssl, const char *identity,
+    unsigned char *psk, unsigned max_psk_len) {
+    CLI *c;
+    PSK_KEYS *found;
+    size_t len;
+
+    c=SSL_get_ex_data(ssl, index_cli);
+    found=psk_find(&c->opt->psk_sorted, identity);
+    if(found) {
+        len=found->key_len;
+    } else {
+        s_log(LOG_ERR, "No key found for PSK identity \"%s\"", identity);
+        len=0;
+    }
+    if(len>max_psk_len) {
+        s_log(LOG_ERR, "PSK too long (%lu>%d bytes)",
+            (long unsigned)len, max_psk_len);
+        len=0;
+    }
+    if(len) {
+        memcpy(psk, found->key_val, len);
+        s_log(LOG_NOTICE, "Key configured for PSK identity \"%s\"", identity);
+    } else { /* block identity probes if possible */
+        if(max_psk_len>=32 && RAND_bytes(psk, 32)>0) {
+            len=32; /* 256 random bits */
+            s_log(LOG_ERR, "Configured random PSK");
+        } else {
+            s_log(LOG_ERR, "Rejecting with unknown_psk_identity alert");
+        }
+    }
+    return (unsigned)len;
+}
+
+NOEXPORT int psk_compar(const void *a, const void *b) {
+    PSK_KEYS *x=*(PSK_KEYS **)a, *y=*(PSK_KEYS **)b;
+
+#if 0
+    s_log(LOG_DEBUG, "PSK cmp: %s %s", x->identity, y->identity);
+#endif
+    return strcmp(x->identity, y->identity);
+}
+
+void psk_sort(PSK_TABLE *table, PSK_KEYS *head) {
+    PSK_KEYS *curr;
+    size_t i;
+
+    table->num=0;
+    for(curr=head; curr; curr=curr->next)
+        ++table->num;
+    s_log(LOG_INFO, "PSK identities: %lu retrieved",
+        (long unsigned)table->num);
+    table->val=str_alloc(table->num*sizeof(PSK_KEYS *));
+    for(curr=head, i=0; i<table->num; ++i) {
+        table->val[i]=curr;
+        curr=curr->next;
+    }
+    qsort(table->val, table->num, sizeof(PSK_KEYS *), psk_compar);
+#if 0
+    for(i=0; i<table->num; ++i)
+        s_log(LOG_DEBUG, "PSK table: %s", table->val[i]->identity);
+#endif
+}
+
+PSK_KEYS *psk_find(const PSK_TABLE *table, const char *identity) {
+    PSK_KEYS key, *ptr=&key, **ret;
+
+    key.identity=(char *)identity;
+    ret=bsearch(&ptr,
+        table->val, table->num, sizeof(PSK_KEYS *), psk_compar);
+    return ret ? *ret : NULL;
+}
+
+#endif /* !defined(OPENSSL_NO_PSK) */
+
+static int cache_initialized=0;
+
+NOEXPORT int load_cert(SERVICE_OPTIONS *section) {
+    /* load the certificate */
+    if(section->cert) {
+        s_log(LOG_INFO, "Loading certificate from file: %s", section->cert);
+        if(!SSL_CTX_use_certificate_chain_file(section->ctx, section->cert)) {
+            sslerror("SSL_CTX_use_certificate_chain_file");
+            return 1; /* FAILED */
+        }
+    }
+
+    /* load the private key */
+    if(!section->key) {
+        s_log(LOG_DEBUG, "No private key specified");
+        return 0; /* OK */
+    }
+#ifndef OPENSSL_NO_ENGINE
+    if(section->engine) {
+        if(load_key_engine(section))
+            return 1; /* FAILED */
+    } else
+#endif
+    {
+        if(load_key_file(section))
+            return 1; /* FAILED */
+    }
+
+    /* validate the private key */
+    if(!SSL_CTX_check_private_key(section->ctx)) {
+        sslerror("Private key does not match the certificate");
+        return 1; /* FAILED */
+    }
+    s_log(LOG_DEBUG, "Private key check succeeded");
+    return 0; /* OK */
+}
+
+NOEXPORT int load_key_file(SERVICE_OPTIONS *section) {
+    int i, reason;
+    UI_DATA ui_data;
+
+    s_log(LOG_INFO, "Loading key from file: %s", section->key);
+    if(file_permissions(section->key))
+        return 1;
+
+    ui_data.section=section; /* setup current section for callbacks */
+    SSL_CTX_set_default_passwd_cb(section->ctx, password_cb);
+
+    for(i=0; i<=3; i++) {
+        if(!i && !cache_initialized)
+            continue; /* there is no cached value */
+        SSL_CTX_set_default_passwd_cb_userdata(section->ctx,
+            i ? &ui_data : NULL); /* try the cached password first */
+        if(SSL_CTX_use_PrivateKey_file(section->ctx, section->key,
+                SSL_FILETYPE_PEM))
+            break;
+        reason=ERR_GET_REASON(ERR_peek_error());
+        if(i<=2 && reason==EVP_R_BAD_DECRYPT) {
+            sslerror_queue(); /* dump the error queue */
+            s_log(LOG_ERR, "Wrong pass phrase: retrying");
+            continue;
+        }
+        sslerror("SSL_CTX_use_PrivateKey_file");
+        return 1; /* FAILED */
+    }
+    return 0; /* OK */
+}
+
+#ifndef OPENSSL_NO_ENGINE
+NOEXPORT int load_key_engine(SERVICE_OPTIONS *section) {
+    int i, reason;
+    UI_DATA ui_data;
+    EVP_PKEY *pkey;
+    UI_METHOD *ui_method;
+
+    s_log(LOG_INFO, "Loading key from engine: %s", section->key);
+
+    ui_data.section=section; /* setup current section for callbacks */
+    SSL_CTX_set_default_passwd_cb(section->ctx, password_cb);
+
+#ifdef USE_WIN32
+    ui_method=UI_create_method("stunnel WIN32 UI");
+    UI_method_set_reader(ui_method, pin_cb);
+#else /* USE_WIN32 */
+    ui_method=UI_OpenSSL();
+    /* workaround for broken engines */
+    /* ui_data.section=NULL; */
+#endif /* USE_WIN32 */
+    for(i=1; i<=3; i++) {
+        pkey=ENGINE_load_private_key(section->engine, section->key,
+            ui_method, &ui_data);
+        if(!pkey) {
+            reason=ERR_GET_REASON(ERR_peek_error());
+            if(i<=2 && (reason==7 || reason==160)) { /* wrong PIN */
+                sslerror_queue(); /* dump the error queue */
+                s_log(LOG_ERR, "Wrong PIN: retrying");
+                continue;
+            }
+            sslerror("ENGINE_load_private_key");
+            return 1; /* FAILED */
+        }
+        if(SSL_CTX_use_PrivateKey(section->ctx, pkey))
+            break; /* success */
+        sslerror("SSL_CTX_use_PrivateKey");
+        return 1; /* FAILED */
+    }
+    return 0; /* OK */
+}
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+NOEXPORT int password_cb(char *buf, int size, int rwflag, void *userdata) {
+    static char cache[PEM_BUFSIZE];
+    int len;
+
+    if(size>PEM_BUFSIZE)
+        size=PEM_BUFSIZE;
+
+    if(userdata) { /* prompt the user */
+#ifdef USE_WIN32
+        len=passwd_cb(buf, size, rwflag, userdata);
+#else
+        len=PEM_def_callback(buf, size, rwflag, NULL);
+#endif
+        memcpy(cache, buf, (size_t)size); /* save in cache */
+        cache_initialized=1;
+    } else { /* try the cached value */
+        strncpy(buf, cache, (size_t)size);
+        buf[size-1]='\0';
+        len=(int)strlen(buf);
+    }
+    return len;
+}
+
+/**************************************** session cache callbacks */
+
+#define CACHE_CMD_NEW     0x00
+#define CACHE_CMD_GET     0x01
+#define CACHE_CMD_REMOVE  0x02
+#define CACHE_RESP_ERR    0x80
+#define CACHE_RESP_OK     0x81
+
+NOEXPORT int sess_new_cb(SSL *ssl, SSL_SESSION *sess) {
+    unsigned char *val, *val_tmp;
+    ssize_t val_len;
+    const unsigned char *session_id;
+    unsigned int session_id_length;
+
+    val_len=i2d_SSL_SESSION(sess, NULL);
+    val_tmp=val=str_alloc((size_t)val_len);
+    i2d_SSL_SESSION(sess, &val_tmp);
+
+#if OPENSSL_VERSION_NUMBER>=0x0090800fL
+    session_id=SSL_SESSION_get_id(sess, &session_id_length);
+#else
+    session_id=(const unsigned char *)sess->session_id;
+    session_id_length=sess->session_id_length;
+#endif
+    cache_transfer(SSL_get_SSL_CTX(ssl), CACHE_CMD_NEW,
+        SSL_SESSION_get_timeout(sess),
+        session_id, session_id_length, val, (size_t)val_len, NULL, NULL);
+    str_free(val);
+    return 1; /* leave the session in local cache for reuse */
+}
+
+NOEXPORT SSL_SESSION *sess_get_cb(SSL *ssl,
+        unsigned char *key, int key_len, int *do_copy) {
+    unsigned char *val, *val_tmp=NULL;
+    ssize_t val_len=0;
+    SSL_SESSION *sess;
+
+    *do_copy = 0; /* allow the session to be freed autmatically */
+    cache_transfer(SSL_get_SSL_CTX(ssl), CACHE_CMD_GET, 0,
+        key, (size_t)key_len, NULL, 0, &val, (size_t *)&val_len);
+    if(!val)
+        return NULL;
+    val_tmp=val;
+    sess=d2i_SSL_SESSION(NULL,
+#if OPENSSL_VERSION_NUMBER>=0x0090800fL
+        (const unsigned char **)
+#endif /* OpenSSL version >= 0.8.0 */
+        &val_tmp, val_len);
+    str_free(val);
+    return sess;
+}
+
+NOEXPORT void sess_remove_cb(SSL_CTX *ctx, SSL_SESSION *sess) {
+    const unsigned char *session_id;
+    unsigned int session_id_length;
+
+#if OPENSSL_VERSION_NUMBER>=0x0090800fL
+    session_id=SSL_SESSION_get_id(sess, &session_id_length);
+#else
+    session_id=(const unsigned char *)sess->session_id;
+    session_id_length=sess->session_id_length;
+#endif
+    cache_transfer(ctx, CACHE_CMD_REMOVE, 0,
+        session_id, session_id_length, NULL, 0, NULL, NULL);
+}
+
+#define MAX_VAL_LEN 512
+typedef struct {
+    u_char version, type;
+    u_short timeout;
+    u_char key[SSL_MAX_SSL_SESSION_ID_LENGTH];
+    u_char val[MAX_VAL_LEN];
+} CACHE_PACKET;
+
+NOEXPORT void cache_transfer(SSL_CTX *ctx, const u_char type,
+        const long timeout,
+        const u_char *key, const size_t key_len,
+        const u_char *val, const size_t val_len,
+        unsigned char **ret, size_t *ret_len) {
+    char session_id_txt[2*SSL_MAX_SSL_SESSION_ID_LENGTH+1];
+    const char hex[16]="0123456789ABCDEF";
+    const char *type_description[]={"new", "get", "remove"};
+    unsigned i;
+    SOCKET s;
+    ssize_t len;
+    struct timeval t;
+    CACHE_PACKET *packet;
+    SERVICE_OPTIONS *section;
+
+    if(ret) /* set error as the default result if required */
+        *ret=NULL;
+
+    /* log the request information */
+    for(i=0; i<key_len && i<SSL_MAX_SSL_SESSION_ID_LENGTH; ++i) {
+        session_id_txt[2*i]=hex[key[i]>>4];
+        session_id_txt[2*i+1]=hex[key[i]&0x0f];
+    }
+    session_id_txt[2*i]='\0';
+    s_log(LOG_INFO,
+        "cache_transfer: request=%s, timeout=%ld, id=%s, length=%lu",
+        type_description[type], timeout, session_id_txt, (long unsigned)val_len);
+
+    /* allocate UDP packet buffer */
+    if(key_len>SSL_MAX_SSL_SESSION_ID_LENGTH) {
+        s_log(LOG_ERR, "cache_transfer: session id too big (%lu bytes)",
+            (unsigned long)key_len);
+        return;
+    }
+    if(val_len>MAX_VAL_LEN) {
+        s_log(LOG_ERR, "cache_transfer: encoded session too big (%lu bytes)",
+            (unsigned long)key_len);
+        return;
+    }
+    packet=str_alloc(sizeof(CACHE_PACKET));
+
+    /* setup packet */
+    packet->version=1;
+    packet->type=type;
+    packet->timeout=htons((u_short)(timeout<64800?timeout:64800));/* 18 hours */
+    memcpy(packet->key, key, key_len);
+    memcpy(packet->val, val, val_len);
+
+    /* create the socket */
+    s=s_socket(AF_INET, SOCK_DGRAM, 0, 0, "cache_transfer: socket");
+    if(s==INVALID_SOCKET) {
+        str_free(packet);
+        return;
+    }
+
+    /* retrieve pointer to the section structure of this ctx */
+    section=SSL_CTX_get_ex_data(ctx, index_opt);
+    if(sendto(s, (void *)packet,
+#ifdef USE_WIN32
+            (int)
+#endif
+            (sizeof(CACHE_PACKET)-MAX_VAL_LEN+val_len),
+            0, &section->sessiond_addr.sa,
+            addr_len(&section->sessiond_addr))<0) {
+        sockerror("cache_transfer: sendto");
+        closesocket(s);
+        str_free(packet);
+        return;
+    }
+
+    if(!ret || !ret_len) { /* no response is required */
+        closesocket(s);
+        str_free(packet);
+        return;
+    }
+
+    /* set recvfrom timeout to 200ms */
+    t.tv_sec=0;
+    t.tv_usec=200;
+    if(setsockopt(s, SOL_SOCKET, SO_RCVTIMEO, (void *)&t, sizeof t)<0) {
+        sockerror("cache_transfer: setsockopt SO_RCVTIMEO");
+        closesocket(s);
+        str_free(packet);
+        return;
+    }
+
+    /* retrieve response */
+    len=recv(s, (void *)packet, sizeof(CACHE_PACKET), 0);
+    closesocket(s);
+    if(len<0) {
+        if(get_last_socket_error()==S_EWOULDBLOCK ||
+                get_last_socket_error()==S_EAGAIN)
+            s_log(LOG_INFO, "cache_transfer: recv timeout");
+        else
+            sockerror("cache_transfer: recv");
+        str_free(packet);
+        return;
+    }
+
+    /* parse results */
+    if(len<(int)sizeof(CACHE_PACKET)-MAX_VAL_LEN || /* too short */
+            packet->version!=1 || /* wrong version */
+            safe_memcmp(packet->key, key, key_len)) { /* wrong session id */
+        s_log(LOG_DEBUG, "cache_transfer: malformed packet received");
+        str_free(packet);
+        return;
+    }
+    if(packet->type!=CACHE_RESP_OK) {
+        s_log(LOG_INFO, "cache_transfer: session not found");
+        str_free(packet);
+        return;
+    }
+    *ret_len=(size_t)len-(sizeof(CACHE_PACKET)-MAX_VAL_LEN);
+    *ret=str_alloc(*ret_len);
+    s_log(LOG_INFO, "cache_transfer: session found");
+    memcpy(*ret, packet->val, *ret_len);
+    str_free(packet);
+}
+
+/**************************************** informational callback */
+
+NOEXPORT void info_callback(const SSL *ssl, int where, int ret) {
+    CLI *c;
+    SSL_CTX *ctx;
+
+    c=SSL_get_ex_data((SSL *)ssl, index_cli);
+    if(c) {
+        if((where&SSL_CB_HANDSHAKE_DONE)
+                && c->reneg_state==RENEG_INIT) {
+            /* first (initial) handshake was completed, remember this,
+             * so that further renegotiation attempts can be detected */
+            c->reneg_state=RENEG_ESTABLISHED;
+        } else if((where&SSL_CB_ACCEPT_LOOP)
+                && c->reneg_state==RENEG_ESTABLISHED) {
+            int state=SSL_get_state((SSL *)ssl);
+
+            if(state==SSL3_ST_SR_CLNT_HELLO_A
+                    || state==SSL23_ST_SR_CLNT_HELLO_A) {
+                /* client hello received after initial handshake,
+                 * this means renegotiation -> mark it */
+                c->reneg_state=RENEG_DETECTED;
+            }
+        }
+        if(c->opt->log_level<LOG_DEBUG) /* performance optimization */
+            return;
+    }
+
+    if(where & SSL_CB_LOOP) {
+        s_log(LOG_DEBUG, "SSL state (%s): %s",
+            where & SSL_ST_CONNECT ? "connect" :
+            where & SSL_ST_ACCEPT ? "accept" :
+            "undefined", SSL_state_string_long(ssl));
+    } else if(where & SSL_CB_ALERT) {
+        s_log(LOG_DEBUG, "SSL alert (%s): %s: %s",
+            where & SSL_CB_READ ? "read" : "write",
+            SSL_alert_type_string_long(ret),
+            SSL_alert_desc_string_long(ret));
+    } else if(where==SSL_CB_HANDSHAKE_DONE) {
+        ctx=SSL_get_SSL_CTX((SSL *)ssl);
+        if(c->opt->option.client) {
+            s_log(LOG_DEBUG, "%6ld client connect(s) requested",
+                SSL_CTX_sess_connect(ctx));
+            s_log(LOG_DEBUG, "%6ld client connect(s) succeeded",
+                SSL_CTX_sess_connect_good(ctx));
+            s_log(LOG_DEBUG, "%6ld client renegotiation(s) requested",
+                SSL_CTX_sess_connect_renegotiate(ctx));
+        } else {
+            s_log(LOG_DEBUG, "%6ld server accept(s) requested",
+                SSL_CTX_sess_accept(ctx));
+            s_log(LOG_DEBUG, "%6ld server accept(s) succeeded",
+                SSL_CTX_sess_accept_good(ctx));
+            s_log(LOG_DEBUG, "%6ld server renegotiation(s) requested",
+                SSL_CTX_sess_accept_renegotiate(ctx));
+        }
+        /* according to the source it not only includes internal
+           and external session caches, but also session tickets */
+        s_log(LOG_DEBUG, "%6ld session reuse(s)",
+            SSL_CTX_sess_hits(ctx));
+        if(!c->opt->option.client) { /* server session cache stats */
+            s_log(LOG_DEBUG, "%6ld internal session cache item(s)",
+                SSL_CTX_sess_number(ctx));
+            s_log(LOG_DEBUG, "%6ld internal session cache fill-up(s)",
+                SSL_CTX_sess_cache_full(ctx));
+            s_log(LOG_DEBUG, "%6ld internal session cache miss(es)",
+                SSL_CTX_sess_misses(ctx));
+            s_log(LOG_DEBUG, "%6ld external session cache hit(s)",
+                SSL_CTX_sess_cb_hits(ctx));
+            s_log(LOG_DEBUG, "%6ld expired session(s) retrieved",
+                SSL_CTX_sess_timeouts(ctx));
+        }
+    }
+}
+
+/**************************************** SSL error reporting */
+
+void sslerror(char *txt) { /* OpenSSL error handler */
+    unsigned long err;
+
+    err=ERR_get_error();
+    if(err) {
+        sslerror_queue();
+        sslerror_log(err, txt);
+    } else {
+        s_log(LOG_ERR, "%s: Peer suddenly disconnected", txt);
+    }
+}
+
+NOEXPORT void sslerror_queue(void) { /* recursive dump of the error queue */
+    unsigned long err;
+
+    err=ERR_get_error();
+    if(err) {
+        sslerror_queue();
+        sslerror_log(err, "error queue");
+    }
+}
+
+NOEXPORT void sslerror_log(unsigned long err, char *txt) {
+    char *error_string;
+
+    error_string=str_alloc(256);
+    ERR_error_string_n(err, error_string, 256);
+    s_log(LOG_ERR, "%s: %lX: %s", txt, err, error_string);
+    str_free(error_string);
+}
+
+/* end of ctx.c */
diff --git a/src/dhparam.c b/src/dhparam.c
new file mode 100644
index 0000000..75dbf82
--- /dev/null
+++ b/src/dhparam.c
@@ -0,0 +1,45 @@
+#include "common.h"
+#ifndef OPENSSL_NO_DH
+#define DN_new DH_new
+#ifndef HEADER_DH_H
+#include <openssl/dh.h>
+#endif
+DH *get_dh2048()
+	{
+	static unsigned char dh2048_p[]={
+		0xF8,0x41,0xAE,0xC8,0x92,0xAF,0xC6,0xD4,0x8B,0xC2,0x06,0x04,
+		0x83,0x57,0x08,0x80,0xD6,0xC3,0xA7,0x8A,0xFD,0x8E,0xCF,0xAC,
+		0x8F,0x8A,0x43,0x20,0x05,0x2B,0xD1,0x70,0x01,0xD0,0x9F,0x7B,
+		0x44,0x92,0xB5,0x64,0xA7,0xE9,0xF1,0x1E,0xBC,0x9E,0x51,0x87,
+		0xDB,0x66,0xA6,0x0A,0xD6,0xF4,0xBD,0xBD,0xDF,0x50,0xF6,0xBA,
+		0x5D,0xB3,0x9C,0x2F,0x3F,0x41,0xEB,0xDD,0xEE,0xE1,0x7B,0xAD,
+		0x99,0x5D,0xA6,0x69,0xC6,0x2F,0x5A,0x2F,0x47,0x5E,0x49,0x48,
+		0xA4,0x87,0xA4,0x65,0x12,0x93,0xB9,0xA3,0x09,0x04,0x01,0xA0,
+		0xD0,0xFB,0x0E,0x47,0x7F,0x8C,0x5C,0x74,0x50,0xEA,0xFB,0xFD,
+		0x39,0xD4,0x00,0x30,0x0A,0xDE,0x7E,0xB7,0xBE,0x5E,0x30,0x06,
+		0x5A,0xAC,0xC2,0x79,0xC3,0x3A,0xFC,0x72,0xC2,0x15,0x7A,0xBE,
+		0x49,0xBE,0x36,0x7A,0xED,0x38,0x83,0x3F,0x44,0xAB,0x26,0x81,
+		0x89,0xEF,0x58,0xDF,0x55,0x14,0xD5,0x42,0xB4,0x57,0xD6,0x01,
+		0xE2,0x9C,0x2D,0x7B,0xC1,0xDA,0xB9,0x10,0x8C,0x5A,0xF7,0x98,
+		0xE2,0x00,0x8F,0xA8,0x22,0x6C,0x60,0x90,0x35,0x6A,0x74,0x29,
+		0x7B,0xE0,0xF9,0x46,0xF3,0x79,0x9C,0x7A,0x30,0x62,0x16,0x9D,
+		0x42,0xBD,0xD2,0x5E,0x17,0x49,0x71,0xC5,0xB0,0x51,0xCA,0xAC,
+		0x53,0xC2,0xC5,0x59,0x9E,0x02,0xA7,0xCB,0x82,0xA7,0x98,0x33,
+		0x2D,0x89,0xC4,0x89,0x46,0x86,0xAF,0x1C,0xDC,0xB8,0x52,0xD1,
+		0x06,0x2D,0x94,0x99,0x67,0x76,0xF5,0xE5,0xA3,0x5D,0x87,0x5F,
+		0xD1,0x77,0x3A,0xEA,0x17,0x05,0xC9,0x87,0x9F,0x24,0x82,0xBD,
+		0xDB,0x15,0x1C,0xBB,
+		};
+	static unsigned char dh2048_g[]={
+		0x02,
+		};
+	DH *dh;
+
+	if ((dh=DH_new()) == NULL) return(NULL);
+	dh->p=BN_bin2bn(dh2048_p,sizeof(dh2048_p),NULL);
+	dh->g=BN_bin2bn(dh2048_g,sizeof(dh2048_g),NULL);
+	if ((dh->p == NULL) || (dh->g == NULL))
+		{ DH_free(dh); return(NULL); }
+	return(dh);
+	}
+#endif /* OPENSSL_NO_DH */
diff --git a/src/env.c b/src/env.c
new file mode 100644
index 0000000..8e4a9f5
--- /dev/null
+++ b/src/env.c
@@ -0,0 +1,70 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+/* getpeername() can't be declared in the following includes */
+#define getpeername no_getpeername
+#include <sys/types.h>
+#include <sys/socket.h> /* for AF_INET */
+#include <netinet/in.h>
+#include <arpa/inet.h>  /* for inet_addr() */
+#include <stdlib.h>     /* for getenv() */
+#ifdef __BEOS__
+#include <be/bone/arpa/inet.h> /* for AF_INET */
+#include <be/bone/sys/socket.h> /* for AF_INET */
+#else
+#include <sys/socket.h> /* for AF_INET */
+#endif
+#undef getpeername
+
+int getpeername(int s, struct sockaddr_in *name, int *len) {
+    char *value;
+
+    (void)s; /* skip warning about unused parameter */
+    (void)len; /* skip warning about unused parameter */
+    name->sin_family=AF_INET;
+    if((value=getenv("REMOTE_HOST")))
+        name->sin_addr.s_addr=inet_addr(value);
+    else
+        name->sin_addr.s_addr=htonl(INADDR_ANY);
+    if((value=getenv("REMOTE_PORT")))
+        name->sin_port=htons((uint16_t)atoi(value));
+    else
+        name->sin_port=htons(0); /* dynamic port allocation */
+    return 0;
+}
+
+/* end of env.c */
diff --git a/src/error.ico b/src/error.ico
new file mode 100644
index 0000000..8d9bed4
--- /dev/null
+++ b/src/error.ico
Binary files differ
diff --git a/src/evc.mak b/src/evc.mak
new file mode 100644
index 0000000..3efd7d2
--- /dev/null
+++ b/src/evc.mak
@@ -0,0 +1,167 @@
+# wce.mak for stunnel.exe by Michal Trojnara 2006-2012
+# with help of Pierre Delaage <delaage.pierre@free.fr>
+# pdelaage 20140610 : added UNICODE optional FLAG, always ACTIVE on WCE because of poor ANSI support
+# pdelaage 20140610 : added _WIN32_WCE flag for RC compilation, to preprocess out "HELP" unsupported menu flag on WCE
+# pdelaage 20140610 : ws2 lib is required to get WSAGetLastError routine (absent from winsock lib)
+# pdelaage 20140610 : /Dx86 flag required for X86/Emulator targets, to get proper definition for InterlockedExchange
+# pdelaage 20140610 : /MT flag is NON-SENSE for X86-WCE platforms, it is only meaningful for X86-W32-Desktop.
+#                     for X86-WCE targets, although compiler "cl.exe" is REALLY the same as desktop W32 VS6 C++ compiler,
+#                     the MT flags relating to LIBCMT is useless BECAUSE LIBCMT does NOT exist on WCE. No msvcrt on WCE either...
+
+# pdelaage 20140610 :  Note on /MC flag 
+# For other targets than X86/Emulator, /MC flag is redundant with "/nodefaultlib coredll.lib corelibc.lib" LD lib list.
+# For << X86 / Emulator >> target, as the cl.exe compiler IS the SAME as the standard VS6.0 C++ compiler for Desktop Pentium processor, 
+# /MC flag is in fact NOT existing, thus requiring an explicit linking with core libs by using : 
+# /NODEFAULTLIB coredll.lib corelibc.lib,
+# something that is correct for any WCE target, X86 and other, and leading /MC flag to be useless ALSO for other target than X86.
+
+
+#
+# DEFAULTLIB management: only 2 are necessary
+# defaultlibS, as given for CLxxx in the MS doc, ARE WRONG
+
+# !!!!!!!!!!!!!!
+# CUSTOMIZE THIS according to your wcecompat and openssl directories
+# !!!!!!!!!!!!!!
+
+# Modify this to point to your actual openssl compile directory
+# (You did already compile openssl, didn't you???)
+SSLDIR=C:\Users\pdelaage\Dvts\Contrib\openssl
+
+# Note that we currently use a multi-target customized version of legacy Essemer/wcecompat lib
+COMPATDIR=C:\Users\pdelaage\Dvts\Contrib\wcecompat\v12\patched3emu
+
+WCEVER=420
+
+# !!!!!!!!!!!!!!!!!!
+# END CUSTOMIZATION
+# !!!!!!!!!!!!!!!!!!
+
+!IF "$(TARGETCPU)"=="X86"
+WCETARGETCPU=_X86_
+LDTARGETCPU=X86
+#pdelaage 20140621 /Dx86 for inline defs of InterlockedExchange inline in winbase.h; no more /MT
+MORECFLAGS=/Dx86
+
+# TODO: continue list for other targets : see wcecompat/wcedefs.mak for a good ref.
+# see also openssl/util/pl/vc-32.pl, also link /?
+# for LDTARGETCPU: /MACHINE:{AM33|ARM|IA64|M32R|MIPS|MIPS16|MIPSFPU|MIPSFPU16|MIPSR41XX|SH3|SH3DSP|SH4|SH5|THUMB|X86}
+# see wce/include/winnt.h for other "target architecture" flag
+
+!ELSEIF "$(TARGETCPU)"=="emulator"
+WCETARGETCPU=_X86_
+LDTARGETCPU=X86
+#pdelaage 20140621 /Dx86 for inline defs of InterlockedExchange inline in winbase.h; no more /MT
+MORECFLAGS=/Dx86
+
+!ELSEIF "$(TARGETCPU)"=="MIPS16" || "$(TARGETCPU)"=="MIPSII" || "$(TARGETCPU)"=="MIPSII_FP" || "$(TARGETCPU)"=="MIPSIV" || "$(TARGETCPU)"=="MIPSIV_FP"
+WCETARGETCPU=_MIPS_
+LDTARGETCPU=MIPS
+#pdelaage 20140621  no more /MC required
+MORECFLAGS=/DMIPS
+
+!ELSEIF "$(TARGETCPU)"=="SH3" || "$(TARGETCPU)"=="SH4"
+WCETARGETCPU=SHx
+LDTARGETCPU=$(TARGETCPU)
+#pdelaage 20140621  no more /MC required
+MORECFLAGS=
+
+!ELSE
+# default is ARM !
+# !IF "$(TARGETCPU)"=="ARMV4" || "$(TARGETCPU)"=="ARMV4I" || "$(TARGETCPU)"=="ARMV4T"
+# the following flag is required by (eg) winnt.h, and is different from targetcpu (armV4)
+WCETARGETCPU=ARM
+LDTARGETCPU=ARM
+#pdelaage 20140621  no more /MC required
+MORECFLAGS=
+!ENDIF
+
+# ceutilsdir probably useless (nb : were tools from essemer; but ms delivers a cecopy anyway, see ms dld site)
+CEUTILSDIR=..\..\ceutils
+# "ce:" is not a correct location , but we never "make install"
+DSTDIR=ce:\stunnel
+# use MS env vars, as in wcecompat and openssl makefiles
+SDKDIR=$(SDKROOT)\$(OSVERSION)\$(PLATFORM)
+INCLUDES=-I$(SSLDIR)\inc32 -I$(COMPATDIR)\include -I"$(SDKDIR)\include\$(TARGETCPU)"
+# for X86 and other it appears that /MC or /ML flags are absurd,
+# we always have to override runtime lib list to coredll and corelibc
+#LIBS=/NODEFAULTLIB winsock.lib wcecompatex.lib libeay32.lib ssleay32.lib coredll.lib corelibc.lib
+LIBS=/NODEFAULTLIB ws2.lib      wcecompatex.lib libeay32.lib ssleay32.lib coredll.lib corelibc.lib
+
+DEFINES=/DHOST=\"$(TARGETCPU)-WCE-eVC-$(WCEVER)\"
+# pdelaage 20140610 added unicode flag : ALWAYS ACTIVE on WCE, because of poor ANSI support by the MS SDK
+UNICODEFLAGS=/DUNICODE -D_UNICODE
+# /O1 /Oi more correct vs MS doc
+CFLAGS=/nologo $(MORECFLAGS) /O1 /Oi /W3 /WX /GF /Gy $(DEFINES) /D$(WCETARGETCPU) /D$(TARGETCPU) /DUNDER_CE=$(WCEVER) /D_WIN32_WCE=$(WCEVER) $(UNICODEFLAGS) $(INCLUDES)
+# pdelaage 20140610 : RC compilation requires D_WIN32_WCE flag to comment out unsupported "HELP" flag in menu definition, in resources.rc file
+RFLAGS=$(DEFINES) /D_WIN32_WCE=$(WCEVER) $(INCLUDES)
+
+# LDFLAGS: since openssl >> 098a (eg 098h) out32dll is out32dll_targetCPU for WCE
+# delaage added $(TARGETCPU) in legacy Essemer/wcecompat libpath
+# to ease multitarget compilation without recompiling everything
+# this customized version is available on:
+# http://delaage.pierre.free.fr/contrib/wcecompat/wcecompat12_patched.zip
+
+LDFLAGS=/nologo /subsystem:windowsce,3.00 /machine:$(LDTARGETCPU) /libpath:"$(SDKDIR)\lib\$(TARGETCPU)" /libpath:"$(COMPATDIR)\lib\$(TARGETCPU)" /libpath:"$(SSLDIR)\out32dll_$(TARGETCPU)"
+
+# Multi-target support for stunnel
+
+SRC=..\src
+OBJROOT=..\obj
+OBJ=$(OBJROOT)\$(TARGETCPU)
+BINROOT=..\bin
+BIN=$(BINROOT)\$(TARGETCPU)
+
+OBJS=$(OBJ)\stunnel.obj $(OBJ)\ssl.obj $(OBJ)\ctx.obj $(OBJ)\verify.obj \
+	$(OBJ)\file.obj $(OBJ)\client.obj $(OBJ)\protocol.obj $(OBJ)\sthreads.obj \
+	$(OBJ)\log.obj $(OBJ)\options.obj $(OBJ)\network.obj $(OBJ)\resolver.obj \
+	$(OBJ)\str.obj $(OBJ)\tls.obj $(OBJ)\fd.obj $(OBJ)\dhparam.obj \
+	$(OBJ)\cron.obj
+
+GUIOBJS=$(OBJ)\ui_win_gui.obj $(OBJ)\resources.res
+CLIOBJS=$(OBJ)\ui_win_cli.obj
+
+{$(SRC)\}.c{$(OBJ)\}.obj:
+	$(CC) $(CFLAGS) -Fo$@ -c $<
+
+{$(SRC)\}.cpp{$(OBJ)\}.obj:
+	$(CC) $(CFLAGS) -Fo$@ -c $<
+	
+{$(SRC)\}.rc{$(OBJ)\}.res:
+	$(RC) $(RFLAGS) -fo$@ -r $<
+
+all: makedirs $(BIN)\stunnel.exe $(BIN)\tstunnel.exe
+
+makedirs:
+	-@ IF NOT EXIST $(OBJROOT) mkdir $(OBJROOT) >NUL 2>&1
+	-@ IF NOT EXIST $(OBJ) mkdir $(OBJ) >NUL 2>&1
+	-@ IF NOT EXIST $(BINROOT) mkdir $(BINROOT) >NUL 2>&1
+	-@ IF NOT EXIST $(BIN) mkdir $(BIN) >NUL 2>&1
+
+$(BIN)\stunnel.exe:$(OBJS) $(GUIOBJS)
+	link $(LDFLAGS)  /out:$(BIN)\stunnel.exe $(LIBS) commctrl.lib $**
+
+$(BIN)\tstunnel.exe:$(OBJS) $(CLIOBJS)
+	link $(LDFLAGS)  /out:$(BIN)\tstunnel.exe $(LIBS) $**
+
+$(OBJ)\resources.res: $(SRC)\resources.rc $(SRC)\resources.h $(SRC)\version.h
+$(OBJ)\ui_win_gui.obj: $(SRC)\ui_win_gui.c $(SRC)\version.h
+$(OBJ)\stunnel.obj: $(SRC)\stunnel.c $(SRC)\version.h
+
+# now list of openssl dll has more files,
+# but we do not use "make install" for stunnel
+# ceutils come from essemer/wcecompat website
+# some tools can be found at MS website
+# TODO: update all this ceutils stuff, or suppress it
+
+install: stunnel.exe tstunnel.exe
+	$(CEUTILSDIR)\cemkdir $(DSTDIR) || echo Directory exists?
+	$(CEUTILSDIR)\cecopy stunnel.exe $(DSTDIR)
+	$(CEUTILSDIR)\cecopy tstunnel.exe $(DSTDIR)
+	$(CEUTILSDIR)\cecopy $(SSLDIR)\out32dll_$(TARGETCPU)\libeay32.dll $(DSTDIR)
+	$(CEUTILSDIR)\cecopy $(SSLDIR)\out32dll_$(TARGETCPU)\ssleay32.dll $(DSTDIR)
+
+clean:
+	-@ IF NOT "$(TARGETCPU)"=="" del $(OBJS) $(GUIOBJS) $(CLIOBJS) $(BIN)\stunnel.exe $(BIN)\tstunnel.exe >NUL 2>&1
+	-@ IF NOT "$(TARGETCPU)"=="" rmdir $(OBJ) >NUL 2>&1
+	-@ IF NOT "$(TARGETCPU)"=="" rmdir $(BIN) >NUL 2>&1
diff --git a/src/fd.c b/src/fd.c
new file mode 100644
index 0000000..bb0208f
--- /dev/null
+++ b/src/fd.c
@@ -0,0 +1,259 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#if defined HAVE_PIPE2 && defined HAVE_ACCEPT4
+#define USE_NEW_LINUX_API 1
+#endif
+
+/* try to use non-POSIX O_NDELAY on obsolete BSD systems */
+#if !defined O_NONBLOCK && defined O_NDELAY
+#define O_NONBLOCK O_NDELAY
+#endif
+
+/**************************************** prototypes */
+
+NOEXPORT SOCKET setup_fd(SOCKET, int, char *);
+
+/**************************************** internal limit of file descriptors */
+
+#ifndef USE_FORK
+
+static SOCKET max_fds;
+
+void get_limits(void) { /* set max_fds and max_clients */
+    /* start with current ulimit */
+#if defined(HAVE_SYSCONF)
+    errno=0;
+    max_fds=(SOCKET)sysconf(_SC_OPEN_MAX);
+    if(errno)
+        ioerror("sysconf");
+    if(max_fds<0)
+        max_fds=0; /* unlimited */
+#elif defined(HAVE_GETRLIMIT)
+    struct rlimit rlim;
+
+    if(getrlimit(RLIMIT_NOFILE, &rlim)<0) {
+        ioerror("getrlimit");
+        max_fds=0; /* unlimited */
+    } else
+        max_fds=rlim.rlim_cur!=RLIM_INFINITY ? rlim.rlim_cur : 0;
+#else
+    max_fds=0; /* unlimited */
+#endif /* HAVE_SYSCONF || HAVE_GETRLIMIT */
+
+#if !defined(USE_WIN32) && !defined(USE_POLL) && !defined(__INNOTEK_LIBC__)
+    /* apply FD_SETSIZE if select() is used on Unix */
+    if(!max_fds || max_fds>FD_SETSIZE)
+        max_fds=FD_SETSIZE; /* start with select() limit */
+#endif /* select() on Unix */
+
+    /* stunnel needs at least 16 file desriptors */
+    if(max_fds && max_fds<16)
+        max_fds=16;
+
+    if(max_fds) {
+        max_clients=(long)(max_fds>=256 ? max_fds*125/256 : (max_fds-6)/2);
+        s_log(LOG_DEBUG, "Clients allowed=%ld", max_clients);
+    } else {
+        max_clients=0;
+        s_log(LOG_DEBUG, "No limit detected for the number of clients");
+    }
+}
+
+#endif
+
+/**************************************** file descriptor validation */
+
+SOCKET s_socket(int domain, int type, int protocol, int nonblock, char *msg) {
+    SOCKET fd;
+
+#ifdef USE_NEW_LINUX_API
+    if(nonblock)
+        type|=SOCK_NONBLOCK;
+    type|=SOCK_CLOEXEC;
+#endif
+#ifdef USE_WIN32
+    /* http://stackoverflow.com/questions/4993119 */
+    /* CreateProcess() needs a non-overlapped handle */
+    fd=WSASocket(domain, type, protocol, NULL, 0, 0);
+#else /* USE_WIN32 */
+    fd=socket(domain, type, protocol);
+#endif /* USE_WIN32 */
+    return setup_fd(fd, nonblock, msg);
+}
+
+SOCKET s_accept(SOCKET sockfd, struct sockaddr *addr, socklen_t *addrlen,
+        int nonblock, char *msg) {
+    SOCKET fd;
+
+#ifdef USE_NEW_LINUX_API
+    if(nonblock)
+        fd=accept4(sockfd, addr, addrlen, SOCK_NONBLOCK|SOCK_CLOEXEC);
+    else
+        fd=accept4(sockfd, addr, addrlen, SOCK_CLOEXEC);
+#else
+    fd=accept(sockfd, addr, addrlen);
+#endif
+    return setup_fd(fd, nonblock, msg);
+}
+
+#ifndef USE_WIN32
+
+int s_socketpair(int domain, int type, int protocol, SOCKET sv[2],
+        int nonblock, char *msg) {
+#ifdef USE_NEW_LINUX_API
+    if(nonblock)
+        type|=SOCK_NONBLOCK;
+    type|=SOCK_CLOEXEC;
+#endif
+    if(socketpair(domain, type, protocol, sv)<0) {
+        ioerror(msg);
+        return -1;
+    }
+    if(setup_fd(sv[0], nonblock, msg)<0) {
+        closesocket(sv[1]);
+        return -1;
+    }
+    if(setup_fd(sv[1], nonblock, msg)<0) {
+        closesocket(sv[0]);
+        return -1;
+    }
+    return 0;
+}
+
+int s_pipe(int pipefd[2], int nonblock, char *msg) {
+    int retval;
+
+#ifdef USE_NEW_LINUX_API
+    if(nonblock)
+        retval=pipe2(pipefd, O_NONBLOCK|O_CLOEXEC);
+    else
+        retval=pipe2(pipefd, O_CLOEXEC);
+#else
+    retval=pipe(pipefd);
+#endif
+    if(retval<0) {
+        ioerror(msg);
+        return -1;
+    }
+    if(setup_fd(pipefd[0], nonblock, msg)<0) {
+        close(pipefd[1]);
+        return -1;
+    }
+    if(setup_fd(pipefd[1], nonblock, msg)<0) {
+        close(pipefd[0]);
+        return -1;
+    }
+    return 0;
+}
+
+#endif /* USE_WIN32 */
+
+NOEXPORT SOCKET setup_fd(SOCKET fd, int nonblock, char *msg) {
+#if !defined USE_NEW_LINUX_API && defined FD_CLOEXEC
+    int err;
+#endif
+
+    if(fd==INVALID_SOCKET) {
+        sockerror(msg);
+        return INVALID_SOCKET;
+    }
+#ifndef USE_FORK
+    if(max_fds && fd>=max_fds) {
+        s_log(LOG_ERR, "%s: FD=%d out of range (max %d)",
+            msg, (int)fd, (int)max_fds);
+        closesocket(fd);
+        return INVALID_SOCKET;
+    }
+#endif
+
+#ifdef USE_NEW_LINUX_API
+    (void)nonblock; /* skip warning about unused parameter */
+#else /* set O_NONBLOCK and F_SETFD */
+    set_nonblock(fd, (unsigned long)nonblock);
+#ifdef FD_CLOEXEC
+    do {
+        err=fcntl(fd, F_SETFD, FD_CLOEXEC);
+    } while(err<0 && get_last_socket_error()==S_EINTR);
+    if(err<0)
+        sockerror("fcntl SETFD"); /* non-critical */
+#endif /* FD_CLOEXEC */
+#endif /* USE_NEW_LINUX_API */
+
+#ifdef DEBUG_FD_ALLOC
+    s_log(LOG_DEBUG, "%s: FD=%d allocated (%sblocking mode)",
+        msg, fd, nonblock?"non-":"");
+#endif /* DEBUG_FD_ALLOC */
+
+    return fd;
+}
+
+void set_nonblock(SOCKET fd, unsigned long nonblock) {
+#if defined F_GETFL && defined F_SETFL && defined O_NONBLOCK && !defined __INNOTEK_LIBC__
+    int err, flags;
+
+    do {
+        flags=fcntl(fd, F_GETFL, 0);
+    } while(flags<0 && get_last_socket_error()==S_EINTR);
+    if(flags<0) {
+        sockerror("fcntl GETFL"); /* non-critical */
+        return;
+    }
+    if(nonblock)
+        flags|=O_NONBLOCK;
+    else
+        flags&=~O_NONBLOCK;
+    do {
+        err=fcntl(fd, F_SETFL, flags);
+    } while(err<0 && get_last_socket_error()==S_EINTR);
+    if(err<0)
+        sockerror("fcntl SETFL"); /* non-critical */
+#else /* WIN32 or similar */
+    if(ioctlsocket(fd, (long)FIONBIO, &nonblock)<0)
+        sockerror("ioctlsocket"); /* non-critical */
+#if 0
+    else
+        s_log(LOG_DEBUG, "Socket %d set to %s mode",
+            fd, nonblock ? "non-blocking" : "blocking");
+#endif
+#endif
+}
+
+/* end of fd.c */
diff --git a/src/file.c b/src/file.c
new file mode 100644
index 0000000..55089f8
--- /dev/null
+++ b/src/file.c
@@ -0,0 +1,266 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifdef USE_WIN32
+
+DISK_FILE *file_open(char *name, FILE_MODE mode) {
+    DISK_FILE *df;
+    LPTSTR tname;
+    HANDLE fh;
+    DWORD desired_access, creation_disposition;
+
+    /* open file */
+    switch(mode) {
+    case FILE_MODE_READ:
+        desired_access=GENERIC_READ;
+        creation_disposition=OPEN_EXISTING;
+        break;
+    case FILE_MODE_APPEND:
+            /* reportedly more compatible than FILE_APPEND_DATA */
+        desired_access=GENERIC_WRITE;
+        creation_disposition=OPEN_ALWAYS; /* keep the data */
+        break;
+    case FILE_MODE_OVERWRITE:
+        desired_access=GENERIC_WRITE;
+        creation_disposition=CREATE_ALWAYS; /* remove the data */
+        break;
+    default: /* invalid mode */
+        return NULL;
+    }
+    tname=str2tstr(name);
+    fh=CreateFile(tname, desired_access, FILE_SHARE_READ, NULL,
+        creation_disposition, FILE_ATTRIBUTE_NORMAL, (HANDLE)NULL);
+    str_free(tname); /* str_free() overwrites GetLastError() value */
+    if(fh==INVALID_HANDLE_VALUE)
+        return NULL;
+    if(mode==FILE_MODE_APPEND) /* workaround for FILE_APPEND_DATA */
+        SetFilePointer(fh, 0, NULL, FILE_END);
+
+    /* setup df structure */
+    df=str_alloc(sizeof df);
+    df->fh=fh;
+    return df;
+}
+
+#else /* USE_WIN32 */
+
+DISK_FILE *file_fdopen(int fd) {
+    DISK_FILE *df;
+
+    df=str_alloc(sizeof(DISK_FILE));
+    df->fd=fd;
+    return df;
+}
+
+DISK_FILE *file_open(char *name, FILE_MODE mode) {
+    DISK_FILE *df;
+    int fd, flags;
+
+    /* open file */
+    switch(mode) {
+    case FILE_MODE_READ:
+        flags=O_RDONLY;
+        break;
+    case FILE_MODE_APPEND:
+        flags=O_CREAT|O_WRONLY|O_APPEND;
+        break;
+    case FILE_MODE_OVERWRITE:
+        flags=O_CREAT|O_WRONLY|O_TRUNC;
+        break;
+    default: /* invalid mode */
+        return NULL;
+    }
+#ifdef O_NONBLOCK
+    flags|=O_NONBLOCK;
+#elif defined O_NDELAY
+    flags|=O_NDELAY;
+#endif
+#ifdef O_CLOEXEC
+    flags|=O_CLOEXEC;
+#endif /* O_CLOEXEC */
+    fd=open(name, flags, 0640);
+    if(fd==INVALID_SOCKET)
+        return NULL;
+
+    /* setup df structure */
+    df=str_alloc(sizeof df);
+    df->fd=fd;
+    return df;
+}
+
+#endif /* USE_WIN32 */
+
+void file_close(DISK_FILE *df) {
+    if(!df) /* nothing to do */
+        return;
+#ifdef USE_WIN32
+    CloseHandle(df->fh);
+#else /* USE_WIN32 */
+    if(df->fd>2) /* never close stdin/stdout/stder */
+        close(df->fd);
+#endif /* USE_WIN32 */
+    str_free(df);
+}
+
+ssize_t file_getline(DISK_FILE *df, char *line, int len) {
+    /* this version is really slow, but performance is not important here */
+    /* (no buffering is implemented) */
+    ssize_t i;
+#ifdef USE_WIN32
+    DWORD num;
+#else /* USE_WIN32 */
+    ssize_t num;
+#endif /* USE_WIN32 */
+
+    if(!df) /* not opened */
+        return -1;
+
+    for(i=0; i<len-1; i++) {
+#ifdef USE_WIN32
+        ReadFile(df->fh, line+i, 1, &num, NULL);
+#else /* USE_WIN32 */
+        num=read(df->fd, line+i, 1);
+#endif /* USE_WIN32 */
+        if(num!=1) { /* EOF */
+            if(i) /* any previously retrieved data */
+                break;
+            else
+                return -1;
+        }
+        if(line[i]=='\n') /* LF */
+            break;
+        if(line[i]=='\r') /* CR */
+            --i; /* ignore - it must be the last check */
+    }
+    line[i]='\0';
+    return i;
+}
+
+ssize_t file_putline(DISK_FILE *df, char *line) {
+    char *buff;
+#ifdef USE_WIN32
+    DWORD len, num;
+#else /* USE_WIN32 */
+    size_t len;
+    ssize_t num;
+#endif /* USE_WIN32 */
+
+    len=strlen(line);
+    buff=str_alloc(len+2); /* +2 for CR+LF */
+    strcpy(buff, line);
+#ifdef USE_WIN32
+    buff[len++]='\r'; /* CR */
+#endif /* USE_WIN32 */
+    buff[len++]='\n'; /* LF */
+#ifdef USE_WIN32
+    WriteFile(df->fh, buff, len, &num, NULL);
+#else /* USE_WIN32 */
+    /* no file -> write to stderr */
+    num=write(df ? df->fd : 2, buff, len);
+#endif /* USE_WIN32 */
+    str_free(buff);
+    return (ssize_t)num;
+}
+
+int file_permissions(const char *file_name) {
+#if !defined(USE_WIN32) && !defined(USE_OS2)
+    struct stat sb; /* buffer for stat */
+
+    /* check permissions of the private key file */
+    if(stat(file_name, &sb)) {
+        ioerror(file_name);
+        return 1; /* FAILED */
+    }
+    if(sb.st_mode & 7)
+        s_log(LOG_WARNING,
+            "Insecure file permissions on %s", file_name);
+#else
+    (void)file_name; /* skip warning about unused parameter */
+#endif
+    return 0;
+}
+
+#ifdef USE_WIN32
+
+LPTSTR str2tstr(LPCSTR in) {
+    LPTSTR out;
+#ifdef UNICODE
+    int len;
+
+    len=MultiByteToWideChar(CP_UTF8, 0, in, -1, NULL, 0);
+    if(!len)
+        return str_tprintf(TEXT("MultiByteToWideChar() failed"));
+    out=str_alloc(((size_t)len+1)*sizeof(WCHAR));
+    len=MultiByteToWideChar(CP_UTF8, 0, in, -1, out, len);
+    if(!len) {
+        str_free(out);
+        return str_tprintf(TEXT("MultiByteToWideChar() failed"));
+    }
+#else
+    /* FIXME: convert UTF-8 to native codepage */
+    out=str_dup(in);
+#endif
+    return out;
+}
+
+LPSTR tstr2str(LPCTSTR in) {
+    LPSTR out;
+#ifdef UNICODE
+    int len;
+
+    len=WideCharToMultiByte(CP_UTF8, 0, in, -1, NULL, 0, NULL, NULL);
+    if(!len)
+        return str_printf("WideCharToMultiByte() failed");
+    out=str_alloc((size_t)len+1);
+    len=WideCharToMultiByte(CP_UTF8, 0, in, -1, out, len, NULL, NULL);
+    if(!len) {
+        str_free(out);
+        return str_printf("WideCharToMultiByte() failed");
+    }
+#else
+    /* FIXME: convert native codepage to UTF-8 */
+    out=str_dup(in);
+#endif
+    return out;
+}
+
+#endif /* USE_WIN32 */
+
+/* end of file.c */
diff --git a/src/idle.ico b/src/idle.ico
new file mode 100644
index 0000000..7af82e5
--- /dev/null
+++ b/src/idle.ico
Binary files differ
diff --git a/src/libwrap.c b/src/libwrap.c
new file mode 100644
index 0000000..3df89b0
--- /dev/null
+++ b/src/libwrap.c
@@ -0,0 +1,321 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifdef USE_LIBWRAP
+
+#include <tcpd.h>
+
+#if defined(USE_PTHREAD) && !defined(__CYGWIN__)
+/* http://wiki.osdev.org/Cygwin_Issues#Passing_file_descriptors */
+#define USE_LIBWRAP_POOL
+#endif /* USE_PTHREAD && !__CYGWIN__ */
+
+NOEXPORT int check(char *, int);
+
+int allow_severity=LOG_NOTICE, deny_severity=LOG_WARNING;
+
+#ifdef USE_LIBWRAP_POOL
+#define SERVNAME_LEN 256
+
+NOEXPORT ssize_t read_fd(int, void *, size_t, int *);
+NOEXPORT ssize_t write_fd(int, void *, size_t, int);
+
+unsigned num_processes=0;
+static int *ipc_socket, *busy;
+#endif /* USE_LIBWRAP_POOL */
+
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-Wunused-result"
+#endif /* __GNUC__ */
+int libwrap_init() {
+#ifdef USE_LIBWRAP_POOL
+    unsigned i, j;
+    int rfd, result;
+    char servname[SERVNAME_LEN];
+    static int initialized=0;
+    SERVICE_OPTIONS *opt;
+
+    if(initialized) /* during startup or previous configuration file reload */
+        return 0;
+    for(opt=service_options.next; opt; opt=opt->next)
+        if(opt->option.libwrap) /* libwrap is enabled for this service */
+            break;
+    if(!opt) /* disabled for all sections or inetd mode (no sections) */
+        return 0;
+
+    num_processes=LIBWRAP_CLIENTS;
+    ipc_socket=str_alloc(2*num_processes*sizeof(int));
+    busy=str_alloc(num_processes*sizeof(int));
+    for(i=0; i<num_processes; ++i) { /* spawn a child */
+        if(s_socketpair(AF_UNIX, SOCK_STREAM, 0, ipc_socket+2*i, 0, "libwrap_init"))
+            return 1;
+        switch(fork()) {
+        case -1:    /* error */
+            ioerror("fork");
+            return 1;
+        case  0:    /* child */
+            tls_alloc(NULL, ui_tls, "libwrap");
+            drop_privileges(0); /* libwrap processes are not chrooted */
+            close(0); /* stdin */
+            close(1); /* stdout */
+            if(!global_options.option.foreground) /* for logging in read_fd */
+                close(2); /* stderr */
+            for(j=0; j<=i; ++j) /* close parent-side sockets created so far */
+                close(ipc_socket[2*j]);
+            while(1) { /* main libwrap child loop */
+                if(read_fd(ipc_socket[2*i+1], servname, SERVNAME_LEN, &rfd)<=0)
+                    _exit(0);
+                result=check(servname, rfd);
+                write(ipc_socket[2*i+1], (uint8_t *)&result, sizeof result);
+                if(rfd>=0)
+                    close(rfd);
+            }
+        default:    /* parent */
+            close(ipc_socket[2*i+1]); /* child-side socket */
+        }
+    }
+    initialized=1;
+#endif /* USE_LIBWRAP_POOL */
+    return 0;
+}
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+
+void libwrap_auth(CLI *c, char *accepted_address) {
+    int result=0; /* deny by default */
+#ifdef USE_LIBWRAP_POOL
+    static volatile unsigned num_busy=0, roundrobin=0;
+    unsigned my_process;
+    int retval;
+    static pthread_mutex_t mutex=PTHREAD_MUTEX_INITIALIZER;
+    static pthread_cond_t cond=PTHREAD_COND_INITIALIZER;
+#endif /* USE_LIBWRAP_POOL */
+
+    if(!c->opt->option.libwrap) /* libwrap is disabled for this service */
+        return; /* allow connection */
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    if(c->peer_addr.sa.sa_family==AF_UNIX) {
+        s_log(LOG_INFO, "Libwrap is not supported on Unix sockets");
+        return;
+    }
+#endif
+#ifdef USE_LIBWRAP_POOL
+    if(num_processes) {
+        s_log(LOG_DEBUG, "Waiting for a libwrap process");
+
+        retval=pthread_mutex_lock(&mutex);
+        if(retval) {
+            errno=retval;
+            ioerror("pthread_mutex_lock");
+            longjmp(c->err, 1);
+        }
+        while(num_busy==num_processes) { /* all child processes are busy */
+            retval=pthread_cond_wait(&cond, &mutex);
+            if(retval) {
+                errno=retval;
+                ioerror("pthread_cond_wait");
+                longjmp(c->err, 1);
+            }
+        }
+        while(busy[roundrobin]) /* find a free child process */
+            roundrobin=(roundrobin+1)%num_processes;
+        my_process=roundrobin; /* the process allocated by this thread */
+        ++num_busy; /* the child process has been allocated */
+        busy[my_process]=1; /* mark the child process as busy */
+        retval=pthread_mutex_unlock(&mutex);
+        if(retval) {
+            errno=retval;
+            ioerror("pthread_mutex_unlock");
+            longjmp(c->err, 1);
+        }
+
+        s_log(LOG_DEBUG, "Acquired libwrap process #%d", my_process);
+        write_fd(ipc_socket[2*my_process], c->opt->servname,
+            strlen(c->opt->servname)+1, c->local_rfd.fd);
+        s_read(c, ipc_socket[2*my_process],
+            (uint8_t *)&result, sizeof result);
+        s_log(LOG_DEBUG, "Releasing libwrap process #%d", my_process);
+
+        retval=pthread_mutex_lock(&mutex);
+        if(retval) {
+            errno=retval;
+            ioerror("pthread_mutex_lock");
+            longjmp(c->err, 1);
+        }
+        busy[my_process]=0; /* mark the child process as free */
+        --num_busy; /* the child process has been released */
+        retval=pthread_cond_signal(&cond); /* signal a waiting thread */
+        if(retval) {
+            errno=retval;
+            ioerror("pthread_cond_signal");
+            longjmp(c->err, 1);
+        }
+        retval=pthread_mutex_unlock(&mutex);
+        if(retval) {
+            errno=retval;
+            ioerror("pthread_mutex_unlock");
+            longjmp(c->err, 1);
+        }
+
+        s_log(LOG_DEBUG, "Released libwrap process #%d", my_process);
+    } else
+#endif /* USE_LIBWRAP_POOL */
+    { /* use original, synchronous libwrap calls */
+        enter_critical_section(CRIT_LIBWRAP);
+        result=check(c->opt->servname, c->local_rfd.fd);
+        leave_critical_section(CRIT_LIBWRAP);
+    }
+    if(!result) {
+        s_log(LOG_WARNING, "Service [%s] REFUSED by libwrap from %s",
+            c->opt->servname, accepted_address);
+        s_log(LOG_DEBUG, "See hosts_access(5) manual for details");
+        longjmp(c->err, 1);
+    }
+    s_log(LOG_DEBUG, "Service [%s] permitted by libwrap from %s",
+        c->opt->servname, accepted_address);
+}
+
+NOEXPORT int check(char *name, int fd) {
+    struct request_info request;
+
+    request_init(&request, RQ_DAEMON, name, RQ_FILE, fd, 0);
+    fromhost(&request);
+    return hosts_access(&request);
+}
+
+#ifdef USE_LIBWRAP_POOL
+
+NOEXPORT ssize_t read_fd(SOCKET fd, void *ptr, size_t nbytes, SOCKET *recvfd) {
+    struct msghdr msg;
+    struct iovec iov[1];
+    ssize_t n;
+
+#ifdef HAVE_MSGHDR_MSG_CONTROL
+    union {
+        struct cmsghdr cm;
+        char control[CMSG_SPACE(sizeof(int))];
+    } control_un;
+    struct cmsghdr *cmptr;
+
+    msg.msg_control=control_un.control;
+    msg.msg_controllen=sizeof control_un.control;
+#else
+    int newfd;
+
+    msg.msg_accrights=(caddr_t)&newfd;
+    msg.msg_accrightslen=sizeof(int);
+#endif
+
+    msg.msg_name=NULL;
+    msg.msg_namelen=0;
+
+    iov[0].iov_base=ptr;
+    iov[0].iov_len=nbytes;
+    msg.msg_iov=iov;
+    msg.msg_iovlen=1;
+
+    *recvfd=INVALID_SOCKET; /* descriptor was not passed */
+    n=recvmsg(fd, &msg, 0);
+    if(n<=0)
+        return n;
+
+#ifdef HAVE_MSGHDR_MSG_CONTROL
+    cmptr=CMSG_FIRSTHDR(&msg);
+    if(!cmptr || cmptr->cmsg_len!=CMSG_LEN(sizeof(int)))
+        return n;
+    if(cmptr->cmsg_level!=SOL_SOCKET) {
+        s_log(LOG_ERR, "control level != SOL_SOCKET");
+        return -1;
+    }
+    if(cmptr->cmsg_type!=SCM_RIGHTS) {
+        s_log(LOG_ERR, "control type != SCM_RIGHTS");
+        return -1;
+    }
+    memcpy(recvfd, CMSG_DATA(cmptr), sizeof(int));
+#else
+    if(msg.msg_accrightslen==sizeof(int))
+        *recvfd=newfd;
+#endif
+
+    return n;
+}
+
+NOEXPORT ssize_t write_fd(int fd, void *ptr, size_t nbytes, int sendfd) {
+    struct msghdr msg;
+    struct iovec iov[1];
+
+#ifdef HAVE_MSGHDR_MSG_CONTROL
+    union {
+        struct cmsghdr cm;
+        char control[CMSG_SPACE(sizeof(int))];
+    } control_un;
+    struct cmsghdr *cmptr;
+
+    msg.msg_control=control_un.control;
+    msg.msg_controllen=sizeof control_un.control;
+
+    cmptr=CMSG_FIRSTHDR(&msg);
+    cmptr->cmsg_len=CMSG_LEN(sizeof(int));
+    cmptr->cmsg_level=SOL_SOCKET;
+    cmptr->cmsg_type=SCM_RIGHTS;
+    memcpy(CMSG_DATA(cmptr), &sendfd, sizeof(int));
+#else
+    msg.msg_accrights=(caddr_t)&sendfd;
+    msg.msg_accrightslen=sizeof(int);
+#endif
+
+    msg.msg_name=NULL;
+    msg.msg_namelen=0;
+
+    iov[0].iov_base=ptr;
+    iov[0].iov_len=nbytes;
+    msg.msg_iov=iov;
+    msg.msg_iovlen=1;
+
+    return sendmsg(fd, &msg, 0);
+}
+
+#endif /* USE_LIBWRAP_POOL */
+
+#endif /* USE_LIBWRAP */
+
+/* end of libwrap.c */
diff --git a/src/log.c b/src/log.c
new file mode 100644
index 0000000..dffb5aa
--- /dev/null
+++ b/src/log.c
@@ -0,0 +1,493 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+NOEXPORT void log_raw(const SERVICE_OPTIONS *, const int,
+    const char *, const char *, const char *);
+NOEXPORT void safestring(char *);
+
+static DISK_FILE *outfile=NULL;
+static struct LIST { /* single-linked list of log lines */
+    struct LIST *next;
+    SERVICE_OPTIONS *opt;
+    int level;
+    char *stamp, *id, *text;
+} *head=NULL, *tail=NULL;
+static LOG_MODE mode=LOG_MODE_NONE;
+
+#if !defined(USE_WIN32) && !defined(__vms)
+
+static int syslog_opened=0;
+
+void syslog_open(void) {
+    syslog_close();
+    if(global_options.option.syslog)
+#ifdef __ultrix__
+        openlog(service_options.servname, 0);
+#else
+        openlog(service_options.servname,
+            LOG_CONS|LOG_NDELAY, global_options.log_facility);
+#endif /* __ultrix__ */
+    syslog_opened=1;
+}
+
+void syslog_close(void) {
+    if(syslog_opened) {
+        if(global_options.option.syslog)
+            closelog();
+        syslog_opened=0;
+    }
+}
+
+#endif /* !defined(USE_WIN32) && !defined(__vms) */
+
+int log_open(void) {
+    if(global_options.output_file) { /* 'output' option specified */
+        outfile=file_open(global_options.output_file,
+            global_options.log_file_mode);
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+        if(!outfile) {
+            char appdata[MAX_PATH], *path;
+            if(SHGetFolderPathA(NULL, CSIDL_LOCAL_APPDATA|CSIDL_FLAG_CREATE,
+                    NULL, 0, appdata)==S_OK) {
+                path=str_printf("%s\\%s", appdata, global_options.output_file);
+                outfile=file_open(path, global_options.log_file_mode);
+                if(outfile)
+                    s_log(LOG_NOTICE, "Logging to %s", path);
+                str_free(path);
+            }
+        }
+#endif
+        if(!outfile) {
+            s_log(LOG_ERR, "Cannot open log file: %s",
+                global_options.output_file);
+            return 1;
+        }
+    }
+    log_flush(LOG_MODE_CONFIGURED);
+    return 0;
+}
+
+void log_close(void) {
+    mode=LOG_MODE_NONE;
+    if(outfile) {
+        file_close(outfile);
+        outfile=NULL;
+    }
+}
+
+void log_flush(LOG_MODE new_mode) {
+    struct LIST *tmp;
+
+    /* prevent changing LOG_MODE_CONFIGURED to LOG_MODE_ERROR
+     * once stderr file descriptor is closed */
+    if(mode!=LOG_MODE_CONFIGURED)
+        mode=new_mode;
+
+    enter_critical_section(CRIT_LOG);
+    while(head) {
+        log_raw(head->opt, head->level, head->stamp, head->id, head->text);
+        str_free(head->stamp);
+        str_free(head->id);
+        str_free(head->text);
+        tmp=head;
+        head=head->next;
+        str_free(tmp);
+    }
+    leave_critical_section(CRIT_LOG);
+    head=tail=NULL;
+}
+
+void s_log(int level, const char *format, ...) {
+    va_list ap;
+    char *text, *stamp, *id;
+    struct LIST *tmp;
+#ifdef USE_WIN32
+    DWORD libc_error;
+#else
+    int libc_error;
+#endif
+    int socket_error;
+    time_t gmt;
+    struct tm *timeptr;
+#if defined(HAVE_LOCALTIME_R) && defined(_REENTRANT)
+    struct tm timestruct;
+#endif
+    TLS_DATA *tls_data;
+
+    tls_data=tls_get();
+    if(!tls_data) {
+        tls_data=tls_alloc(NULL, NULL, "log");
+        s_log(LOG_ERR, "INTERNAL ERROR: Uninitialized TLS at %s, line %d",
+            __FILE__, __LINE__);
+    }
+
+    /* performance optimization: skip the trivial case early */
+    if(mode==LOG_MODE_CONFIGURED && level>tls_data->opt->log_level)
+        return;
+
+    libc_error=get_last_error();
+    socket_error=get_last_socket_error();
+
+    /* format the id to be logged */
+    time(&gmt);
+#if defined(HAVE_LOCALTIME_R) && defined(_REENTRANT)
+    timeptr=localtime_r(&gmt, &timestruct);
+#else
+    timeptr=localtime(&gmt);
+#endif
+    stamp=str_printf("%04d.%02d.%02d %02d:%02d:%02d",
+        timeptr->tm_year+1900, timeptr->tm_mon+1, timeptr->tm_mday,
+        timeptr->tm_hour, timeptr->tm_min, timeptr->tm_sec);
+    id=str_printf("LOG%d[%s]", level, tls_data->id);
+
+    /* format the text to be logged */
+    va_start(ap, format);
+    text=str_vprintf(format, ap);
+    va_end(ap);
+    safestring(text);
+
+    if(mode==LOG_MODE_NONE) { /* save the text to log it later */
+        enter_critical_section(CRIT_LOG);
+        tmp=str_alloc_detached(sizeof(struct LIST));
+        tmp->next=NULL;
+        tmp->opt=tls_data->opt;
+        tmp->level=level;
+        tmp->stamp=stamp;
+        str_detach(tmp->stamp);
+        tmp->id=id;
+        str_detach(tmp->id);
+        tmp->text=text;
+        str_detach(tmp->text);
+        if(tail)
+            tail->next=tmp;
+        else
+            head=tmp;
+        tail=tmp;
+        leave_critical_section(CRIT_LOG);
+    } else { /* ready log the text directly */
+        log_raw(tls_data->opt, level, stamp, id, text);
+        str_free(stamp);
+        str_free(id);
+        str_free(text);
+    }
+
+    set_last_error(libc_error);
+    set_last_socket_error(socket_error);
+}
+
+NOEXPORT void log_raw(const SERVICE_OPTIONS *opt,
+        const int level, const char *stamp,
+        const char *id, const char *text) {
+    char *line;
+
+    /* build the line and log it to syslog/file */
+    if(mode==LOG_MODE_CONFIGURED) { /* configured */
+        line=str_printf("%s %s: %s", stamp, id, text);
+        if(level<=opt->log_level) {
+#if !defined(USE_WIN32) && !defined(__vms)
+            if(global_options.option.syslog)
+                syslog(level, "%s: %s", id, text);
+#endif /* USE_WIN32, __vms */
+            if(outfile)
+                file_putline(outfile, line); /* send log to file */
+        }
+    } else if(mode==LOG_MODE_ERROR) {
+        if(level>=0 && level<=7) /* just in case */
+            line=str_printf("[%c] %s", "***!:.  "[level], text);
+        else
+            line=str_printf("[?] %s", text);
+    } else /* LOG_MODE_INFO */
+        line=str_dup(text); /* don't log the time stamp in error mode */
+
+    /* log the line to the UI (GUI, stderr, etc.) */
+    if(mode==LOG_MODE_ERROR ||
+            (mode==LOG_MODE_INFO && level<LOG_DEBUG) ||
+#if defined(USE_WIN32) || defined(USE_JNI)
+            level<=opt->log_level
+#else
+            (level<=opt->log_level &&
+            global_options.option.foreground)
+#endif
+            )
+        ui_new_log(line);
+
+    str_free(line);
+}
+
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-Wformat"
+#pragma GCC diagnostic ignored "-Wformat-extra-args"
+#endif /* __GNUC__ */
+char *log_id(CLI *c) {
+    static volatile unsigned long long seq=0;
+    unsigned long long my_seq;
+    const char table[62]=
+        "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";
+    unsigned char rnd[22];
+    char *uniq;
+    size_t i;
+    unsigned long tid;
+
+    switch(c->opt->log_id) {
+    case LOG_ID_SEQENTIAL:
+        enter_critical_section(CRIT_ID);
+        my_seq=seq++;
+        leave_critical_section(CRIT_ID);
+        return str_printf("%llu", my_seq);
+    case LOG_ID_UNIQUE:
+        if(RAND_bytes(rnd, sizeof rnd)<=0) /* log2(62^22)=130.99 */
+            return str_dup("error");
+        for(i=0; i<sizeof rnd; ++i) {
+            rnd[i]&=63;
+            while(rnd[i]>=62) {
+                if(RAND_bytes(rnd+i, 1)<=0)
+                    return str_dup("error");
+                rnd[i]&=63;
+            }
+        }
+        uniq=str_alloc(sizeof rnd+1);
+        for(i=0; i<sizeof rnd; ++i)
+            uniq[i]=table[rnd[i]];
+        uniq[sizeof rnd]='\0';
+        return uniq;
+    case LOG_ID_THREAD:
+        tid=stunnel_thread_id();
+        if(!tid) /* currently USE_FORK */
+            tid=stunnel_process_id();
+        return str_printf("%lu", tid);
+    }
+    return str_dup("error");
+}
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+
+/* critical problem handling */
+/* str.c functions are not safe to use here */
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-Wunused-result"
+#endif /* __GNUC__ */
+void fatal_debug(char *txt, const char *file, int line) {
+    char msg[80];
+#ifdef USE_WIN32
+    DWORD num;
+#ifdef UNICODE
+    TCHAR tmsg[80];
+#endif
+#endif /* USE_WIN32 */
+
+    snprintf(msg, sizeof msg, /* with newline */
+        "INTERNAL ERROR: %s at %s, line %d\n", txt, file, line);
+
+    if(outfile) {
+#ifdef USE_WIN32
+        WriteFile(outfile->fh, msg, strlen(msg), &num, NULL);
+#else /* USE_WIN32 */
+        /* no file -> write to stderr */
+        /* no meaningful way here to handle the result */
+        write(outfile ? outfile->fd : 2, msg, strlen(msg));
+#endif /* USE_WIN32 */
+    }
+
+#ifndef USE_WIN32
+    if(mode!=LOG_MODE_CONFIGURED || global_options.option.foreground) {
+        fputs(msg, stderr);
+        fflush(stderr);
+    }
+#endif /* !USE_WIN32 */
+
+    snprintf(msg, sizeof msg, /* without newline */
+        "INTERNAL ERROR: %s at %s, line %d", txt, file, line);
+
+#if !defined(USE_WIN32) && !defined(__vms)
+    if(global_options.option.syslog)
+        syslog(LOG_CRIT, "%s", msg);
+#endif /* USE_WIN32, __vms */
+
+#ifdef USE_WIN32
+#ifdef UNICODE
+    if(MultiByteToWideChar(CP_UTF8, 0, msg, -1, tmsg, 80))
+        message_box(tmsg, MB_ICONERROR);
+#else
+    message_box(msg, MB_ICONERROR);
+#endif
+#endif /* USE_WIN32 */
+
+    abort();
+}
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+
+void ioerror(const char *txt) { /* input/output error */
+    log_error(LOG_ERR, (int)get_last_error(), txt);
+}
+
+void sockerror(const char *txt) { /* socket error */
+    log_error(LOG_ERR, get_last_socket_error(), txt);
+}
+
+void log_error(int level, int error, const char *txt) { /* generic error */
+    s_log(level, "%s: %s (%d)", txt, s_strerror(error), error);
+}
+
+char *s_strerror(int errnum) {
+    switch(errnum) {
+#ifdef USE_WIN32
+    case 10004:
+        return "Interrupted system call (WSAEINTR)";
+    case 10009:
+        return "Bad file number (WSAEBADF)";
+    case 10013:
+        return "Permission denied (WSAEACCES)";
+    case 10014:
+        return "Bad address (WSAEFAULT)";
+    case 10022:
+        return "Invalid argument (WSAEINVAL)";
+    case 10024:
+        return "Too many open files (WSAEMFILE)";
+    case 10035:
+        return "Operation would block (WSAEWOULDBLOCK)";
+    case 10036:
+        return "Operation now in progress (WSAEINPROGRESS)";
+    case 10037:
+        return "Operation already in progress (WSAEALREADY)";
+    case 10038:
+        return "Socket operation on non-socket (WSAENOTSOCK)";
+    case 10039:
+        return "Destination address required (WSAEDESTADDRREQ)";
+    case 10040:
+        return "Message too long (WSAEMSGSIZE)";
+    case 10041:
+        return "Protocol wrong type for socket (WSAEPROTOTYPE)";
+    case 10042:
+        return "Bad protocol option (WSAENOPROTOOPT)";
+    case 10043:
+        return "Protocol not supported (WSAEPROTONOSUPPORT)";
+    case 10044:
+        return "Socket type not supported (WSAESOCKTNOSUPPORT)";
+    case 10045:
+        return "Operation not supported on socket (WSAEOPNOTSUPP)";
+    case 10046:
+        return "Protocol family not supported (WSAEPFNOSUPPORT)";
+    case 10047:
+        return "Address family not supported by protocol family (WSAEAFNOSUPPORT)";
+    case 10048:
+        return "Address already in use (WSAEADDRINUSE)";
+    case 10049:
+        return "Can't assign requested address (WSAEADDRNOTAVAIL)";
+    case 10050:
+        return "Network is down (WSAENETDOWN)";
+    case 10051:
+        return "Network is unreachable (WSAENETUNREACH)";
+    case 10052:
+        return "Net dropped connection or reset (WSAENETRESET)";
+    case 10053:
+        return "Software caused connection abort (WSAECONNABORTED)";
+    case 10054:
+        return "Connection reset by peer (WSAECONNRESET)";
+    case 10055:
+        return "No buffer space available (WSAENOBUFS)";
+    case 10056:
+        return "Socket is already connected (WSAEISCONN)";
+    case 10057:
+        return "Socket is not connected (WSAENOTCONN)";
+    case 10058:
+        return "Can't send after socket shutdown (WSAESHUTDOWN)";
+    case 10059:
+        return "Too many references, can't splice (WSAETOOMANYREFS)";
+    case 10060:
+        return "Connection timed out (WSAETIMEDOUT)";
+    case 10061:
+        return "Connection refused (WSAECONNREFUSED)";
+    case 10062:
+        return "Too many levels of symbolic links (WSAELOOP)";
+    case 10063:
+        return "File name too long (WSAENAMETOOLONG)";
+    case 10064:
+        return "Host is down (WSAEHOSTDOWN)";
+    case 10065:
+        return "No Route to Host (WSAEHOSTUNREACH)";
+    case 10066:
+        return "Directory not empty (WSAENOTEMPTY)";
+    case 10067:
+        return "Too many processes (WSAEPROCLIM)";
+    case 10068:
+        return "Too many users (WSAEUSERS)";
+    case 10069:
+        return "Disc Quota Exceeded (WSAEDQUOT)";
+    case 10070:
+        return "Stale NFS file handle (WSAESTALE)";
+    case 10091:
+        return "Network SubSystem is unavailable (WSASYSNOTREADY)";
+    case 10092:
+        return "WINSOCK DLL Version out of range (WSAVERNOTSUPPORTED)";
+    case 10093:
+        return "Successful WSASTARTUP not yet performed (WSANOTINITIALISED)";
+    case 10071:
+        return "Too many levels of remote in path (WSAEREMOTE)";
+    case 11001:
+        return "Host not found (WSAHOST_NOT_FOUND)";
+    case 11002:
+        return "Non-Authoritative Host not found (WSATRY_AGAIN)";
+    case 11003:
+        return "Non-Recoverable errors: FORMERR, REFUSED, NOTIMP (WSANO_RECOVERY)";
+    case 11004:
+        return "Valid name, no data record of requested type (WSANO_DATA)";
+#if 0
+    case 11004: /* typically, only WSANO_DATA is reported */
+        return "No address, look for MX record (WSANO_ADDRESS)";
+#endif
+#endif /* defined USE_WIN32 */
+    default:
+        return strerror(errnum);
+    }
+}
+
+/* replace non-UTF-8 and non-printable control characters with '.' */
+NOEXPORT void safestring(char *c) {
+    for(; *c; ++c)
+        if(!(*c&0x80 || isprint(*c)))
+            *c='.';
+}
+
+/* end of log.c */
diff --git a/src/make.bat b/src/make.bat
new file mode 100644
index 0000000..2961154
--- /dev/null
+++ b/src/make.bat
@@ -0,0 +1,8 @@
+@echo off

+:: pdelaage commented : make.exe -f mingw.mak %1 %2 %3 %4 %5 %6 %7 %8 %9

+:: on Windows, make is Borland make, but mingw.mak is NOW only compatible

+:: with gnu make (due to various improvments I made, for compatibility between

+:: linux and Windows host environments.

+:: and echo OFF is the sign we are HERE on Windows, isn't it?...

+

+mingw32-make.exe -f mingw.mak %1 %2 %3 %4 %5 %6 %7 %8 %9

diff --git a/src/makece.bat b/src/makece.bat
new file mode 100644
index 0000000..8edd440
--- /dev/null
+++ b/src/makece.bat
@@ -0,0 +1,73 @@
+@echo off

+:: created by pdelaage on 20100928

+:: usage : makece ARMV4|X86|... other cpus: see bat scripts in evc/bin

+::     eg  makece X86, makece X86 clean

+::     makece <=> makece ARMV4 all

+:: NEVER DO makece clean ! but makece TARGETCPU clean !

+:: Note : adapt EVC/bin/WCE<target>.bat scripts

+Title WCE STUNNEL

+

+:: !!!!!!!!!!!!!!

+:: CUSTOMIZE THIS according to your EVC INSTALLED ENVIRONMENT

+:: !!!!!!!!!!!!!!

+

+set OSVERSION=WCE420

+set PLATFORM=STANDARDSDK

+set WCEROOT=C:\Program Files\MSEVC4

+set SDKROOT=C:\Program Files\Microsoft SDKs

+

+:: !!!!!!!!!!!!!!!!!!

+:: END CUSTOMIZATION

+:: !!!!!!!!!!!!!!!!!!

+

+:: Define TARGET CPU 

+:: -----------------

+

+:: define "new" target (useful if one wants to compile for various WCE target CPUs)

+if "%1"=="" echo "USAGE : makece TARGETCPU other_make_options..."

+if "%1"=="" echo "TARGETCPU=(ARMV4|ARMV4I|ARMV4T|MIPS16|MIPSII|MIPSII_FP|MIPSIV|MIPSIV_FP|SH3|SH4|X86), other cpu: see bat scripts in evc/bin"

+if "%1"=="" echo "!!! do not hesitate to adapt evc.mak for CPU and/or better compilation flags !!!"

+if "%1"=="" exit /B

+

+:: old code to default to ARMV4, but it is better that users are WARNED that the script now need an explicit target!

+::if "%1"=="" set NEWTGTCPU=ARMV4

+

+if NOT DEFINED TARGETCPU set TARGETCPU=XXXXX

+if NOT "%1"=="" set NEWTGTCPU=%1

+if NOT "%1"=="" shift

+

+echo WCE TARGET CPU is %NEWTGTCPU%

+

+rem Adjust MS EVC env vars

+rem ----------------------

+

+rem Check MSenv vars against our ref values

+

+set isenvok=0

+if "%NEWTGTCPU%"=="%TARGETCPU%"  set /A "isenvok+=1"

+

+if %isenvok%==1 echo WCE ENVIRONMENT OK

+if %isenvok%==1 goto envisok

+

+:: useless since separated tgt folders

+::echo WCE TARGET CPU changed, destroying every obj files

+::del .\*.obj

+

+:: if env is NOT ok, adjust MS EVC env vars to be used by MS WCE<CPU>.BAT

+:: (this is to avoid repetitive pollution of PATH)

+

+echo WCE ENVIRONMENT ADJUSTED

+

+:: call "%WCEROOT%\EVC\WCE420\BIN\WCE%NEWTGTCPU%.BAT"

+call "%WCEROOT%\EVC\%OSVERSION%\bin\WCE%NEWTGTCPU%.BAT"

+

+set TARGETCPU=%NEWTGTCPU%

+

+:envisok

+

+::exit /B

+

+rem make everything

+rem ---------------

+

+nmake /NOLOGO -f evc.mak %1 %2 %3 %4 %5 %6 %7 %8 %9

diff --git a/src/makew32.bat b/src/makew32.bat
new file mode 100644
index 0000000..4fc7780
--- /dev/null
+++ b/src/makew32.bat
@@ -0,0 +1,45 @@
+@echo off

+TITLE W32 STUNNEL 

+::pdelaage 20101026: for use with MS VCexpress 2008 (v9)

+::some trick to avoid re-pollution of env vars as much as possible

+

+:: In multitarget compilation environment, it is better to open a new cmd.exe window

+:: to avoid pollution of PATH from, eg, some previous WCE compilation attempts.

+

+set NEWTGTCPU=W32

+

+rem Adjust MS VC env vars

+rem ---------------------

+

+rem Check MSenv vars against our ref values

+

+set isenvok=0

+if NOT DEFINED TARGETCPU set TARGETCPU=XXXXX

+if "%NEWTGTCPU%"=="%TARGETCPU%"  set /A "isenvok+=1"

+

+if %isenvok%==1 echo W32 ENVIRONMENT OK

+if %isenvok%==1 goto envisok

+

+:: useless since separated tgt folders

+::echo W32 TARGET CPU changed, destroying every obj files

+::del .\*.obj

+

+:: if env is NOT ok, adjust MS VC env vars to be used by MS VC

+:: (this is to avoid repetitive pollution of PATH)

+

+echo W32 ENVIRONMENT ADJUSTED

+

+:: reset of INCLUDE needed because of accumulation of includes in vcvars32

+

+set INCLUDE=

+

+call "C:\Program Files\Microsoft Visual Studio 9.0\VC\bin\vcvars32.bat"

+

+set TARGETCPU=%NEWTGTCPU%

+

+:envisok

+

+rem make everything

+rem ---------------

+

+nmake.exe -f vc.mak %1 %2 %3 %4 %5 %6 %7 %8 %9

diff --git a/src/mingw.mak b/src/mingw.mak
new file mode 100644
index 0000000..311aaaa
--- /dev/null
+++ b/src/mingw.mak
@@ -0,0 +1,163 @@
+# Simple Makefile.w32 for stunnel.exe by Michal Trojnara 1998-2007
+#
+# Modified by Brian Hatch  (bri@stunnel.org)
+# 20101030 pdelaage:
+# + multi-HOST management (if used on Windows host or Linux Host)
+# + lack of gnu-win32 (rm) detection
+# note: rm is used INTERNALLY by gcc for deletion if intermediate files.
+
+# This makefile is only tested on the mingw compiler.  Mingw can successfully
+# compile both openssl and stunnel.  If you want to use another compiler, give
+# it a shot, and tell us how it went.
+
+# pdelaage : THIS makefile can be used with mingw-make on Windows or gnu make
+# on Linux, to produce the Win32 version of stunnel (target is win32).  It
+# requires, on Windows, the use of gnu-win32 tools: rm, mkdir, rmdir that
+# manages files and dirs BOTH on linux and Windows with / as path separator.
+# Note: Native windows equivalent, del and mkdir/rmdir, badly manage / and \,
+# so they cannot be used here.
+# On Windows host, download:
+# http://gnuwin32.sourceforge.net/downlinks/coreutils.php
+# if you have forgotten this, this makefile will remind you...
+ 
+# Modify this to point to your actual openssl compile directory
+# (You did already compile openssl, didn't you???)
+SSLDIR=../openssl-1.0.0f
+#SSLDIR=C:/Users/standard/Documents/Dvts/Contrib/openssl/v1.0.0c/patched3
+
+# c:\, backslash is not correctly recognized by mingw32-make, produces some
+# "missing separator" issue.
+# pdelaage: simple trick to detect if we are using mingw-gcc on a Windows host,
+# or on a linux host.  windir is a system environment variable on windows NT
+# and above, and then redefine some macros.
+# note: ifdef is !IFDEF in MS nmake or Borland make.
+#       $(info is !MESSAGE in MS nmake or Borland make.
+
+ifdef windir
+$(info  host machine is a Windows machine )
+NULLDEV=NUL
+MKDIR="C:\Program Files\GnuWin32\bin\mkdir.exe"
+DELFILES="C:\Program Files\GnuWin32\bin\rm.exe" -f
+DELDIR="C:\Program Files\GnuWin32\bin\rm.exe" -rf
+else
+$(info  host machine is a linux machine )
+NULLDEV=/dev/null
+MKDIR=mkdir
+DELFILES=rm -f
+DELDIR=rm -rf
+endif
+
+TARGETCPU=MGW32
+SRC=../src
+OBJROOT=../obj
+OBJ=$(OBJROOT)/$(TARGETCPU)
+BINROOT=../bin
+BIN=$(BINROOT)/$(TARGETCPU)
+
+OBJS=$(OBJ)/stunnel.o $(OBJ)/ssl.o $(OBJ)/ctx.o $(OBJ)/verify.o \
+	$(OBJ)/file.o $(OBJ)/client.o $(OBJ)/protocol.o $(OBJ)/sthreads.o \
+	$(OBJ)/log.o $(OBJ)/options.o $(OBJ)/network.o $(OBJ)/resolver.o \
+	$(OBJ)/ui_win_gui.o $(OBJ)/resources.o $(OBJ)/str.o $(OBJ)\tls.obj \
+	$(OBJ)/fd.o $(OBJ)/dhparam.o $(OBJ)/cron.o
+
+CC=gcc
+RC=windres
+
+# pdelaage note: as a workaround for windres bug on resources.rc, equivalent to
+# "use a temp file instead of popen" option between cpp and windres!
+RCP=gcc -E -xc-header -DRC_INVOKED
+
+DEFINES=-D_WIN32_WINNT=0x0501
+
+# some preprocessing debug : $(info  DEFINES is $(DEFINES) )
+
+#CFLAGS=-g -O2 -Wall $(DEFINES) -I$(SSLDIR)/outinc
+#pdelaage : outinc not correct, it is inc32!
+CFLAGS=-g -O2 -Wall $(DEFINES) -I$(SSLDIR)/inc32
+
+# RFLAGS, note of pdelaage: windres accepts -fo for compatibility with ms tools
+# default options : -J rc -O coff, input rc file, output coff file.
+
+RFLAGS=-v --use-temp-file $(DEFINES)
+# following RFLAGS2 useful if one day use-temp-file does not exist anymore 
+RFLAGS2=-v $(DEFINES)
+LDFLAGS=-s
+
+# LIBS=-L$(SSLDIR)/out -lssl -lcrypto -lwsock32 -lgdi32 -lcrypt32
+#20101030 pdelaage fix winsock2 and BAD sslpath  ! LIBS=-L$(SSLDIR)/out -lzdll -leay32 -lssl32 -lwsock32 -lgdi32 -lcrypt32
+# added libeay instead of eay, ssleay instead of ssl32, suppressed zdll useless.
+LIBS=-L$(SSLDIR)/out32dll -lssleay32 -llibeay32 -lws2_32 -lpsapi -lgdi32 -lcrypt32
+# IMPORTANT pdelaage : restore this if you need (but I do not see why) -lzdll
+
+$(OBJ)/%.o: $(SRC)/%.c
+	$(CC) $(CFLAGS) -o$@ -c $<
+
+$(OBJ)/%.o: $(SRC)/%.cpp
+	$(CC) $(CFLAGS) -o$@ -c $<
+	
+$(OBJ)/%.o: $(SRC)/%.rc
+	$(RC) $(RFLAGS) -o$@ $<
+
+# pdelaage : trick for windres preprocessing popen bug on Windows, in case the windres option
+# use_temp_file disappear one day...
+# comment out the $(RC) rule above to activate the following 
+
+$(OBJ)/%.rcp: $(SRC)/%.rc
+	$(RCP) $(DEFINES) -o$@ $<
+	
+$(OBJ)/%.o: $(OBJ)/%.rcp
+	$(RC) $(RFLAGS2) -o$@ $<
+
+# Note : gnu-make will automatically RM the intermediate "rcp" file 
+# BUT it will ABSOLUTELY NEED the "rm" command available : not a problem on linux
+# but on a windows dev host machine, one will need to install gnu-win32/rm command
+# in the system...
+# for debug of the preprocessed rcp file, because it is automatically deleted by gnu-make:	cp $< $<.2
+
+all: testenv makedirs $(BIN)/stunnel.exe
+
+#pdelaage : testenv purpose is to detect, on windows, whether Gnu-win32 has been properly installed...
+# a first call to "true" is made to detect availability, a second is made to stop the make process.
+ifdef windir
+testenv:
+	-@ echo OFF
+	-@ true >$(NULLDEV) 2>&1 || echo You MUST install Gnu-Win32 coreutils \
+	from http://gnuwin32.sourceforge.net/downlinks/coreutils.php \
+	and set PATH to include C:\Program Files\GnuWin32\bin
+	@true >$(NULLDEV) 2>&1
+else
+testenv:
+	-@ true >$(NULLDEV) 2>&1 || echo Your system lacks Gnu coreutils tools !!!
+	@true >$(NULLDEV) 2>&1
+endif
+	
+clean: 
+	-@ $(DELFILES) $(OBJ)/*.o
+	-@ $(DELFILES) $(BIN)/stunnel.exe >$(NULLDEV) 2>&1
+	-@ $(DELDIR) $(OBJ)   >$(NULLDEV) 2>&1
+	-@ $(DELDIR) $(BIN)   >$(NULLDEV) 2>&1
+
+makedirs:
+	-@ $(MKDIR) $(OBJROOT) >$(NULLDEV) 2>&1
+	-@ $(MKDIR) $(OBJ) >$(NULLDEV) 2>&1
+	-@ $(MKDIR) $(BINROOT) >$(NULLDEV) 2>&1
+	-@ $(MKDIR) $(BIN) >$(NULLDEV) 2>&1
+
+# pseudo-target for RC-preprocessor debugging  
+# result appears OK, as a text file
+faketest:
+	gcc -E -xc-header -DRC_INVOKED $(DEFINES) -o $(SRC)/resources.rcp $(SRC)/resources.rc  
+
+$(OBJS): *.h mingw.mak
+
+$(BIN)/stunnel.exe: $(OBJS)
+	$(CC) $(LDFLAGS) -o $(BIN)/stunnel.exe $(OBJS) $(LIBS) -mwindows
+
+# "missing separator" issue with mingw32-make: tabs MUST BE TABS in your text
+# editor, and not set of spaces even if your development host is windows.
+# Some \ are badly tolerated by mingw32-make "!" directives, eg as !IF,
+# accepted in MS nmake and Borland make ARE NOT supported by gnu make but they
+# all have their equivalents.
+# Gnu-make is case sensitive, while ms nmake or borland make are not. Anyway,
+# on reference to env vars nmake convert env vars to UPPERCASE macro names...
+
diff --git a/src/network.c b/src/network.c
new file mode 100644
index 0000000..72d5e3c
--- /dev/null
+++ b/src/network.c
@@ -0,0 +1,858 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#if defined(_WIN32) || defined(_WIN32_WCE)
+/* bypass automatic index bound checks in the FD_SET() macro */
+#define FD_SETSIZE 1000000
+#endif
+
+#include "common.h"
+#include "prototypes.h"
+
+/* #define DEBUG_UCONTEXT */
+
+NOEXPORT void s_poll_realloc(s_poll_set *);
+NOEXPORT int get_socket_error(const SOCKET);
+
+/**************************************** s_poll functions */
+
+#ifdef USE_POLL
+
+s_poll_set *s_poll_alloc() {
+    /* it needs to be filled with zeros */
+    return str_alloc(sizeof(s_poll_set));
+}
+
+void s_poll_free(s_poll_set *fds) {
+    if(fds) {
+        str_free(fds->ufds);
+        str_free(fds);
+    }
+}
+
+void s_poll_init(s_poll_set *fds) {
+    fds->nfds=0;
+    fds->allocated=4; /* prealloc 4 file desciptors */
+    s_poll_realloc(fds);
+}
+
+void s_poll_add(s_poll_set *fds, SOCKET fd, int rd, int wr) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds && fds->ufds[i].fd!=fd; i++)
+        ;
+    if(i==fds->nfds) { /* not found */
+        if(i==fds->allocated) {
+            fds->allocated=i+1;
+            s_poll_realloc(fds);
+        }
+        fds->ufds[i].fd=fd;
+        fds->ufds[i].events=0;
+        fds->nfds++;
+    }
+    if(rd) {
+        fds->ufds[i].events|=POLLIN;
+#ifdef POLLRDHUP
+        fds->ufds[i].events|=POLLRDHUP;
+#endif
+    }
+    if(wr)
+        fds->ufds[i].events|=POLLOUT;
+}
+
+void s_poll_remove(s_poll_set *fds, SOCKET fd) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds && fds->ufds[i].fd!=fd; i++)
+        ;
+    if(i<fds->nfds) { /* found */
+        memmove(fds->ufds+i, fds->ufds+i+1,
+            (fds->nfds-i-1)*sizeof(struct pollfd));
+        fds->nfds--;
+    }
+}
+
+int s_poll_canread(s_poll_set *fds, SOCKET fd) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds; i++)
+        if(fds->ufds[i].fd==fd)
+            return fds->ufds[i].revents&(POLLIN|POLLERR);
+    return 0; /* not listed in fds */
+}
+
+int s_poll_canwrite(s_poll_set *fds, SOCKET fd) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds; i++)
+        if(fds->ufds[i].fd==fd)
+            return fds->ufds[i].revents&(POLLOUT|POLLERR);
+    return 0; /* not listed in fds */
+}
+
+/* best doc: http://lxr.free-electrons.com/source/net/ipv4/tcp.c#L456 */
+
+int s_poll_hup(s_poll_set *fds, SOCKET fd) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds; i++)
+        if(fds->ufds[i].fd==fd)
+            return fds->ufds[i].revents&POLLHUP; /* read and write closed */
+    return 0; /* not listed in fds */
+}
+
+int s_poll_rdhup(s_poll_set *fds, SOCKET fd) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds; i++)
+        if(fds->ufds[i].fd==fd)
+#ifdef POLLRDHUP
+            return fds->ufds[i].revents&POLLRDHUP; /* read closed */
+#else
+            return fds->ufds[i].revents&POLLHUP; /* read and write closed */
+#endif
+    return 0; /* not listed in fds */
+}
+
+NOEXPORT void s_poll_realloc(s_poll_set *fds) {
+    fds->ufds=str_realloc(fds->ufds, fds->allocated*sizeof(struct pollfd));
+}
+
+void s_poll_dump(s_poll_set *fds, int level) {
+    unsigned i;
+
+    for(i=0; i<fds->nfds; i++)
+        s_log(level, "fd=%d events=0x%X revents=0x%X",
+            fds->ufds[i].fd, fds->ufds[i].events, fds->ufds[i].revents);
+}
+
+#ifdef USE_UCONTEXT
+
+/* move ready contexts from waiting queue to ready queue */
+NOEXPORT void scan_waiting_queue(void) {
+    int retval;
+    CONTEXT *context, *prev;
+    int min_timeout;
+    unsigned nfds, i;
+    time_t now;
+    static unsigned max_nfds=0;
+    static struct pollfd *ufds=NULL;
+
+    time(&now);
+    /* count file descriptors */
+    min_timeout=-1; /* infinity */
+    nfds=0;
+    for(context=waiting_head; context; context=context->next) {
+        nfds+=context->fds->nfds;
+        if(context->finish>=0) /* finite time */
+            if(min_timeout<0 || min_timeout>context->finish-now)
+                min_timeout=
+                    (int)(context->finish-now<0 ? 0 : context->finish-now);
+    }
+    /* setup ufds structure */
+    if(nfds>max_nfds) { /* need to allocate more memory */
+        ufds=str_realloc(ufds, nfds*sizeof(struct pollfd));
+        max_nfds=nfds;
+    }
+    nfds=0;
+    for(context=waiting_head; context; context=context->next)
+        for(i=0; i<context->fds->nfds; i++) {
+            ufds[nfds].fd=context->fds->ufds[i].fd;
+            ufds[nfds].events=context->fds->ufds[i].events;
+            nfds++;
+        }
+
+#ifdef DEBUG_UCONTEXT
+    s_log(LOG_DEBUG, "Waiting %d second(s) for %d file descriptor(s)",
+        min_timeout, nfds);
+#endif
+    do { /* skip "Interrupted system call" errors */
+        retval=poll(ufds, nfds, min_timeout<0 ? -1 : 1000*min_timeout);
+    } while(retval<0 && get_last_socket_error()==S_EINTR);
+    time(&now);
+    /* process the returned data */
+    nfds=0;
+    prev=NULL; /* previous element of the waiting queue */
+    context=waiting_head;
+    while(context) {
+        context->ready=0;
+        /* count ready file descriptors in each context */
+        for(i=0; i<context->fds->nfds; i++) {
+            context->fds->ufds[i].revents=ufds[nfds].revents;
+#ifdef DEBUG_UCONTEXT
+            s_log(LOG_DEBUG, "CONTEXT %ld, FD=%d,%s%s ->%s%s%s%s%s",
+                context->id, ufds[nfds].fd,
+                ufds[nfds].events & POLLIN ? " IN" : "",
+                ufds[nfds].events & POLLOUT ? " OUT" : "",
+                ufds[nfds].revents & POLLIN ? " IN" : "",
+                ufds[nfds].revents & POLLOUT ? " OUT" : "",
+                ufds[nfds].revents & POLLERR ? " ERR" : "",
+                ufds[nfds].revents & POLLHUP ? " HUP" : "",
+                ufds[nfds].revents & POLLNVAL ? " NVAL" : "");
+#endif
+            if(ufds[nfds].revents)
+                context->ready++;
+            nfds++;
+        }
+        if(context->ready || (context->finish>=0 && context->finish<=now)) {
+            /* remove context from the waiting queue */
+            if(prev)
+                prev->next=context->next;
+            else
+                waiting_head=context->next;
+            if(!context->next) /* same as context==waiting_tail */
+                waiting_tail=prev;
+
+            /* append context context to the ready queue */
+            context->next=NULL;
+            if(ready_tail)
+                ready_tail->next=context;
+            ready_tail=context;
+            if(!ready_head)
+                ready_head=context;
+        } else { /* leave the context context in the waiting queue */
+            prev=context;
+        }
+        context=prev ? prev->next : waiting_head;
+    }
+}
+
+int s_poll_wait(s_poll_set *fds, int sec, int msec) {
+    CONTEXT *context; /* current context */
+    static CONTEXT *to_free=NULL; /* delayed memory deallocation */
+
+    /* FIXME: msec parameter is currently ignored with UCONTEXT threads */
+    (void)msec; /* skip warning about unused parameter */
+
+    /* remove the current context from ready queue */
+    context=ready_head;
+    ready_head=ready_head->next;
+    if(!ready_head) /* the queue is empty */
+        ready_tail=NULL;
+    /* it is safe to s_log() after new ready_head is set */
+
+    /* it is illegal to deallocate the stack of the current context */
+    if(to_free) { /* a delayed deallocation is scheduled */
+#ifdef DEBUG_UCONTEXT
+        s_log(LOG_DEBUG, "Releasing context %ld", to_free->id);
+#endif
+        str_free(to_free->stack);
+        str_free(to_free);
+        to_free=NULL;
+    }
+
+    /* manage the current thread */
+    if(fds) { /* something to wait for -> swap the context */
+        context->fds=fds; /* set file descriptors to wait for */
+        context->finish=sec<0 ? -1 : time(NULL)+sec;
+
+        /* append the current context to the waiting queue */
+        context->next=NULL;
+        if(waiting_tail)
+            waiting_tail->next=context;
+        waiting_tail=context;
+        if(!waiting_head)
+            waiting_head=context;
+    } else { /* nothing to wait for -> drop the context */
+        to_free=context; /* schedule for delayed deallocation */
+    }
+
+    while(!ready_head) /* wait until there is a thread to switch to */
+        scan_waiting_queue();
+
+    /* switch threads */
+    if(fds) { /* swap the current context */
+        if(context->id!=ready_head->id) {
+#ifdef DEBUG_UCONTEXT
+            s_log(LOG_DEBUG, "Context swap: %ld -> %ld",
+                context->id, ready_head->id);
+#endif
+            swapcontext(&context->context, &ready_head->context);
+#ifdef DEBUG_UCONTEXT
+            s_log(LOG_DEBUG, "Current context: %ld", ready_head->id);
+#endif
+        }
+        return ready_head->ready;
+    } else { /* drop the current context */
+#ifdef DEBUG_UCONTEXT
+        s_log(LOG_DEBUG, "Context set: %ld (dropped) -> %ld",
+            context->id, ready_head->id);
+#endif
+        setcontext(&ready_head->context);
+        ioerror("setcontext"); /* should not ever happen */
+        return 0;
+    }
+}
+
+#else /* USE_UCONTEXT */
+
+int s_poll_wait(s_poll_set *fds, int sec, int msec) {
+    int retval;
+
+    do { /* skip "Interrupted system call" errors */
+        retval=poll(fds->ufds, fds->nfds, sec<0 ? -1 : 1000*sec+msec);
+    } while(retval<0 && get_last_socket_error()==S_EINTR);
+    return retval;
+}
+
+#endif /* USE_UCONTEXT */
+
+#else /* select */
+
+s_poll_set *s_poll_alloc() {
+    /* it needs to be filled with zeros */
+    return str_alloc(sizeof(s_poll_set));
+}
+
+void s_poll_free(s_poll_set *fds) {
+    if(fds) {
+        str_free(fds->irfds);
+        str_free(fds->iwfds);
+        str_free(fds->ixfds);
+        str_free(fds->orfds);
+        str_free(fds->owfds);
+        str_free(fds->oxfds);
+        str_free(fds);
+    }
+}
+
+void s_poll_init(s_poll_set *fds) {
+#ifdef USE_WIN32
+    fds->allocated=4; /* prealloc 4 file desciptors */
+#endif
+    s_poll_realloc(fds);
+    FD_ZERO(fds->irfds);
+    FD_ZERO(fds->iwfds);
+    FD_ZERO(fds->ixfds);
+    fds->max=0; /* no file descriptors */
+}
+
+void s_poll_add(s_poll_set *fds, SOCKET fd, int rd, int wr) {
+#ifdef USE_WIN32
+    /* fds->ixfds contains union of fds->irfds and fds->iwfds */
+    if(fds->ixfds->fd_count>=fds->allocated) {
+        fds->allocated=fds->ixfds->fd_count+1;
+        s_poll_realloc(fds);
+    }
+#endif
+    if(rd)
+        FD_SET(fd, fds->irfds);
+    if(wr)
+        FD_SET(fd, fds->iwfds);
+    /* always expect errors (and the Spanish Inquisition) */
+    FD_SET(fd, fds->ixfds);
+    if(fd>fds->max)
+        fds->max=fd;
+}
+
+void s_poll_remove(s_poll_set *fds, SOCKET fd) {
+    FD_CLR(fd, fds->irfds);
+    FD_CLR(fd, fds->iwfds);
+    FD_CLR(fd, fds->ixfds);
+}
+
+int s_poll_canread(s_poll_set *fds, SOCKET fd) {
+    return FD_ISSET(fd, fds->orfds) || FD_ISSET(fd, fds->oxfds);
+}
+
+int s_poll_canwrite(s_poll_set *fds, SOCKET fd) {
+    return FD_ISSET(fd, fds->owfds) || FD_ISSET(fd, fds->oxfds);
+}
+
+int s_poll_hup(s_poll_set *fds, SOCKET fd) {
+    (void)fds; /* skip warning about unused parameter */
+    (void)fd; /* skip warning about unused parameter */
+    return 0; /* FIXME: how to detect HUP condition with select()? */
+}
+
+int s_poll_rdhup(s_poll_set *fds, SOCKET fd) {
+    (void)fds; /* skip warning about unused parameter */
+    (void)fd; /* skip warning about unused parameter */
+    return 0; /* FIXME: how to detect RDHUP condition with select()? */
+}
+
+#ifdef USE_WIN32
+#define FD_SIZE(fds) (sizeof(u_int)+(fds)->allocated*sizeof(SOCKET))
+#else
+#define FD_SIZE(fds) (sizeof(fd_set))
+#endif
+
+int s_poll_wait(s_poll_set *fds, int sec, int msec) {
+    int retval;
+    struct timeval tv, *tv_ptr;
+
+    do { /* skip "Interrupted system call" errors */
+        memcpy(fds->orfds, fds->irfds, FD_SIZE(fds));
+        memcpy(fds->owfds, fds->iwfds, FD_SIZE(fds));
+        memcpy(fds->oxfds, fds->ixfds, FD_SIZE(fds));
+        if(sec<0) { /* infinite timeout */
+            tv_ptr=NULL;
+        } else {
+            tv.tv_sec=sec;
+            tv.tv_usec=1000*msec;
+            tv_ptr=&tv;
+        }
+        retval=select((int)fds->max+1,
+            fds->orfds, fds->owfds, fds->oxfds, tv_ptr);
+    } while(retval<0 && get_last_socket_error()==S_EINTR);
+    return retval;
+}
+
+NOEXPORT void s_poll_realloc(s_poll_set *fds) {
+    fds->irfds=str_realloc(fds->irfds, FD_SIZE(fds));
+    fds->iwfds=str_realloc(fds->iwfds, FD_SIZE(fds));
+    fds->ixfds=str_realloc(fds->ixfds, FD_SIZE(fds));
+    fds->orfds=str_realloc(fds->orfds, FD_SIZE(fds));
+    fds->owfds=str_realloc(fds->owfds, FD_SIZE(fds));
+    fds->oxfds=str_realloc(fds->oxfds, FD_SIZE(fds));
+}
+
+void s_poll_dump(s_poll_set *fds, int level) {
+    SOCKET fd;
+    int ir, iw, ix, or, ow, ox;
+
+    for(fd=0; fd<fds->max; fd++) {
+        ir=FD_ISSET(fd, fds->irfds);
+        iw=FD_ISSET(fd, fds->iwfds);
+        ix=FD_ISSET(fd, fds->ixfds);
+        or=FD_ISSET(fd, fds->orfds);
+        ow=FD_ISSET(fd, fds->owfds);
+        ox=FD_ISSET(fd, fds->oxfds);
+        if(ir || iw || ix || or || ow || ox)
+            s_log(level, "fd=%d ifds=%c%c%c ofds=%c%c%c", fd,
+                ir?'r':'-', iw?'w':'-', ix?'x':'-',
+                or?'r':'-', ow?'w':'-', ox?'x':'-');
+    }
+}
+
+#endif /* USE_POLL */
+
+/**************************************** fd management */
+
+int set_socket_options(SOCKET s, int type) {
+    SOCK_OPT *ptr;
+    extern SOCK_OPT sock_opts[];
+    static char *type_str[3]={"accept", "local", "remote"};
+    socklen_t opt_size;
+    int retval=0; /* no error found */
+
+    for(ptr=sock_opts; ptr->opt_str; ptr++) {
+        if(!ptr->opt_val[type])
+            continue; /* default */
+        switch(ptr->opt_type) {
+        case TYPE_LINGER:
+            opt_size=sizeof(struct linger);
+            break;
+        case TYPE_TIMEVAL:
+            opt_size=sizeof(struct timeval);
+            break;
+        case TYPE_STRING:
+            opt_size=(socklen_t)strlen(ptr->opt_val[type]->c_val)+1;
+            break;
+        default:
+            opt_size=sizeof(int);
+        }
+        if(setsockopt(s, ptr->opt_level, ptr->opt_name,
+                (void *)ptr->opt_val[type], opt_size)) {
+            if(get_last_socket_error()==S_EOPNOTSUPP) {
+                /* most likely stdin/stdout or AF_UNIX socket */
+                s_log(LOG_DEBUG,
+                    "Option %s not supported on %s socket",
+                    ptr->opt_str, type_str[type]);
+            } else {
+                sockerror(ptr->opt_str);
+                retval=-1; /* failed to set this option */
+            }
+        }
+#ifdef DEBUG_FD_ALLOC
+        else {
+            s_log(LOG_DEBUG, "Option %s set on %s socket",
+                ptr->opt_str, type_str[type]);
+        }
+#endif /* DEBUG_FD_ALLOC */
+    }
+    return retval; /* returns 0 when all options succeeded */
+}
+
+NOEXPORT int get_socket_error(const SOCKET fd) {
+    int err;
+    socklen_t optlen=sizeof err;
+
+    if(getsockopt(fd, SOL_SOCKET, SO_ERROR, (void *)&err, &optlen))
+        err=get_last_socket_error(); /* failed -> ask why */
+    return err==S_ENOTSOCK ? 0 : err;
+}
+
+/**************************************** simulate blocking I/O */
+
+int s_connect(CLI *c, SOCKADDR_UNION *addr, socklen_t addrlen) {
+    int error;
+    char *dst;
+
+    dst=s_ntop(addr, addrlen);
+    s_log(LOG_INFO, "s_connect: connecting %s", dst);
+
+    if(!connect(c->fd, &addr->sa, addrlen)) {
+        s_log(LOG_INFO, "s_connect: connected %s", dst);
+        str_free(dst);
+        return 0; /* no error -> success (on some OSes over the loopback) */
+    }
+    error=get_last_socket_error();
+    if(error!=S_EINPROGRESS && error!=S_EWOULDBLOCK) {
+        s_log(LOG_ERR, "s_connect: connect %s: %s (%d)",
+            dst, s_strerror(error), error);
+        str_free(dst);
+        return -1;
+    }
+
+    s_log(LOG_DEBUG, "s_connect: s_poll_wait %s: waiting %d seconds",
+        dst, c->opt->timeout_connect);
+    s_poll_init(c->fds);
+    s_poll_add(c->fds, c->fd, 1, 1);
+    switch(s_poll_wait(c->fds, c->opt->timeout_connect, 0)) {
+    case -1:
+        error=get_last_socket_error();
+        s_log(LOG_ERR, "s_connect: s_poll_wait %s: %s (%d)",
+            dst, s_strerror(error), error);
+        str_free(dst);
+        return -1;
+    case 0:
+        s_log(LOG_ERR, "s_connect: s_poll_wait %s:"
+            " TIMEOUTconnect exceeded", dst);
+        str_free(dst);
+        return -1;
+    default:
+        error=get_socket_error(c->fd);
+        if(error) {
+            s_log(LOG_ERR, "s_connect: connect %s: %s (%d)",
+               dst, s_strerror(error), error);
+            str_free(dst);
+            return -1;
+        }
+        if(s_poll_canwrite(c->fds, c->fd)) {
+            s_log(LOG_NOTICE, "s_connect: connected %s", dst);
+            str_free(dst);
+            return 0; /* success */
+        }
+        s_log(LOG_ERR, "s_connect: s_poll_wait %s: internal error",
+            dst);
+        str_free(dst);
+        return -1;
+    }
+    return -1; /* should not be possible */
+}
+
+void s_write(CLI *c, SOCKET fd, const void *buf, size_t len) {
+        /* simulate a blocking write */
+    uint8_t *ptr=(uint8_t *)buf;
+    ssize_t num;
+
+    while(len>0) {
+        s_poll_init(c->fds);
+        s_poll_add(c->fds, fd, 0, 1); /* write */
+        switch(s_poll_wait(c->fds, c->opt->timeout_busy, 0)) {
+        case -1:
+            sockerror("s_write: s_poll_wait");
+            longjmp(c->err, 1); /* error */
+        case 0:
+            s_log(LOG_INFO, "s_write: s_poll_wait:"
+                " TIMEOUTbusy exceeded: sending reset");
+            longjmp(c->err, 1); /* timeout */
+        case 1:
+            break; /* OK */
+        default:
+            s_log(LOG_ERR, "s_write: s_poll_wait: unknown result");
+            longjmp(c->err, 1); /* error */
+        }
+        num=writesocket(fd, (void *)ptr, len);
+        if(num==-1) { /* error */
+            sockerror("writesocket (s_write)");
+            longjmp(c->err, 1);
+        }
+        ptr+=(size_t)num;
+        len-=(size_t)num;
+    }
+}
+
+void s_read(CLI *c, SOCKET fd, void *ptr, size_t len) {
+        /* simulate a blocking read */
+    ssize_t num;
+
+    while(len>0) {
+        s_poll_init(c->fds);
+        s_poll_add(c->fds, fd, 1, 0); /* read */
+        switch(s_poll_wait(c->fds, c->opt->timeout_busy, 0)) {
+        case -1:
+            sockerror("s_read: s_poll_wait");
+            longjmp(c->err, 1); /* error */
+        case 0:
+            s_log(LOG_INFO, "s_read: s_poll_wait:"
+                " TIMEOUTbusy exceeded: sending reset");
+            longjmp(c->err, 1); /* timeout */
+        case 1:
+            break; /* OK */
+        default:
+            s_log(LOG_ERR, "s_read: s_poll_wait: unknown result");
+            longjmp(c->err, 1); /* error */
+        }
+        num=readsocket(fd, ptr, len);
+        switch(num) {
+        case -1: /* error */
+            sockerror("readsocket (s_read)");
+            longjmp(c->err, 1);
+        case 0: /* EOF */
+            s_log(LOG_ERR, "Unexpected socket close (s_read)");
+            longjmp(c->err, 1);
+        }
+        ptr=(uint8_t *)ptr+num;
+        len-=(size_t)num;
+    }
+}
+
+void fd_putline(CLI *c, SOCKET fd, const char *line) {
+    char *tmpline;
+    const char crlf[]="\r\n";
+    size_t len;
+
+    tmpline=str_printf("%s%s", line, crlf);
+    len=strlen(tmpline);
+    s_write(c, fd, tmpline, len);
+    tmpline[len-2]='\0'; /* remove CRLF */
+    s_log(LOG_DEBUG, " -> %s", tmpline);
+    str_free(tmpline);
+}
+
+char *fd_getline(CLI *c, SOCKET fd) {
+    char *line;
+    size_t ptr=0, allocated=32;
+
+    line=str_alloc(allocated);
+    for(;;) {
+        if(ptr>65536) { /* >64KB --> DoS protection */
+            s_log(LOG_ERR, "fd_getline: Line too long");
+            str_free(line);
+            longjmp(c->err, 1);
+        }
+        if(allocated<ptr+1) {
+            allocated*=2;
+            line=str_realloc(line, allocated);
+        }
+        s_read(c, fd, line+ptr, 1);
+        if(line[ptr]=='\r')
+            continue;
+        if(line[ptr]=='\n')
+            break;
+        if(line[ptr]=='\0')
+            break;
+        ++ptr;
+    }
+    line[ptr]='\0';
+    s_log(LOG_DEBUG, " <- %s", line);
+    return line;
+}
+
+void fd_printf(CLI *c, SOCKET fd, const char *format, ...) {
+    va_list ap;
+    char *line;
+
+    va_start(ap, format);
+    line=str_vprintf(format, ap);
+    va_end(ap);
+    if(!line) {
+        s_log(LOG_ERR, "fd_printf: str_vprintf failed");
+        longjmp(c->err, 1);
+    }
+    fd_putline(c, fd, line);
+    str_free(line);
+}
+
+void s_ssl_write(CLI *c, const void *buf, int len) {
+        /* simulate a blocking SSL_write */
+    uint8_t *ptr=(uint8_t *)buf;
+    int num;
+
+    while(len>0) {
+        s_poll_init(c->fds);
+        s_poll_add(c->fds, c->ssl_wfd->fd, 0, 1); /* write */
+        switch(s_poll_wait(c->fds, c->opt->timeout_busy, 0)) {
+        case -1:
+            sockerror("s_write: s_poll_wait");
+            longjmp(c->err, 1); /* error */
+        case 0:
+            s_log(LOG_INFO, "s_write: s_poll_wait:"
+                " TIMEOUTbusy exceeded: sending reset");
+            longjmp(c->err, 1); /* timeout */
+        case 1:
+            break; /* OK */
+        default:
+            s_log(LOG_ERR, "s_write: s_poll_wait: unknown result");
+            longjmp(c->err, 1); /* error */
+        }
+        num=SSL_write(c->ssl, (void *)ptr, len);
+        if(num==-1) { /* error */
+            sockerror("SSL_write (s_ssl_write)");
+            longjmp(c->err, 1);
+        }
+        ptr+=num;
+        len-=num;
+    }
+}
+
+void s_ssl_read(CLI *c, void *ptr, int len) {
+        /* simulate a blocking SSL_read */
+    int num;
+
+    while(len>0) {
+        if(!SSL_pending(c->ssl)) {
+            s_poll_init(c->fds);
+            s_poll_add(c->fds, c->ssl_rfd->fd, 1, 0); /* read */
+            switch(s_poll_wait(c->fds, c->opt->timeout_busy, 0)) {
+            case -1:
+                sockerror("s_read: s_poll_wait");
+                longjmp(c->err, 1); /* error */
+            case 0:
+                s_log(LOG_INFO, "s_read: s_poll_wait:"
+                    " TIMEOUTbusy exceeded: sending reset");
+                longjmp(c->err, 1); /* timeout */
+            case 1:
+                break; /* OK */
+            default:
+                s_log(LOG_ERR, "s_read: s_poll_wait: unknown result");
+                longjmp(c->err, 1); /* error */
+            }
+        }
+        num=SSL_read(c->ssl, ptr, len);
+        switch(num) {
+        case -1: /* error */
+            sockerror("SSL_read (s_ssl_read)");
+            longjmp(c->err, 1);
+        case 0: /* EOF */
+            s_log(LOG_ERR, "Unexpected socket close (s_ssl_read)");
+            longjmp(c->err, 1);
+        }
+        ptr=(uint8_t *)ptr+num;
+        len-=num;
+    }
+}
+
+char *ssl_getstring(CLI *c) { /* get null-terminated string */
+    char *line;
+    size_t ptr=0, allocated=32;
+
+    line=str_alloc(allocated);
+    for(;;) {
+        if(ptr>65536) { /* >64KB --> DoS protection */
+            s_log(LOG_ERR, "fd_getline: Line too long");
+            str_free(line);
+            longjmp(c->err, 1);
+        }
+        if(allocated<ptr+1) {
+            allocated*=2;
+            line=str_realloc(line, allocated);
+        }
+        s_ssl_read(c, line+ptr, 1);
+        if(line[ptr]=='\0')
+            break;
+        ++ptr;
+    }
+    return line;
+}
+
+#define INET_SOCKET_PAIR
+
+int make_sockets(SOCKET fd[2]) { /* make a pair of connected ipv4 sockets */
+#ifdef INET_SOCKET_PAIR
+    struct sockaddr_in addr;
+    socklen_t addrlen;
+    SOCKET s; /* temporary socket awaiting for connection */
+
+    /* create two *blocking* sockets first */
+    s=s_socket(AF_INET, SOCK_STREAM, 0, 0, "make_sockets: s_socket#1");
+    if(s==INVALID_SOCKET)
+        return 1;
+    fd[1]=s_socket(AF_INET, SOCK_STREAM, 0, 0, "make_sockets: s_socket#2");
+    if(fd[1]==INVALID_SOCKET) {
+        closesocket(s);
+        return 1;
+    }
+
+    addrlen=sizeof addr;
+    memset(&addr, 0, sizeof addr);
+    addr.sin_family=AF_INET;
+    addr.sin_addr.s_addr=htonl(INADDR_LOOPBACK);
+    addr.sin_port=htons(0); /* dynamic port allocation */
+    if(bind(s, (struct sockaddr *)&addr, addrlen))
+        log_error(LOG_DEBUG, get_last_socket_error(), "make_sockets: bind#1");
+    if(bind(fd[1], (struct sockaddr *)&addr, addrlen))
+        log_error(LOG_DEBUG, get_last_socket_error(), "make_sockets: bind#2");
+
+    if(listen(s, 1)) {
+        sockerror("make_sockets: listen");
+        closesocket(s);
+        closesocket(fd[1]);
+        return 1;
+    }
+    if(getsockname(s, (struct sockaddr *)&addr, &addrlen)) {
+        sockerror("make_sockets: getsockname");
+        closesocket(s);
+        closesocket(fd[1]);
+        return 1;
+    }
+    if(connect(fd[1], (struct sockaddr *)&addr, addrlen)) {
+        sockerror("make_sockets: connect");
+        closesocket(s);
+        closesocket(fd[1]);
+        return 1;
+    }
+    fd[0]=s_accept(s, (struct sockaddr *)&addr, &addrlen, 1,
+        "make_sockets: s_accept");
+    if(fd[0]==INVALID_SOCKET) {
+        closesocket(s);
+        closesocket(fd[1]);
+        return 1;
+    }
+    closesocket(s); /* don't care about the result */
+    set_nonblock(fd[0], 1);
+    set_nonblock(fd[1], 1);
+#else
+    if(s_socketpair(AF_UNIX, SOCK_STREAM, 0, fd, 1, "make_sockets: socketpair"))
+        return 1;
+#endif
+    return 0;
+}
+
+/* end of network.c */
diff --git a/src/options.c b/src/options.c
new file mode 100644
index 0000000..01edddd
--- /dev/null
+++ b/src/options.c
@@ -0,0 +1,3461 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#if defined(_WIN32_WCE) && !defined(CONFDIR)
+#define CONFDIR "\\stunnel"
+#endif
+
+#define CONFLINELEN (16*1024)
+
+typedef enum {
+    CMD_BEGIN,      /* initialize defaults */
+    CMD_EXEC,       /* process command */
+    CMD_END,        /* end of section */
+    CMD_FREE,       /* TODO: deallocate memory */
+    CMD_DEFAULT,    /* print default value */
+    CMD_HELP        /* print help */
+} CMD;
+
+NOEXPORT int options_file(char *, CONF_TYPE, SERVICE_OPTIONS **);
+NOEXPORT int options_include(char *, SERVICE_OPTIONS **);
+#ifdef USE_WIN32
+struct dirent {
+    char d_name[MAX_PATH];
+};
+int scandir(const char *, struct dirent ***,
+    int (*)(const struct dirent *),
+    int (*)(const struct dirent **, const struct dirent **));
+int alphasort(const struct dirent **, const struct dirent **);
+#endif
+NOEXPORT char *parse_global_option(CMD, char *, char *);
+NOEXPORT char *parse_service_option(CMD, SERVICE_OPTIONS *, char *, char *);
+
+#ifndef OPENSSL_NO_TLSEXT
+NOEXPORT char *sni_init(SERVICE_OPTIONS *);
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+
+NOEXPORT char *parse_debug_level(char *, SERVICE_OPTIONS *);
+
+#ifndef OPENSSL_NO_PSK
+NOEXPORT PSK_KEYS *psk_read(char *);
+NOEXPORT void psk_free(PSK_KEYS *);
+#endif /* !defined(OPENSSL_NO_PSK) */
+
+typedef struct {
+    char *name;
+    long value;
+} SSL_OPTION;
+
+static const SSL_OPTION ssl_opts[] = {
+    {"MICROSOFT_SESS_ID_BUG", SSL_OP_MICROSOFT_SESS_ID_BUG},
+    {"NETSCAPE_CHALLENGE_BUG", SSL_OP_NETSCAPE_CHALLENGE_BUG},
+#ifdef SSL_OP_LEGACY_SERVER_CONNECT
+    {"LEGACY_SERVER_CONNECT", SSL_OP_LEGACY_SERVER_CONNECT},
+#endif
+    {"NETSCAPE_REUSE_CIPHER_CHANGE_BUG",
+        SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG},
+#ifdef SSL_OP_TLSEXT_PADDING
+    {"TLSEXT_PADDING", SSL_OP_TLSEXT_PADDING},
+#endif
+    {"MICROSOFT_BIG_SSLV3_BUFFER", SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER},
+#ifdef SSL_OP_SAFARI_ECDHE_ECDSA_BUG
+    {"SAFARI_ECDHE_ECDSA_BUG", SSL_OP_SAFARI_ECDHE_ECDSA_BUG},
+#endif
+    {"SSLEAY_080_CLIENT_DH_BUG", SSL_OP_SSLEAY_080_CLIENT_DH_BUG},
+    {"TLS_D5_BUG", SSL_OP_TLS_D5_BUG},
+    {"TLS_BLOCK_PADDING_BUG", SSL_OP_TLS_BLOCK_PADDING_BUG},
+#ifdef SSL_OP_MSIE_SSLV2_RSA_PADDING
+    {"MSIE_SSLV2_RSA_PADDING", SSL_OP_MSIE_SSLV2_RSA_PADDING},
+#endif
+    {"SSLREF2_REUSE_CERT_TYPE_BUG", SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG},
+#ifdef SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS
+    {"DONT_INSERT_EMPTY_FRAGMENTS", SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS},
+#endif
+    {"ALL", (long)SSL_OP_ALL},
+#ifdef SSL_OP_NO_QUERY_MTU
+    {"NO_QUERY_MTU", SSL_OP_NO_QUERY_MTU},
+#endif
+#ifdef SSL_OP_COOKIE_EXCHANGE
+    {"COOKIE_EXCHANGE", SSL_OP_COOKIE_EXCHANGE},
+#endif
+#ifdef SSL_OP_NO_TICKET
+    {"NO_TICKET", SSL_OP_NO_TICKET},
+#endif
+#ifdef SSL_OP_CISCO_ANYCONNECT
+    {"CISCO_ANYCONNECT", SSL_OP_CISCO_ANYCONNECT},
+#endif
+#ifdef SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION
+    {"NO_SESSION_RESUMPTION_ON_RENEGOTIATION",
+        SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION},
+#endif
+#ifdef SSL_OP_NO_COMPRESSION
+    {"NO_COMPRESSION", SSL_OP_NO_COMPRESSION},
+#endif
+#ifdef SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
+    {"ALLOW_UNSAFE_LEGACY_RENEGOTIATION",
+        SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION},
+#endif
+#ifdef SSL_OP_SINGLE_ECDH_USE
+    {"SINGLE_ECDH_USE", SSL_OP_SINGLE_ECDH_USE},
+#endif
+    {"SINGLE_DH_USE", SSL_OP_SINGLE_DH_USE},
+    {"EPHEMERAL_RSA", SSL_OP_EPHEMERAL_RSA},
+#ifdef SSL_OP_CIPHER_SERVER_PREFERENCE
+    {"CIPHER_SERVER_PREFERENCE", SSL_OP_CIPHER_SERVER_PREFERENCE},
+#endif
+    {"TLS_ROLLBACK_BUG", SSL_OP_TLS_ROLLBACK_BUG},
+    {"NO_SSLv2", SSL_OP_NO_SSLv2},
+    {"NO_SSLv3", SSL_OP_NO_SSLv3},
+    {"NO_TLSv1", SSL_OP_NO_TLSv1},
+#ifdef SSL_OP_NO_TLSv1_1
+    {"NO_TLSv1.1", SSL_OP_NO_TLSv1_1},
+#endif
+#ifdef SSL_OP_NO_TLSv1_2
+    {"NO_TLSv1.2", SSL_OP_NO_TLSv1_2},
+#endif
+    {"PKCS1_CHECK_1", SSL_OP_PKCS1_CHECK_1},
+    {"PKCS1_CHECK_2", SSL_OP_PKCS1_CHECK_2},
+    {"NETSCAPE_CA_DN_BUG", SSL_OP_NETSCAPE_CA_DN_BUG},
+#ifdef SSL_OP_NON_EXPORT_FIRST
+    {"NON_EXPORT_FIRST", SSL_OP_NON_EXPORT_FIRST},
+#endif
+    {"NETSCAPE_DEMO_CIPHER_CHANGE_BUG", SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG},
+#ifdef SSL_OP_CRYPTOPRO_TLSEXT_BUG
+    {"CRYPTOPRO_TLSEXT_BUG", (long)SSL_OP_CRYPTOPRO_TLSEXT_BUG},
+#endif
+    {NULL, 0}
+};
+
+NOEXPORT long parse_ssl_option(char *);
+NOEXPORT void print_ssl_options(void);
+
+NOEXPORT int print_socket_options(void);
+NOEXPORT char *print_option(int, OPT_UNION *);
+NOEXPORT int parse_socket_option(char *);
+
+#ifndef OPENSSL_NO_OCSP
+NOEXPORT unsigned long parse_ocsp_flag(char *);
+#endif /* !defined(OPENSSL_NO_OCSP) */
+
+#ifndef OPENSSL_NO_ENGINE
+NOEXPORT void engine_reset_list(void);
+NOEXPORT char *engine_auto(void);
+NOEXPORT char *engine_open(const char *);
+NOEXPORT char *engine_ctrl(const char *, const char *);
+NOEXPORT char *engine_default(const char *);
+NOEXPORT char *engine_init(void);
+NOEXPORT void engine_next(void);
+NOEXPORT ENGINE *engine_get_by_id(const char *);
+NOEXPORT ENGINE *engine_get_by_num(const int);
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+NOEXPORT void print_syntax(void);
+
+NOEXPORT void name_list_append(NAME_LIST **, char *);
+#ifndef USE_WIN32
+NOEXPORT char **argalloc(char *);
+#endif
+
+char *configuration_file=
+#ifdef CONFDIR
+            CONFDIR
+#ifdef USE_WIN32
+            "\\"
+#else
+            "/"
+#endif
+#endif
+            "stunnel.conf";
+
+GLOBAL_OPTIONS global_options;
+SERVICE_OPTIONS service_options;
+
+static GLOBAL_OPTIONS new_global_options;
+static SERVICE_OPTIONS new_service_options;
+
+static char *option_not_found=
+    "Specified option name is not valid here";
+
+static char *stunnel_cipher_list=
+    "HIGH:+3DES:+DH:!aNULL:!SSLv2";
+
+/**************************************** parse commandline parameters */
+
+int options_cmdline(char *name, char *parameter) {
+    CONF_TYPE type=CONF_FILE;
+
+#ifdef USE_WIN32
+    (void)parameter; /* skip warning about unused parameter */
+#endif
+    if(!name) {
+        /* leave the previous value of configuration_file */
+    } else if(!strcasecmp(name, "-help")) {
+        parse_global_option(CMD_HELP, NULL, NULL);
+        parse_service_option(CMD_HELP, NULL, NULL, NULL);
+        log_flush(LOG_MODE_INFO);
+        return 1;
+    } else if(!strcasecmp(name, "-version")) {
+        parse_global_option(CMD_DEFAULT, NULL, NULL);
+        parse_service_option(CMD_DEFAULT, NULL, NULL, NULL);
+        log_flush(LOG_MODE_INFO);
+        return 1;
+    } else if(!strcasecmp(name, "-sockets")) {
+        print_socket_options();
+        log_flush(LOG_MODE_INFO);
+        return 1;
+    } else if(!strcasecmp(name, "-options")) {
+        print_ssl_options();
+        log_flush(LOG_MODE_INFO);
+        return 1;
+    } else
+#ifndef USE_WIN32
+    if(!strcasecmp(name, "-fd")) {
+        if(!parameter) {
+            s_log(LOG_ERR, "No file descriptor specified");
+            print_syntax();
+            return 1;
+        }
+        configuration_file=parameter;
+        type=CONF_FD;
+    } else
+#endif
+        configuration_file=name;
+    configuration_file=str_dup(configuration_file);
+    str_detach(configuration_file); /* do not track this allocation */
+
+    return options_parse(type);
+}
+
+/**************************************** parse configuration file */
+
+int options_parse(CONF_TYPE type) {
+    SERVICE_OPTIONS *section;
+    char *errstr;
+
+    options_defaults();
+    section=&new_service_options;
+    if(options_file(configuration_file, type, &section))
+        return 1;
+
+    if(new_service_options.next) { /* daemon mode: initialize sections */
+        for(section=new_service_options.next; section; section=section->next) {
+            s_log(LOG_INFO, "Initializing service [%s]", section->servname);
+            errstr=parse_service_option(CMD_END, section, NULL, NULL);
+            if(errstr)
+                break;
+        }
+    } else { /* inetd mode: need to initialize global options */
+        errstr=parse_global_option(CMD_END, NULL, NULL);
+        if(errstr) {
+            s_log(LOG_ERR, "Global options: %s", errstr);
+            return 1;
+        }
+        s_log(LOG_INFO, "Initializing inetd mode configuration");
+        section=&new_service_options;
+        errstr=parse_service_option(CMD_END, section, NULL, NULL);
+    }
+    if(errstr) {
+        s_log(LOG_ERR, "Service [%s]: %s", section->servname, errstr);
+        return 1;
+    }
+
+    s_log(LOG_NOTICE, "Configuration successful");
+    return 0;
+}
+
+NOEXPORT int options_file(char *path, CONF_TYPE type, SERVICE_OPTIONS **section) {
+    DISK_FILE *df;
+    char line_text[CONFLINELEN], *errstr;
+    char config_line[CONFLINELEN], *config_opt, *config_arg;
+    int i, line_number=0;
+#ifndef USE_WIN32
+    int fd;
+    char *tmp_str;
+#endif
+
+    s_log(LOG_NOTICE, "Reading configuration from %s %s",
+        type==CONF_FD ? "descriptor" : "file", path);
+#ifndef USE_WIN32
+    if(type==CONF_FD) { /* file descriptor */
+        fd=(int)strtol(path, &tmp_str, 10);
+        if(tmp_str==path || *tmp_str) { /* not a number */
+            s_log(LOG_ERR, "Invalid file descriptor number");
+            print_syntax();
+            return 1;
+        }
+        df=file_fdopen(fd);
+    } else
+#endif
+        df=file_open(path, FILE_MODE_READ);
+    if(!df) {
+        s_log(LOG_ERR, "Cannot open configuration file");
+        if(type!=CONF_RELOAD)
+            print_syntax();
+        return 1;
+    }
+
+    while(file_getline(df, line_text, CONFLINELEN)>=0) {
+        memcpy(config_line, line_text, CONFLINELEN);
+        ++line_number;
+        config_opt=config_line;
+        if(line_number==1) {
+            if(config_opt[0]==(char)0xef &&
+                    config_opt[1]==(char)0xbb &&
+                    config_opt[2]==(char)0xbf) {
+                s_log(LOG_NOTICE, "UTF-8 byte order mark detected");
+                config_opt+=3;
+            } else {
+                s_log(LOG_NOTICE, "UTF-8 byte order mark not detected");
+            }
+        }
+
+        while(isspace((unsigned char)*config_opt))
+            ++config_opt; /* remove initial whitespaces */
+        for(i=(int)strlen(config_opt)-1; i>=0 && isspace((unsigned char)config_opt[i]); --i)
+            config_opt[i]='\0'; /* remove trailing whitespaces */
+        if(config_opt[0]=='\0' || config_opt[0]=='#' || config_opt[0]==';') /* empty or comment */
+            continue;
+
+        if(config_opt[0]=='[' && config_opt[strlen(config_opt)-1]==']') { /* new section */
+            SERVICE_OPTIONS *new_section;
+
+            if(!new_service_options.next) { /* initialize global options */
+                errstr=parse_global_option(CMD_END, NULL, NULL);
+                if(errstr) {
+                    s_log(LOG_ERR, "%s:%d: \"%s\": %s",
+                        path, line_number, line_text, errstr);
+                    file_close(df);
+                    return 1;
+                }
+            }
+            ++config_opt;
+            config_opt[strlen(config_opt)-1]='\0';
+            new_section=str_alloc(sizeof(SERVICE_OPTIONS));
+            memcpy(new_section, &new_service_options, sizeof(SERVICE_OPTIONS));
+            new_section->servname=str_dup(config_opt);
+            new_section->session=NULL;
+            new_section->next=NULL;
+            (*section)->next=new_section;
+            *section=new_section;
+            continue;
+        }
+
+        config_arg=strchr(config_line, '=');
+        if(!config_arg) {
+            s_log(LOG_ERR, "%s:%d: \"%s\": No '=' found",
+                path, line_number, line_text);
+            file_close(df);
+            return 1;
+        }
+        *config_arg++='\0'; /* split into option name and argument value */
+        for(i=(int)strlen(config_opt)-1; i>=0 && isspace((unsigned char)config_opt[i]); --i)
+            config_opt[i]='\0'; /* remove trailing whitespaces */
+        while(isspace((unsigned char)*config_arg))
+            ++config_arg; /* remove initial whitespaces */
+
+        if(!strcasecmp(config_opt, "include")) {
+            if(options_include(config_arg, section)) {
+                s_log(LOG_ERR, "%s:%d: Failed to include directory \"%s\"",
+                    path, line_number, config_arg);
+                file_close(df);
+                return 1;
+            }
+            continue;
+        }
+
+        errstr=option_not_found;
+        /* try global options first (e.g. for 'debug') */
+        if(!new_service_options.next)
+            errstr=parse_global_option(CMD_EXEC, config_opt, config_arg);
+        if(errstr==option_not_found)
+            errstr=parse_service_option(CMD_EXEC, *section, config_opt, config_arg);
+        if(errstr) {
+            s_log(LOG_ERR, "%s:%d: \"%s\": %s",
+                path, line_number, line_text, errstr);
+            file_close(df);
+            return 1;
+        }
+    }
+    file_close(df);
+    return 0;
+}
+
+NOEXPORT int options_include(char *directory, SERVICE_OPTIONS **section) {
+    struct dirent **namelist;
+    int i, num, err=0;
+
+    num=scandir(directory, &namelist, NULL, alphasort);
+    if(num<0) {
+        ioerror("scandir");
+        return 1;
+    }
+    for(i=0; i<num; ++i) {
+        if(!err) {
+            struct stat sb;
+            char *name=str_printf(
+#ifdef USE_WIN32
+                "%s\\%s",
+#else
+                "%s/%s",
+#endif
+                directory, namelist[i]->d_name);
+            stat(name, &sb);
+            if(S_ISREG(sb.st_mode))
+                err=options_file(name, CONF_FILE, section);
+            else
+                s_log(LOG_DEBUG, "\"%s\" is not a file", name);
+            str_free(name);
+        }
+        free(namelist[i]);
+    }
+    free(namelist);
+    return err;
+}
+
+#ifdef USE_WIN32
+
+int scandir(const char *dirp, struct dirent ***namelist,
+        int (*filter)(const struct dirent *),
+        int (*compar)(const struct dirent **, const struct dirent **)) {
+    WIN32_FIND_DATA data;
+    HANDLE h;
+    unsigned num=0, allocated=0;
+    LPTSTR path, pattern;
+    char *name;
+    DWORD saved_errno;
+
+    (void)filter; /* skip warning about unused parameter */
+    (void)compar; /* skip warning about unused parameter */
+    path=str2tstr(dirp);
+    pattern=str_tprintf(TEXT("%s\\*"), path);
+    str_free(path);
+    h=FindFirstFile(pattern, &data);
+    saved_errno=GetLastError();
+    str_free(pattern);
+    SetLastError(saved_errno);
+    if(h==INVALID_HANDLE_VALUE)
+        return -1;
+    *namelist=NULL;
+    do {
+        if(num>=allocated) {
+            allocated+=16;
+            *namelist=realloc(*namelist, allocated*sizeof(**namelist));
+        }
+        (*namelist)[num]=malloc(sizeof(struct dirent));
+        if(!(*namelist)[num])
+            return -1;
+        name=tstr2str(data.cFileName);
+        strncpy((*namelist)[num]->d_name, name, MAX_PATH-1);
+        (*namelist)[num]->d_name[MAX_PATH-1]='\0';
+        str_free(name);
+        ++num;
+    } while(FindNextFile(h, &data));
+    FindClose(h);
+    return (int)num;
+}
+
+int alphasort(const struct dirent **a, const struct dirent **b) {
+    (void)a; /* skip warning about unused parameter */
+    (void)b; /* skip warning about unused parameter */
+    /* most Windows filesystem return sorted data */
+    return 0;
+}
+
+#endif
+
+void options_defaults() {
+    /* initialize globals *before* opening the config file */
+    memset(&new_global_options, 0, sizeof(GLOBAL_OPTIONS)); /* reset global options */
+    memset(&new_service_options, 0, sizeof(SERVICE_OPTIONS)); /* reset local options */
+    new_service_options.next=NULL;
+    parse_global_option(CMD_BEGIN, NULL, NULL);
+    parse_service_option(CMD_BEGIN, &new_service_options, NULL, NULL);
+}
+
+void options_apply() { /* apply default/validated configuration */
+    /* FIXME: this operation may be unsafe, as client() threads use it */
+    memcpy(&global_options, &new_global_options, sizeof(GLOBAL_OPTIONS));
+    /* service_options are used for inetd mode and to enumerate services */
+    memcpy(&service_options, &new_service_options, sizeof(SERVICE_OPTIONS));
+}
+
+/**************************************** global options */
+
+NOEXPORT char *parse_global_option(CMD cmd, char *opt, char *arg) {
+    char *tmp_str;
+#ifndef USE_WIN32
+    struct group *gr;
+    struct passwd *pw;
+#endif
+
+    if(cmd==CMD_DEFAULT || cmd==CMD_HELP) {
+        s_log(LOG_NOTICE, " ");
+        s_log(LOG_NOTICE, "Global options:");
+    }
+
+    /* chroot */
+#ifdef HAVE_CHROOT
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.chroot_dir=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "chroot"))
+            break;
+        new_global_options.chroot_dir=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = directory to chroot stunnel process", "chroot");
+        break;
+    }
+#endif /* HAVE_CHROOT */
+
+    /* compression */
+#ifndef OPENSSL_NO_COMP
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.compression=COMP_NONE;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "compression"))
+            break;
+        if(SSLeay()>=0x00908051L && !strcasecmp(arg, "deflate"))
+            new_global_options.compression=COMP_DEFLATE;
+        else if(!strcasecmp(arg, "zlib"))
+            new_global_options.compression=COMP_ZLIB;
+        else
+            return "Specified compression type is not available";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = compression type",
+            "compression");
+        break;
+    }
+#endif /* !defined(OPENSSL_NO_COMP) */
+
+    /* debug */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_service_options.log_level=LOG_NOTICE;
+#if !defined (USE_WIN32) && !defined (__vms)
+        new_global_options.log_facility=LOG_DAEMON;
+#endif
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "debug"))
+            break;
+        return parse_debug_level(arg, &new_service_options);
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#if !defined (USE_WIN32) && !defined (__vms)
+        s_log(LOG_NOTICE, "%-22s = %s", "debug", "daemon.notice");
+#else
+        s_log(LOG_NOTICE, "%-22s = %s", "debug", "notice");
+#endif
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = [facility].level (e.g. daemon.info)", "debug");
+        break;
+    }
+
+    /* EGD */
+    switch(cmd) {
+    case CMD_BEGIN:
+#ifdef EGD_SOCKET
+        new_global_options.egd_sock=EGD_SOCKET;
+#else
+        new_global_options.egd_sock=NULL;
+#endif
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "EGD"))
+            break;
+        new_global_options.egd_sock=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#ifdef EGD_SOCKET
+        s_log(LOG_NOTICE, "%-22s = %s", "EGD", EGD_SOCKET);
+#endif
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = path to Entropy Gathering Daemon socket", "EGD");
+        break;
+    }
+
+#ifndef OPENSSL_NO_ENGINE
+
+    /* engine */
+    switch(cmd) {
+    case CMD_BEGIN:
+        engine_reset_list();
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "engine"))
+            break;
+        if(!strcasecmp(arg, "auto"))
+            return engine_auto();
+        else
+            return engine_open(arg);
+    case CMD_END:
+        engine_next();
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = auto|engine_id",
+            "engine");
+        break;
+    }
+
+    /* engineCtrl */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "engineCtrl"))
+            break;
+        tmp_str=strchr(arg, ':');
+        if(tmp_str)
+            *tmp_str++='\0';
+        return engine_ctrl(arg, tmp_str);
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = cmd[:arg]",
+            "engineCtrl");
+        break;
+    }
+
+    /* engineDefault */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "engineDefault"))
+            break;
+        return engine_default(arg);
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = TASK_LIST",
+            "engineDefault");
+        break;
+    }
+
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+    /* fips */
+    switch(cmd) {
+    case CMD_BEGIN:
+#ifdef USE_FIPS
+        new_global_options.option.fips=0;
+#endif /* USE_FIPS */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "fips"))
+            break;
+#ifdef USE_FIPS
+        if(!strcasecmp(arg, "yes"))
+            new_global_options.option.fips=1;
+        else if(!strcasecmp(arg, "no"))
+            new_global_options.option.fips=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+#else
+        if(strcasecmp(arg, "no"))
+            return "FIPS support is not available";
+#endif /* USE_FIPS */
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+#ifdef USE_FIPS
+        s_log(LOG_NOTICE, "%-22s = yes|no FIPS 140-2 mode",
+            "fips");
+#endif /* USE_FIPS */
+        break;
+    }
+
+    /* foreground */
+#ifndef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.option.foreground=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "foreground"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            new_global_options.option.foreground=1;
+        else if(!strcasecmp(arg, "no"))
+            new_global_options.option.foreground=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no foreground mode (don't fork, log to stderr)",
+            "foreground");
+        break;
+    }
+#endif
+
+#ifdef ICON_IMAGE
+
+    /* iconActive */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.icon[ICON_ACTIVE]=load_icon_default(ICON_ACTIVE);
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "iconActive"))
+            break;
+        if(!(new_global_options.icon[ICON_ACTIVE]=load_icon_file(arg)))
+            return "Failed to load the specified icon";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = icon when connections are established", "iconActive");
+        break;
+    }
+
+    /* iconError */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.icon[ICON_ERROR]=load_icon_default(ICON_ERROR);
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "iconError"))
+            break;
+        if(!(new_global_options.icon[ICON_ERROR]=load_icon_file(arg)))
+            return "Failed to load the specified icon";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = icon for invalid configuration file", "iconError");
+        break;
+    }
+
+    /* iconIdle */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.icon[ICON_IDLE]=load_icon_default(ICON_IDLE);
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "iconIdle"))
+            break;
+        if(!(new_global_options.icon[ICON_IDLE]=load_icon_file(arg)))
+            return "Failed to load the specified icon";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = icon when no connections were established", "iconIdle");
+        break;
+    }
+
+#endif /* ICON_IMAGE */
+
+    /* log */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.log_file_mode=FILE_MODE_APPEND;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "log"))
+            break;
+        if(!strcasecmp(arg, "append"))
+            new_global_options.log_file_mode=FILE_MODE_APPEND;
+        else if(!strcasecmp(arg, "overwrite"))
+            new_global_options.log_file_mode=FILE_MODE_OVERWRITE;
+        else
+            return "The argument needs to be either 'append' or 'overwrite'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = append|overwrite log file",
+            "log");
+        break;
+    }
+
+    /* output */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.output_file=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "output"))
+            break;
+        new_global_options.output_file=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = file to append log messages", "output");
+        break;
+    }
+
+    /* pid */
+#ifndef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.pidfile=NULL; /* do not create a pid file */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "pid"))
+            break;
+        if(arg[0]) /* is argument not empty? */
+            new_global_options.pidfile=str_dup(arg);
+        else
+            new_global_options.pidfile=NULL; /* empty -> do not create a pid file */
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = pid file", "pid");
+        break;
+    }
+#endif
+
+    /* RNDbytes */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.random_bytes=RANDOM_BYTES;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "RNDbytes"))
+            break;
+        new_global_options.random_bytes=(long)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal number of bytes to read from random seed files";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d", "RNDbytes", RANDOM_BYTES);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = bytes to read from random seed files", "RNDbytes");
+        break;
+    }
+
+    /* RNDfile */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.rand_file=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "RNDfile"))
+            break;
+        new_global_options.rand_file=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#ifdef RANDOM_FILE
+        s_log(LOG_NOTICE, "%-22s = %s", "RNDfile", RANDOM_FILE);
+#endif
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = path to file with random seed data", "RNDfile");
+        break;
+    }
+
+    /* RNDoverwrite */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.option.rand_write=1;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "RNDoverwrite"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            new_global_options.option.rand_write=1;
+        else if(!strcasecmp(arg, "no"))
+            new_global_options.option.rand_write=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = yes", "RNDoverwrite");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no overwrite seed datafiles with new random data",
+            "RNDoverwrite");
+        break;
+    }
+
+#ifndef USE_WIN32
+    /* service */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_service_options.servname=str_dup("stunnel");
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "service"))
+            break;
+        new_service_options.servname=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = service name", "service");
+        break;
+    }
+#endif
+
+#ifndef USE_WIN32
+    /* setgid */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.gid=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "setgid"))
+            break;
+        gr=getgrnam(arg);
+        if(gr) {
+            new_global_options.gid=gr->gr_gid;
+            return NULL; /* OK */
+        }
+        new_global_options.gid=(gid_t)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal GID";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = groupname for setgid()", "setgid");
+        break;
+    }
+#endif
+
+#ifndef USE_WIN32
+    /* setuid */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.uid=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "setuid"))
+            break;
+        pw=getpwnam(arg);
+        if(pw) {
+            new_global_options.uid=pw->pw_uid;
+            return NULL; /* OK */
+        }
+        new_global_options.uid=(uid_t)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal UID";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = username for setuid()", "setuid");
+        break;
+    }
+#endif
+
+    /* socket */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "socket"))
+            break;
+        if(parse_socket_option(arg))
+            return "Illegal socket option";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = a|l|r:option=value[:value]", "socket");
+        s_log(LOG_NOTICE, "%25sset an option on accept/local/remote socket", "");
+        break;
+    }
+
+    /* syslog */
+#ifndef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.option.syslog=1;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "syslog"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            new_global_options.option.syslog=1;
+        else if(!strcasecmp(arg, "no"))
+            new_global_options.option.syslog=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no send logging messages to syslog",
+            "syslog");
+        break;
+    }
+#endif
+
+    /* taskbar */
+#ifdef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_global_options.option.taskbar=1;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "taskbar"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            new_global_options.option.taskbar=1;
+        else if(!strcasecmp(arg, "no"))
+            new_global_options.option.taskbar=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = yes", "taskbar");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no enable the taskbar icon", "taskbar");
+        break;
+    }
+#endif
+
+    if(cmd==CMD_EXEC)
+        return option_not_found;
+
+    if(cmd==CMD_END) {
+        /* FIPS needs to be initialized as early as possible */
+        if(ssl_configure(&new_global_options)) /* configure global SSL settings */
+            return "Failed to initialize SSL";
+    }
+    return NULL; /* OK */
+}
+
+/**************************************** service-level options */
+
+NOEXPORT char *parse_service_option(CMD cmd, SERVICE_OPTIONS *section,
+        char *opt, char *arg) {
+    char *tmp_str;
+    int endpoints=0;
+    long tmp_long;
+
+    if(cmd==CMD_DEFAULT || cmd==CMD_HELP) {
+        s_log(LOG_NOTICE, " ");
+        s_log(LOG_NOTICE, "Service-level options:");
+    }
+
+    /* accept */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.accept=0;
+        memset(&section->local_addr, 0, sizeof(SOCKADDR_UNION));
+        section->local_addr.in.sin_family=AF_INET;
+        section->fd=INVALID_SOCKET;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "accept"))
+            break;
+        section->option.accept=1;
+        if(!name2addr(&section->local_addr, arg, 1))
+            return "Failed to resolve accepting address";
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->option.accept)
+            ++endpoints;
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = [host:]port accept connections on specified host:port",
+            "accept");
+        break;
+    }
+
+    /* CApath */
+    switch(cmd) {
+    case CMD_BEGIN:
+#if 0
+        section->ca_dir=(char *)X509_get_default_cert_dir();
+#endif
+        section->ca_dir=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "CApath"))
+            break;
+        if(arg[0]) /* not empty */
+            section->ca_dir=str_dup(arg);
+        else
+            section->ca_dir=NULL;
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#if 0
+        s_log(LOG_NOTICE, "%-22s = %s", "CApath",
+            section->ca_dir ? section->ca_dir : "(none)");
+#endif
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = CA certificate directory for 'verify' option",
+            "CApath");
+        break;
+    }
+
+    /* CAfile */
+    switch(cmd) {
+    case CMD_BEGIN:
+#if 0
+        section->ca_file=(char *)X509_get_default_certfile();
+#endif
+        section->ca_file=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "CAfile"))
+            break;
+        if(arg[0]) /* not empty */
+            section->ca_file=str_dup(arg);
+        else
+            section->ca_file=NULL;
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#if 0
+        s_log(LOG_NOTICE, "%-22s = %s", "CAfile",
+            section->ca_file ? section->ca_file : "(none)");
+#endif
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = CA certificate file for 'verify' option",
+            "CAfile");
+        break;
+    }
+
+    /* cert */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->cert=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "cert"))
+            break;
+        section->cert=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+#ifndef OPENSSL_NO_PSK
+        if(section->psk_keys)
+            break;
+#endif /* !defined(OPENSSL_NO_PSK) */
+#ifndef OPENSSL_NO_ENGINE
+        if(section->engine)
+            break;
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+        if(!section->option.client && !section->cert)
+            return "SSL server needs a certificate";
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break; /* no default certificate */
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = certificate chain", "cert");
+        break;
+    }
+
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+
+    /* checkEmail */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->check_email=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "checkEmail"))
+            break;
+        name_list_append(&section->check_email, arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = peer certificate email address",
+            "checkEmail");
+        break;
+    }
+
+    /* checkHost */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->check_host=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "checkHost"))
+            break;
+        name_list_append(&section->check_host, arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = peer certificate host name pattern",
+            "checkHost");
+        break;
+    }
+
+    /* checkIP */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->check_ip=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "checkIP"))
+            break;
+        name_list_append(&section->check_ip, arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = peer certificate IP address",
+            "checkIP");
+        break;
+    }
+
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+
+    /* ciphers */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->cipher_list=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "ciphers"))
+            break;
+        section->cipher_list=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+#ifdef USE_FIPS
+        if(new_global_options.option.fips) {
+            if(!new_service_options.cipher_list)
+                new_service_options.cipher_list="FIPS";
+        } else
+#endif /* USE_FIPS */
+        {
+            if(!new_service_options.cipher_list)
+                new_service_options.cipher_list=stunnel_cipher_list;
+        }
+
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+#ifdef USE_FIPS
+        s_log(LOG_NOTICE, "%-22s = %s %s", "ciphers",
+            "FIPS", "(with \"fips = yes\")");
+        s_log(LOG_NOTICE, "%-22s = %s %s", "ciphers",
+            stunnel_cipher_list, "(with \"fips = no\")");
+#else
+        s_log(LOG_NOTICE, "%-22s = %s", "ciphers", stunnel_cipher_list);
+#endif /* USE_FIPS */
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = list of permitted SSL ciphers", "ciphers");
+        break;
+    }
+
+    /* client */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.client=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "client"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.client=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.client=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no client mode (remote service uses SSL)",
+            "client");
+        break;
+    }
+
+    /* connect */
+    switch(cmd) {
+    case CMD_BEGIN:
+        addrlist_clear(&section->connect_addr, 0);
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "connect"))
+            break;
+        name_list_append(&section->connect_addr.names, arg);
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->connect_addr.names) {
+            if(!section->option.delayed_lookup &&
+                    !addrlist_resolve(&section->connect_addr)) {
+                s_log(LOG_INFO,
+                    "Cannot resolve connect target - delaying DNS lookup");
+                section->redirect_addr.num=0;
+                str_free(section->redirect_addr.names);
+                section->redirect_addr.names=NULL;
+                section->option.delayed_lookup=1;
+            }
+            ++endpoints;
+        }
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = [host:]port to connect",
+            "connect");
+        break;
+    }
+
+    /* CRLpath */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->crl_dir=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "CRLpath"))
+            break;
+        if(arg[0]) /* not empty */
+            section->crl_dir=str_dup(arg);
+        else
+            section->crl_dir=NULL;
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = CRL directory", "CRLpath");
+        break;
+    }
+
+    /* CRLfile */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->crl_file=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "CRLfile"))
+            break;
+        if(arg[0]) /* not empty */
+            section->crl_file=str_dup(arg);
+        else
+            section->crl_file=NULL;
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = CRL file", "CRLfile");
+        break;
+    }
+
+#ifndef OPENSSL_NO_ECDH
+
+    /* curve */
+#define DEFAULT_CURVE NID_X9_62_prime256v1
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->curve=DEFAULT_CURVE;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "curve"))
+            break;
+        section->curve=OBJ_txt2nid(arg);
+        if(section->curve==NID_undef)
+            return "Curve name not supported";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %s", "curve", OBJ_nid2ln(DEFAULT_CURVE));
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = ECDH curve name", "curve");
+        break;
+    }
+
+#endif /* !defined(OPENSSL_NO_ECDH) */
+
+    /* debug */
+    switch(cmd) {
+    case CMD_BEGIN:
+        new_service_options.log_level=LOG_NOTICE;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "debug"))
+            break;
+        return parse_debug_level(arg, section);
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %s", "debug", "notice");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = level (e.g. info)", "debug");
+        break;
+    }
+
+    /* delay */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.delayed_lookup=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "delay"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.delayed_lookup=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.delayed_lookup=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE,
+            "%-22s = yes|no delay DNS lookup for 'connect' option",
+            "delay");
+        break;
+    }
+
+#ifndef OPENSSL_NO_ENGINE
+
+    /* engineId */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "engineId"))
+            break;
+        section->engine=engine_get_by_id(arg);
+        if(!section->engine)
+            return "Engine ID not found";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = ID of engine to read the key from",
+            "engineId");
+        break;
+    }
+
+    /* engineNum */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "engineNum"))
+            break;
+        {
+            int tmp_int=(int)strtol(arg, &tmp_str, 10);
+            if(tmp_str==arg || *tmp_str) /* not a number */
+                return "Illegal engine number";
+            section->engine=engine_get_by_num(tmp_int-1);
+        }
+        if(!section->engine)
+            return "Illegal engine number";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = number of engine to read the key from",
+            "engineNum");
+        break;
+    }
+
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+    /* exec */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->exec_name=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "exec"))
+            break;
+        section->exec_name=str_dup(arg);
+#ifdef USE_WIN32
+        section->exec_args=str_dup(arg);
+#else
+        if(!section->exec_args) {
+            section->exec_args=str_alloc(2*sizeof(char *));
+            section->exec_args[0]=section->exec_name;
+            section->exec_args[1]=NULL; /* to show that it's null-terminated */
+        }
+#endif
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->exec_name)
+            ++endpoints;
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = file execute local inetd-type program",
+            "exec");
+        break;
+    }
+
+    /* execArgs */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->exec_args=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "execArgs"))
+            break;
+#ifdef USE_WIN32
+        section->exec_args=str_dup(arg);
+#else
+        section->exec_args=argalloc(arg);
+#endif
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = arguments for 'exec' (including $0)",
+            "execArgs");
+        break;
+    }
+
+    /* failover */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->failover=FAILOVER_RR;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "failover"))
+            break;
+        if(!strcasecmp(arg, "rr"))
+            section->failover=FAILOVER_RR;
+        else if(!strcasecmp(arg, "prio"))
+            section->failover=FAILOVER_PRIO;
+        else
+            return "The argument needs to be either 'rr' or 'prio'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = rr|prio failover strategy",
+            "failover");
+        break;
+    }
+
+    /* ident */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->username=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "ident"))
+            break;
+        section->username=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = username for IDENT (RFC 1413) checking", "ident");
+        break;
+    }
+
+    /* key */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->key=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "key"))
+            break;
+        section->key=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->cert && !section->key)
+            section->key=str_dup(section->cert);
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = certificate private key", "key");
+        break;
+    }
+
+#ifdef USE_LIBWRAP
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.libwrap=0; /* disable libwrap by default */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "libwrap"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.libwrap=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.libwrap=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no use /etc/hosts.allow and /etc/hosts.deny",
+            "libwrap");
+        break;
+    }
+#endif /* USE_LIBWRAP */
+
+    /* local */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.local=0;
+        memset(&section->source_addr, 0, sizeof(SOCKADDR_UNION));
+        section->source_addr.in.sin_family=AF_INET;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "local"))
+            break;
+        section->option.local=1;
+        if(!hostport2addr(&section->source_addr, arg, "0", 1))
+            return "Failed to resolve local address";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = IP address to be used as source for remote"
+            " connections", "local");
+        break;
+    }
+
+    /* logId */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->log_id=LOG_ID_SEQENTIAL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "logId"))
+            break;
+        if(!strcasecmp(arg, "sequential"))
+            section->log_id=LOG_ID_SEQENTIAL;
+        else if(!strcasecmp(arg, "unique"))
+            section->log_id=LOG_ID_UNIQUE;
+        else if(!strcasecmp(arg, "thread"))
+            section->log_id=LOG_ID_THREAD;
+        else
+            return "Invalid connection identifier type";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %s", "logId", "sequential");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = connection identifier type",
+            "logId");
+        break;
+    }
+
+#ifndef OPENSSL_NO_OCSP
+
+    /* OCSP */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->ocsp_url=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "ocsp"))
+            break;
+        section->ocsp_url=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = OCSP server URL", "ocsp");
+        break;
+    }
+
+    /* OCSPaia */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.aia=0; /* disable AIA by default */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "OCSPaia"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.aia=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.aia=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no check the AIA responders from certificates",
+            "OCSPaia");
+        break;
+    }
+
+    /* OCSPflag */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->ocsp_flags=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "OCSPflag"))
+            break;
+        {
+            unsigned long tmp_ulong=parse_ocsp_flag(arg);
+            if(!tmp_ulong)
+                return "Illegal OCSP flag";
+            section->ocsp_flags|=tmp_ulong;
+        }
+        return NULL;
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = OCSP server flags", "OCSPflag");
+        break;
+    }
+
+#endif /* !defined(OPENSSL_NO_OCSP) */
+
+    /* options */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->ssl_options_set|=SSL_OP_NO_SSLv2|SSL_OP_NO_SSLv3;
+#if OPENSSL_VERSION_NUMBER>=0x009080dfL
+        section->ssl_options_clear=0;
+#endif /* OpenSSL 0.9.8m or later */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "options"))
+            break;
+#if OPENSSL_VERSION_NUMBER>=0x009080dfL
+        if(*arg=='-') {
+            tmp_long=parse_ssl_option(arg+1);
+            if(!tmp_long)
+                return "Illegal SSL option";
+            section->ssl_options_clear|=tmp_long;
+            return NULL; /* OK */
+        }
+#endif /* OpenSSL 0.9.8m or later */
+        tmp_long=parse_ssl_option(arg);
+        if(!tmp_long)
+            return "Illegal SSL option";
+        section->ssl_options_set|=tmp_long;
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %s", "options", "NO_SSLv2");
+        s_log(LOG_NOTICE, "%-22s = %s", "options", "NO_SSLv3");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = SSL option", "options");
+        s_log(LOG_NOTICE, "%25sset an SSL option", "");
+        break;
+    }
+
+    /* protocol */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->protocol=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "protocol"))
+            break;
+        section->protocol=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        /* this also initializes section->option.connect_before_ssl */
+        tmp_str=protocol(NULL, section, PROTOCOL_CHECK);
+        if(tmp_str)
+            return tmp_str;
+        if(section->protocol && !strcasecmp(section->protocol, "socks")) {
+            ++endpoints;
+        }
+#ifdef SSL_OP_NO_TICKET
+        /* disable RFC4507 support introduced in OpenSSL 0.9.8f */
+        /* session tickets do not support SSL_SESSION_*_ex_data() */
+        if(!section->option.connect_before_ssl) /* address cache can be used */
+            section->ssl_options_set|=SSL_OP_NO_TICKET;
+#endif
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = protocol to negotiate before SSL initialization",
+            "protocol");
+        s_log(LOG_NOTICE, "%25scurrently supported: cifs, connect, imap,", "");
+        s_log(LOG_NOTICE, "%25s    nntp, pgsql, pop3, proxy, smtp", "");
+        break;
+    }
+
+    /* protocolAuthentication */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->protocol_authentication="basic";
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "protocolAuthentication"))
+            break;
+        section->protocol_authentication=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = authentication type for protocol negotiations",
+            "protocolAuthentication");
+        break;
+    }
+
+    /* protocolHost */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->protocol_host=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "protocolHost"))
+            break;
+        section->protocol_host=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = host:port for protocol negotiations",
+            "protocolHost");
+        break;
+    }
+
+    /* protocolPassword */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->protocol_password=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "protocolPassword"))
+            break;
+        section->protocol_password=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = password for protocol negotiations",
+            "protocolPassword");
+        break;
+    }
+
+    /* protocolUsername */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->protocol_username=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "protocolUsername"))
+            break;
+        section->protocol_username=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = username for protocol negotiations",
+            "protocolUsername");
+        break;
+    }
+
+#ifndef OPENSSL_NO_PSK
+
+    /* PSKidentity */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->psk_identity=NULL;
+        section->psk_selected=NULL;
+        section->psk_sorted.val=NULL;
+        section->psk_sorted.num=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "PSKidentity"))
+            break;
+        section->psk_identity=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        if(!section->psk_keys) /* PSK not configured */
+            break;
+        psk_sort(&section->psk_sorted, section->psk_keys);
+        if(section->option.client) {
+            if(section->psk_identity) {
+                section->psk_selected=
+                    psk_find(&section->psk_sorted, section->psk_identity);
+                if(!section->psk_selected)
+                    return "No key found for the specified PSK identity";
+            } else { /* take the first specified identity as default */
+                section->psk_selected=section->psk_keys;
+            }
+        } else {
+            if(section->psk_identity)
+                s_log(LOG_NOTICE,
+                    "PSK identity is ignored in the server mode");
+        }
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = identity for PSK authentication",
+            "PSKidentity");
+        break;
+    }
+
+    /* PSKsecrets */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->psk_keys=NULL;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "PSKsecrets"))
+            break;
+        section->psk_keys=psk_read(arg);
+        if(!section->psk_keys)
+            return "Failed to read PSK secrets";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        psk_free(section->psk_keys);
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = secrets for PSK authentication",
+            "PSKsecrets");
+        break;
+    }
+
+#endif /* !defined(OPENSSL_NO_PSK) */
+
+    /* pty */
+#ifndef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.pty=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "pty"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.pty=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.pty=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no allocate pseudo terminal for 'exec' option",
+            "pty");
+        break;
+    }
+#endif
+
+    /* redirect */
+    switch(cmd) {
+    case CMD_BEGIN:
+        addrlist_clear(&section->redirect_addr, 0);
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "redirect"))
+            break;
+#ifdef SSL_OP_NO_TICKET
+        /* disable RFC4507 support introduced in OpenSSL 0.9.8f */
+        /* session tickets do not support SSL_SESSION_*_ex_data() */
+        section->ssl_options_set|=SSL_OP_NO_TICKET;
+#endif
+        name_list_append(&section->redirect_addr.names, arg);
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->redirect_addr.names) {
+            if(!section->option.delayed_lookup &&
+                    !addrlist_resolve(&section->redirect_addr)) {
+                s_log(LOG_INFO,
+                    "Cannot resolve redirect target - delaying DNS lookup");
+                section->connect_addr.num=0;
+                str_free(section->connect_addr.names);
+                section->connect_addr.names=NULL;
+                section->option.delayed_lookup=1;
+            }
+            if(section->verify_level<1)
+                return "\"verify\" needs to be 1 or higher for \"redirect\" to work";
+        }
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE,
+            "%-22s = [host:]port to redirect on authentication failures",
+            "redirect");
+        break;
+    }
+
+    /* renegotiation */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.renegotiation=1;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "renegotiation"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.renegotiation=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.renegotiation=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no support renegotiation",
+              "renegotiation");
+        break;
+    }
+
+    /* reset */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.reset=1; /* enabled by default */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "reset"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.reset=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.reset=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no send TCP RST on error",
+            "retry");
+        break;
+    }
+
+    /* retry */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.retry=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "retry"))
+            break;
+        if(!strcasecmp(arg, "yes"))
+            section->option.retry=1;
+        else if(!strcasecmp(arg, "no"))
+            section->option.retry=0;
+        else
+            return "The argument needs to be either 'yes' or 'no'";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = yes|no retry connect+exec section",
+            "retry");
+        break;
+    }
+
+    /* sessionCacheSize */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->session_size=1000L;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "sessionCacheSize"))
+            break;
+        section->session_size=strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal session cache size";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %ld", "sessionCacheSize", 1000L);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = session cache size", "sessionCacheSize");
+        break;
+    }
+
+    /* sessionCacheTimeout */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->session_timeout=300L;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "sessionCacheTimeout") && strcasecmp(opt, "session"))
+            break;
+        section->session_timeout=strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal session cache timeout";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %ld seconds", "sessionCacheTimeout", 300L);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = session cache timeout (in seconds)",
+            "sessionCacheTimeout");
+        break;
+    }
+
+    /* sessiond */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.sessiond=0;
+        memset(&section->sessiond_addr, 0, sizeof(SOCKADDR_UNION));
+        section->sessiond_addr.in.sin_family=AF_INET;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "sessiond"))
+            break;
+        section->option.sessiond=1;
+#ifdef SSL_OP_NO_TICKET
+        /* disable RFC4507 support introduced in OpenSSL 0.9.8f */
+        /* this prevents session callbacks from beeing executed */
+        section->ssl_options_set|=SSL_OP_NO_TICKET;
+#endif
+        if(!name2addr(&section->sessiond_addr, arg, 0))
+            return "Failed to resolve sessiond server address";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = [host:]port use sessiond at host:port",
+            "sessiond");
+        break;
+    }
+
+#ifndef OPENSSL_NO_TLSEXT
+    /* sni */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->servername_list_head=NULL;
+        section->servername_list_tail=NULL;
+        section->option.sni=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "sni"))
+            break;
+        section->sni=str_dup(arg);
+        return NULL; /* OK */
+    case CMD_END:
+        tmp_str=sni_init(section);
+        if(tmp_str)
+            return tmp_str;
+        if(section->option.sni)
+            ++endpoints;
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = master_service:host_name for an SNI virtual service",
+            "sni");
+        break;
+    }
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+
+    /* sslVersion */
+    switch(cmd) {
+    case CMD_BEGIN:
+#if OPENSSL_VERSION_NUMBER>=0x10100000L
+        section->client_method=(SSL_METHOD *)TLS_client_method();
+        section->server_method=(SSL_METHOD *)TLS_server_method();
+#else
+        section->client_method=(SSL_METHOD *)SSLv23_client_method();
+        section->server_method=(SSL_METHOD *)SSLv23_server_method();
+#endif
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "sslVersion"))
+            break;
+        if(!strcasecmp(arg, "all")) {
+#if OPENSSL_VERSION_NUMBER>=0x10100000L
+            section->client_method=(SSL_METHOD *)TLS_client_method();
+            section->server_method=(SSL_METHOD *)TLS_server_method();
+#else
+            section->client_method=(SSL_METHOD *)SSLv23_client_method();
+            section->server_method=(SSL_METHOD *)SSLv23_server_method();
+#endif
+        } else if(!strcasecmp(arg, "SSLv2")) {
+#ifndef OPENSSL_NO_SSL2
+            section->client_method=(SSL_METHOD *)SSLv2_client_method();
+            section->server_method=(SSL_METHOD *)SSLv2_server_method();
+#else /* defined(OPENSSL_NO_SSL2) */
+            return "SSLv2 not supported";
+#endif /* !defined(OPENSSL_NO_SSL2) */
+        } else if(!strcasecmp(arg, "SSLv3")) {
+#ifndef OPENSSL_NO_SSL3
+            section->client_method=(SSL_METHOD *)SSLv3_client_method();
+            section->server_method=(SSL_METHOD *)SSLv3_server_method();
+#else /* defined(OPENSSL_NO_SSL3) */
+            return "SSLv3 not supported";
+#endif /* !defined(OPENSSL_NO_SSL3) */
+        } else if(!strcasecmp(arg, "TLSv1")) {
+#ifndef OPENSSL_NO_TLS1
+            section->client_method=(SSL_METHOD *)TLSv1_client_method();
+            section->server_method=(SSL_METHOD *)TLSv1_server_method();
+#else /* defined(OPENSSL_NO_TLS1) */
+            return "TLSv1 not supported";
+#endif /* !defined(OPENSSL_NO_TLS1) */
+        } else if(!strcasecmp(arg, "TLSv1.1")) {
+#ifndef OPENSSL_NO_TLS1_1
+            section->client_method=(SSL_METHOD *)TLSv1_1_client_method();
+            section->server_method=(SSL_METHOD *)TLSv1_1_server_method();
+#else /* defined(OPENSSL_NO_TLS1_1) */
+            return "TLSv1.1 not supported";
+#endif /* !defined(OPENSSL_NO_TLS1_1) */
+        } else if(!strcasecmp(arg, "TLSv1.2")) {
+#ifndef OPENSSL_NO_TLS1_2
+            section->client_method=(SSL_METHOD *)TLSv1_2_client_method();
+            section->server_method=(SSL_METHOD *)TLSv1_2_server_method();
+#else /* defined(OPENSSL_NO_TLS1_2) */
+            return "TLSv1.2 not supported";
+#endif /* !defined(OPENSSL_NO_TLS1_2) */
+        } else
+            return "Incorrect version of SSL protocol";
+        return NULL; /* OK */
+    case CMD_END:
+#ifdef USE_FIPS
+        if(new_global_options.option.fips) {
+#ifndef OPENSSL_NO_SSL2
+            if(section->option.client ?
+                    section->client_method==(SSL_METHOD *)SSLv2_client_method() :
+                    section->server_method==(SSL_METHOD *)SSLv2_server_method())
+                return "\"sslVersion = SSLv2\" not supported in FIPS mode";
+#endif /* !defined(OPENSSL_NO_SSL2) */
+#ifndef OPENSSL_NO_SSL3
+            if(section->option.client ?
+                    section->client_method==(SSL_METHOD *)SSLv3_client_method() :
+                    section->server_method==(SSL_METHOD *)SSLv3_server_method())
+                return "\"sslVersion = SSLv3\" not supported in FIPS mode";
+#endif /* !defined(OPENSSL_NO_SSL3) */
+        }
+#endif /* USE_FIPS */
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = all|SSLv2|SSLv3|TLSv1"
+#if OPENSSL_VERSION_NUMBER>=0x10001000L
+            "|TLSv1.1|TLSv1.2"
+#endif
+            " SSL method", "sslVersion");
+        break;
+    }
+
+#ifndef USE_FORK
+    /* stack */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->stack_size=DEFAULT_STACK_SIZE;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "stack"))
+            break;
+        section->stack_size=(size_t)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal thread stack size";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d bytes", "stack", DEFAULT_STACK_SIZE);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = thread stack size (in bytes)", "stack");
+        break;
+    }
+#endif
+
+    /* TIMEOUTbusy */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->timeout_busy=300; /* 5 minutes */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "TIMEOUTbusy"))
+            break;
+        section->timeout_busy=(int)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal busy timeout";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d seconds", "TIMEOUTbusy", 300);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = seconds to wait for expected data", "TIMEOUTbusy");
+        break;
+    }
+
+    /* TIMEOUTclose */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->timeout_close=60; /* 1 minute */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "TIMEOUTclose"))
+            break;
+        section->timeout_close=(int)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal close timeout";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d seconds", "TIMEOUTclose", 60);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = seconds to wait for close_notify",
+            "TIMEOUTclose");
+        break;
+    }
+
+    /* TIMEOUTconnect */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->timeout_connect=10; /* 10 seconds */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "TIMEOUTconnect"))
+            break;
+        section->timeout_connect=(int)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal connect timeout";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d seconds", "TIMEOUTconnect", 10);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = seconds to connect remote host", "TIMEOUTconnect");
+        break;
+    }
+
+    /* TIMEOUTidle */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->timeout_idle=43200; /* 12 hours */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "TIMEOUTidle"))
+            break;
+        section->timeout_idle=(int)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Illegal idle timeout";
+        return NULL; /* OK */
+    case CMD_END:
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = %d seconds", "TIMEOUTidle", 43200);
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE, "%-22s = seconds to keep an idle connection", "TIMEOUTidle");
+        break;
+    }
+
+    /* transparent */
+#ifndef USE_WIN32
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->option.transparent_src=0;
+        section->option.transparent_dst=0;
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "transparent"))
+            break;
+        if(!strcasecmp(arg, "none") || !strcasecmp(arg, "no")) {
+            section->option.transparent_src=0;
+            section->option.transparent_dst=0;
+        } else if(!strcasecmp(arg, "source") || !strcasecmp(arg, "yes")) {
+            section->option.transparent_src=1;
+            section->option.transparent_dst=0;
+#ifdef SO_ORIGINAL_DST
+        } else if(!strcasecmp(arg, "destination")) {
+            section->option.transparent_src=0;
+            section->option.transparent_dst=1;
+        } else if(!strcasecmp(arg, "both")) {
+            section->option.transparent_src=1;
+            section->option.transparent_dst=1;
+#endif
+        } else
+            return "Selected transparent proxy mode is not available";
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->option.transparent_dst)
+            ++endpoints;
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE,
+            "%-22s = none|source|destination|both transparent proxy mode",
+            "transparent");
+        break;
+    }
+#endif
+
+    /* verify */
+    switch(cmd) {
+    case CMD_BEGIN:
+        section->verify_level=-1; /* do not even request a certificate */
+        break;
+    case CMD_EXEC:
+        if(strcasecmp(opt, "verify"))
+            break;
+        section->verify_level=(int)strtol(arg, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return "Bad verify level";
+        if(section->verify_level<0 || section->verify_level>4)
+            return "Bad verify level";
+        return NULL; /* OK */
+    case CMD_END:
+        if(section->verify_level>0 && !section->ca_file && !section->ca_dir)
+            return "Either \"CAfile\" or \"CApath\" has to be configured";
+        break;
+    case CMD_FREE:
+        break;
+    case CMD_DEFAULT:
+        s_log(LOG_NOTICE, "%-22s = none", "verify");
+        break;
+    case CMD_HELP:
+        s_log(LOG_NOTICE,
+            "%-22s = level of peer certificate verification", "verify");
+        s_log(LOG_NOTICE,
+            "%25slevel 0 - request and ignore peer cert", "");
+        s_log(LOG_NOTICE,
+            "%25slevel 1 - only validate peer cert if present", "");
+        s_log(LOG_NOTICE,
+            "%25slevel 2 - always require a valid peer cert", "");
+        s_log(LOG_NOTICE,
+            "%25slevel 3 - verify peer with locally installed cert", "");
+        s_log(LOG_NOTICE,
+            "%25slevel 4 - ignore CA chain and only verify peer cert", "");
+        break;
+    }
+
+    /* final checks */
+    switch(cmd) {
+    case CMD_BEGIN:
+        break;
+    case CMD_EXEC:
+        return option_not_found;
+    case CMD_END:
+        if(new_service_options.next) { /* daemon mode checks */
+            if(endpoints!=2)
+                return "Each service must define two endpoints";
+        } else { /* inetd mode checks */
+            if(section->option.accept)
+                return "'accept' option is only allowed in a [section]";
+            /* no need to check for section->option.sni in inetd mode,
+               as it requires valid sections to be set */
+            if(endpoints!=1)
+                return "Inetd mode must define one endpoint";
+        }
+        if(context_init(section)) /* initialize SSL context */
+            return "Failed to initialize SSL context";
+    case CMD_FREE:
+    case CMD_DEFAULT:
+    case CMD_HELP:
+        break;
+    }
+
+    return NULL; /* OK */
+}
+
+/**************************************** validate and initialize configuration */
+
+#ifndef OPENSSL_NO_TLSEXT
+NOEXPORT char *sni_init(SERVICE_OPTIONS *section) {
+    char *tmp_str;
+    SERVICE_OPTIONS *tmpsrv;
+
+    /* server mode: update servername_list based on the SNI option */
+    if(!section->option.client && section->sni) {
+        tmp_str=strchr(section->sni, ':');
+        if(!tmp_str)
+            return "Invalid SNI parameter format";
+        *tmp_str++='\0';
+        for(tmpsrv=new_service_options.next; tmpsrv; tmpsrv=tmpsrv->next)
+            if(!strcmp(tmpsrv->servname, section->sni))
+                break;
+        if(!tmpsrv)
+            return "SNI section name not found";
+        if(tmpsrv->option.client)
+            return "SNI master service is a TLS client";
+        if(tmpsrv->servername_list_tail) {
+            tmpsrv->servername_list_tail->next=str_alloc(sizeof(SERVERNAME_LIST));
+            tmpsrv->servername_list_tail=tmpsrv->servername_list_tail->next;
+        } else { /* first virtual service */
+            tmpsrv->servername_list_head=
+                tmpsrv->servername_list_tail=
+                str_alloc(sizeof(SERVERNAME_LIST));
+            tmpsrv->ssl_options_set|=
+                SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION;
+        }
+        tmpsrv->servername_list_tail->servername=str_dup(tmp_str);
+        tmpsrv->servername_list_tail->opt=section;
+        tmpsrv->servername_list_tail->next=NULL;
+        section->option.sni=1;
+        /* always negotiate a new session on renegotiation, as the SSL
+         * context settings (including access control) may be different */
+        section->ssl_options_set|=
+            SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION;
+    }
+
+    /* client mode: setup SNI default based on 'protocolHost' and 'connect' options */
+    if(section->option.client && !section->sni) {
+        /* setup host_name for SNI, prefer SNI and protocolHost if specified */
+        if(section->protocol_host) /* 'protocolHost' option */
+            section->sni=str_dup(section->protocol_host);
+        else if(section->connect_addr.names) /* 'connect' option */
+            section->sni=str_dup(section->connect_addr.names->name); /* first hostname */
+        if(section->sni) { /* either 'protocolHost' or 'connect' specified */
+            tmp_str=strrchr(section->sni, ':');
+            if(tmp_str) { /* 'host:port' -> drop ':port' */
+                *tmp_str='\0';
+            } else { /* 'port' -> default to 'localhost' */
+                str_free(section->sni);
+                section->sni=str_dup("localhost");
+            }
+        }
+    }
+    return NULL;
+}
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+
+/**************************************** facility/debug level */
+
+typedef struct {
+    char *name;
+    int value;
+} facilitylevel;
+
+NOEXPORT char *parse_debug_level(char *arg, SERVICE_OPTIONS *section) {
+    char *arg_copy;
+    char *string;
+    facilitylevel *fl;
+
+/* facilities only make sense on unix */
+#if !defined (USE_WIN32) && !defined (__vms)
+    facilitylevel facilities[] = {
+        {"auth", LOG_AUTH},     {"cron", LOG_CRON},     {"daemon", LOG_DAEMON},
+        {"kern", LOG_KERN},     {"lpr", LOG_LPR},       {"mail", LOG_MAIL},
+        {"news", LOG_NEWS},     {"syslog", LOG_SYSLOG}, {"user", LOG_USER},
+        {"uucp", LOG_UUCP},     {"local0", LOG_LOCAL0}, {"local1", LOG_LOCAL1},
+        {"local2", LOG_LOCAL2}, {"local3", LOG_LOCAL3}, {"local4", LOG_LOCAL4},
+        {"local5", LOG_LOCAL5}, {"local6", LOG_LOCAL6}, {"local7", LOG_LOCAL7},
+
+        /* some facilities are not defined on all Unices */
+#ifdef LOG_AUTHPRIV
+        {"authpriv", LOG_AUTHPRIV},
+#endif
+#ifdef LOG_FTP
+        {"ftp", LOG_FTP},
+#endif
+#ifdef LOG_NTP
+        {"ntp", LOG_NTP},
+#endif
+        {NULL, 0}
+    };
+#endif /* USE_WIN32, __vms */
+
+    facilitylevel levels[] = {
+        {"emerg", LOG_EMERG},     {"alert", LOG_ALERT},
+        {"crit", LOG_CRIT},       {"err", LOG_ERR},
+        {"warning", LOG_WARNING}, {"notice", LOG_NOTICE},
+        {"info", LOG_INFO},       {"debug", LOG_DEBUG},
+        {NULL, -1}
+    };
+
+    arg_copy=str_dup(arg);
+    string=arg_copy;
+
+/* facilities only make sense on Unix */
+#if !defined (USE_WIN32) && !defined (__vms)
+    if(section==&new_service_options && strchr(string, '.')) {
+        /* a facility was specified in the global options */
+        new_global_options.log_facility=-1;
+        string=strtok(arg_copy, "."); /* break it up */
+
+        for(fl=facilities; fl->name; ++fl) {
+            if(!strcasecmp(fl->name, string)) {
+                new_global_options.log_facility=fl->value;
+                break;
+            }
+        }
+        if(new_global_options.log_facility==-1)
+            return "Illegal syslog facility";
+        string=strtok(NULL, ".");    /* set to the remainder */
+    }
+#endif /* USE_WIN32, __vms */
+
+    /* time to check the syslog level */
+    if(string && strlen(string)==1 && *string>='0' && *string<='7') {
+        section->log_level=*string-'0';
+        return NULL; /* OK */
+    }
+    section->log_level=8;    /* illegal level */
+    for(fl=levels; fl->name; ++fl) {
+        if(!strcasecmp(fl->name, string)) {
+            section->log_level=fl->value;
+            break;
+        }
+    }
+    if(section->log_level==8)
+        return "Illegal debug level"; /* FAILED */
+    return NULL; /* OK */
+}
+
+/**************************************** SSL options */
+
+NOEXPORT long parse_ssl_option(char *arg) {
+    SSL_OPTION *option;
+
+    for(option=(SSL_OPTION *)ssl_opts; option->name; ++option)
+        if(!strcasecmp(option->name, arg))
+            return option->value;
+    return 0; /* FAILED */
+}
+
+NOEXPORT void print_ssl_options(void) {
+    SSL_OPTION *option;
+
+    s_log(LOG_NOTICE, " ");
+    s_log(LOG_NOTICE, "Supported SSL options:");
+    for(option=(SSL_OPTION *)ssl_opts; option->name; ++option)
+        s_log(LOG_NOTICE, "options = %s", option->name);
+}
+
+/**************************************** read PSK file */
+
+#ifndef OPENSSL_NO_PSK
+
+NOEXPORT PSK_KEYS *psk_read(char *key_file) {
+    DISK_FILE *df;
+    char line[CONFLINELEN], *key_val;
+    size_t key_len;
+    PSK_KEYS *head=NULL, *tail=NULL, *curr;
+    int line_number=0;
+
+    if(file_permissions(key_file))
+        return NULL;
+    df=file_open(key_file, FILE_MODE_READ);
+    if(!df) {
+        s_log(LOG_ERR, "Cannot open PSKsecrets file");
+        return NULL;
+    }
+    while(file_getline(df, line, CONFLINELEN)>=0) {
+        ++line_number;
+        if(!line[0]) /* empty line */
+            continue;
+        key_val=strchr(line, ':');
+        if(!key_val) {
+            s_log(LOG_ERR,
+                "PSKsecrets line %d: Not in identity:key format",
+                line_number);
+            file_close(df);
+            psk_free(head);
+            return NULL;
+        }
+        *key_val++='\0';
+        key_len=strlen(key_val);
+        if(strlen(line)+1>PSK_MAX_IDENTITY_LEN) { /* with the trailing '\0' */
+            s_log(LOG_ERR,
+                "PSKsecrets line %d: Identity longer than %d characters",
+                line_number, PSK_MAX_IDENTITY_LEN);
+            file_close(df);
+            psk_free(head);
+            return NULL;
+        }
+        if(key_len>PSK_MAX_PSK_LEN) {
+            s_log(LOG_ERR,
+                "PSKsecrets line %d: Key longer than %d characters",
+                line_number, PSK_MAX_PSK_LEN);
+            file_close(df);
+            psk_free(head);
+            return NULL;
+        }
+        if(key_len<20) {
+            /* shorter keys are unlikely to have sufficient entropy */
+            s_log(LOG_ERR,
+                "PSKsecrets line %d: Key shorter than 20 characters",
+                line_number);
+            file_close(df);
+            psk_free(head);
+            return NULL;
+        }
+        curr=str_alloc(sizeof(PSK_KEYS));
+        curr->identity=str_dup(line);
+        curr->key_val=(unsigned char *)str_dup(key_val);
+        curr->key_len=key_len;
+        curr->next=NULL;
+        if(head)
+            tail->next=curr;
+        else
+            head=curr;
+        tail=curr;
+    }
+    file_close(df);
+    return head;
+}
+
+NOEXPORT void psk_free(PSK_KEYS *head) {
+    PSK_KEYS *next;
+
+    while(head) {
+        next=head->next;
+        str_free(head->identity);
+        str_free(head->key_val);
+        str_free(head);
+        head=next;
+    }
+}
+
+#endif
+
+/**************************************** socket options */
+
+static int on=1;
+#define DEF_ON ((void *)&on)
+
+SOCK_OPT sock_opts[] = {
+    {"SO_DEBUG",        SOL_SOCKET,  SO_DEBUG,        TYPE_FLAG,    {NULL, NULL, NULL}},
+    {"SO_DONTROUTE",    SOL_SOCKET,  SO_DONTROUTE,    TYPE_FLAG,    {NULL, NULL, NULL}},
+    {"SO_KEEPALIVE",    SOL_SOCKET,  SO_KEEPALIVE,    TYPE_FLAG,    {NULL, NULL, NULL}},
+    {"SO_LINGER",       SOL_SOCKET,  SO_LINGER,       TYPE_LINGER,  {NULL, NULL, NULL}},
+    {"SO_OOBINLINE",    SOL_SOCKET,  SO_OOBINLINE,    TYPE_FLAG,    {NULL, NULL, NULL}},
+    {"SO_RCVBUF",       SOL_SOCKET,  SO_RCVBUF,       TYPE_INT,     {NULL, NULL, NULL}},
+    {"SO_SNDBUF",       SOL_SOCKET,  SO_SNDBUF,       TYPE_INT,     {NULL, NULL, NULL}},
+#ifdef SO_RCVLOWAT
+    {"SO_RCVLOWAT",     SOL_SOCKET,  SO_RCVLOWAT,     TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef SO_SNDLOWAT
+    {"SO_SNDLOWAT",     SOL_SOCKET,  SO_SNDLOWAT,     TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef SO_RCVTIMEO
+    {"SO_RCVTIMEO",     SOL_SOCKET,  SO_RCVTIMEO,     TYPE_TIMEVAL, {NULL, NULL, NULL}},
+#endif
+#ifdef SO_SNDTIMEO
+    {"SO_SNDTIMEO",     SOL_SOCKET,  SO_SNDTIMEO,     TYPE_TIMEVAL, {NULL, NULL, NULL}},
+#endif
+    {"SO_REUSEADDR",    SOL_SOCKET,  SO_REUSEADDR,    TYPE_FLAG,    {DEF_ON, NULL, NULL}},
+#ifdef SO_BINDTODEVICE
+    {"SO_BINDTODEVICE", SOL_SOCKET,  SO_BINDTODEVICE, TYPE_STRING,  {NULL, NULL, NULL}},
+#endif
+#ifdef TCP_KEEPCNT
+    {"TCP_KEEPCNT",     SOL_TCP,     TCP_KEEPCNT,     TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef TCP_KEEPIDLE
+    {"TCP_KEEPIDLE",    SOL_TCP,     TCP_KEEPIDLE,    TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef TCP_KEEPINTVL
+    {"TCP_KEEPINTVL",   SOL_TCP,     TCP_KEEPINTVL,   TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef IP_TOS
+    {"IP_TOS",          IPPROTO_IP,  IP_TOS,          TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef IP_TTL
+    {"IP_TTL",          IPPROTO_IP,  IP_TTL,          TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+#ifdef IP_MAXSEG
+    {"TCP_MAXSEG",      IPPROTO_TCP, TCP_MAXSEG,      TYPE_INT,     {NULL, NULL, NULL}},
+#endif
+    {"TCP_NODELAY",     IPPROTO_TCP, TCP_NODELAY,     TYPE_FLAG,    {NULL, DEF_ON, DEF_ON}},
+#ifdef IP_FREEBIND
+    {"IP_FREEBIND",     IPPROTO_IP,  IP_FREEBIND,     TYPE_FLAG,    {NULL, NULL, NULL}},
+#endif
+#ifdef IP_BINDANY
+    {"IP_BINDANY",      IPPROTO_IP,  IP_BINDANY,      TYPE_FLAG,    {NULL, NULL, NULL}},
+#endif
+#ifdef IPV6_BINDANY
+    {"IPV6_BINDANY",    IPPROTO_IPV6,IPV6_BINDANY,    TYPE_FLAG,    {NULL, NULL, NULL}},
+#endif
+    {NULL,              0,           0,               TYPE_NONE,    {NULL, NULL, NULL}}
+};
+
+NOEXPORT int print_socket_options(void) {
+    SOCKET fd;
+    socklen_t optlen;
+    SOCK_OPT *ptr;
+    OPT_UNION val;
+    char *ta, *tl, *tr, *td;
+
+    fd=socket(AF_INET, SOCK_STREAM, 0);
+
+    s_log(LOG_NOTICE, " ");
+    s_log(LOG_NOTICE, "Socket option defaults:");
+    s_log(LOG_NOTICE,
+        "    Option Name     |  Accept  |   Local  |  Remote  |OS default");
+    s_log(LOG_NOTICE,
+        "    ----------------+----------+----------+----------+----------");
+    for(ptr=sock_opts; ptr->opt_str; ++ptr) {
+        /* get OS default value */
+        optlen=sizeof val;
+        if(getsockopt(fd, ptr->opt_level,
+                ptr->opt_name, (void *)&val, &optlen)) {
+            if(get_last_socket_error()!=S_ENOPROTOOPT) {
+                s_log(LOG_ERR, "Failed to get %s OS default", ptr->opt_str);
+                sockerror("getsockopt");
+                closesocket(fd);
+                return 1; /* FAILED */
+            }
+            td=str_dup("write-only");
+        } else
+            td=print_option(ptr->opt_type, &val);
+        /* get stunnel default values */
+        ta=print_option(ptr->opt_type, ptr->opt_val[0]);
+        tl=print_option(ptr->opt_type, ptr->opt_val[1]);
+        tr=print_option(ptr->opt_type, ptr->opt_val[2]);
+        /* print collected data and fee the memory */
+        s_log(LOG_NOTICE, "    %-16s|%10s|%10s|%10s|%10s",
+            ptr->opt_str, ta, tl, tr, td);
+        str_free(ta); str_free(tl); str_free(tr); str_free(td);
+    }
+    closesocket(fd);
+    return 0; /* OK */
+}
+
+NOEXPORT char *print_option(int type, OPT_UNION *val) {
+    if(!val)
+        return str_dup("    --    ");
+    switch(type) {
+    case TYPE_FLAG:
+        return str_printf("%s", val->i_val ? "yes" : "no");
+    case TYPE_INT:
+        return str_printf("%d", val->i_val);
+    case TYPE_LINGER:
+        return str_printf("%d:%d",
+            val->linger_val.l_onoff, val->linger_val.l_linger);
+    case TYPE_TIMEVAL:
+        return str_printf("%d:%d",
+            (int)val->timeval_val.tv_sec, (int)val->timeval_val.tv_usec);
+    case TYPE_STRING:
+        return str_printf("%s", val->c_val);
+    }
+    return str_dup("  Ooops?  "); /* internal error? */
+}
+
+NOEXPORT int parse_socket_option(char *arg) {
+    int socket_type; /* 0-accept, 1-local, 2-remote */
+    char *opt_val_str, *opt_val2_str, *tmp_str;
+    SOCK_OPT *ptr;
+
+    if(arg[1]!=':')
+        return 1; /* FAILED */
+    switch(arg[0]) {
+    case 'a':
+        socket_type=0; break;
+    case 'l':
+        socket_type=1; break;
+    case 'r':
+        socket_type=2; break;
+    default:
+        return 1; /* FAILED */
+    }
+    arg+=2;
+    opt_val_str=strchr(arg, '=');
+    if(!opt_val_str) /* no '='? */
+        return 1; /* FAILED */
+    *opt_val_str++='\0';
+    ptr=sock_opts;
+    for(;;) {
+        if(!ptr->opt_str)
+            return 1; /* FAILED */
+        if(!strcmp(arg, ptr->opt_str))
+            break; /* option name found */
+        ++ptr;
+    }
+    ptr->opt_val[socket_type]=str_alloc(sizeof(OPT_UNION));
+    switch(ptr->opt_type) {
+    case TYPE_FLAG:
+        if(!strcasecmp(opt_val_str, "yes") || !strcmp(opt_val_str, "1")) {
+            ptr->opt_val[socket_type]->i_val=1;
+            return 0; /* OK */
+        }
+        if(!strcasecmp(opt_val_str, "no") || !strcmp(opt_val_str, "0")) {
+            ptr->opt_val[socket_type]->i_val=0;
+            return 0; /* OK */
+        }
+        return 1; /* FAILED */
+    case TYPE_INT:
+        ptr->opt_val[socket_type]->i_val=(int)strtol(opt_val_str, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return 1; /* FAILED */
+        return 0; /* OK */
+    case TYPE_LINGER:
+        opt_val2_str=strchr(opt_val_str, ':');
+        if(opt_val2_str) {
+            *opt_val2_str++='\0';
+            ptr->opt_val[socket_type]->linger_val.l_linger=
+                (u_short)strtol(opt_val2_str, &tmp_str, 10);
+            if(tmp_str==arg || *tmp_str) /* not a number */
+                return 1; /* FAILED */
+        } else {
+            ptr->opt_val[socket_type]->linger_val.l_linger=0;
+        }
+        ptr->opt_val[socket_type]->linger_val.l_onoff=
+            (u_short)strtol(opt_val_str, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return 1; /* FAILED */
+        return 0; /* OK */
+    case TYPE_TIMEVAL:
+        opt_val2_str=strchr(opt_val_str, ':');
+        if(opt_val2_str) {
+            *opt_val2_str++='\0';
+            ptr->opt_val[socket_type]->timeval_val.tv_usec=
+                strtol(opt_val2_str, &tmp_str, 10);
+            if(tmp_str==arg || *tmp_str) /* not a number */
+                return 1; /* FAILED */
+        } else {
+            ptr->opt_val[socket_type]->timeval_val.tv_usec=0;
+        }
+        ptr->opt_val[socket_type]->timeval_val.tv_sec=strtol(opt_val_str, &tmp_str, 10);
+        if(tmp_str==arg || *tmp_str) /* not a number */
+            return 1; /* FAILED */
+        return 0; /* OK */
+    case TYPE_STRING:
+        if(strlen(opt_val_str)+1>sizeof(OPT_UNION))
+            return 1; /* FAILED */
+        strcpy(ptr->opt_val[socket_type]->c_val, opt_val_str);
+        return 0; /* OK */
+    default:
+        ; /* ANSI C compiler needs it */
+    }
+    return 1; /* FAILED */
+}
+
+/**************************************** OCSP */
+
+#ifndef OPENSSL_NO_OCSP
+
+NOEXPORT unsigned long parse_ocsp_flag(char *arg) {
+    struct {
+        char *name;
+        unsigned long value;
+    } ocsp_opts[] = {
+        {"NOCERTS", OCSP_NOCERTS},
+        {"NOINTERN", OCSP_NOINTERN},
+        {"NOSIGS", OCSP_NOSIGS},
+        {"NOCHAIN", OCSP_NOCHAIN},
+        {"NOVERIFY", OCSP_NOVERIFY},
+        {"NOEXPLICIT", OCSP_NOEXPLICIT},
+        {"NOCASIGN", OCSP_NOCASIGN},
+        {"NODELEGATED", OCSP_NODELEGATED},
+        {"NOCHECKS", OCSP_NOCHECKS},
+        {"TRUSTOTHER", OCSP_TRUSTOTHER},
+        {"RESPID_KEY", OCSP_RESPID_KEY},
+        {"NOTIME", OCSP_NOTIME},
+        {NULL, 0}
+    }, *option;
+
+    for(option=ocsp_opts; option->name; ++option)
+        if(!strcasecmp(option->name, arg))
+            return option->value;
+    return 0; /* FAILED */
+}
+
+#endif /* !defined(OPENSSL_NO_OCSP) */
+
+/**************************************** engine */
+
+#ifndef OPENSSL_NO_ENGINE
+
+#define MAX_ENGINES 256
+static ENGINE *engines[MAX_ENGINES]; /* table of engines for config parser */
+static int current_engine;
+static int engine_initialized;
+
+NOEXPORT void engine_reset_list(void) {
+    current_engine=-1;
+}
+
+NOEXPORT char *engine_auto(void) {
+    ENGINE *e;
+
+    s_log(LOG_DEBUG, "Enabling automatic engine support");
+    ENGINE_register_all_complete();
+    current_engine=-1;
+    /* rebuild the internal list of engines */
+    for(e=ENGINE_get_first(); e; e=ENGINE_get_next(e)) {
+        if(++current_engine>=MAX_ENGINES)
+            return "Too many open engines";
+        engines[current_engine]=e;
+        s_log(LOG_INFO, "Engine #%d (%s) registered",
+            current_engine+1, ENGINE_get_id(e));
+    }
+    engine_initialized=1;
+    s_log(LOG_DEBUG, "Automatic engine support enabled");
+    return NULL; /* OK */
+}
+
+NOEXPORT char *engine_open(const char *name) {
+    engine_next();
+    if(current_engine>=MAX_ENGINES)
+        return "Too many open engines";
+    s_log(LOG_DEBUG, "Enabling support for engine \"%s\"", name);
+    engines[current_engine]=ENGINE_by_id(name);
+    engine_initialized=0;
+    if(!engines[current_engine]) {
+        sslerror("ENGINE_by_id");
+        return "Failed to open the engine";
+    }
+    return NULL; /* OK */
+}
+
+NOEXPORT char *engine_ctrl(const char *cmd, const char *arg) {
+    if(current_engine<0)
+        return "No engine was defined";
+    if(!strcasecmp(cmd, "INIT")) /* special control command */
+        return engine_init();
+    if(arg)
+        s_log(LOG_DEBUG, "Executing engine control command %s:%s", cmd, arg);
+    else
+        s_log(LOG_DEBUG, "Executing engine control command %s", cmd);
+    if(!ENGINE_ctrl_cmd_string(engines[current_engine], cmd, arg, 0)) {
+        sslerror("ENGINE_ctrl_cmd_string");
+        return "Failed to execute the engine control command";
+    }
+    return NULL; /* OK */
+}
+
+NOEXPORT char *engine_default(const char *list) {
+    if(current_engine<0)
+        return "No engine was defined";
+    if(!ENGINE_set_default_string(engines[current_engine], list)) {
+        sslerror("ENGINE_set_default_string");
+        return "Failed to set engine as default";
+    }
+    s_log(LOG_INFO, "Engine #%d (%s) set as default for %s",
+        current_engine+1, ENGINE_get_id(engines[current_engine]), list);
+    return NULL;
+}
+
+NOEXPORT char *engine_init(void) {
+    if(current_engine<0)
+        return "No engine was defined";
+    if(engine_initialized)
+        return NULL; /* OK */
+    s_log(LOG_DEBUG, "Initializing engine #%d (%s)",
+        current_engine+1, ENGINE_get_id(engines[current_engine]));
+    if(!ENGINE_init(engines[current_engine])) {
+        if(ERR_peek_last_error()) /* really an error */
+            sslerror("ENGINE_init");
+        else
+            s_log(LOG_ERR, "Engine #%d (%s) not initialized",
+                current_engine+1, ENGINE_get_id(engines[current_engine]));
+        return "Engine initialization failed";
+    }
+#if 0
+    /* it is a bad idea to set the engine as default for all sections */
+    /* the "engine=auto" or "engineDefault" options should be used instead */
+    if(!ENGINE_set_default(engines[current_engine], ENGINE_METHOD_ALL)) {
+        sslerror("ENGINE_set_default");
+        return "Selecting default engine failed";
+    }
+#endif
+    s_log(LOG_INFO, "Engine #%d (%s) initialized",
+        current_engine+1, ENGINE_get_id(engines[current_engine]));
+    engine_initialized=1;
+    return NULL; /* OK */
+}
+
+NOEXPORT void engine_next(void) {
+    if(current_engine>=0)
+        engine_init();
+    ++current_engine;
+}
+
+NOEXPORT ENGINE *engine_get_by_id(const char *id) {
+    int i;
+
+    for(i=0; i<current_engine; ++i)
+        if(!strcmp(id, ENGINE_get_id(engines[i])))
+            return engines[i];
+    return NULL;
+}
+
+NOEXPORT ENGINE *engine_get_by_num(const int i) {
+    if(i<0 || i>=current_engine)
+        return NULL;
+    return engines[i];
+}
+
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+/**************************************** fatal error */
+
+NOEXPORT void print_syntax(void) {
+    s_log(LOG_NOTICE, " ");
+    s_log(LOG_NOTICE, "Syntax:");
+    s_log(LOG_NOTICE, "stunnel "
+#ifdef USE_WIN32
+#ifndef _WIN32_WCE
+        "[ [-install | -uninstall | -reload | -reopen] "
+#endif
+        "[-quiet] "
+#endif
+        "[<filename>] ] "
+#ifndef USE_WIN32
+        "-fd <n> "
+#endif
+        "| -help | -version | -sockets");
+    s_log(LOG_NOTICE, "    <filename>  - use specified config file");
+#ifdef USE_WIN32
+#ifndef _WIN32_WCE
+    s_log(LOG_NOTICE, "    -install    - install NT service");
+    s_log(LOG_NOTICE, "    -uninstall  - uninstall NT service");
+    s_log(LOG_NOTICE, "    -reload     - reload configuration for NT service");
+    s_log(LOG_NOTICE, "    -reopen     - reopen log file for NT service");
+#endif
+    s_log(LOG_NOTICE, "    -quiet      - don't display message boxes");
+#else
+    s_log(LOG_NOTICE, "    -fd <n>     - read the config file from a file descriptor");
+#endif
+    s_log(LOG_NOTICE, "    -help       - get config file help");
+    s_log(LOG_NOTICE, "    -version    - display version and defaults");
+    s_log(LOG_NOTICE, "    -sockets    - display default socket options");
+}
+
+/**************************************** various supporting functions */
+
+NOEXPORT void name_list_append(NAME_LIST **ptr, char *name) {
+    while(*ptr) /* find the null pointer */
+        ptr=&(*ptr)->next;
+    *ptr=str_alloc(sizeof(NAME_LIST));
+    (*ptr)->name=str_dup(name);
+    (*ptr)->next=NULL;
+}
+
+#ifndef USE_WIN32
+
+NOEXPORT char **argalloc(char *str) { /* allocate 'exec' argumets */
+    size_t max_arg, i;
+    char *ptr, **retval;
+
+    max_arg=strlen(str)/2+1;
+    ptr=str_dup(str);
+    retval=str_alloc((max_arg+1)*sizeof(char *));
+    i=0;
+    while(*ptr && i<max_arg) {
+        retval[i++]=ptr;
+        while(*ptr && !isspace((unsigned char)*ptr))
+            ++ptr;
+        while(*ptr && isspace((unsigned char)*ptr))
+            *ptr++='\0';
+    }
+    retval[i]=NULL; /* to show that it's null-terminated */
+    return retval;
+}
+#endif
+
+/* end of options.c */
diff --git a/src/os2.mak b/src/os2.mak
new file mode 100644
index 0000000..7ab6cfe
--- /dev/null
+++ b/src/os2.mak
@@ -0,0 +1,78 @@
+prefix=.
+DEFS = -DPACKAGE_NAME=\"stunnel\" \
+	-DPACKAGE_TARNAME=\"stunnel\" \
+	-DPACKAGE_VERSION=\"5.22\" \
+	-DPACKAGE_STRING=\"stunnel\ 5.22\" \
+	-DPACKAGE_BUGREPORT=\"\" \
+	-DPACKAGE=\"stunnel\" \
+	-DVERSION=\"5.22\" \
+	-DSTDC_HEADERS=1 \
+	-DHAVE_SYS_TYPES_H=1 \
+	-DHAVE_SYS_STAT_H=1 \
+	-DHAVE_STDLIB_H=1 \
+	-DHAVE_STRING_H=1 \
+	-DHAVE_MEMORY_H=1 \
+	-DHAVE_STRINGS_H=1 \
+	-DHAVE_UNISTD_H=1 \
+	-DHAVE_OSSL_ENGINE_H=1 \
+	-DSSLDIR=\"/usr\" \
+	-DHOST=\"i386-pc-os2-emx\" \
+	-DHAVE_LIBSOCKET=1 \
+	-DHAVE_GRP_H=1 \
+	-DHAVE_UNISTD_H=1 \
+	-DHAVE_SYS_SELECT_H=1 \
+	-DHAVE_SYS_IOCTL_H=1 \
+	-DHAVE_SYS_RESOURCE_H=1 \
+	-DHAVE_SNPRINTF=1 \
+	-DHAVE_VSNPRINTF=1 \
+	-DHAVE_WAITPID=1 \
+	-DHAVE_SYSCONF=1 \
+	-DHAVE_ENDHOSTENT=1 \
+        -DUSE_OS2=1 \
+	-DSIZEOF_UNSIGNED_CHAR=1 \
+	-DSIZEOF_UNSIGNED_SHORT=2 \
+	-DSIZEOF_UNSIGNED_INT=4 \
+	-DSIZEOF_UNSIGNED_LONG=4 \
+      	-DLIBDIR=\"$(prefix)/lib\" \
+        -DCONFDIR=\"$(prefix)/etc\"
+
+CC = gcc
+.SUFFIXES = .c .o
+OPENSSLDIR = u:/extras
+#SYSLOGDIR = /unixos2/workdir/syslog
+INCLUDES = -I$(OPENSSLDIR)/outinc
+LIBS = -lsocket -L$(OPENSSLDIR)/out -lssl -lcrypto -lz -lsyslog
+OBJS = file.o client.o log.o options.o protocol.o network.o ssl.o ctx.o verify.o sthreads.o stunnel.o pty.o resolver.o str.o tls.o fd.o dhparam.o cron.o
+LIBDIR = .
+CFLAGS = -O2 -Wall -Wshadow -Wcast-align -Wpointer-arith
+
+all: stunnel.exe
+
+stunnel.exe: $(OBJS)
+	$(CC) -Zmap $(CFLAGS) -o $@ $(OBJS) $(LIBS)
+
+.c.o:
+	$(CC) $(CFLAGS) $(DEFS) $(INCLUDES) -o $@ -c $<
+
+client.o: client.c common.h prototypes.h
+#env.o: env.c common.h prototypes.h
+#gui.o: gui.c common.h prototypes.h
+file.o: file.c common.h prototypes.h
+network.o: network.c common.h prototypes.h
+options.o: options.c common.h prototypes.h
+protocol.o: protocol.c common.h prototypes.h
+pty.o: pty.c common.h prototypes.h
+ssl.o: ssl.c common.h prototypes.h
+ctx.o: ctx.c common.h prototypes.h
+verify.o: verify.c common.h prototypes.h
+sthreads.o: sthreads.c common.h prototypes.h
+stunnel.o: stunnel.c common.h prototypes.h
+resolver.o: resolver.c common.h prototypes.h
+str.o: str.c common.h prototypes.h
+tls.o: tls.c common.h prototypes.h
+fd.o: fd.c common.h prototypes.h
+dhparam.o: dhparam.c common.h prototypes.h
+cron.o: cron.c common.h prototypes.h
+
+clean:
+	rm -f *.o *.exe
diff --git a/src/protocol.c b/src/protocol.c
new file mode 100644
index 0000000..e62c848
--- /dev/null
+++ b/src/protocol.c
@@ -0,0 +1,1139 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#define is_prefix(a, b) (strncasecmp((a), (b), strlen(b))==0)
+
+/* protocol-specific function prototypes */
+NOEXPORT char *socks_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT void socks4_server(CLI *);
+NOEXPORT void socks5_server_method(CLI *);
+NOEXPORT void socks5_server(CLI *);
+NOEXPORT char *proxy_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *cifs_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *cifs_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *pgsql_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *pgsql_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *smtp_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *smtp_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *pop3_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *pop3_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *imap_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *imap_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *nntp_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *connect_server(CLI *, SERVICE_OPTIONS *, const PHASE);
+NOEXPORT char *connect_client(CLI *, SERVICE_OPTIONS *, const PHASE);
+#ifndef OPENSSL_NO_MD4
+NOEXPORT void ntlm(CLI *, SERVICE_OPTIONS *);
+NOEXPORT char *ntlm1();
+NOEXPORT char *ntlm3(char *, char *, char *);
+NOEXPORT void crypt_DES(DES_cblock, DES_cblock, DES_cblock);
+#endif
+NOEXPORT char *base64(int, char *, int);
+
+/**************************************** framework */
+
+char *protocol(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    if(phase==PROTOCOL_CHECK) /* default to be overridden by protocols */
+        opt->option.connect_before_ssl=opt->option.client;
+    if(!opt->protocol) /* no protocol specified */
+        return NULL; /* skip further actions */
+    if(!strcasecmp(opt->protocol, "socks"))
+        return opt->option.client ?
+            "The 'socks' protocol is not supported in client mode" :
+            socks_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "proxy"))
+        return opt->option.client ?
+            "The 'proxy' protocol is not supported in client mode" :
+            proxy_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "cifs"))
+        return opt->option.client ?
+            cifs_client(c, opt, phase) :
+            cifs_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "pgsql"))
+        return opt->option.client ?
+            pgsql_client(c, opt, phase) :
+            pgsql_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "smtp"))
+        return opt->option.client ?
+            smtp_client(c, opt, phase) :
+            smtp_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "pop3"))
+        return opt->option.client ?
+            pop3_client(c, opt, phase) :
+            pop3_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "imap"))
+        return opt->option.client ?
+            imap_client(c, opt, phase) :
+            imap_server(c, opt, phase);
+    if(!strcasecmp(opt->protocol, "nntp"))
+        return opt->option.client ?
+            nntp_client(c, opt, phase) :
+            "The 'nntp' protocol is not supported in server mode";
+    if(!strcasecmp(opt->protocol, "connect"))
+        return opt->option.client ?
+            connect_client(c, opt, phase) :
+            connect_server(c, opt, phase);
+    return "Protocol not supported";
+}
+
+/**************************************** socks */
+
+/* SOCKS over SSL (SOCKS protocol itself is also encrypted) */
+/* FIXME: connect() failures are not currently reported with SOCKS protocol */
+
+NOEXPORT char *socks_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    uint8_t version;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+
+    s_log(LOG_DEBUG, "Waiting for the SOCKS request");
+    s_ssl_read(c, &version, sizeof version);
+    switch(version) {
+    case 4:
+        socks4_server(c);
+        break;
+    case 5:
+        socks5_server_method(c);
+        socks5_server(c);
+        break;
+    default:
+        s_log(LOG_ERR, "Unsupported SOCKS version %u", version);
+        longjmp(c->err, 1);
+    }
+    return NULL;
+}
+
+/* SOCKS4 or SOCKS4a */
+/* BIND command is not supported */
+/* USERID parameter is ignored */
+
+NOEXPORT void socks4_server(CLI *c) {
+    struct {
+        uint8_t vn, cd;
+        u_short sin_port;
+        struct in_addr sin_addr;
+    } socks;
+    char *user_name, *host_name, *port_name;
+    SOCKADDR_UNION addr;
+    int close_connection=1;
+
+    s_ssl_read(c, &socks.cd, sizeof socks-sizeof socks.vn);
+    socks.vn=0; /* response version 0 */
+    user_name=ssl_getstring(c); /* ignore the username */
+    str_free(user_name);
+
+    if(socks.cd==0x01) { /* CONNECT */
+        if(ntohl(socks.sin_addr.s_addr)>0 &&
+                ntohl(socks.sin_addr.s_addr)<256) { /* 0.0.0.x */
+            host_name=ssl_getstring(c);
+            port_name=str_printf("%u", ntohs(socks.sin_port));
+            hostport2addrlist(&c->connect_addr, host_name, port_name);
+            str_free(port_name);
+            if(c->connect_addr.num) {
+                s_log(LOG_INFO, "SOCKS4a resolved \"%s\" to %u host(s)",
+                    host_name, c->connect_addr.num);
+                socks.cd=90;
+                close_connection=0;
+            } else {
+                s_log(LOG_ERR, "SOCKS4a failed to resolve \"%s\"", host_name);
+                socks.cd=91;
+            }
+            str_free(host_name);
+        } else {
+            c->connect_addr.num=1;
+            c->connect_addr.addr=str_alloc(sizeof(SOCKADDR_UNION));
+            c->connect_addr.addr[0].in.sin_family=AF_INET;
+            c->connect_addr.addr[0].in.sin_port=socks.sin_port;
+            c->connect_addr.addr[0].in.sin_addr.s_addr=socks.sin_addr.s_addr;
+            s_log(LOG_INFO, "SOCKS4 address received");
+            socks.cd=90;
+            close_connection=0;
+        }
+    } else if(socks.cd==0xf0) { /* RESOLVE (a TOR extension) */
+        host_name=ssl_getstring(c);
+        if(hostport2addr(&addr, host_name, "0", 0) && addr.sa.sa_family==AF_INET) {
+            memcpy(&socks.sin_addr, &addr.in.sin_addr, 4);
+            s_log(LOG_INFO, "SOCKS4a/TOR resolved \"%s\"", host_name);
+            socks.cd=90;
+        } else {
+            s_log(LOG_ERR, "SOCKS4a/TOR failed to resolve \"%s\"", host_name);
+            socks.cd=91;
+        }
+        str_free(host_name);
+    } else {
+        s_log(LOG_ERR, "Unsupported SOCKS4/SOCKS4a command %u", socks.cd);
+        socks.cd=91;
+    }
+    s_ssl_write(c, &socks, sizeof socks);
+    if(close_connection)
+        longjmp(c->err, 2); /* don't reset */
+}
+
+NOEXPORT void socks5_server_method(CLI *c) {
+    uint8_t nmethods, *methods;
+    struct {
+        uint8_t ver, method;
+    } response;
+    int i;
+
+    response.ver=0x05;
+    response.method=0xff; /* NO ACCEPTABLE METHODS */
+    s_ssl_read(c, &nmethods, sizeof nmethods);
+    methods=str_alloc(nmethods);
+    s_ssl_read(c, methods, nmethods);
+    for(i=0; i<nmethods; ++i)
+        if(methods[i]==0x00) { /* NO AUTHENTICATION REQUIRED */
+            response.method=0x00; /* use this method */
+            break;
+        }
+    str_free(methods);
+    s_ssl_write(c, &response, sizeof response);
+    if(response.method) { /* request failed */
+        s_log(LOG_ERR, "No supported SOCKS5 authentication method received");
+        longjmp(c->err, 2); /* don't reset */
+    }
+}
+
+/* CONNECT does not return valid BND.ADDR and BND.PORT values */
+
+NOEXPORT void socks5_server(CLI *c) {
+    union {
+        struct {
+            uint8_t ver, cmd, rsv, atyp;
+        } req;
+        struct {
+            uint8_t ver, cmd, rsv, atyp, addr[4], port[2];
+        } v4;
+        struct {
+            uint8_t ver, cmd, rsv, atyp, addr[16], port[2];
+        } v6;
+        struct {
+            uint8_t ver, rep, rsv, atyp;
+        } resp;
+    } socks;
+    uint8_t host_len;
+    char *host_name, *port_name;
+    u_short port_number;
+    SOCKADDR_UNION addr;
+    int close_connection=1;
+
+    /* parse request */
+    memset(&socks, 0, sizeof socks);
+    s_ssl_read(c, &socks, sizeof socks.req);
+    if(socks.req.ver!=0x05) {
+        s_log(LOG_ERR, "Invalid SOCKS5 message version %u", socks.req.ver);
+        socks.resp.ver=0x05; /* response version 5 */
+        socks.resp.rep=0x01; /* general SOCKS server failure */
+    } else if(socks.req.cmd==0x01) { /* CONNECT */
+        if(socks.req.atyp==0x01) { /* IP v4 address */
+            c->connect_addr.num=1;
+            c->connect_addr.addr=str_alloc(sizeof(SOCKADDR_UNION));
+            c->connect_addr.addr[0].in.sin_family=AF_INET;
+            s_ssl_read(c, &socks.v4.addr, 4+2);
+            memcpy(&c->connect_addr.addr[0].in.sin_addr, &socks.v4.addr, 4);
+            memcpy(&c->connect_addr.addr[0].in.sin_port, &socks.v4.port, 2);
+            s_log(LOG_INFO, "SOCKS5 IPv4 address received");
+            socks.resp.rep=0x00; /* succeeded */
+            close_connection=0;
+        } else if(socks.req.atyp==0x03) { /* DOMAINNAME */
+            s_ssl_read(c, &host_len, sizeof host_len);
+            host_name=str_alloc((size_t)host_len+1);
+            s_ssl_read(c, host_name, host_len);
+            host_name[host_len]='\0';
+            s_ssl_read(c, &port_number, 2);
+            port_name=str_printf("%u", ntohs(port_number));
+            hostport2addrlist(&c->connect_addr, host_name, port_name);
+            str_free(port_name);
+            if(c->connect_addr.num) {
+                s_log(LOG_INFO, "SOCKS5 resolved \"%s\" to %u host(s)",
+                    host_name, c->connect_addr.num);
+                socks.resp.rep=0x00; /* succeeded */
+                close_connection=0;
+            } else {
+                s_log(LOG_ERR, "SOCKS5 failed to resolve \"%s\"", host_name);
+                socks.resp.rep=0x04; /* Host unreachable */
+            }
+            str_free(host_name);
+#ifdef USE_IPv6
+        } else if(socks.req.atyp==0x04) { /* IP v6 address */
+            c->connect_addr.num=1;
+            c->connect_addr.addr=str_alloc(sizeof(SOCKADDR_UNION));
+            c->connect_addr.addr[0].in6.sin6_family=AF_INET6;
+            s_ssl_read(c, &socks.v6.addr, 16+2);
+            memcpy(&c->connect_addr.addr[0].in6.sin6_addr, &socks.v6.addr, 16);
+            memcpy(&c->connect_addr.addr[0].in6.sin6_port, &socks.v6.port, 2);
+            s_log(LOG_INFO, "SOCKS5 IPv6 address received");
+            socks.resp.rep=0x00; /* succeeded */
+            close_connection=0;
+#endif
+        } else {
+            s_log(LOG_ERR, "Unsupported SOCKS5 address type %u", socks.req.atyp);
+            socks.resp.rep=0x07; /* Address type not supported */
+        }
+    } else if(socks.req.cmd==0xf0) { /* RESOLVE (a TOR extension) */
+        host_name=ssl_getstring(c);
+        if(hostport2addr(&addr, host_name, "0", 0)) {
+            if(addr.sa.sa_family==AF_INET) {
+                s_log(LOG_INFO, "SOCKS5/TOR resolved \"%s\" to IPv4", host_name);
+                memcpy(&socks.v4.addr, &addr.in.sin_addr, 4);
+                socks.resp.atyp=0x01; /* IP v4 address */
+                socks.resp.rep=0x00; /* succeeded */
+#ifdef USE_IPv6
+            } else if(addr.sa.sa_family==AF_INET6) {
+                s_log(LOG_INFO, "SOCKS5/TOR resolved \"%s\" to IPv6", host_name);
+                memcpy(&socks.v6.addr, &addr.in6.sin6_addr, 16);
+                socks.resp.atyp=0x04; /* IP v6 address */
+                socks.resp.rep=0x00; /* succeeded */
+#endif
+            } else {
+                s_log(LOG_ERR, "SOCKS5/TOR unsupported address family for \"%s\"",
+                    host_name);
+                socks.resp.rep=0x04; /* Host unreachable */
+            }
+        } else {
+            s_log(LOG_ERR, "SOCKS5/TOR failed to resolve \"%s\"", host_name);
+            socks.resp.rep=0x04; /* Host unreachable */
+        }
+        str_free(host_name);
+    } else {
+        s_log(LOG_ERR, "Unsupported SOCKS5 command %u", socks.req.cmd);
+        socks.resp.rep=0x07; /* Command not supported */
+    }
+
+    /* send response */
+    /* broken clients tend to expect the same address family for response,
+     * so stunnel tries to preserve the address family if possible */
+    if(socks.resp.atyp==0x04) { /* IP V6 address */
+        s_ssl_write(c, &socks, sizeof socks.v6);
+    } else {
+        socks.resp.atyp=0x01; /* IP v4 address */
+        s_ssl_write(c, &socks, sizeof socks.v4);
+    }
+    if(close_connection) /* request failed */
+        longjmp(c->err, 2); /* don't reset */
+}
+
+/**************************************** proxy */
+
+/*
+ * PROXY protocol: http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt
+ * this is a protocol client support for stunnel acting as an SSL server
+ * I don't think anything else is useful, but feel free to discuss on the
+ * stunnel-users mailing list if you disagree
+ */
+
+/* IP address textual representation length */
+/* 1234:6789:1234:6789:1234:6789:1234:6789 -> 40 chars with '\0' */
+#define IP_LEN 40
+#define PORT_LEN 6
+
+NOEXPORT char *proxy_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    SOCKADDR_UNION addr;
+    socklen_t addrlen;
+    char src_host[IP_LEN], dst_host[IP_LEN];
+    char src_port[PORT_LEN], dst_port[PORT_LEN], *proto;
+    int err;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_LATE)
+        return NULL;
+    addrlen=sizeof addr;
+    if(getpeername(c->local_rfd.fd, &addr.sa, &addrlen)) {
+        sockerror("getpeername");
+        longjmp(c->err, 1);
+    }
+    err=getnameinfo(&addr.sa, addr_len(&addr), src_host, IP_LEN,
+        src_port, PORT_LEN, NI_NUMERICHOST|NI_NUMERICSERV);
+    if(err) {
+        s_log(LOG_ERR, "getnameinfo: %s", s_gai_strerror(err));
+        longjmp(c->err, 1);
+    }
+
+    addrlen=sizeof addr;
+    if(getsockname(c->local_rfd.fd, &addr.sa, &addrlen)) {
+        sockerror("getsockname");
+        longjmp(c->err, 1);
+    }
+    err=getnameinfo(&addr.sa, addr_len(&addr), dst_host, IP_LEN,
+        dst_port, PORT_LEN, NI_NUMERICHOST|NI_NUMERICSERV);
+    if(err) {
+        s_log(LOG_ERR, "getnameinfo: %s", s_gai_strerror(err));
+        longjmp(c->err, 1);
+    }
+
+    switch(addr.sa.sa_family) {
+    case AF_INET:
+        proto="TCP4";
+        break;
+#ifdef USE_IPv6
+    case AF_INET6:
+        proto="TCP6";
+        break;
+#endif
+    default: /* AF_UNIX */
+        proto="UNKNOWN";
+    }
+    fd_printf(c, c->remote_fd.fd, "PROXY %s %s %s %s %s",
+        proto, src_host, dst_host, src_port, dst_port);
+    return NULL;
+}
+
+/**************************************** cifs */
+
+NOEXPORT char *cifs_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    uint8_t buffer[5];
+    uint8_t request_dummy[4] = {0x81, 0, 0, 0}; /* a zero-length request */
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    s_write(c, c->remote_fd.fd, request_dummy, 4);
+    s_read(c, c->remote_fd.fd, buffer, 5);
+    if(buffer[0]!=0x83) { /* NB_SSN_NEGRESP */
+        s_log(LOG_ERR, "Negative response expected");
+        longjmp(c->err, 1);
+    }
+    if(buffer[2]!=0 || buffer[3]!=1) { /* length != 1 */
+        s_log(LOG_ERR, "Unexpected NetBIOS response size");
+        longjmp(c->err, 1);
+    }
+    if(buffer[4]!=0x8e) { /* use SSL */
+        s_log(LOG_ERR, "Remote server does not require SSL");
+        longjmp(c->err, 1);
+    }
+    return NULL;
+}
+
+NOEXPORT char *cifs_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    uint8_t buffer[128];
+    uint8_t response_access_denied[5] = {0x83, 0, 0, 1, 0x81};
+    uint8_t response_use_ssl[5] = {0x83, 0, 0, 1, 0x8e};
+    uint16_t len;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_EARLY)
+        return NULL;
+    s_read(c, c->local_rfd.fd, buffer, 4) ;/* NetBIOS header */
+    len=(uint16_t)(((uint16_t)(buffer[2])<<8)|buffer[3]);
+    if(len>sizeof buffer-4) {
+        s_log(LOG_ERR, "Received block too long");
+        longjmp(c->err, 1);
+    }
+    s_read(c, c->local_rfd.fd, buffer+4, len);
+    if(buffer[0]!=0x81) { /* NB_SSN_REQUEST */
+        s_log(LOG_ERR, "Client did not send session setup");
+        s_write(c, c->local_wfd.fd, response_access_denied, 5);
+        longjmp(c->err, 1);
+    }
+    s_write(c, c->local_wfd.fd, response_use_ssl, 5);
+    return NULL;
+}
+
+/**************************************** pgsql */
+
+/* http://www.postgresql.org/docs/8.3/static/protocol-flow.html#AEN73982 */
+static const uint8_t ssl_request[8]={0, 0, 0, 8, 0x04, 0xd2, 0x16, 0x2f};
+
+NOEXPORT char *pgsql_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    uint8_t buffer[1];
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    s_write(c, c->remote_fd.fd, ssl_request, sizeof ssl_request);
+    s_read(c, c->remote_fd.fd, buffer, 1);
+    /* S - accepted, N - rejected, non-SSL preferred */
+    if(buffer[0]!='S') {
+        s_log(LOG_ERR, "PostgreSQL server rejected SSL");
+        longjmp(c->err, 1);
+    }
+    return NULL;
+}
+
+NOEXPORT char *pgsql_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    uint8_t buffer[8], ssl_ok[1]={'S'};
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_EARLY)
+        return NULL;
+    memset(buffer, 0, sizeof buffer);
+    s_read(c, c->local_rfd.fd, buffer, sizeof buffer);
+    if(safe_memcmp(buffer, ssl_request, sizeof ssl_request)) {
+        s_log(LOG_ERR, "PostgreSQL client did not request SSL, rejecting");
+        /* no way to send error on startup, so just drop the client */
+        longjmp(c->err, 1);
+    }
+    s_write(c, c->local_wfd.fd, ssl_ok, sizeof ssl_ok);
+    return NULL;
+}
+
+/**************************************** smtp */
+
+NOEXPORT char *smtp_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    line=str_dup("");
+    do { /* copy multiline greeting */
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+        fd_putline(c, c->local_wfd.fd, line);
+    } while(is_prefix(line, "220-"));
+
+    fd_putline(c, c->remote_fd.fd, "EHLO localhost");
+    do { /* skip multiline reply */
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+    } while(is_prefix(line, "250-"));
+    if(!is_prefix(line, "250 ")) { /* error */
+        s_log(LOG_ERR, "Remote server is not RFC 1425 compliant");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+
+    fd_putline(c, c->remote_fd.fd, "STARTTLS");
+    do { /* skip multiline reply */
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+    } while(is_prefix(line, "220-"));
+    if(!is_prefix(line, "220 ")) { /* error */
+        s_log(LOG_ERR, "Remote server is not RFC 2487 compliant");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    str_free(line);
+    return NULL;
+}
+
+NOEXPORT char *smtp_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line, *domain, *greeting;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase==PROTOCOL_CHECK)
+        opt->option.connect_before_ssl=1; /* c->remote_fd needed */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+
+    /* detect RFC 2487 */
+    s_poll_init(c->fds);
+    s_poll_add(c->fds, c->local_rfd.fd, 1, 0);
+    switch(s_poll_wait(c->fds, 0, 200)) { /* wait up to 200ms */
+    case 0: /* fd not ready to read */
+        s_log(LOG_DEBUG, "RFC 2487 detected");
+        break;
+    case 1: /* fd ready to read */
+        s_log(LOG_DEBUG, "RFC 2487 not detected");
+        return NULL; /* return if RFC 2487 is not used */
+    default: /* -1 */
+        sockerror("RFC2487 (s_poll_wait)");
+        longjmp(c->err, 1);
+    }
+
+    /* process server's greeting */
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!(is_prefix(line, "220 ") || is_prefix(line, "220-"))) {
+        s_log(LOG_ERR, "Unknown server welcome");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    domain=str_dup(line+4); /* skip "220" and the separator */
+    line[4]='\0';     /* only leave "220" and the separator */
+    greeting=strchr(domain, ' ');
+    if(greeting) {
+        *greeting++='\0'; /* truncate anything after the domain name */
+        fd_printf(c, c->local_wfd.fd, "%s%s stunnel for %s",
+            line, domain, greeting);
+    } else {
+        fd_printf(c, c->local_wfd.fd, "%s%s stunnel", line, domain);
+    }
+    while(is_prefix(line, "220-")) { /* copy multiline greeting */
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+        fd_putline(c, c->local_wfd.fd, line);
+    }
+    str_free(line);
+
+    /* process client's EHLO */
+    line=fd_getline(c, c->local_rfd.fd);
+    if(!is_prefix(line, "EHLO ")) {
+        s_log(LOG_ERR, "Unknown client EHLO");
+        str_free(line);
+        str_free(domain);
+        longjmp(c->err, 1);
+    }
+    str_free(line);
+    fd_printf(c, c->local_wfd.fd, "250-%s", domain);
+    str_free(domain);
+    fd_putline(c, c->local_wfd.fd, "250 STARTTLS");
+
+    /* process client's STARTTLS */
+    line=fd_getline(c, c->local_rfd.fd);
+    if(!is_prefix(line, "STARTTLS")) {
+        s_log(LOG_ERR, "STARTTLS expected");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    fd_putline(c, c->local_wfd.fd, "220 Go ahead");
+    str_free(line);
+
+    return NULL;
+}
+
+/**************************************** pop3 */
+
+NOEXPORT char *pop3_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "+OK ")) {
+        s_log(LOG_ERR, "Unknown server welcome");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    fd_putline(c, c->local_wfd.fd, line);
+    fd_putline(c, c->remote_fd.fd, "STLS");
+    str_free(line);
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "+OK ")) {
+        s_log(LOG_ERR, "Server does not support TLS");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    str_free(line);
+    return NULL;
+}
+
+NOEXPORT char *pop3_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase==PROTOCOL_CHECK)
+        opt->option.connect_before_ssl=1; /* c->remote_fd needed */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    line=fd_getline(c, c->remote_fd.fd);
+    fd_printf(c, c->local_wfd.fd, "%s + stunnel", line);
+    str_free(line);
+    line=fd_getline(c, c->local_rfd.fd);
+    if(is_prefix(line, "CAPA")) { /* client wants RFC 2449 extensions */
+        fd_putline(c, c->local_wfd.fd, "+OK Stunnel capability list follows");
+        fd_putline(c, c->local_wfd.fd, "STLS");
+        fd_putline(c, c->local_wfd.fd, ".");
+        str_free(line);
+        line=fd_getline(c, c->local_rfd.fd);
+    }
+    if(!is_prefix(line, "STLS")) {
+        s_log(LOG_ERR, "Client does not want TLS");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    str_free(line);
+    fd_putline(c, c->local_wfd.fd, "+OK Stunnel starts TLS negotiation");
+    return NULL;
+}
+
+/**************************************** imap */
+
+NOEXPORT char *imap_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "* OK")) {
+        s_log(LOG_ERR, "Unknown server welcome");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    fd_putline(c, c->local_wfd.fd, line);
+    fd_putline(c, c->remote_fd.fd, "stunnel STARTTLS");
+    str_free(line);
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "stunnel OK")) {
+        fd_putline(c, c->local_wfd.fd,
+            "* BYE stunnel: Server does not support TLS");
+        s_log(LOG_ERR, "Server does not support TLS");
+        str_free(line);
+        longjmp(c->err, 2); /* don't reset */
+    }
+    str_free(line);
+    return NULL;
+}
+
+NOEXPORT char *imap_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line, *id, *tail, *capa;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase==PROTOCOL_CHECK)
+        opt->option.connect_before_ssl=1; /* c->remote_fd needed */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    s_poll_init(c->fds);
+    s_poll_add(c->fds, c->local_rfd.fd, 1, 0);
+    switch(s_poll_wait(c->fds, 0, 200)) {
+    case 0: /* fd not ready to read */
+        s_log(LOG_DEBUG, "RFC 2595 detected");
+        break;
+    case 1: /* fd ready to read */
+        s_log(LOG_DEBUG, "RFC 2595 not detected");
+        return NULL; /* return if RFC 2595 is not used */
+    default: /* -1 */
+        sockerror("RFC2595 (s_poll_wait)");
+        longjmp(c->err, 1);
+    }
+
+    /* process server welcome and send it to client */
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "* OK")) {
+        s_log(LOG_ERR, "Unknown server welcome");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    capa=strstr(line, "CAPABILITY");
+    if(!capa)
+        capa=strstr(line, "capability");
+    if(capa)
+        *capa='K'; /* disable CAPABILITY within greeting */
+    fd_printf(c, c->local_wfd.fd, "%s (stunnel)", line);
+
+    id=str_dup("");
+    while(1) { /* process client commands */
+        str_free(line);
+        line=fd_getline(c, c->local_rfd.fd);
+        /* split line into id and tail */
+        str_free(id);
+        id=str_dup(line);
+        tail=strchr(id, ' ');
+        if(!tail)
+            break;
+        *tail++='\0';
+
+        if(is_prefix(tail, "STARTTLS")) {
+            fd_printf(c, c->local_wfd.fd,
+                "%s OK Begin TLS negotiation now", id);
+            str_free(line);
+            str_free(id);
+            return NULL; /* success */
+        } else if(is_prefix(tail, "CAPABILITY")) {
+            fd_putline(c, c->remote_fd.fd, line); /* send it to server */
+            str_free(line);
+            line=fd_getline(c, c->remote_fd.fd); /* get the capabilites */
+            if(*line=='*') {
+                /*
+                 * append STARTTLS
+                 * should also add LOGINDISABLED, but can't because
+                 * of Mozilla bug #324138/#312009
+                 * LOGIN would fail as "unexpected command", anyway
+                 */
+                fd_printf(c, c->local_wfd.fd, "%s STARTTLS", line);
+                str_free(line);
+                line=fd_getline(c, c->remote_fd.fd); /* next line */
+            }
+            fd_putline(c, c->local_wfd.fd, line); /* forward to the client */
+            tail=strchr(line, ' ');
+            if(!tail || !is_prefix(tail+1, "OK")) { /* not OK? */
+                fd_putline(c, c->local_wfd.fd,
+                    "* BYE unexpected server response");
+                s_log(LOG_ERR, "Unexpected server response: %s", line);
+                break;
+            }
+        } else if(is_prefix(tail, "LOGOUT")) {
+            fd_putline(c, c->local_wfd.fd, "* BYE server terminating");
+            fd_printf(c, c->local_wfd.fd, "%s OK LOGOUT completed", id);
+            break;
+        } else {
+            fd_putline(c, c->local_wfd.fd, "* BYE stunnel: unexpected command");
+            fd_printf(c, c->local_wfd.fd, "%s BAD %s unexpected", id, tail);
+            s_log(LOG_ERR, "Unexpected client command %s", tail);
+            break;
+        }
+    }
+    /* clean server shutdown */
+    str_free(id);
+    fd_putline(c, c->remote_fd.fd, "stunnel LOGOUT");
+    str_free(line);
+    line=fd_getline(c, c->remote_fd.fd);
+    if(*line=='*') {
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+    }
+    str_free(line);
+    longjmp(c->err, 2); /* don't reset */
+    return NULL; /* some C compilers require a return value */
+}
+
+/**************************************** nntp */
+
+NOEXPORT char *nntp_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "200 ") && !is_prefix(line, "201 ")) {
+        s_log(LOG_ERR, "Unknown server welcome");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    fd_putline(c, c->local_wfd.fd, line);
+    fd_putline(c, c->remote_fd.fd, "STARTTLS");
+    str_free(line);
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "382 ")) {
+        s_log(LOG_ERR, "Server does not support TLS");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    str_free(line);
+    return NULL;
+}
+
+/**************************************** connect */
+
+NOEXPORT char *connect_server(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *request, *proto, *header;
+
+    (void)opt; /* skip warning about unused parameter */
+    if(phase!=PROTOCOL_EARLY)
+        return NULL;
+    request=fd_getline(c, c->local_rfd.fd);
+    if(!is_prefix(request, "CONNECT ")) {
+        fd_putline(c, c->local_wfd.fd, "HTTP/1.0 400 Bad Request Method");
+        fd_putline(c, c->local_wfd.fd, "Server: stunnel/" STUNNEL_VERSION);
+        fd_putline(c, c->local_wfd.fd, "");
+        str_free(request);
+        longjmp(c->err, 1);
+    }
+    proto=strchr(request+8, ' ');
+    if(!proto || !is_prefix(proto, " HTTP/")) {
+        fd_putline(c, c->local_wfd.fd, "HTTP/1.0 400 Bad Request Protocol");
+        fd_putline(c, c->local_wfd.fd, "Server: stunnel/" STUNNEL_VERSION);
+        fd_putline(c, c->local_wfd.fd, "");
+        str_free(request);
+        longjmp(c->err, 1);
+    }
+    *proto='\0';
+
+    header=str_dup("");
+    do { /* ignore any headers */
+        str_free(header);
+        header=fd_getline(c, c->local_rfd.fd);
+    } while(*header); /* not empty */
+    str_free(header);
+
+    if(!name2addrlist(&c->connect_addr, request+8)) {
+        fd_putline(c, c->local_wfd.fd, "HTTP/1.0 404 Not Found");
+        fd_putline(c, c->local_wfd.fd, "Server: stunnel/" STUNNEL_VERSION);
+        fd_putline(c, c->local_wfd.fd, "");
+        str_free(request);
+        longjmp(c->err, 1);
+    }
+    str_free(request);
+    fd_putline(c, c->local_wfd.fd, "HTTP/1.0 200 OK");
+    fd_putline(c, c->local_wfd.fd, "Server: stunnel/" STUNNEL_VERSION);
+    fd_putline(c, c->local_wfd.fd, "");
+    return NULL;
+}
+
+NOEXPORT char *connect_client(CLI *c, SERVICE_OPTIONS *opt, const PHASE phase) {
+    char *line, *encoded;
+
+    if(phase!=PROTOCOL_MIDDLE)
+        return NULL;
+    if(!opt->protocol_host) {
+        s_log(LOG_ERR, "protocolHost not specified");
+        longjmp(c->err, 1);
+    }
+    fd_printf(c, c->remote_fd.fd, "CONNECT %s HTTP/1.1",
+        opt->protocol_host);
+    fd_printf(c, c->remote_fd.fd, "Host: %s", opt->protocol_host);
+    if(opt->protocol_username && opt->protocol_password) {
+        if(!strcasecmp(opt->protocol_authentication, "ntlm")) {
+#ifndef OPENSSL_NO_MD4
+            ntlm(c, opt);
+#else
+            s_log(LOG_ERR, "NTLM authentication is not available");
+            longjmp(c->err, 1);
+#endif
+        } else { /* basic authentication */
+            line=str_printf("%s:%s",
+                opt->protocol_username, opt->protocol_password);
+            encoded=base64(1, line, (int)strlen(line));
+            str_free(line);
+            if(!encoded) {
+                s_log(LOG_ERR, "Base64 encoder failed");
+                longjmp(c->err, 1);
+            }
+            fd_printf(c, c->remote_fd.fd, "Proxy-Authorization: basic %s",
+                encoded);
+            str_free(encoded);
+        }
+    }
+    fd_putline(c, c->remote_fd.fd, ""); /* empty line */
+    line=fd_getline(c, c->remote_fd.fd);
+    if(!is_prefix(line, "HTTP/1.0 2") && !is_prefix(line, "HTTP/1.1 2")) {
+        /* not "HTTP/1.x 2xx Connection established" */
+        s_log(LOG_ERR, "CONNECT request rejected");
+        do { /* read all headers */
+            str_free(line);
+            line=fd_getline(c, c->remote_fd.fd);
+        } while(*line);
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    s_log(LOG_INFO, "CONNECT request accepted");
+    do {
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd); /* read all headers */
+    } while(*line);
+    str_free(line);
+    return NULL;
+}
+
+#ifndef OPENSSL_NO_MD4
+
+/*
+ * NTLM code is based on the following documentation:
+ * http://davenport.sourceforge.net/ntlm.html
+ * http://www.innovation.ch/personal/ronald/ntlm.html
+ */
+
+#define s_min(a, b) ((a)>(b)?(b):(a))
+
+NOEXPORT void ntlm(CLI *c, SERVICE_OPTIONS *opt) {
+    char *line, buf[BUFSIZ], *ntlm1_txt, *ntlm2_txt, *ntlm3_txt, *tmpstr;
+    long content_length=0; /* no HTTP content */
+
+    /* send Proxy-Authorization (phase 1) */
+    fd_printf(c, c->remote_fd.fd, "Proxy-Connection: keep-alive");
+    ntlm1_txt=ntlm1();
+    if(!ntlm1_txt) {
+        s_log(LOG_ERR, "Proxy-Authenticate: Failed to build NTLM request");
+        longjmp(c->err, 1);
+    }
+    fd_printf(c, c->remote_fd.fd, "Proxy-Authorization: NTLM %s", ntlm1_txt);
+    str_free(ntlm1_txt);
+    fd_putline(c, c->remote_fd.fd, ""); /* empty line */
+    line=fd_getline(c, c->remote_fd.fd);
+
+    /* receive Proxy-Authenticate (phase 2) */
+    if(!is_prefix(line, "HTTP/1.0 407") && !is_prefix(line, "HTTP/1.1 407")) {
+        s_log(LOG_ERR, "Proxy-Authenticate: NTLM authorization request rejected");
+        do { /* read all headers */
+            str_free(line);
+            line=fd_getline(c, c->remote_fd.fd);
+        } while(*line);
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+    ntlm2_txt=NULL;
+    do { /* read all headers */
+        str_free(line);
+        line=fd_getline(c, c->remote_fd.fd);
+        if(is_prefix(line, "Proxy-Authenticate: NTLM "))
+            ntlm2_txt=str_dup(line+25);
+        else if(is_prefix(line, "Content-Length: ")) {
+            content_length=strtol(line+16, &tmpstr, 10);
+            if(tmpstr>line+16) /* found some digits */
+                while(*tmpstr && isspace(*tmpstr))
+                    ++tmpstr;
+            if(tmpstr==line+16 || *tmpstr || content_length<0) {
+                s_log(LOG_ERR, "Proxy-Authenticate: Invalid Content-Length");
+                str_free(line);
+                longjmp(c->err, 1);
+            }
+        }
+    } while(*line);
+    if(!ntlm2_txt) { /* no Proxy-Authenticate: NTLM header */
+        s_log(LOG_ERR, "Proxy-Authenticate: NTLM header not found");
+        str_free(line);
+        longjmp(c->err, 1);
+    }
+
+    /* read and ignore HTTP content (if any) */
+    while(content_length>0) {
+        size_t n=s_min((size_t)content_length, BUFSIZ);
+        s_read(c, c->remote_fd.fd, buf, n);
+        content_length-=(long)n;
+    }
+
+    /* send Proxy-Authorization (phase 3) */
+    fd_printf(c, c->remote_fd.fd, "CONNECT %s HTTP/1.1", opt->protocol_host);
+    fd_printf(c, c->remote_fd.fd, "Host: %s", opt->protocol_host);
+    ntlm3_txt=ntlm3(opt->protocol_username, opt->protocol_password, ntlm2_txt);
+    str_free(ntlm2_txt);
+    if(!ntlm3_txt) {
+        s_log(LOG_ERR, "Proxy-Authenticate: Failed to build NTLM response");
+        longjmp(c->err, 1);
+    }
+    fd_printf(c, c->remote_fd.fd, "Proxy-Authorization: NTLM %s", ntlm3_txt);
+    str_free(ntlm3_txt);
+}
+
+NOEXPORT char *ntlm1() {
+    char phase1[16];
+
+    memset(phase1, 0, sizeof phase1);
+    strcpy(phase1, "NTLMSSP");
+    phase1[8]=1; /* type: 1 */
+    phase1[12]=2; /* flag: negotiate OEM */
+    phase1[13]=2; /* flag: negotiate NTLM */
+    return base64(1, phase1, sizeof phase1); /* encode */
+}
+
+NOEXPORT char *ntlm3(char *username, char *password, char *phase2) {
+    MD4_CTX md4;
+    uint8_t *decoded; /* decoded reply from proxy */
+    uint8_t phase3[146];
+    uint8_t md4_hash[21];
+    size_t userlen=strlen(username);
+    size_t phase3len=s_min(88+userlen, sizeof phase3);
+
+    /* setup phase3 structure */
+    memset(phase3, 0, sizeof phase3);
+    strcpy((char *)phase3, "NTLMSSP");
+    phase3[8]=3;                    /* type: 3 */
+    phase3[16]=(uint8_t)phase3len;  /* LM-resp off */
+    phase3[20]=24;                  /* NT-resp len */
+    phase3[22]=24;                  /* NT-Resp len */
+    phase3[24]=64;                  /* NT-resp off */
+    phase3[32]=(uint8_t)phase3len;  /* domain offset */
+    phase3[36]=(uint8_t)userlen;    /* user length */
+    phase3[38]=(uint8_t)userlen;    /* user length */
+    phase3[40]=88;                  /* user offset */
+    phase3[48]=(uint8_t)phase3len;  /* host offset */
+    phase3[56]=(uint8_t)phase3len;  /* message len */
+    phase3[60]=2;                   /* flag: negotiate OEM */
+    phase3[61]=2;                   /* flag: negotiate NTLM */
+
+    /* calculate MD4 of UTF-16 encoded password */
+    MD4_Init(&md4);
+    while(*password) {
+        MD4_Update(&md4, password++, 1);
+        MD4_Update(&md4, "", 1); /* UTF-16 */
+    }
+    MD4_Final(md4_hash, &md4);
+    memset(md4_hash+16, 0, 5); /* pad to 21 bytes */
+
+    /* decode challenge and calculate response */
+    decoded=(uint8_t *)base64(0, phase2, (int)strlen(phase2)); /* decode */
+    if(!decoded)
+        return NULL;
+    crypt_DES(phase3+64, decoded+24, md4_hash);
+    crypt_DES(phase3+72, decoded+24, md4_hash+7);
+    crypt_DES(phase3+80, decoded+24, md4_hash+14);
+    str_free(decoded);
+
+    strncpy((char *)phase3+88, username, sizeof phase3-88);
+
+    return base64(1, (char *)phase3, (int)phase3len); /* encode */
+}
+
+NOEXPORT void crypt_DES(DES_cblock dst, const_DES_cblock src, DES_cblock hash) {
+    DES_cblock key;
+    DES_key_schedule sched;
+
+    /* convert key from 56 to 64 bits */
+    key[0]=hash[0];
+    key[1]=(unsigned char)(((hash[0]&1)<<7)|(hash[1]>>1));
+    key[2]=(unsigned char)(((hash[1]&3)<<6)|(hash[2]>>2));
+    key[3]=(unsigned char)(((hash[2]&7)<<5)|(hash[3]>>3));
+    key[4]=(unsigned char)(((hash[3]&15)<<4)|(hash[4]>>4));
+    key[5]=(unsigned char)(((hash[4]&31)<<3)|(hash[5]>>5));
+    key[6]=(unsigned char)(((hash[5]&63)<<2)|(hash[6]>>6));
+    key[7]=(unsigned char)(((hash[6]&127)<<1));
+    DES_set_odd_parity(&key);
+
+    /* encrypt */
+    DES_set_key_unchecked(&key, &sched);
+    DES_ecb_encrypt((const_DES_cblock *)src,
+        (DES_cblock *)dst, &sched, DES_ENCRYPT);
+}
+
+#endif
+
+NOEXPORT char *base64(int encode, char *in, int len) {
+    BIO *bio, *b64;
+    char *out;
+    int n;
+
+    b64=BIO_new(BIO_f_base64());
+    if(!b64)
+        return NULL;
+    BIO_set_flags(b64, BIO_FLAGS_BASE64_NO_NL);
+    bio=BIO_new(BIO_s_mem());
+    if(!bio) {
+        str_free(b64);
+        return NULL;
+    }
+    if(encode)
+        bio=BIO_push(b64, bio);
+    BIO_write(bio, in, len);
+    (void)BIO_flush(bio); /* ignore the error if any */
+    if(encode) {
+        bio=BIO_pop(bio);
+        BIO_free(b64);
+    } else {
+        bio=BIO_push(b64, bio);
+    }
+    n=BIO_pending(bio);
+    /* 32 bytes as a safety precaution for passing decoded data to crypt_DES */
+    /* n+1 to get null-terminated string on encode */
+    out=str_alloc(n<32?32:(size_t)n+1);
+    n=BIO_read(bio, out, n);
+    if(n<0) {
+        BIO_free_all(bio);
+        str_free(out);
+        return NULL;
+    }
+    BIO_free_all(bio);
+    return out;
+}
+
+/* end of protocol.c */
diff --git a/src/prototypes.h b/src/prototypes.h
new file mode 100644
index 0000000..ba0cf7f
--- /dev/null
+++ b/src/prototypes.h
@@ -0,0 +1,760 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ * 
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ * 
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ * 
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ * 
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ * 
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#ifndef PROTOTYPES_H
+#define PROTOTYPES_H
+
+#include "common.h"
+
+/**************************************** forward declarations */
+
+typedef struct tls_data_struct TLS_DATA;
+
+/**************************************** data structures */
+
+/* non-zero constants for the "redirect" option */
+#define REDIRECT_ON         1
+#define REDIRECT_OFF        2
+
+#if defined (USE_WIN32)
+#define ICON_IMAGE HICON
+#elif defined(__APPLE__)
+#define ICON_IMAGE void *
+#endif
+
+typedef enum {
+    ICON_ERROR,
+    ICON_IDLE,
+    ICON_ACTIVE,
+    ICON_NONE /* it has to be the last one */
+} ICON_TYPE;
+
+typedef enum {
+    LOG_MODE_NONE,
+    LOG_MODE_ERROR,
+    LOG_MODE_INFO,
+    LOG_MODE_CONFIGURED
+} LOG_MODE;
+
+typedef enum {
+    LOG_ID_SEQENTIAL,
+    LOG_ID_UNIQUE,
+    LOG_ID_THREAD
+} LOG_ID;
+
+typedef enum {
+    FILE_MODE_READ,
+    FILE_MODE_APPEND,
+    FILE_MODE_OVERWRITE
+} FILE_MODE;
+
+typedef union sockaddr_union {
+    struct sockaddr sa;
+    struct sockaddr_in in;
+#ifdef USE_IPv6
+    struct sockaddr_in6 in6;
+#endif
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    struct sockaddr_un un;
+#endif
+} SOCKADDR_UNION;
+
+typedef struct name_list_struct {
+    char *name;
+    struct name_list_struct *next;
+} NAME_LIST;
+
+typedef struct sockaddr_list {                          /* list of addresses */
+    SOCKADDR_UNION *addr;                           /* the list of addresses */
+    unsigned *rr_ptr, rr_val;             /* current address for round-robin */
+    unsigned num;                             /* how many addresses are used */
+    int passive;                                         /* listening socket */
+    NAME_LIST *names;                          /* a list of unresolved names */
+} SOCKADDR_LIST;
+
+#ifndef OPENSSL_NO_COMP
+typedef enum {
+    COMP_NONE, COMP_DEFLATE, COMP_ZLIB
+} COMP_TYPE;
+#endif /* !defined(OPENSSL_NO_COMP) */
+
+typedef struct {
+        /* some data for SSL initialization in ssl.c */
+#ifndef OPENSSL_NO_COMP
+    COMP_TYPE compression;                               /* compression type */
+#endif /* !defined(OPENSSL_NO_COMP) */
+    char *egd_sock;                       /* entropy gathering daemon socket */
+    char *rand_file;                                /* file with random data */
+    long random_bytes;                      /* how many random bytes to read */
+
+        /* some global data for stunnel.c */
+#ifndef USE_WIN32
+#ifdef HAVE_CHROOT
+    char *chroot_dir;
+#endif
+    unsigned long dpid;
+    char *pidfile;
+    uid_t uid;
+    gid_t gid;
+#endif
+
+        /* logging-support data for log.c */
+#ifndef USE_WIN32
+    int log_facility;                           /* debug facility for syslog */
+#endif
+    char *output_file;
+    FILE_MODE log_file_mode;
+
+        /* user interface configuraion */
+#ifdef ICON_IMAGE
+    ICON_IMAGE icon[ICON_NONE];                  /* user-specified GUI icons */
+#endif
+
+        /* on/off switches */
+    struct {
+        unsigned rand_write:1;                        /* overwrite rand_file */
+#ifdef USE_WIN32
+        unsigned taskbar:1;                       /* enable the taskbar icon */
+#else /* !USE_WIN32 */
+        unsigned foreground:1;
+        unsigned syslog:1;
+#endif
+#ifdef USE_FIPS
+        unsigned fips:1;                           /* enable FIPS 140-2 mode */
+#endif
+    } option;
+} GLOBAL_OPTIONS;
+
+extern GLOBAL_OPTIONS global_options;
+
+#ifndef OPENSSL_NO_TLSEXT
+typedef struct servername_list_struct SERVERNAME_LIST;/* forward declaration */
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+
+#ifndef OPENSSL_NO_PSK
+typedef struct psk_keys_struct {
+    char *identity;
+    unsigned char *key_val;
+    size_t key_len;
+    struct psk_keys_struct *next;
+} PSK_KEYS;
+typedef struct psk_table_struct {
+    PSK_KEYS **val;
+    size_t num;
+} PSK_TABLE;
+#endif /* !defined(OPENSSL_NO_PSK) */
+
+typedef struct service_options_struct {
+    struct service_options_struct *next;   /* next node in the services list */
+    SSL_CTX *ctx;                                            /*  SSL context */
+    char *servname;        /* service name for logging & permission checking */
+
+        /* service-specific data for log.c */
+    int log_level;                                /* debug level for logging */
+    LOG_ID log_id;                                /* logging session id type */
+
+        /* service-specific data for sthreads.c */
+#ifndef USE_FORK
+    size_t stack_size;                         /* stack size for this thread */
+#endif
+
+        /* service-specific data for verify.c */
+    char *ca_dir;                              /* directory for hashed certs */
+    char *ca_file;                       /* file containing bunches of certs */
+    char *crl_dir;                              /* directory for hashed CRLs */
+    char *crl_file;                       /* file containing bunches of CRLs */
+    int verify_level;
+    X509_STORE *revocation_store;             /* cert store for CRL checking */
+#ifndef OPENSSL_NO_OCSP
+    char *ocsp_url;
+    unsigned long ocsp_flags;
+#endif /* !defined(OPENSSL_NO_OCSP) */
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+    NAME_LIST *check_host, *check_email, *check_ip;   /* cert subject checks */
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+
+        /* service-specific data for ctx.c */
+    char *cipher_list;
+    char *cert;                                             /* cert filename */
+    char *key;                               /* pem (priv key/cert) filename */
+    long session_size, session_timeout;
+    long ssl_options_set;
+#if OPENSSL_VERSION_NUMBER>=0x009080dfL
+    long ssl_options_clear;
+#endif /* OpenSSL 0.9.8m or later */
+    SSL_METHOD *client_method, *server_method;
+    SOCKADDR_UNION sessiond_addr;
+#ifndef OPENSSL_NO_TLSEXT
+    char *sni;
+    SERVERNAME_LIST *servername_list_head, *servername_list_tail;
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+#ifndef OPENSSL_NO_PSK
+    char *psk_identity;
+    PSK_KEYS *psk_keys, *psk_selected;
+    PSK_TABLE psk_sorted;
+#endif /* !defined(OPENSSL_NO_PSK) */
+#ifndef OPENSSL_NO_ECDH
+    int curve;
+#endif /* !defined(OPENSSL_NO_ECDH) */
+#ifndef OPENSSL_NO_ENGINE
+    ENGINE *engine;                        /* engine to read the private key */
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+        /* service-specific data for client.c */
+    SOCKET fd;     /* file descriptor accepting connections for this service */
+    SSL_SESSION *session;                           /* recently used session */
+    char *exec_name;                          /* program name for local mode */
+#ifdef USE_WIN32
+    char *exec_args;                     /* program arguments for local mode */
+#else
+    char **exec_args;                    /* program arguments for local mode */
+#endif
+    SOCKADDR_UNION local_addr, source_addr;
+    SOCKADDR_LIST connect_addr, redirect_addr;
+    int timeout_busy;                       /* maximum waiting for data time */
+    int timeout_close;                          /* maximum close_notify time */
+    int timeout_connect;                           /* maximum connect() time */
+    int timeout_idle;                        /* maximum idle connection time */
+    enum {FAILOVER_RR, FAILOVER_PRIO} failover;         /* failover strategy */
+    char *username;
+
+        /* service-specific data for protocol.c */
+    char * protocol;
+    char *protocol_host;
+    char *protocol_username;
+    char *protocol_password;
+    char *protocol_authentication;
+
+        /* service-specific data for ui_*.c */
+#ifdef USE_WIN32
+    LPTSTR file, help;
+#endif
+    unsigned section_number;
+    char *chain;
+
+        /* on/off switches */
+    struct {
+        unsigned accept:1;              /* endpoint: accept */
+        unsigned client:1;
+        unsigned delayed_lookup:1;
+#ifdef USE_LIBWRAP
+        unsigned libwrap:1;
+#endif
+        unsigned local:1;               /* outgoing interface specified */
+        unsigned retry:1;               /* loop remote+program */
+        unsigned sessiond:1;
+#ifndef OPENSSL_NO_TLSEXT
+        unsigned sni:1;                 /* endpoint: sni */
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+#ifndef USE_WIN32
+        unsigned pty:1;
+        unsigned transparent_src:1;
+        unsigned transparent_dst:1;     /* endpoint: transparent destination */
+#endif
+        unsigned reset:1;               /* reset sockets on error */
+        unsigned renegotiation:1;
+        unsigned connect_before_ssl:1;
+#ifndef OPENSSL_NO_OCSP
+        unsigned aia:1;                 /* Authority Information Access */
+#endif /* !defined(OPENSSL_NO_OCSP) */
+#ifndef OPENSSL_NO_DH
+        unsigned dh_needed:1;
+#endif /* OPENSSL_NO_DH */
+    } option;
+} SERVICE_OPTIONS;
+
+extern SERVICE_OPTIONS service_options;
+
+#ifndef OPENSSL_NO_TLSEXT
+struct servername_list_struct {
+    char *servername;
+    SERVICE_OPTIONS *opt;
+    struct servername_list_struct *next;
+};
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+
+typedef enum {
+    TYPE_NONE, TYPE_FLAG, TYPE_INT, TYPE_LINGER, TYPE_TIMEVAL, TYPE_STRING
+} VAL_TYPE;
+
+typedef union {
+    int            i_val;
+    long           l_val;
+    char           c_val[16];
+    struct linger  linger_val;
+    struct timeval timeval_val;
+} OPT_UNION;
+
+typedef struct {
+    char *opt_str;
+    int  opt_level;
+    int  opt_name;
+    VAL_TYPE opt_type;
+    OPT_UNION *opt_val[3];
+} SOCK_OPT;
+
+typedef enum {
+    CONF_RELOAD, CONF_FILE, CONF_FD
+} CONF_TYPE;
+
+        /* s_poll_set definition for network.c */
+
+typedef struct {
+#ifdef USE_POLL
+    struct pollfd *ufds;
+    unsigned nfds;
+    unsigned allocated;
+#else /* select */
+    fd_set *irfds, *iwfds, *ixfds, *orfds, *owfds, *oxfds;
+    SOCKET max;
+#ifdef USE_WIN32
+    unsigned allocated;
+#endif
+#endif
+} s_poll_set;
+
+typedef struct disk_file {
+#ifdef USE_WIN32
+    HANDLE fh;
+#else
+    int fd;
+#endif
+    /* the inteface is prepared to easily implement buffering if needed */
+} DISK_FILE;
+
+    /* definitions for client.c */
+
+typedef struct {
+    SOCKET fd; /* file descriptor */
+    int is_socket; /* file descriptor is a socket */
+} FD;
+
+typedef enum {
+    RENEG_INIT, /* initial state */
+    RENEG_ESTABLISHED, /* initial handshake completed */
+    RENEG_DETECTED /* renegotiation detected */
+} RENEG_STATE;
+
+typedef struct {
+    jmp_buf err; /* exception handler needs to be 16-byte aligned on Itanium */
+    SSL *ssl; /* SSL connnection */
+    SERVICE_OPTIONS *opt;
+    TLS_DATA *tls;
+
+    SOCKADDR_UNION peer_addr; /* peer address */
+    socklen_t peer_addr_len;
+    SOCKADDR_UNION *bind_addr; /* address to bind() the socket */
+    SOCKADDR_LIST connect_addr; /* either copied or resolved dynamically */
+    FD local_rfd, local_wfd; /* read and write local descriptors */
+    FD remote_fd; /* remote file descriptor */
+        /* IP for explicit local bind or transparent proxy */
+    unsigned long pid; /* PID of the local process */
+    SOCKET fd; /* temporary file descriptor */
+    RENEG_STATE reneg_state; /* used to track renegotiation attempts */
+
+    /* data for transfer() function */
+    char sock_buff[BUFFSIZE]; /* socket read buffer */
+    char ssl_buff[BUFFSIZE]; /* SSL read buffer */
+    unsigned long sock_ptr, ssl_ptr; /* index of the first unused byte */
+    FD *sock_rfd, *sock_wfd; /* read and write socket descriptors */
+    FD *ssl_rfd, *ssl_wfd; /* read and write SSL descriptors */
+    uint64_t sock_bytes, ssl_bytes; /* bytes written to socket and SSL */
+    s_poll_set *fds; /* file descriptors */
+    uintptr_t redirect; /* redirect to another destination after failed auth */
+} CLI;
+
+/**************************************** prototypes for stunnel.c */
+
+#ifndef USE_FORK
+extern long max_clients;
+extern volatile long num_clients;
+#endif
+
+void main_init(void);
+int main_configure(char *, char *);
+void main_cleanup(void);
+int drop_privileges(int);
+void daemon_loop(void);
+void unbind_ports(void);
+int bind_ports(void);
+void signal_post(int);
+#if !defined(USE_WIN32) && !defined(USE_OS2)
+void child_status(void);  /* dead libwrap or 'exec' process detected */
+#endif
+void stunnel_info(int);
+
+/**************************************** prototypes for options.c */
+
+extern char *configuration_file;
+
+int options_cmdline(char *, char *);
+int options_parse(CONF_TYPE);
+void options_defaults(void);
+void options_apply(void);
+
+/**************************************** prototypes for fd.c */
+
+#ifndef USE_FORK
+void get_limits(void); /* setup global max_clients and max_fds */
+#endif
+SOCKET s_socket(int, int, int, int, char *);
+int s_pipe(int[2], int, char *);
+int s_socketpair(int, int, int, SOCKET[2], int, char *);
+SOCKET s_accept(SOCKET, struct sockaddr *, socklen_t *, int, char *);
+void set_nonblock(SOCKET, unsigned long);
+
+/**************************************** prototypes for log.c */
+
+#if !defined(USE_WIN32) && !defined(__vms)
+void syslog_open(void);
+void syslog_close(void);
+#endif
+int log_open(void);
+void log_close(void);
+void log_flush(LOG_MODE);
+void s_log(int, const char *, ...)
+#ifdef __GNUC__
+    __attribute__((format(printf, 2, 3)));
+#else
+    ;
+#endif
+char *log_id(CLI *);
+void fatal_debug(char *, const char *, int);
+#define fatal(a) fatal_debug((a), __FILE__, __LINE__)
+void ioerror(const char *);
+void sockerror(const char *);
+void log_error(int, int, const char *);
+char *s_strerror(int);
+
+/**************************************** prototypes for pty.c */
+
+int pty_allocate(int *, int *, char *);
+
+/**************************************** prototypes for dhparam.c */
+
+DH *get_dh2048(void);
+
+/**************************************** prototypes for cron.c */
+
+int cron_init(void);
+
+/**************************************** prototypes for ssl.c */
+
+extern int index_cli, index_opt, index_redirect, index_addr;
+
+int ssl_init(void);
+int ssl_configure(GLOBAL_OPTIONS *);
+
+/**************************************** prototypes for ctx.c */
+
+typedef struct {
+    SERVICE_OPTIONS *section;
+    char pass[PEM_BUFSIZE];
+} UI_DATA;
+
+#ifndef OPENSSL_NO_DH
+extern DH *dh_params;
+extern int dh_needed;
+#endif /* OPENSSL_NO_DH */
+
+int context_init(SERVICE_OPTIONS *);
+#ifndef OPENSSL_NO_PSK
+void psk_sort(PSK_TABLE *, PSK_KEYS *);
+PSK_KEYS *psk_find(const PSK_TABLE *, const char *);
+#endif /* !defined(OPENSSL_NO_PSK) */
+void sslerror(char *);
+
+/**************************************** prototypes for verify.c */
+
+int verify_init(SERVICE_OPTIONS *);
+char *X509_NAME2text(X509_NAME *);
+
+/**************************************** prototypes for network.c */
+
+s_poll_set *s_poll_alloc(void);
+void s_poll_free(s_poll_set *);
+void s_poll_init(s_poll_set *);
+void s_poll_add(s_poll_set *, SOCKET, int, int);
+void s_poll_remove(s_poll_set *, SOCKET);
+int s_poll_canread(s_poll_set *, SOCKET);
+int s_poll_canwrite(s_poll_set *, SOCKET);
+int s_poll_hup(s_poll_set *, SOCKET);
+int s_poll_rdhup(s_poll_set *, SOCKET);
+int s_poll_wait(s_poll_set *, int, int);
+void s_poll_dump(s_poll_set *, int);
+
+#ifdef USE_WIN32
+#define SIGNAL_RELOAD_CONFIG    1
+#define SIGNAL_REOPEN_LOG       2
+#define SIGNAL_TERMINATE        3
+#else
+#define SIGNAL_RELOAD_CONFIG    SIGHUP
+#define SIGNAL_REOPEN_LOG       SIGUSR1
+#define SIGNAL_TERMINATE        SIGTERM
+#endif
+
+int set_socket_options(SOCKET, int);
+int make_sockets(SOCKET[2]);
+
+/**************************************** prototypes for client.c */
+
+CLI *alloc_client_session(SERVICE_OPTIONS *, SOCKET, SOCKET);
+void *client_thread(void *);
+void client_main(CLI *);
+
+/**************************************** prototypes for network.c */
+
+int s_connect(CLI *, SOCKADDR_UNION *, socklen_t);
+void s_write(CLI *, SOCKET fd, const void *, size_t);
+void s_read(CLI *, SOCKET fd, void *, size_t);
+void fd_putline(CLI *, SOCKET, const char *);
+char *fd_getline(CLI *, SOCKET);
+/* descriptor versions of fprintf/fscanf */
+void fd_printf(CLI *, SOCKET, const char *, ...)
+#ifdef __GNUC__
+    __attribute__((format(printf, 3, 4)));
+#else
+    ;
+#endif
+void s_ssl_write(CLI *, const void *, int);
+void s_ssl_read(CLI *, void *, int);
+char *ssl_getstring(CLI *c);
+
+/**************************************** prototype for protocol.c */
+
+typedef enum {
+    PROTOCOL_CHECK,
+    PROTOCOL_EARLY,
+    PROTOCOL_MIDDLE,
+    PROTOCOL_LATE
+} PHASE;
+
+char *protocol(CLI *, SERVICE_OPTIONS *opt, const PHASE);
+
+/**************************************** prototypes for resolver.c */
+
+void resolver_init();
+
+unsigned name2addr(SOCKADDR_UNION *, char *, int);
+unsigned hostport2addr(SOCKADDR_UNION *, char *, char *, int);
+
+unsigned name2addrlist(SOCKADDR_LIST *, char *);
+unsigned hostport2addrlist(SOCKADDR_LIST *, char *, char *);
+
+void addrlist_clear(SOCKADDR_LIST *, int);
+unsigned addrlist_dup(SOCKADDR_LIST *, const SOCKADDR_LIST *);
+unsigned addrlist_resolve(SOCKADDR_LIST *);
+
+char *s_ntop(SOCKADDR_UNION *, socklen_t);
+socklen_t addr_len(const SOCKADDR_UNION *);
+const char *s_gai_strerror(int);
+
+#ifndef HAVE_GETNAMEINFO
+
+#ifndef NI_NUMERICHOST
+#define NI_NUMERICHOST  2
+#endif
+#ifndef NI_NUMERICSERV
+#define NI_NUMERICSERV  8
+#endif
+
+#ifdef USE_WIN32
+
+/* rename some locally shadowed declarations */
+#define getnameinfo     local_getnameinfo
+
+#ifndef _WIN32_WCE
+typedef int (CALLBACK * GETADDRINFO) (const char *,
+    const char *, const struct addrinfo *, struct addrinfo **);
+typedef void (CALLBACK * FREEADDRINFO) (struct addrinfo FAR *);
+typedef int (CALLBACK * GETNAMEINFO) (const struct sockaddr *, socklen_t,
+    char *, size_t, char *, size_t, int);
+extern GETADDRINFO s_getaddrinfo;
+extern FREEADDRINFO s_freeaddrinfo;
+extern GETNAMEINFO s_getnameinfo;
+#endif /* ! _WIN32_WCE */
+
+#endif /* USE_WIN32 */
+
+int getnameinfo(const struct sockaddr *, socklen_t,
+    char *, size_t, char *, size_t, int);
+
+#endif /* !defined HAVE_GETNAMEINFO */
+
+/**************************************** prototypes for sthreads.c */
+
+typedef enum {
+    CRIT_SESSION, CRIT_ADDR,
+    CRIT_CLIENTS, CRIT_SSL,                 /* client.c */
+    CRIT_INET,                              /* resolver.c */
+#ifndef USE_WIN32
+    CRIT_LIBWRAP,                           /* libwrap.c */
+#endif
+    CRIT_LOG, CRIT_ID, CRIT_LEAK,           /* log.c */
+#ifndef OPENSSL_NO_DH
+    CRIT_DH,                                /* ctx.c */
+#endif /* OPENSSL_NO_DH */
+    CRIT_SECTIONS                           /* number of critical sections */
+} SECTION_CODE;
+
+void enter_critical_section(SECTION_CODE);
+void leave_critical_section(SECTION_CODE);
+int sthreads_init(void);
+unsigned long stunnel_process_id(void);
+unsigned long stunnel_thread_id(void);
+int create_client(SOCKET, SOCKET, CLI *, void *(*)(void *));
+#ifdef USE_UCONTEXT
+typedef struct CONTEXT_STRUCTURE {
+    char *stack; /* CPU stack for this thread */
+    unsigned long id;
+    ucontext_t context;
+    s_poll_set *fds;
+    int ready; /* number of ready file descriptors */
+    time_t finish; /* when to finish poll() for this context */
+    struct CONTEXT_STRUCTURE *next; /* next context on a list */
+    void *tls; /* thread local storage for tls.c */
+} CONTEXT;
+extern CONTEXT *ready_head, *ready_tail;
+extern CONTEXT *waiting_head, *waiting_tail;
+#endif
+#ifdef _WIN32_WCE
+long _beginthread(void (*)(void *), int, void *);
+void _endthread(void);
+#endif
+#ifdef DEBUG_STACK_SIZE
+void stack_info(int);
+#endif
+
+/**************************************** prototypes for file.c */
+
+#ifndef USE_WIN32
+DISK_FILE *file_fdopen(int);
+#endif
+DISK_FILE *file_open(char *, FILE_MODE mode);
+void file_close(DISK_FILE *);
+ssize_t file_getline(DISK_FILE *, char *, int);
+ssize_t file_putline(DISK_FILE *, char *);
+int file_permissions(const char *);
+
+#ifdef USE_WIN32
+LPTSTR str2tstr(LPCSTR);
+LPSTR tstr2str(LPCTSTR);
+#endif
+
+/**************************************** prototypes for libwrap.c */
+
+int libwrap_init();
+void libwrap_auth(CLI *, char *);
+
+/**************************************** prototypes for tls.c */
+
+extern volatile int tls_initialized;
+
+void tls_init();
+TLS_DATA *tls_alloc(CLI *, TLS_DATA *, char *);
+void tls_cleanup();
+void tls_set(TLS_DATA *);
+TLS_DATA *tls_get();
+
+/**************************************** prototypes for str.c */
+
+extern TLS_DATA *ui_tls;
+typedef struct alloc_list_struct ALLOC_LIST;
+
+struct tls_data_struct {
+    ALLOC_LIST *alloc_head;
+    size_t alloc_bytes, alloc_blocks;
+    CLI *c;
+    SERVICE_OPTIONS *opt;
+    char *id;
+};
+
+void str_init(TLS_DATA *);
+void str_cleanup(TLS_DATA *);
+char *str_dup_debug(const char *, const char *, int);
+#define str_dup(a) str_dup_debug((a), __FILE__, __LINE__)
+char *str_vprintf(const char *, va_list);
+char *str_printf(const char *, ...)
+#ifdef __GNUC__
+    __attribute__((format(printf, 1, 2)));
+#else
+    ;
+#endif
+#ifdef USE_WIN32
+LPTSTR str_tprintf(LPCTSTR, ...);
+#endif
+
+void str_canary_init();
+void str_stats();
+void *str_alloc_debug(size_t, const char *, int);
+#define str_alloc(a) str_alloc_debug((a), __FILE__, __LINE__)
+void *str_alloc_detached_debug(size_t, const char *, int);
+#define str_alloc_detached(a) str_alloc_detached_debug((a), __FILE__, __LINE__)
+void *str_realloc_debug(void *, size_t, const char *, int);
+#define str_realloc(a, b) str_realloc_debug((a), (b), __FILE__, __LINE__)
+void str_detach_debug(void *, const char *, int);
+#define str_detach(a) str_detach_debug((a), __FILE__, __LINE__)
+void str_free_debug(void *, const char *, int);
+#define str_free(a) str_free_debug((a), __FILE__, __LINE__), (a)=NULL
+#define str_free_expression(a) str_free_debug((a), __FILE__, __LINE__)
+
+int safe_memcmp(const void *, const void *, size_t);
+
+/**************************************** prototypes for ui_*.c */
+
+void ui_config_reloaded(void);
+void ui_new_chain(const unsigned);
+void ui_clients(const long);
+
+void ui_new_log(const char *);
+#ifdef USE_WIN32
+void message_box(LPCTSTR, const UINT);
+#endif /* USE_WIN32 */
+
+int passwd_cb(char *, int, int, void *);
+#ifndef OPENSSL_NO_ENGINE
+int pin_cb(UI *, UI_STRING *);
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+
+#ifdef ICON_IMAGE
+ICON_IMAGE load_icon_default(ICON_TYPE);
+ICON_IMAGE load_icon_file(const char *);
+#endif
+
+#endif /* defined PROTOTYPES_H */
+
+/* end of prototypes.h */
diff --git a/src/pty.c b/src/pty.c
new file mode 100644
index 0000000..c17bcd5
--- /dev/null
+++ b/src/pty.c
@@ -0,0 +1,221 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+#ifdef HAVE_UTIL_H
+#include <util.h>
+#endif /* HAVE_UTIL_H */
+
+#ifdef HAVE_SYS_IOCTL_H
+#include <sys/ioctl.h>
+#endif /* HAVE_SYS_IOCTL_H */
+
+/* pty allocated with _getpty gets broken if we do I_PUSH:es to it. */
+#if defined(HAVE__GETPTY) || defined(HAVE_OPENPTY)
+#undef HAVE_DEV_PTMX
+#endif /* HAVE__GETPTY || HAVE_OPENPTY */
+
+#ifdef HAVE_PTY_H
+#include <pty.h>
+#endif /* HAVE_PTY_H */
+
+#ifdef HAVE_LIBUTIL_H
+#include <libutil.h>
+#endif /* HAVE_LIBUTIL_H */
+
+#ifndef O_NOCTTY
+#define O_NOCTTY 0
+#endif /* O_NOCTTY */
+
+/*
+ * allocates and opens a pty
+ * returns -1 if no pty could be allocated, or zero if a pty was successfully
+ * allocated
+ * on success, open file descriptors for the pty and tty sides and the name of
+ * the tty side are returned
+ * the buffer must be able to hold at least 64 characters
+ */
+
+int pty_allocate(int *ptyfd, int *ttyfd, char *namebuf) {
+#if defined(HAVE_OPENPTY) || defined(BSD4_4) && !defined(__INNOTEK_LIBC__)
+    /* openpty(3) exists in OSF/1 and some other os'es */
+    char buf[64];
+    int i;
+
+    i=openpty(ptyfd, ttyfd, buf, NULL, NULL);
+    if(i<0) {
+        ioerror("openpty");
+        return -1;
+    }
+    strcpy(namebuf, buf); /* possible truncation */
+    return 0;
+#else /* HAVE_OPENPTY */
+#ifdef HAVE__GETPTY
+    /*
+     * _getpty(3) exists in SGI Irix 4.x, 5.x & 6.x -- it generates more
+     * pty's automagically when needed
+     */
+    char *slave;
+
+    slave=_getpty(ptyfd, O_RDWR, 0622, 0);
+    if(slave==NULL) {
+        ioerror("_getpty");
+        return -1;
+    }
+    strcpy(namebuf, slave);
+    /* open the slave side */
+    *ttyfd=open(namebuf, O_RDWR|O_NOCTTY);
+    if(*ttyfd<0) {
+        ioerror(namebuf);
+        close(*ptyfd);
+        return -1;
+    }
+    return 0;
+#else /* HAVE__GETPTY */
+#if defined(HAVE_DEV_PTMX)
+    /*
+     * this code is used e.g. on Solaris 2.x
+     * note that Solaris 2.3 * also has bsd-style ptys, but they simply do not
+     * work
+     */
+    int ptm; char *pts;
+
+    ptm=open("/dev/ptmx", O_RDWR|O_NOCTTY);
+    if(ptm<0) {
+        ioerror("/dev/ptmx");
+        return -1;
+    }
+    if(grantpt(ptm)<0) {
+        ioerror("grantpt");
+        /* return -1; */
+        /* can you tell me why it doesn't work? */
+    }
+    if(unlockpt(ptm)<0) {
+        ioerror("unlockpt");
+        return -1;
+    }
+    pts=ptsname(ptm);
+    if(pts==NULL)
+        s_log(LOG_ERR, "Slave pty side name could not be obtained");
+    strcpy(namebuf, pts);
+    *ptyfd=ptm;
+
+    /* open the slave side */
+    *ttyfd=open(namebuf, O_RDWR|O_NOCTTY);
+    if(*ttyfd<0) {
+        ioerror(namebuf);
+        close(*ptyfd);
+        return -1;
+    }
+    /* push the appropriate streams modules, as described in Solaris pts(7) */
+    if(ioctl(*ttyfd, I_PUSH, "ptem")<0)
+        ioerror("ioctl I_PUSH ptem");
+    if(ioctl(*ttyfd, I_PUSH, "ldterm")<0)
+        ioerror("ioctl I_PUSH ldterm");
+    if(ioctl(*ttyfd, I_PUSH, "ttcompat")<0)
+        ioerror("ioctl I_PUSH ttcompat");
+    return 0;
+#else /* HAVE_DEV_PTMX */
+#ifdef HAVE_DEV_PTS_AND_PTC
+    /* AIX-style pty code. */
+    const char *name;
+
+    *ptyfd=open("/dev/ptc", O_RDWR|O_NOCTTY);
+    if(*ptyfd<0) {
+        ioerror("open(/dev/ptc)");
+        return -1;
+    }
+    name=ttyname(*ptyfd);
+    if(!name) {
+        s_log(LOG_ERR, "Open of /dev/ptc returns device for which ttyname fails");
+        return -1;
+    }
+    strcpy(namebuf, name);
+    *ttyfd=open(name, O_RDWR|O_NOCTTY);
+    if(*ttyfd<0) {
+        ioerror(name);
+        close(*ptyfd);
+        return -1;
+    }
+    return 0;
+#else /* HAVE_DEV_PTS_AND_PTC */
+    /* BSD-style pty code. */
+    char buf[64];
+    size_t i;
+    const char *ptymajors="pqrstuvwxyzabcdefghijklmnoABCDEFGHIJKLMNOPQRSTUVWXYZ";
+    const char *ptyminors="0123456789abcdef";
+    size_t num_minors=strlen(ptyminors);
+    size_t num_ptys=strlen(ptymajors)*num_minors;
+
+    for(i=0; i<num_ptys; i++) {
+#ifdef HAVE_SNPRINTF
+        snprintf(buf, sizeof buf,
+#else
+        sprintf(buf,
+#endif
+             "/dev/pty%c%c", ptymajors[i/num_minors],
+             ptyminors[i%num_minors]);
+        *ptyfd=open(buf, O_RDWR|O_NOCTTY);
+        if(*ptyfd<0)
+            continue;
+#ifdef HAVE_SNPRINTF
+        snprintf(namebuf, 64,
+#else
+        sprintf(namebuf,
+#endif
+            "/dev/tty%c%c",
+            ptymajors[i/num_minors], ptyminors[i%num_minors]);
+
+        /* open the slave side */
+        *ttyfd=open(namebuf, O_RDWR | O_NOCTTY);
+        if(*ttyfd<0) {
+            ioerror(namebuf);
+            close(*ptyfd);
+            return -1;
+        }
+        return 0;
+    }
+    return -1;
+#endif /* HAVE_DEV_PTS_AND_PTC */
+#endif /* HAVE_DEV_PTMX */
+#endif /* HAVE__GETPTY */
+#endif /* HAVE_OPENPTY */
+}
+
+/* end of pty.c */
diff --git a/src/resolver.c b/src/resolver.c
new file mode 100644
index 0000000..7edc4f3
--- /dev/null
+++ b/src/resolver.c
@@ -0,0 +1,603 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+/**************************************** prototypes */
+
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+NOEXPORT int get_ipv6(LPTSTR);
+#endif
+NOEXPORT void addrlist2addr(SOCKADDR_UNION *, SOCKADDR_LIST *);
+NOEXPORT void addrlist_reset(SOCKADDR_LIST *);
+
+#ifndef HAVE_GETADDRINFO
+
+#ifndef EAI_MEMORY
+#define EAI_MEMORY 1
+#endif
+#ifndef EAI_NONAME
+#define EAI_NONAME 2
+#endif
+#ifndef EAI_SERVICE
+#define EAI_SERVICE 8
+#endif
+
+/* rename some potentially locally shadowed declarations */
+#define getaddrinfo     local_getaddrinfo
+#define freeaddrinfo    local_freeaddrinfo
+
+#ifndef HAVE_STRUCT_ADDRINFO
+struct addrinfo {
+    int ai_flags;
+    int ai_family;
+    int ai_socktype;
+    int ai_protocol;
+    int ai_addrlen;
+    struct sockaddr *ai_addr;
+    char *ai_canonname;
+    struct addrinfo *ai_next;
+};
+#endif
+
+#ifndef AI_PASSIVE
+#define AI_PASSIVE 1
+#endif
+
+NOEXPORT int getaddrinfo(const char *, const char *,
+    const struct addrinfo *, struct addrinfo **);
+NOEXPORT int alloc_addresses(struct hostent *, const struct addrinfo *,
+    u_short port, struct addrinfo **, struct addrinfo **);
+NOEXPORT void freeaddrinfo(struct addrinfo *);
+
+#endif /* !defined HAVE_GETADDRINFO */
+
+/**************************************** resolver initialization */
+
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+GETADDRINFO s_getaddrinfo;
+FREEADDRINFO s_freeaddrinfo;
+GETNAMEINFO s_getnameinfo;
+#endif
+
+void resolver_init() {
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+    if(get_ipv6(TEXT("ws2_32.dll"))) /* IPv6 in Windows XP or higher */
+        return;
+    if(get_ipv6(TEXT("wship6.dll"))) /* experimental IPv6 for Windows 2000 */
+        return;
+    /* fall back to the built-in emulation */
+#endif
+}
+
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+NOEXPORT int get_ipv6(LPTSTR file) {
+    HINSTANCE handle;
+
+    handle=LoadLibrary(file);
+    if(!handle)
+        return 0;
+    s_getaddrinfo=(GETADDRINFO)GetProcAddress(handle, "getaddrinfo");
+    s_freeaddrinfo=(FREEADDRINFO)GetProcAddress(handle, "freeaddrinfo");
+    s_getnameinfo=(GETNAMEINFO)GetProcAddress(handle, "getnameinfo");
+    if(!s_getaddrinfo || !s_freeaddrinfo || !s_getnameinfo) {
+        s_getaddrinfo=NULL;
+        s_freeaddrinfo=NULL;
+        s_getnameinfo=NULL;
+        FreeLibrary(handle);
+        return 0;
+    }
+    return 1; /* IPv6 detected -> OK */
+}
+#endif
+
+/**************************************** stunnel resolver API */
+
+unsigned name2addr(SOCKADDR_UNION *addr, char *name, int passive) {
+    SOCKADDR_LIST *addr_list;
+    unsigned retval;
+
+    addr_list=str_alloc(sizeof(SOCKADDR_LIST));
+    addrlist_clear(addr_list, passive);
+    retval=name2addrlist(addr_list, name);
+    if(retval)
+        addrlist2addr(addr, addr_list);
+    str_free(addr_list->addr);
+    str_free(addr_list);
+    return retval;
+}
+
+unsigned hostport2addr(SOCKADDR_UNION *addr,
+        char *host_name, char *port_name, int passive) {
+    SOCKADDR_LIST *addr_list;
+    unsigned retval;
+
+    addr_list=str_alloc(sizeof(SOCKADDR_LIST));
+    addrlist_clear(addr_list, passive);
+    retval=hostport2addrlist(addr_list, host_name, port_name);
+    if(retval)
+        addrlist2addr(addr, addr_list);
+    str_free(addr_list->addr);
+    str_free(addr_list);
+    return retval;
+}
+
+NOEXPORT void addrlist2addr(SOCKADDR_UNION *addr, SOCKADDR_LIST *addr_list) {
+    unsigned i;
+
+    for(i=0; i<addr_list->num; ++i) { /* find the first IPv4 address */
+        if(addr_list->addr[i].in.sin_family==AF_INET) {
+            memcpy(addr, &addr_list->addr[i], sizeof(SOCKADDR_UNION));
+            return;
+        }
+    }
+#ifdef USE_IPv6
+    for(i=0; i<addr_list->num; ++i) { /* find the first IPv6 address */
+        if(addr_list->addr[i].in.sin_family==AF_INET6) {
+            memcpy(addr, &addr_list->addr[i], sizeof(SOCKADDR_UNION));
+            return;
+        }
+    }
+#endif
+    /* copy the first address resolved (curently AF_UNIX) */
+    memcpy(addr, &addr_list->addr[0], sizeof(SOCKADDR_UNION));
+}
+
+unsigned name2addrlist(SOCKADDR_LIST *addr_list, char *name) {
+    char *tmp, *host_name, *port_name;
+    unsigned retval;
+
+    /* first check if this is a UNIX socket */
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    if(*name=='/') {
+        if(offsetof(struct sockaddr_un, sun_path)+strlen(name)+1
+                > sizeof(struct sockaddr_un)) {
+            s_log(LOG_ERR, "Unix socket path is too long");
+            return 0; /* no results */
+        }
+        addr_list->addr=str_realloc(addr_list->addr,
+            (addr_list->num+1)*sizeof(SOCKADDR_UNION));
+        addr_list->addr[addr_list->num].un.sun_family=AF_UNIX;
+        strcpy(addr_list->addr[addr_list->num].un.sun_path, name);
+        return ++(addr_list->num); /* ok - return the number of addresses */
+    }
+#endif
+
+    /* setup host_name and port_name */
+    tmp=str_dup(name);
+    port_name=strrchr(tmp, ':');
+    if(port_name) {
+        host_name=tmp;
+        *port_name++='\0';
+    } else { /* no ':' - use default host IP */
+        host_name=NULL;
+        port_name=tmp;
+    }
+
+    /* fill addr_list structure */
+    retval=hostport2addrlist(addr_list, host_name, port_name);
+    str_free(tmp);
+    return retval;
+}
+
+unsigned hostport2addrlist(SOCKADDR_LIST *addr_list,
+        char *host_name, char *port_name) {
+    struct addrinfo hints, *res=NULL, *cur;
+    int err, retry=0;
+
+    memset(&hints, 0, sizeof hints);
+#if defined(USE_IPv6) || defined(USE_WIN32)
+    hints.ai_family=AF_UNSPEC;
+#else
+    hints.ai_family=AF_INET;
+#endif
+    hints.ai_socktype=SOCK_STREAM;
+    hints.ai_protocol=IPPROTO_TCP;
+    hints.ai_flags=0;
+    if(addr_list->passive) {
+        hints.ai_family=AF_INET; /* first try IPv4 for passive requests */
+        hints.ai_flags|=AI_PASSIVE;
+    }
+    for(;;) {
+        err=getaddrinfo(host_name, port_name, &hints, &res);
+        if(!err)
+            break;
+        if(res)
+            freeaddrinfo(res);
+        if(err==EAI_AGAIN && ++retry<=3) {
+            s_log(LOG_DEBUG, "getaddrinfo: EAI_AGAIN received: retrying");
+            sleep(1);
+            continue;
+        }
+#if defined(USE_IPv6) || defined(USE_WIN32)
+        if(hints.ai_family==AF_INET) {
+            hints.ai_family=AF_UNSPEC;
+            continue; /* retry for non-IPv4 addresses */
+        }
+#endif
+        break;
+    }
+    if(err==EAI_SERVICE) {
+        s_log(LOG_ERR, "Unknown TCP service \"%s\"", port_name);
+        return 0; /* error */
+    }
+    if(err) {
+        s_log(LOG_ERR, "Error resolving \"%s\": %s",
+            host_name ? host_name :
+                (addr_list->passive ? DEFAULT_ANY : DEFAULT_LOOPBACK),
+            s_gai_strerror(err));
+        return 0; /* error */
+    }
+
+    /* copy the list of addresses */
+    for(cur=res; cur; cur=cur->ai_next) {
+        if(cur->ai_addrlen>(int)sizeof(SOCKADDR_UNION)) {
+            s_log(LOG_ERR, "INTERNAL ERROR: ai_addrlen value too big");
+            freeaddrinfo(res);
+            return 0; /* no results */
+        }
+        addr_list->addr=str_realloc(addr_list->addr,
+            (addr_list->num+1)*sizeof(SOCKADDR_UNION));
+        memcpy(&addr_list->addr[addr_list->num], cur->ai_addr,
+            (size_t)cur->ai_addrlen);
+        ++(addr_list->num);
+    }
+    freeaddrinfo(res);
+    return addr_list->num; /* ok - return the number of addresses */
+}
+
+/* initialize the structure */
+void addrlist_clear(SOCKADDR_LIST *addr_list, int passive) {
+    addrlist_reset(addr_list);
+    addr_list->names=NULL;
+    addr_list->passive=passive;
+}
+
+/* prepare the structure to resolve new hosts */
+NOEXPORT void addrlist_reset(SOCKADDR_LIST *addr_list) {
+    addr_list->num=0;
+    addr_list->addr=NULL;
+    addr_list->rr_val=0; /* reset the round-robin counter */
+    /* allow structures created with sockaddr_dup() to modify
+     * the original rr_val rather than its local copy */
+    addr_list->rr_ptr=&addr_list->rr_val;
+}
+
+unsigned addrlist_dup(SOCKADDR_LIST *dst, const SOCKADDR_LIST *src) {
+    memcpy(dst, src, sizeof(SOCKADDR_LIST));
+    if(src->num) { /* already resolved */
+        dst->addr=str_alloc(src->num*sizeof(SOCKADDR_UNION));
+        memcpy(dst->addr, src->addr, src->num*sizeof(SOCKADDR_UNION));
+    } else { /* delayed resolver */
+        addrlist_resolve(dst);
+    }
+    return dst->num;
+}
+
+unsigned addrlist_resolve(SOCKADDR_LIST *addr_list) {
+    unsigned num=0, rnd;
+    NAME_LIST *host;
+
+    addrlist_reset(addr_list);
+    for(host=addr_list->names; host; host=host->next)
+        num+=name2addrlist(addr_list, host->name);
+    switch(num) {
+    case 0:
+    case 1:
+        addr_list->rr_val=0;
+        break;
+    default:
+        /* randomize the initial value of round-robin counter */
+        /* ignore the error value and the distribution bias */
+        RAND_bytes((unsigned char *)&rnd, sizeof rnd);
+        addr_list->rr_val=rnd%num;
+    }
+    return num;
+}
+
+char *s_ntop(SOCKADDR_UNION *addr, socklen_t addrlen) {
+    int err;
+    char *host, *port, *retval;
+
+    if(addrlen==sizeof(u_short)) /* see UNIX(7) manual for details */
+        return str_dup("unnamed socket");
+    host=str_alloc(256);
+    port=str_alloc(256); /* needs to be long enough for AF_UNIX path */
+    err=getnameinfo(&addr->sa, addrlen,
+        host, 256, port, 256, NI_NUMERICHOST|NI_NUMERICSERV);
+    if(err) {
+        s_log(LOG_ERR, "getnameinfo: %s", s_gai_strerror(err));
+        retval=str_dup("unresolvable address");
+    } else
+        retval=str_printf("%s:%s", host, port);
+    str_free(host);
+    str_free(port);
+    return retval;
+}
+
+socklen_t addr_len(const SOCKADDR_UNION *addr) {
+    if(addr->sa.sa_family==AF_INET)
+        return sizeof(struct sockaddr_in);
+#ifdef USE_IPv6
+    if(addr->sa.sa_family==AF_INET6)
+        return sizeof(struct sockaddr_in6);
+#endif
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    if(addr->sa.sa_family==AF_UNIX)
+        return sizeof(struct sockaddr_un);
+#endif
+    s_log(LOG_ERR, "INTERNAL ERROR: Unknown sa_family: %d",
+        addr->sa.sa_family);
+    return sizeof(SOCKADDR_UNION);
+}
+
+/**************************************** my getaddrinfo() */
+/* implementation is limited to functionality needed by stunnel */
+
+#ifndef HAVE_GETADDRINFO
+NOEXPORT int getaddrinfo(const char *node, const char *service,
+        const struct addrinfo *hints, struct addrinfo **res) {
+    struct hostent *h;
+#ifndef _WIN32_WCE
+    struct servent *p;
+#endif
+    u_short port;
+    struct addrinfo *ai;
+    int retval;
+    char *tmpstr;
+
+    if(!node)
+        node=hints->ai_flags&AI_PASSIVE ? DEFAULT_ANY : DEFAULT_LOOPBACK;
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+    if(s_getaddrinfo)
+        return s_getaddrinfo(node, service, hints, res);
+#endif
+    /* decode service name */
+    port=htons((u_short)strtol(service, &tmpstr, 10));
+    if(tmpstr==service || *tmpstr) { /* not a number */
+#ifdef _WIN32_WCE
+        return EAI_NONAME;
+#else /* defined(_WIN32_WCE) */
+        p=getservbyname(service, "tcp");
+        if(!p)
+            return EAI_NONAME;
+        port=(u_short)p->s_port;
+#endif /* defined(_WIN32_WCE) */
+    }
+
+    /* allocate addrlist structure */
+    ai=str_alloc(sizeof(struct addrinfo));
+    if(hints)
+        memcpy(ai, hints, sizeof(struct addrinfo));
+
+    /* try to decode numerical address */
+#if defined(USE_IPv6) && !defined(USE_WIN32)
+    ai->ai_family=AF_INET6;
+    ai->ai_addrlen=sizeof(struct sockaddr_in6);
+    ai->ai_addr=str_alloc((size_t)ai->ai_addrlen);
+    ai->ai_addr->sa_family=AF_INET6;
+    if(inet_pton(AF_INET6, node,
+            &((struct sockaddr_in6 *)ai->ai_addr)->sin6_addr)>0) {
+#else
+    ai->ai_family=AF_INET;
+    ai->ai_addrlen=sizeof(struct sockaddr_in);
+    ai->ai_addr=str_alloc(ai->ai_addrlen);
+    ai->ai_addr->sa_family=AF_INET;
+    ((struct sockaddr_in *)ai->ai_addr)->sin_addr.s_addr=inet_addr(node);
+    if(((struct sockaddr_in *)ai->ai_addr)->sin_addr.s_addr+1) {
+    /* (signed)((struct sockaddr_in *)ai->ai_addr)->sin_addr.s_addr!=-1 */
+#endif
+        ((struct sockaddr_in *)ai->ai_addr)->sin_port=port;
+        *res=ai;
+        return 0; /* numerical address resolved */
+    }
+    str_free(ai->ai_addr);
+    str_free(ai);
+
+    /* not numerical: need to call resolver library */
+    *res=NULL;
+    ai=NULL;
+    enter_critical_section(CRIT_INET);
+#ifdef HAVE_GETHOSTBYNAME2
+    h=gethostbyname2(node, AF_INET6);
+    if(h) /* some IPv6 addresses found */
+        alloc_addresses(h, hints, port, res, &ai); /* ignore the error */
+#endif
+    h=gethostbyname(node); /* get list of addresses */
+    if(h)
+        retval=ai ?
+            alloc_addresses(h, hints, port, &ai->ai_next, &ai) :
+            alloc_addresses(h, hints, port, res, &ai);
+    else if(!*res)
+        retval=EAI_NONAME; /* no results */
+    else
+        retval=0;
+#ifdef HAVE_ENDHOSTENT
+    endhostent();
+#endif
+    leave_critical_section(CRIT_INET);
+    if(retval) { /* error: free allocated memory */
+        freeaddrinfo(*res);
+        *res=NULL;
+    }
+    return retval;
+}
+
+NOEXPORT int alloc_addresses(struct hostent *h, const struct addrinfo *hints,
+        u_short port, struct addrinfo **head, struct addrinfo **tail) {
+    int i;
+    struct addrinfo *ai;
+
+    /* copy addresses */
+    for(i=0; h->h_addr_list[i]; i++) {
+        ai=str_alloc(sizeof(struct addrinfo));
+        if(hints)
+            memcpy(ai, hints, sizeof(struct addrinfo));
+        ai->ai_next=NULL; /* just in case */
+        if(*tail) { /* list not empty: add a node */
+            (*tail)->ai_next=ai;
+            *tail=ai;
+        } else { /* list empty: create it */
+            *head=ai;
+            *tail=ai;
+        }
+        ai->ai_family=h->h_addrtype;
+#if defined(USE_IPv6)
+        if(h->h_addrtype==AF_INET6) {
+            ai->ai_addrlen=sizeof(struct sockaddr_in6);
+            ai->ai_addr=str_alloc((size_t)ai->ai_addrlen);
+            memcpy(&((struct sockaddr_in6 *)ai->ai_addr)->sin6_addr,
+                h->h_addr_list[i], (size_t)h->h_length);
+        } else
+#endif
+        {
+            ai->ai_addrlen=sizeof(struct sockaddr_in);
+            ai->ai_addr=str_alloc((size_t)ai->ai_addrlen);
+            memcpy(&((struct sockaddr_in *)ai->ai_addr)->sin_addr,
+                h->h_addr_list[i], (size_t)h->h_length);
+        }
+        ai->ai_addr->sa_family=(u_short)h->h_addrtype;
+        /* offsets of sin_port and sin6_port should be the same */
+        ((struct sockaddr_in *)ai->ai_addr)->sin_port=port;
+    }
+    return 0; /* success */
+}
+
+NOEXPORT void freeaddrinfo(struct addrinfo *current) {
+    struct addrinfo *next;
+
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+    if(s_freeaddrinfo) {
+        s_freeaddrinfo(current);
+    return;
+    }
+#endif
+    while(current) {
+        str_free(current->ai_addr);
+        str_free(current->ai_canonname);
+        next=current->ai_next;
+        str_free(current);
+        current=next;
+    }
+}
+#endif /* !defined HAVE_GETADDRINFO */
+
+/* due to a problem with Mingw32 I decided to define my own gai_strerror() */
+const char *s_gai_strerror(int err) {
+    switch(err) {
+#ifdef EAI_BADFLAGS
+        case EAI_BADFLAGS:
+            return "Invalid value for ai_flags (EAI_BADFLAGS)";
+#endif
+        case EAI_NONAME:
+            return "Neither nodename nor servname known (EAI_NONAME)";
+#ifdef EAI_AGAIN
+        case EAI_AGAIN:
+            return "Temporary failure in name resolution (EAI_AGAIN)";
+#endif
+#ifdef EAI_FAIL
+        case EAI_FAIL:
+            return "Non-recoverable failure in name resolution (EAI_FAIL)";
+#endif
+#ifdef EAI_NODATA
+#if EAI_NODATA!=EAI_NONAME
+        case EAI_NODATA:
+            return "No address associated with nodename (EAI_NODATA)";
+#endif /* EAI_NODATA!=EAI_NONAME */
+#endif /* defined EAI_NODATA */
+#ifdef EAI_FAMILY
+        case EAI_FAMILY:
+            return "ai_family not supported (EAI_FAMILY)";
+#endif
+#ifdef EAI_SOCKTYPE
+        case EAI_SOCKTYPE:
+            return "ai_socktype not supported (EAI_SOCKTYPE)";
+#endif
+#ifdef EAI_SERVICE
+        case EAI_SERVICE:
+            return "servname is not supported for ai_socktype (EAI_SERVICE)";
+#endif
+#ifdef EAI_ADDRFAMILY
+        case EAI_ADDRFAMILY:
+            return "Address family for nodename not supported (EAI_ADDRFAMILY)";
+#endif /* EAI_ADDRFAMILY */
+        case EAI_MEMORY:
+            return "Memory allocation failure (EAI_MEMORY)";
+#ifdef EAI_SYSTEM
+        case EAI_SYSTEM:
+            return "System error returned in errno (EAI_SYSTEM)";
+#endif /* EAI_SYSTEM */
+        default:
+            return "Unknown error";
+    }
+}
+
+/**************************************** my getnameinfo() */
+/* implementation is limited to functionality needed by stunnel */
+
+#ifndef HAVE_GETNAMEINFO
+int getnameinfo(const struct sockaddr *sa, socklen_t salen,
+    char *host, size_t hostlen, char *serv, size_t servlen, int flags) {
+
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+    if(s_getnameinfo)
+        return s_getnameinfo(sa, salen, host, hostlen, serv, servlen, flags);
+#endif
+    if(host && hostlen) {
+#if defined(USE_IPv6) && !defined(USE_WIN32)
+        inet_ntop(sa->sa_family, sa->sa_family==AF_INET6 ?
+                (void *)&((struct sockaddr_in6 *)sa)->sin6_addr :
+                (void *)&((struct sockaddr_in *)sa)->sin_addr,
+            host, hostlen);
+#else /* USE_IPv6 */
+        enter_critical_section(CRIT_INET); /* inet_ntoa is not mt-safe */
+        strncpy(host, inet_ntoa(((struct sockaddr_in *)sa)->sin_addr),
+            hostlen);
+        leave_critical_section(CRIT_INET);
+        host[hostlen-1]='\0';
+#endif /* USE_IPv6 */
+    }
+    if(serv && servlen)
+        sprintf(serv, "%u", ntohs(((struct sockaddr_in *)sa)->sin_port));
+    /* sin_port is in the same place both in sockaddr_in and sockaddr_in6 */
+    /* ignore servlen since it's long enough in stunnel code */
+    return 0;
+}
+#endif
+
+/* end of resolver.c */
diff --git a/src/resources.h b/src/resources.h
new file mode 100644
index 0000000..3cedaaa
--- /dev/null
+++ b/src/resources.h
@@ -0,0 +1,36 @@
+#define WM_SYSTRAY          (WM_USER+0)
+
+#define WM_VALID_CONFIG     (WM_APP+0)
+#define WM_INVALID_CONFIG   (WM_APP+1)
+#define WM_LOG              (WM_APP+2)
+#define WM_NEW_CHAIN        (WM_APP+3)
+#define WM_CLIENTS          (WM_APP+4)
+
+#define IDI_STUNNEL_MAIN    10
+#define IDI_STUNNEL_ACTIVE  11
+#define IDI_STUNNEL_ERROR   12
+#define IDI_STUNNEL_IDLE    13
+
+#define IDE_EDIT            20
+#define IDE_PASSEDIT        21
+#define IDE_PINEDIT         22
+
+#define IDM_TRAYMENU        30
+#define IDM_MAINMENU        31
+#define IDM_CLOSE           32
+#define IDM_EXIT            33
+#define IDM_SHOW_LOG        34
+
+#define IDM_SAVE_LOG        40
+#define IDM_REOPEN_LOG      41
+#define IDM_EDIT_CONFIG     42
+#define IDM_RELOAD_CONFIG   43
+
+#define IDM_ABOUT           50
+#define IDM_MANPAGE         51
+#define IDM_HOMEPAGE        52
+
+#define IDM_PEER_MENU       60
+
+#define IDS_SERVICE_DESC    70
+
diff --git a/src/resources.rc b/src/resources.rc
new file mode 100644
index 0000000..1a1fb2c
--- /dev/null
+++ b/src/resources.rc
@@ -0,0 +1,142 @@
+#include <windows.h>

+#include "resources.h"

+#include "version.h"

+

+VS_VERSION_INFO VERSIONINFO

+FILEVERSION     STUNNEL_VERSION_FIELDS

+PRODUCTVERSION  STUNNEL_VERSION_FIELDS

+FILEFLAGSMASK   VS_FFI_FILEFLAGSMASK

+FILEFLAGS       0

+FILEOS          VOS__WINDOWS32

+FILETYPE        VFT_APP

+FILESUBTYPE     VFT2_UNKNOWN

+BEGIN

+    BLOCK "StringFileInfo"

+    BEGIN

+        BLOCK "040904E4"

+        BEGIN

+            VALUE "CompanyName",        "Michal Trojnara"

+            VALUE "FileDescription",    "stunnel - TLS offloading and load-balancing proxy"

+            VALUE "FileVersion",        STUNNEL_VERSION

+            VALUE "InternalName",       "stunnel"

+            VALUE "LegalCopyright",     "© by Michal Trojnara, 1998-2015"

+            VALUE "OriginalFilename",   "stunnel.exe"

+            VALUE "ProductName",        STUNNEL_PRODUCTNAME

+            VALUE "ProductVersion",     STUNNEL_VERSION

+        END

+    END

+    BLOCK "VarFileInfo"

+    BEGIN

+        VALUE "Translation", 0x409, 1252

+    END

+END

+

+IDI_STUNNEL_MAIN    ICON "stunnel.ico"

+IDI_STUNNEL_ACTIVE  ICON "active.ico"

+IDI_STUNNEL_ERROR   ICON "error.ico"

+IDI_STUNNEL_IDLE    ICON "idle.ico"

+

+IDM_MAINMENU MENU

+BEGIN

+    POPUP "&File"

+    BEGIN

+        MENUITEM "&Save Log As",            IDM_SAVE_LOG

+        MENUITEM "Reopen &Log File",        IDM_REOPEN_LOG, GRAYED

+        MENUITEM SEPARATOR

+        MENUITEM "E&xit",                   IDM_EXIT

+        MENUITEM SEPARATOR

+        MENUITEM "&Close",                  IDM_CLOSE

+    END

+#ifdef _WIN32_WCE

+    POPUP "&Config"

+#else

+    POPUP "&Configuration"

+#endif

+    BEGIN

+        MENUITEM "&Edit Configuration",      IDM_EDIT_CONFIG

+        MENUITEM "&Reload Configuration",    IDM_RELOAD_CONFIG

+    END

+#ifdef _WIN32_WCE

+    POPUP "&Save Peer Certs"

+#else

+    POPUP "&Save Peer Certificate"

+#endif

+    BEGIN

+        MENUITEM "dummy",                   0, GRAYED

+    END

+    POPUP "&Help"

+    BEGIN

+        MENUITEM "&About",                  IDM_ABOUT

+        MENUITEM SEPARATOR

+        MENUITEM "&Manual",                 IDM_MANPAGE

+        MENUITEM "&Homepage",               IDM_HOMEPAGE

+    END

+END

+

+IDM_TRAYMENU MENU

+BEGIN

+    POPUP "Ooops?"

+    BEGIN

+        MENUITEM "Show Log &Window",        IDM_SHOW_LOG

+        MENUITEM SEPARATOR

+        POPUP "&Save Peer Certificate"

+        BEGIN

+            MENUITEM "dummy",               0, GRAYED

+        END

+        MENUITEM SEPARATOR

+        MENUITEM "&Edit Configuration",      IDM_EDIT_CONFIG

+        MENUITEM "&Reload Configuration",    IDM_RELOAD_CONFIG

+        MENUITEM "Reopen &Log File",        IDM_REOPEN_LOG, GRAYED

+        MENUITEM SEPARATOR

+        MENUITEM "&Homepage",               IDM_HOMEPAGE

+        MENUITEM "&Manual",                 IDM_MANPAGE

+        MENUITEM "&About",                  IDM_ABOUT

+        MENUITEM SEPARATOR

+        MENUITEM "E&xit",                   IDM_EXIT

+    END

+END

+

+ABOUTBOX DIALOG DISCARDABLE  0, 0, 140, 68

+STYLE DS_MODALFRAME|DS_CENTER|WS_POPUP|WS_CAPTION|WS_SYSMENU

+CAPTION "About stunnel"

+FONT 8, "MS Sans Serif"

+BEGIN

+    ICON            IDI_STUNNEL_MAIN, -1,                        6,  6,  20, 20

+    LTEXT           "stunnel version", -1,                      30,  4,  49,  8

+    LTEXT           STUNNEL_VERSION, -1,                        79,  4,  57,  8

+    LTEXT           "© by Michal Trojnara, 1998-2015", -1,      30, 12, 106,  8

+    LTEXT           "All Rights Reserved", -1,                  30, 20, 106,  8

+    LTEXT           "Licensed under the GNU GPL version 2", -1,  4, 28, 132,  8

+    LTEXT           "with a special exception for OpenSSL", -1,  4, 36, 132,  8

+    DEFPUSHBUTTON   "OK",IDOK,                                  54, 48,  32, 14, WS_GROUP

+END

+

+PASSBOX DIALOG DISCARDABLE 0, 0, 156, 51

+STYLE DS_MODALFRAME|DS_CENTER|WS_POPUP|WS_CAPTION|WS_SYSMENU

+CAPTION ""

+FONT 8, "MS Sans Serif"

+BEGIN

+    ICON            IDI_STUNNEL_MAIN, -1,     6,  6, 20, 20

+    LTEXT           "Key passphrase:", -1,   30, 13, 56,  8

+    EDITTEXT        IDE_PASSEDIT,            86, 11, 64, 12, ES_PASSWORD|ES_AUTOHSCROLL

+    DEFPUSHBUTTON   "OK",IDOK,                6, 30, 50, 14

+    PUSHBUTTON      "Cancel",IDCANCEL,      100, 30, 50, 14

+END

+

+PINBOX DIALOG DISCARDABLE 0, 0, 156, 51

+STYLE DS_MODALFRAME|DS_CENTER|WS_POPUP|WS_CAPTION|WS_SYSMENU

+CAPTION ""

+FONT 8, "MS Sans Serif"

+BEGIN

+    ICON            IDI_STUNNEL_MAIN, -1,     6,  6, 20, 20

+    LTEXT           "SmartCard PIN:", -1,    30, 13, 56,  8

+    EDITTEXT        IDE_PINEDIT,             86, 11, 64, 12, ES_PASSWORD|ES_AUTOHSCROLL

+    DEFPUSHBUTTON   "OK",IDOK,                6, 30, 50, 14

+    PUSHBUTTON      "Cancel",IDCANCEL,      100, 30, 50, 14

+END

+

+STRINGTABLE

+BEGIN

+IDS_SERVICE_DESC  "TLS offloading and load-balancing proxy"

+END

+

diff --git a/src/ssl.c b/src/ssl.c
new file mode 100644
index 0000000..4805df7
--- /dev/null
+++ b/src/ssl.c
@@ -0,0 +1,261 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+    /* global OpenSSL initalization: compression, engine, entropy */
+NOEXPORT void cb_free(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
+    int idx, long argl, void *argp);
+#ifndef OPENSSL_NO_COMP
+NOEXPORT int compression_init(GLOBAL_OPTIONS *);
+#endif
+NOEXPORT int prng_init(GLOBAL_OPTIONS *);
+NOEXPORT int add_rand_file(GLOBAL_OPTIONS *, const char *);
+
+int index_cli, index_opt, index_redirect, index_addr;
+
+int ssl_init(void) { /* init SSL before parsing configuration file */
+    SSL_load_error_strings();
+    SSL_library_init();
+    index_cli=SSL_get_ex_new_index(0, "cli index",
+        NULL, NULL, NULL);
+    index_opt=SSL_CTX_get_ex_new_index(0, "opt index",
+        NULL, NULL, NULL);
+    index_redirect=SSL_SESSION_get_ex_new_index(0, "redirect index",
+        NULL, NULL, NULL);
+    index_addr=SSL_SESSION_get_ex_new_index(0, "addr index",
+        NULL, NULL, cb_free);
+    if(index_cli<0 || index_opt<0 || index_redirect<0 || index_addr<0) {
+        s_log(LOG_ERR, "Application specific data initialization failed");
+        return 1;
+    }
+#ifndef OPENSSL_NO_ENGINE
+    ENGINE_load_builtin_engines();
+#endif
+#ifndef OPENSSL_NO_DH
+    dh_params=get_dh2048();
+    if(!dh_params) {
+        s_log(LOG_ERR, "Failed to get default DH parameters");
+        return 1;
+    }
+#endif /* OPENSSL_NO_DH */
+    return 0;
+}
+
+NOEXPORT void cb_free(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
+        int idx, long argl, void *argp) {
+    (void)parent; /* skip warning about unused parameter */
+    (void)ad; /* skip warning about unused parameter */
+    (void)idx; /* skip warning about unused parameter */
+    (void)argl; /* skip warning about unused parameter */
+    s_log(LOG_DEBUG, "Deallocating application specific data for %s",
+        (char *)argp);
+    str_free(ptr);
+}
+
+int ssl_configure(GLOBAL_OPTIONS *global) { /* configure global SSL settings */
+#ifdef USE_FIPS
+    if(FIPS_mode()!=global->option.fips) {
+        RAND_set_rand_method(NULL); /* reset RAND methods */
+        if(!FIPS_mode_set(global->option.fips)) {
+            ERR_load_crypto_strings();
+            sslerror("FIPS_mode_set");
+            return 1;
+        }
+    }
+    s_log(LOG_NOTICE, "FIPS mode %s",
+        global->option.fips ? "enabled" : "disabled");
+#endif /* USE_FIPS */
+#ifndef OPENSSL_NO_COMP
+    if(compression_init(global))
+        return 1;
+#endif /* OPENSSL_NO_COMP */
+    if(prng_init(global))
+        return 1;
+    s_log(LOG_DEBUG, "PRNG seeded successfully");
+    return 0; /* SUCCESS */
+}
+
+#ifndef OPENSSL_NO_COMP
+NOEXPORT int compression_init(GLOBAL_OPTIONS *global) {
+    STACK_OF(SSL_COMP) *methods;
+
+    methods=SSL_COMP_get_compression_methods();
+    if(!methods) {
+        if(global->compression==COMP_NONE) {
+            s_log(LOG_NOTICE, "Failed to get compression methods");
+            return 0; /* ignore */
+        } else {
+            s_log(LOG_ERR, "Failed to get compression methods");
+            return 1;
+        }
+    }
+
+    if(global->compression==COMP_NONE ||
+            SSLeay()<0x00908051L /* 0.9.8e-beta1 */) {
+        /* delete OpenSSL defaults (empty the SSL_COMP stack) */
+        /* cannot use sk_SSL_COMP_pop_free,
+         * as it also destroys the stack itself */
+        /* only leave the standard RFC 1951 (DEFLATE) algorithm,
+         * if any of the private algorithms is enabled */
+        /* only allow DEFLATE with OpenSSL 0.9.8 or later
+         * with OpenSSL #1468 zlib memory leak fixed */
+        while(sk_SSL_COMP_num(methods))
+#if OPENSSL_VERSION_NUMBER>=0x10100000L
+            /* FIXME: remove when sk_SSL_COMP_pop() works again */
+            OPENSSL_free(sk_pop((void *)methods));
+#else
+            OPENSSL_free(sk_SSL_COMP_pop(methods));
+#endif
+    }
+
+    if(global->compression==COMP_NONE) {
+        s_log(LOG_DEBUG, "Compression disabled");
+        return 0; /* success */
+    }
+
+    /* also insert the obsolete ZLIB algorithm */
+    if(global->compression==COMP_ZLIB) {
+        /* 224 - within the private range (193 to 255) */
+        COMP_METHOD *meth=COMP_zlib();
+#if OPENSSL_VERSION_NUMBER>=0x10100000L
+        if(!meth || COMP_get_type(meth)==NID_undef) {
+#else
+        if(!meth || meth->type==NID_undef) {
+#endif
+            s_log(LOG_ERR, "ZLIB compression is not supported");
+            return 1;
+        }
+        SSL_COMP_add_compression_method(0xe0, meth);
+    }
+    s_log(LOG_INFO, "Compression enabled: %d method(s)",
+        sk_SSL_COMP_num(methods));
+    return 0; /* success */
+}
+#endif /* OPENSSL_NO_COMP */
+
+NOEXPORT int prng_init(GLOBAL_OPTIONS *global) {
+    int totbytes=0;
+    char filename[256];
+#ifndef USE_WIN32
+    int bytes;
+#endif
+
+    filename[0]='\0';
+
+    /* if they specify a rand file on the command line we
+       assume that they really do want it, so try it first */
+    if(global->rand_file) {
+        totbytes+=add_rand_file(global, global->rand_file);
+        if(RAND_status())
+            return 0; /* success */
+    }
+
+    /* try the $RANDFILE or $HOME/.rnd files */
+    RAND_file_name(filename, 256);
+    if(filename[0]) {
+        totbytes+=add_rand_file(global, filename);
+        if(RAND_status())
+            return 0; /* success */
+    }
+
+#ifdef RANDOM_FILE
+    totbytes+=add_rand_file(global, RANDOM_FILE);
+    if(RAND_status())
+        return 0; /* success */
+#endif
+
+#ifdef USE_WIN32
+    RAND_screen();
+    if(RAND_status()) {
+        s_log(LOG_DEBUG, "Seeded PRNG with RAND_screen");
+        return 0; /* success */
+    }
+    s_log(LOG_DEBUG, "RAND_screen failed to sufficiently seed PRNG");
+#else
+    if(global->egd_sock) {
+        if((bytes=RAND_egd(global->egd_sock))==-1) {
+            s_log(LOG_WARNING, "EGD Socket %s failed", global->egd_sock);
+            bytes=0;
+        } else {
+            totbytes+=bytes;
+            s_log(LOG_DEBUG, "Snagged %d random bytes from EGD Socket %s",
+                bytes, global->egd_sock);
+            return 0; /* OpenSSL always gets what it needs or fails,
+                         so no need to check if seeded sufficiently */
+        }
+    }
+    /* try the good-old default /dev/urandom, if available  */
+    totbytes+=add_rand_file(global, "/dev/urandom");
+    if(RAND_status())
+        return 0; /* success */
+#endif /* USE_WIN32 */
+
+    /* random file specified during configure */
+    s_log(LOG_ERR, "PRNG seeded with %d bytes total", totbytes);
+    s_log(LOG_ERR, "PRNG was not seeded with enough random bytes");
+    return 1; /* FAILED */
+}
+
+NOEXPORT int add_rand_file(GLOBAL_OPTIONS *global, const char *filename) {
+    int readbytes;
+    int writebytes;
+    struct stat sb;
+
+    if(stat(filename, &sb))
+        return 0; /* could not stat() file --> return 0 bytes */
+    if((readbytes=RAND_load_file(filename, global->random_bytes)))
+        s_log(LOG_DEBUG, "Snagged %d random bytes from %s",
+            readbytes, filename);
+    else
+        s_log(LOG_INFO, "Cannot retrieve any random data from %s",
+            filename);
+    /* write new random data for future seeding if it's a regular file */
+    if(global->option.rand_write && S_ISREG(sb.st_mode)) {
+        writebytes=RAND_write_file(filename);
+        if(writebytes==-1)
+            s_log(LOG_WARNING, "Failed to write strong random data to %s - "
+                "may be a permissions or seeding problem", filename);
+        else
+            s_log(LOG_DEBUG, "Wrote %d new random bytes to %s",
+                writebytes, filename);
+    }
+    return readbytes;
+}
+
+/* end of ssl.c */
diff --git a/src/sthreads.c b/src/sthreads.c
new file mode 100644
index 0000000..5fecc3c
--- /dev/null
+++ b/src/sthreads.c
@@ -0,0 +1,559 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#ifdef USE_OS2
+#define INCL_DOSPROCESS
+#include <os2.h>
+#endif
+
+#include "common.h"
+#include "prototypes.h"
+
+#if defined(USE_UCONTEXT) || defined(USE_FORK)
+/* no need for critical sections */
+
+void enter_critical_section(SECTION_CODE i) {
+    (void)i; /* skip warning about unused parameter */
+    /* empty */
+}
+
+void leave_critical_section(SECTION_CODE i) {
+    (void)i; /* skip warning about unused parameter */
+    /* empty */
+}
+
+#endif /* USE_UCONTEXT || USE_FORK */
+
+#ifdef USE_UCONTEXT
+
+#if defined(CPU_SPARC) && ( \
+        defined(OS_SOLARIS2_0) || \
+        defined(OS_SOLARIS2_1) || \
+        defined(OS_SOLARIS2_2) || \
+        defined(OS_SOLARIS2_3) || \
+        defined(OS_SOLARIS2_4) || \
+        defined(OS_SOLARIS2_5) || \
+        defined(OS_SOLARIS2_6) || \
+        defined(OS_SOLARIS2_7) || \
+        defined(OS_SOLARIS2_8))
+#define ARGC 2
+#else
+#define ARGC 1
+#endif
+
+/* first context on the ready list is the active context */
+CONTEXT *ready_head=NULL, *ready_tail=NULL;         /* ready to execute */
+CONTEXT *waiting_head=NULL, *waiting_tail=NULL;     /* waiting on poll() */
+
+unsigned long stunnel_process_id(void) {
+    return (unsigned long)getpid();
+}
+
+unsigned long stunnel_thread_id(void) {
+    return ready_head ? ready_head->id : 0;
+}
+
+NOEXPORT CONTEXT *new_context(void) {
+    static unsigned long next_id=1;
+    CONTEXT *context;
+
+    /* allocate and fill the CONTEXT structure */
+    context=str_alloc_detached(sizeof(CONTEXT));
+    context->id=next_id++;
+    context->fds=NULL;
+    context->ready=0;
+
+    /* append to the tail of the ready queue */
+    context->next=NULL;
+    if(ready_tail)
+        ready_tail->next=context;
+    ready_tail=context;
+    if(!ready_head)
+        ready_head=context;
+
+    return context;
+}
+
+int sthreads_init(void) {
+    /* create the first (listening) context and put it in the running queue */
+    if(!new_context()) {
+        s_log(LOG_ERR, "Cannot create the listening context");
+        return 1;
+    }
+    /* update tls for newly allocated ready_head */
+    ui_tls=tls_alloc(NULL, ui_tls, "ui");
+    /* no need to initialize ucontext_t structure here
+       it will be initialied with swapcontext() call */
+    return 0;
+}
+
+int create_client(SOCKET ls, SOCKET s, CLI *arg, void *(*cli)(void *)) {
+    CONTEXT *context;
+
+    (void)ls; /* this parameter is only used with USE_FORK */
+
+    s_log(LOG_DEBUG, "Creating a new context");
+    context=new_context();
+    if(!context) {
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+        return -1;
+    }
+
+    /* initialize context_t structure */
+    if(getcontext(&context->context)<0) {
+        str_free(context);
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+        ioerror("getcontext");
+        return -1;
+    }
+    context->context.uc_link=NULL; /* stunnel does not use uc_link */
+
+    /* create stack */
+    context->stack=str_alloc_detached(arg->opt->stack_size);
+#if defined(__sgi) || ARGC==2 /* obsolete ss_sp semantics */
+    context->context.uc_stack.ss_sp=context->stack+arg->opt->stack_size-8;
+#else
+    context->context.uc_stack.ss_sp=context->stack;
+#endif
+    context->context.uc_stack.ss_size=arg->opt->stack_size;
+    context->context.uc_stack.ss_flags=0;
+
+    makecontext(&context->context, (void(*)(void))cli, ARGC, arg);
+    s_log(LOG_DEBUG, "New context created");
+    return 0;
+}
+
+#endif /* USE_UCONTEXT */
+
+#ifdef USE_FORK
+
+int sthreads_init(void) {
+    return 0;
+}
+
+unsigned long stunnel_process_id(void) {
+    return (unsigned long)getpid();
+}
+
+unsigned long stunnel_thread_id(void) {
+    return 0L;
+}
+
+NOEXPORT void null_handler(int sig) {
+    (void)sig; /* skip warning about unused parameter */
+    signal(SIGCHLD, null_handler);
+}
+
+int create_client(SOCKET ls, SOCKET s, CLI *arg, void *(*cli)(void *)) {
+    switch(fork()) {
+    case -1:    /* error */
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+        return -1;
+    case  0:    /* child */
+        if(ls>=0)
+            closesocket(ls);
+        signal(SIGCHLD, null_handler);
+        cli(arg);
+        _exit(0);
+    default:    /* parent */
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+    }
+    return 0;
+}
+
+#endif /* USE_FORK */
+
+#ifdef USE_PTHREAD
+
+static pthread_mutex_t stunnel_cs[CRIT_SECTIONS];
+static pthread_mutex_t *lock_cs;
+
+void enter_critical_section(SECTION_CODE i) {
+    pthread_mutex_lock(stunnel_cs+i);
+}
+
+void leave_critical_section(SECTION_CODE i) {
+    pthread_mutex_unlock(stunnel_cs+i);
+}
+
+NOEXPORT void locking_callback(int mode, int type, const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    if(mode&CRYPTO_LOCK)
+        pthread_mutex_lock(lock_cs+type);
+    else
+        pthread_mutex_unlock(lock_cs+type);
+}
+
+struct CRYPTO_dynlock_value {
+    pthread_mutex_t mutex;
+};
+
+NOEXPORT struct CRYPTO_dynlock_value *dyn_create_function(const char *file,
+        int line) {
+    struct CRYPTO_dynlock_value *value;
+
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    value=str_alloc_detached(sizeof(struct CRYPTO_dynlock_value));
+    pthread_mutex_init(&value->mutex, NULL);
+    return value;
+}
+
+NOEXPORT void dyn_lock_function(int mode, struct CRYPTO_dynlock_value *value,
+        const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    if(mode&CRYPTO_LOCK)
+        pthread_mutex_lock(&value->mutex);
+    else
+        pthread_mutex_unlock(&value->mutex);
+}
+
+NOEXPORT void dyn_destroy_function(struct CRYPTO_dynlock_value *value,
+        const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    pthread_mutex_destroy(&value->mutex);
+    str_free(value);
+}
+
+unsigned long stunnel_process_id(void) {
+    return (unsigned long)getpid();
+}
+
+unsigned long stunnel_thread_id(void) {
+#if defined(SYS_gettid) && defined(__linux__)
+    return (unsigned long)syscall(SYS_gettid);
+#else
+    return (unsigned long)pthread_self();
+#endif
+}
+
+#if OPENSSL_VERSION_NUMBER>=0x10000000L
+NOEXPORT void threadid_func(CRYPTO_THREADID *tid) {
+    CRYPTO_THREADID_set_numeric(tid, stunnel_thread_id());
+}
+#endif
+
+int sthreads_init(void) {
+    int i;
+
+    /* initialize stunnel critical sections */
+    for(i=0; i<CRIT_SECTIONS; i++)
+        pthread_mutex_init(stunnel_cs+i, NULL);
+
+    /* initialize OpenSSL locking callback */
+    lock_cs=str_alloc_detached(
+        (size_t)CRYPTO_num_locks()*sizeof(pthread_mutex_t));
+    for(i=0; i<CRYPTO_num_locks(); i++)
+        pthread_mutex_init(lock_cs+i, NULL);
+#if OPENSSL_VERSION_NUMBER>=0x10000000L
+    CRYPTO_THREADID_set_callback(threadid_func);
+#else
+    CRYPTO_set_id_callback(stunnel_thread_id);
+#endif
+    CRYPTO_set_locking_callback(locking_callback);
+
+    /* initialize OpenSSL dynamic locks callbacks */
+    CRYPTO_set_dynlock_create_callback(dyn_create_function);
+    CRYPTO_set_dynlock_lock_callback(dyn_lock_function);
+    CRYPTO_set_dynlock_destroy_callback(dyn_destroy_function);
+
+    return 0;
+}
+
+int create_client(SOCKET ls, SOCKET s, CLI *arg, void *(*cli)(void *)) {
+    pthread_t thread;
+    pthread_attr_t pth_attr;
+    int error;
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    /* disabled on OS X due to strange problems on Mac OS X 10.5
+       it seems to restore signal mask somewhere (I couldn't find where)
+       effectively blocking signals after first accepted connection */
+    sigset_t new_set, old_set;
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+
+    (void)ls; /* this parameter is only used with USE_FORK */
+
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    /* the idea is that only the main thread handles all the signals with
+     * posix threads;  signals are blocked for any other thread */
+    sigfillset(&new_set);
+    pthread_sigmask(SIG_SETMASK, &new_set, &old_set); /* block signals */
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+    pthread_attr_init(&pth_attr);
+    pthread_attr_setdetachstate(&pth_attr, PTHREAD_CREATE_DETACHED);
+    pthread_attr_setstacksize(&pth_attr, arg->opt->stack_size);
+    error=pthread_create(&thread, &pth_attr, cli, arg);
+    pthread_attr_destroy(&pth_attr);
+#if defined(HAVE_PTHREAD_SIGMASK) && !defined(__APPLE__)
+    pthread_sigmask(SIG_SETMASK, &old_set, NULL); /* unblock signals */
+#endif /* HAVE_PTHREAD_SIGMASK && !__APPLE__*/
+
+    if(error) {
+        errno=error;
+        ioerror("pthread_create");
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+        return -1;
+    }
+    return 0;
+}
+
+#endif /* USE_PTHREAD */
+
+#ifdef USE_WIN32
+
+static CRITICAL_SECTION stunnel_cs[CRIT_SECTIONS];
+static CRITICAL_SECTION *lock_cs;
+
+void enter_critical_section(SECTION_CODE i) {
+    EnterCriticalSection(stunnel_cs+i);
+}
+
+void leave_critical_section(SECTION_CODE i) {
+    LeaveCriticalSection(stunnel_cs+i);
+}
+
+NOEXPORT void locking_callback(int mode, int type, const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    if(mode&CRYPTO_LOCK)
+        EnterCriticalSection(lock_cs+type);
+    else
+        LeaveCriticalSection(lock_cs+type);
+}
+
+struct CRYPTO_dynlock_value {
+    CRITICAL_SECTION mutex;
+};
+
+NOEXPORT struct CRYPTO_dynlock_value *dyn_create_function(const char *file,
+        int line) {
+    struct CRYPTO_dynlock_value *value;
+
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    value=str_alloc_detached(sizeof(struct CRYPTO_dynlock_value));
+    InitializeCriticalSection(&value->mutex);
+    return value;
+}
+
+NOEXPORT void dyn_lock_function(int mode, struct CRYPTO_dynlock_value *value,
+        const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    if(mode&CRYPTO_LOCK)
+        EnterCriticalSection(&value->mutex);
+    else
+        LeaveCriticalSection(&value->mutex);
+}
+
+NOEXPORT void dyn_destroy_function(struct CRYPTO_dynlock_value *value,
+        const char *file, int line) {
+    (void)file; /* skip warning about unused parameter */
+    (void)line; /* skip warning about unused parameter */
+    DeleteCriticalSection(&value->mutex);
+    str_free(value);
+}
+
+unsigned long stunnel_process_id(void) {
+    return GetCurrentProcessId() & 0x00ffffff;
+}
+
+unsigned long stunnel_thread_id(void) {
+    return GetCurrentThreadId() & 0x00ffffff;
+}
+
+int sthreads_init(void) {
+    int i;
+
+    /* initialize stunnel critical sections */
+    for(i=0; i<CRIT_SECTIONS; i++)
+        InitializeCriticalSection(stunnel_cs+i);
+
+    /* initialize OpenSSL locking callback */
+    lock_cs=str_alloc_detached(
+        (size_t)CRYPTO_num_locks()*sizeof(CRITICAL_SECTION));
+    for(i=0; i<CRYPTO_num_locks(); i++)
+        InitializeCriticalSection(lock_cs+i);
+    CRYPTO_set_locking_callback(locking_callback);
+
+    /* initialize OpenSSL dynamic locks callbacks */
+    CRYPTO_set_dynlock_create_callback(dyn_create_function);
+    CRYPTO_set_dynlock_lock_callback(dyn_lock_function);
+    CRYPTO_set_dynlock_destroy_callback(dyn_destroy_function);
+
+    return 0;
+}
+
+int create_client(SOCKET ls, SOCKET s, CLI *arg, void *(*cli)(void *)) {
+    (void)ls; /* this parameter is only used with USE_FORK */
+    s_log(LOG_DEBUG, "Creating a new thread");
+    if((long)_beginthread((void(*)(void *))cli, arg->opt->stack_size, arg)==-1) {
+        ioerror("_beginthread");
+        str_free(arg);
+        if(s!=INVALID_SOCKET)
+            closesocket(s);
+        return -1;
+    }
+    s_log(LOG_DEBUG, "New thread created");
+    return 0;
+}
+
+#endif /* USE_WIN32 */
+
+#ifdef USE_OS2
+
+void enter_critical_section(SECTION_CODE i) {
+    DosEnterCritSec();
+}
+
+void leave_critical_section(SECTION_CODE i) {
+    DosExitCritSec();
+}
+
+int sthreads_init(void) {
+    return 0;
+}
+
+unsigned long stunnel_process_id(void) {
+    PTIB ptib=NULL;
+    DosGetInfoBlocks(&ptib, NULL);
+    return (unsigned long)ptib->tib_ordinal;
+}
+
+unsigned long stunnel_thread_id(void) {
+    PPIB ppib=NULL;
+    DosGetInfoBlocks(NULL, &ppib);
+    return (unsigned long)ppib->pib_ulpid;
+}
+
+int create_client(SOCKET ls, SOCKET s, CLI *arg, void *(*cli)(void *)) {
+    (void)ls; /* this parameter is only used with USE_FORK */
+    s_log(LOG_DEBUG, "Creating a new thread");
+    if((long)_beginthread((void(*)(void *))cli, NULL, arg->opt->stack_size, arg)==-1L) {
+        ioerror("_beginthread");
+        str_free(arg);
+        if(s>=0)
+            closesocket(s);
+        return -1;
+    }
+    s_log(LOG_DEBUG, "New thread created");
+    return 0;
+}
+
+#endif /* USE_OS2 */
+
+#ifdef _WIN32_WCE
+
+long _beginthread(void (*start_address)(void *),
+        int stack_size, void *arglist) {
+    DWORD thread_id;
+    HANDLE handle;
+
+    handle=CreateThread(NULL, stack_size,
+        (LPTHREAD_START_ROUTINE)start_address, arglist,
+        STACK_SIZE_PARAM_IS_A_RESERVATION, &thread_id);
+    if(!handle)
+        return -1L;
+    CloseHandle(handle);
+    return 0;
+}
+
+void _endthread(void) {
+    ExitThread(0);
+}
+
+#endif /* _WIN32_WCE */
+
+#ifdef DEBUG_STACK_SIZE
+
+#define STACK_RESERVE (STACK_SIZE/8)
+#define VERIFY_AREA ((STACK_SIZE-STACK_RESERVE)/sizeof(uint32_t))
+#define TEST_VALUE 0xdeadbeef
+
+/* some heuristic to determine the usage of client stack size */
+void stack_info(int init) { /* 1-initialize, 0-display */
+    uint32_t table[VERIFY_AREA];
+    int i, num;
+    static int min_num=VERIFY_AREA;
+
+    if(init) {
+        for(i=0; i<VERIFY_AREA; i++)
+            table[i]=TEST_VALUE;
+    } else {
+        /* the stack is growing down */
+        for(i=0; i<VERIFY_AREA; i++)
+            if(table[i]!=TEST_VALUE)
+                break;
+        num=i;
+        /* the stack is growing up */
+        for(i=0; i<VERIFY_AREA; i++)
+            if(table[VERIFY_AREA-i-1]!=TEST_VALUE)
+                break;
+        if(i>num) /* use the higher value */
+            num=i;
+        if(num<64) {
+            s_log(LOG_NOTICE, "STACK_RESERVE is too high");
+            return;
+        }
+        if(num<min_num)
+            min_num=num;
+        s_log(LOG_NOTICE,
+            "stack_info: size=%d, current=%d (%d%%), maximum=%d (%d%%)",
+            STACK_SIZE,
+            (int)((VERIFY_AREA-num)*sizeof(uint32_t)),
+            (int)((VERIFY_AREA-num)*sizeof(uint32_t)*100/STACK_SIZE),
+            (int)((VERIFY_AREA-min_num)*sizeof(uint32_t)),
+            (int)((VERIFY_AREA-min_num)*sizeof(uint32_t)*100/STACK_SIZE));
+    }
+}
+
+#endif /* DEBUG_STACK_SIZE */
+
+/* end of sthreads.c */
diff --git a/src/str.c b/src/str.c
new file mode 100644
index 0000000..7a45834
--- /dev/null
+++ b/src/str.c
@@ -0,0 +1,403 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+struct alloc_list_struct {
+    ALLOC_LIST *prev, *next;
+    TLS_DATA *tls;
+    size_t size;
+    const char *alloc_file, *free_file;
+    int alloc_line, free_line;
+    unsigned valid_canary, magic;
+        /* at least on IA64 allocations need to be aligned */
+#ifdef __GNUC__
+} __attribute__((aligned(16)));
+#else
+    uint64_t :0; /* align the structure */
+};
+#endif
+
+#ifdef USE_WIN32
+NOEXPORT LPTSTR str_vtprintf(LPCTSTR, va_list);
+#endif /* USE_WIN32 */
+
+NOEXPORT ALLOC_LIST *get_alloc_list_ptr(void *, const char *, int);
+NOEXPORT void str_leak_debug(ALLOC_LIST *, int);
+
+TLS_DATA *ui_tls;
+static uint8_t canary[10]; /* 80-bit canary value */
+static volatile unsigned canary_initialized=0xabadbabe;
+
+/**************************************** string manipulation functions */
+
+#ifndef va_copy
+#ifdef __va_copy
+#define va_copy(dst, src) __va_copy((dst), (src))
+#else /* __va_copy */
+#define va_copy(dst, src) memcpy(&(dst), &(src), sizeof(va_list))
+#endif /* __va_copy */
+#endif /* va_copy */
+
+char *str_dup_debug(const char *str, const char *file, int line) {
+    char *retval;
+
+    retval=str_alloc_debug(strlen(str)+1, file, line);
+    strcpy(retval, str);
+    return retval;
+}
+
+char *str_printf(const char *format, ...) {
+    char *txt;
+    va_list arglist;
+
+    va_start(arglist, format);
+    txt=str_vprintf(format, arglist);
+    va_end(arglist);
+    return txt;
+}
+
+char *str_vprintf(const char *format, va_list start_ap) {
+    int n;
+    size_t size=32;
+    char *p;
+    va_list ap;
+
+    p=str_alloc(size);
+    for(;;) {
+        va_copy(ap, start_ap);
+        n=vsnprintf(p, size, format, ap);
+        if(n>-1 && n<(int)size)
+            return p;
+        if(n>-1)                /* glibc 2.1 */
+            size=(size_t)n+1;   /* precisely what is needed */
+        else                    /* glibc 2.0, WIN32, etc. */
+            size*=2;            /* twice the old size */
+        p=str_realloc(p, size);
+    }
+}
+
+#ifdef USE_WIN32
+
+LPTSTR str_tprintf(LPCTSTR format, ...) {
+    LPTSTR txt;
+    va_list arglist;
+
+    va_start(arglist, format);
+    txt=str_vtprintf(format, arglist);
+    va_end(arglist);
+    return txt;
+}
+
+NOEXPORT LPTSTR str_vtprintf(LPCTSTR format, va_list start_ap) {
+    int n;
+    size_t size=32;
+    LPTSTR p;
+    va_list ap;
+
+    p=str_alloc(size*sizeof(TCHAR));
+    for(;;) {
+        va_copy(ap, start_ap);
+        n=_vsntprintf(p, size, format, ap);
+        if(n>-1 && n<(int)size)
+            return p;
+        size*=2;
+        p=str_realloc(p, size*sizeof(TCHAR));
+    }
+}
+
+#endif
+
+/**************************************** memory allocation wrappers */
+
+void str_init(TLS_DATA *tls_data) {
+    tls_data->alloc_head=NULL;
+    tls_data->alloc_bytes=tls_data->alloc_blocks=0;
+}
+
+void str_cleanup(TLS_DATA *tls_data) {
+    /* free all attached allocations */
+    while(tls_data->alloc_head) /* str_free macro requires an lvalue */
+        str_free_expression(tls_data->alloc_head+1);
+}
+
+void str_canary_init() {
+    if(canary_initialized!=0xabadbabe)
+        return; /* prevent double initialization on config reload */
+    RAND_bytes(canary, sizeof canary);
+    /* an error would reduce the effectiveness of canaries */
+    /* this is nothing critical, so the return value is ignored here */
+    canary_initialized=0xc0ded; /* after RAND_bytes */
+}
+
+void str_stats() {
+    TLS_DATA *tls_data;
+    ALLOC_LIST *alloc_list;
+    int i=0;
+
+    if(!tls_initialized)
+        fatal("str not initialized");
+    tls_data=tls_get();
+    if(!tls_data || (!tls_data->alloc_blocks && !tls_data->alloc_bytes))
+        return; /* skip if no data is allocated */
+    s_log(LOG_DEBUG, "str_stats: %lu block(s), "
+            "%lu data byte(s), %lu control byte(s)",
+        (unsigned long)tls_data->alloc_blocks,
+        (unsigned long)tls_data->alloc_bytes,
+        (unsigned long)(tls_data->alloc_blocks*
+            (sizeof(ALLOC_LIST)+sizeof canary)));
+    for(alloc_list=tls_data->alloc_head; alloc_list; alloc_list=alloc_list->next) {
+        if(++i>10) /* limit the number of results */
+            break;
+        s_log(LOG_DEBUG, "str_stats: %lu byte(s) at %s:%d",
+            (unsigned long)alloc_list->size,
+            alloc_list->alloc_file, alloc_list->alloc_line);
+    }
+}
+
+void *str_alloc_debug(size_t size, const char *file, int line) {
+    TLS_DATA *tls_data;
+    ALLOC_LIST *alloc_list;
+
+    if(!tls_initialized)
+        fatal_debug("str not initialized", file, line);
+    tls_data=tls_get();
+    if(!tls_data) {
+        tls_data=tls_alloc(NULL, NULL, "alloc");
+        s_log(LOG_ERR, "INTERNAL ERROR: Uninitialized TLS at %s, line %d",
+            file, line);
+    }
+
+    alloc_list=(ALLOC_LIST *)str_alloc_detached_debug(size, file, line)-1;
+    alloc_list->prev=NULL;
+    alloc_list->next=tls_data->alloc_head;
+    alloc_list->tls=tls_data;
+    if(tls_data->alloc_head)
+        tls_data->alloc_head->prev=alloc_list;
+    tls_data->alloc_head=alloc_list;
+    tls_data->alloc_bytes+=size;
+    tls_data->alloc_blocks++;
+
+    return alloc_list+1;
+}
+
+void *str_alloc_detached_debug(size_t size, const char *file, int line) {
+    ALLOC_LIST *alloc_list;
+
+#if 0
+    printf("allocating %lu bytes at %s:%d\n", (unsigned long)size, file, line);
+#endif
+    alloc_list=calloc(1, sizeof(ALLOC_LIST)+size+sizeof canary);
+    if(!alloc_list)
+        fatal_debug("Out of memory", file, line);
+    alloc_list->prev=NULL; /* for debugging */
+    alloc_list->next=NULL; /* for debugging */
+    alloc_list->tls=NULL;
+    alloc_list->size=size;
+    alloc_list->alloc_file=file;
+    alloc_list->alloc_line=line;
+    alloc_list->free_file="none";
+    alloc_list->free_line=0;
+    alloc_list->valid_canary=canary_initialized; /* before memcpy */
+    memcpy((uint8_t *)(alloc_list+1)+size, canary, sizeof canary);
+    alloc_list->magic=0xa110c8ed;
+    str_leak_debug(alloc_list, 1);
+
+    return alloc_list+1;
+}
+
+void *str_realloc_debug(void *ptr, size_t size, const char *file, int line) {
+    ALLOC_LIST *prev_alloc_list, *alloc_list;
+
+    if(!ptr)
+        return str_alloc_debug(size, file, line);
+    prev_alloc_list=get_alloc_list_ptr(ptr, file, line);
+    str_leak_debug(prev_alloc_list, -1);
+    if(prev_alloc_list->size>size) /* shrinking the allocation */
+        memset((uint8_t *)ptr+size, 0, prev_alloc_list->size-size); /* paranoia */
+    alloc_list=realloc(prev_alloc_list,
+        sizeof(ALLOC_LIST)+size+sizeof canary);
+    if(!alloc_list)
+        fatal_debug("Out of memory", file, line);
+    ptr=alloc_list+1;
+    if(size>alloc_list->size) /* growing the allocation */
+        memset((uint8_t *)ptr+alloc_list->size, 0, size-alloc_list->size);
+    if(alloc_list->tls) { /* not detached */
+        /* refresh possibly invalidated linked list pointers */
+        if(alloc_list->tls->alloc_head==prev_alloc_list)
+            alloc_list->tls->alloc_head=alloc_list;
+        if(alloc_list->next)
+            alloc_list->next->prev=alloc_list;
+        if(alloc_list->prev)
+            alloc_list->prev->next=alloc_list;
+        /* update statistics while the old size is still available */
+        alloc_list->tls->alloc_bytes+=size-alloc_list->size;
+    }
+    alloc_list->size=size;
+    alloc_list->alloc_file=file;
+    alloc_list->alloc_line=line;
+    alloc_list->free_file="none";
+    alloc_list->free_line=0;
+    alloc_list->valid_canary=canary_initialized; /* before memcpy */
+    memcpy((uint8_t *)ptr+size, canary, sizeof canary);
+    str_leak_debug(alloc_list, 1);
+    return ptr;
+}
+
+/* detach from thread automatic deallocation list */
+/* it has no effect if the allocation is already detached */
+void str_detach_debug(void *ptr, const char *file, int line) {
+    ALLOC_LIST *alloc_list;
+
+    if(!ptr) /* do not attempt to free null pointers */
+        return;
+    alloc_list=get_alloc_list_ptr(ptr, file, line);
+    if(alloc_list->tls) { /* not detached */
+        /* remove from linked list */
+        if(alloc_list->tls->alloc_head==alloc_list)
+            alloc_list->tls->alloc_head=alloc_list->next;
+        if(alloc_list->next)
+            alloc_list->next->prev=alloc_list->prev;
+        if(alloc_list->prev)
+            alloc_list->prev->next=alloc_list->next;
+        /* update statistics */
+        alloc_list->tls->alloc_bytes-=alloc_list->size;
+        alloc_list->tls->alloc_blocks--;
+        /* clear pointers */
+        alloc_list->next=NULL;
+        alloc_list->prev=NULL;
+        alloc_list->tls=NULL;
+    }
+}
+
+void str_free_debug(void *ptr, const char *file, int line) {
+    ALLOC_LIST *alloc_list;
+
+    if(!ptr) /* do not attempt to free null pointers */
+        return;
+    alloc_list=(ALLOC_LIST *)ptr-1;
+    if(alloc_list->magic==0xdefec8ed) {
+        /* this may (unlikely) log garbage instead of file names */
+        s_log(LOG_CRIT,
+            "Double free attempt: ptr=%p alloc=%s:%d free#1=%s:%d free#2=%s:%d",
+            ptr,
+            alloc_list->alloc_file, alloc_list->alloc_line,
+            alloc_list->free_file, alloc_list->free_line,
+            file, line);
+        return;
+    }
+    str_detach_debug(ptr, file, line);
+    str_leak_debug(alloc_list, -1);
+    alloc_list->free_file=file;
+    alloc_list->free_line=line;
+    alloc_list->magic=0xdefec8ed; /* to detect double free attempts */
+    memset(ptr, 0, alloc_list->size); /* paranoia */
+    free(alloc_list);
+}
+
+NOEXPORT ALLOC_LIST *get_alloc_list_ptr(void *ptr, const char *file, int line) {
+    ALLOC_LIST *alloc_list;
+
+    if(!tls_initialized)
+        fatal_debug("str not initialized", file, line);
+    alloc_list=(ALLOC_LIST *)ptr-1;
+    if(alloc_list->magic!=0xa110c8ed) /* not allocated by str_alloc() */
+        fatal_debug("Bad magic", file, line); /* LOL */
+    if(alloc_list->tls /* not detached */ && alloc_list->tls!=tls_get())
+        fatal_debug("Memory allocated in a different thread", file, line);
+    if(alloc_list->valid_canary!=0xabadbabe &&
+            safe_memcmp((uint8_t *)ptr+alloc_list->size, canary, sizeof canary))
+        fatal_debug("Dead canary", file, line); /* LOL */
+    return alloc_list;
+}
+
+/* #define STR_LEAK_DEBUG */
+/* the implementation is slow, but it's not going to be used in production */
+NOEXPORT void str_leak_debug(ALLOC_LIST *alloc_list, int change) {
+#ifndef STR_LEAK_DEBUG
+    (void)alloc_list; /* skip warning about unused parameter */
+    (void)change; /* skip warning about unused parameter */
+#else
+#define ALLOC_TABLE_SIZE 1000
+#define MAX_ALLOCS 200
+    static struct {
+        const char *alloc_file;
+        int alloc_line;
+        int num;
+    } alloc_table[ALLOC_TABLE_SIZE];
+    static size_t alloc_num=0;
+    size_t i;
+
+    enter_critical_section(CRIT_LEAK);
+    for(i=0; i<alloc_num; ++i)
+        if(alloc_table[i].alloc_file==alloc_list->alloc_file &&
+                alloc_table[i].alloc_line==alloc_list->alloc_line)
+            break;
+    if(i==alloc_num) {
+        if(alloc_num==ALLOC_TABLE_SIZE) {
+            leave_critical_section(CRIT_LEAK);
+            return;
+        }
+        alloc_table[i].alloc_file=alloc_list->alloc_file;
+        alloc_table[i].alloc_line=alloc_list->alloc_line;
+        alloc_table[i].num=0;
+        ++alloc_num;
+    }
+    alloc_table[i].num+=change;
+    leave_critical_section(CRIT_LEAK);
+    if(alloc_table[i].num>MAX_ALLOCS &&
+            strcmp(alloc_table[i].alloc_file, "lhash.c"))
+        fprintf(stderr, "%d allocations detected at %s:%d\n",
+            alloc_table[i].num,
+            alloc_table[i].alloc_file, alloc_table[i].alloc_line);
+#endif
+}
+
+/**************************************** memcmp() replacement */
+
+/* a version of memcmp() with execution time not dependent on data values */
+/* it does *not* allow to test wheter s1 is greater or lesser than s2  */
+int safe_memcmp(const void *s1, const void *s2, size_t n) {
+    uint8_t *p1=(uint8_t *)s1, *p2=(uint8_t *)s2;
+    int r=0;
+    while(n--)
+        r|=*p1++^*p2++;
+    return r;
+}
+
+/* end of str.c */
diff --git a/src/stunnel.c b/src/stunnel.c
new file mode 100644
index 0000000..17d3fae
--- /dev/null
+++ b/src/stunnel.c
@@ -0,0 +1,859 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+/* http://www.openssl.org/support/faq.html#PROG2 */
+#ifdef USE_WIN32
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-pedantic"
+#endif /* __GNUC__ */
+#ifdef __GNUC__
+#include <../ms/applink.c>
+#else /* __GNUC__ */
+#include <openssl/applink.c>
+#endif /* __GNUC__ */
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+#endif /* USE_WIN32 */
+
+/**************************************** prototypes */
+
+#ifdef __INNOTEK_LIBC__
+struct sockaddr_un {
+    u_char  sun_len;             /* sockaddr len including null */
+    u_char  sun_family;          /* AF_OS2 or AF_UNIX */
+    char    sun_path[108];       /* path name */
+};
+#endif
+
+NOEXPORT int accept_connection(SERVICE_OPTIONS *);
+#ifdef HAVE_CHROOT
+NOEXPORT int change_root(void);
+#endif
+NOEXPORT int signal_pipe_init(void);
+NOEXPORT int signal_pipe_dispatch(void);
+#ifdef USE_FORK
+NOEXPORT void client_status(void); /* dead children detected */
+#endif
+NOEXPORT char *signal_name(int);
+
+/**************************************** global variables */
+
+static SOCKET signal_pipe[2]={INVALID_SOCKET, INVALID_SOCKET};
+
+#ifndef USE_FORK
+long max_clients=0;
+/* -1 before a valid config is loaded, then the current number of clients */
+volatile long num_clients=-1;
+#endif
+s_poll_set *fds; /* file descriptors of listening sockets */
+int systemd_fds; /* number of file descriptors passed by systemd */
+int listen_fds_start; /* base for systemd-provided file descriptors */
+
+/**************************************** startup */
+
+void main_init() { /* one-time initialization */
+#ifdef USE_SYSTEMD
+    int i;
+
+    systemd_fds=sd_listen_fds(1);
+    if(systemd_fds<0)
+        fatal("systemd initialization failed");
+    listen_fds_start=SD_LISTEN_FDS_START;
+    /* set non-blocking mode on systemd file descriptors */
+    for(i=0; i<systemd_fds; ++i)
+        set_nonblock(listen_fds_start+i, 1);
+#else
+    systemd_fds=0; /* no descriptors received */
+    listen_fds_start=3; /* the value is not really important */
+#endif
+    /* basic initialization contains essential functions required for logging
+     * subsystem to function properly, thus all errors here are fatal */
+    if(ssl_init()) /* initialize SSL library */
+        fatal("SSL initialization failed");
+    if(sthreads_init()) /* initialize critical sections & SSL callbacks */
+        fatal("Threads initialization failed");
+    if(cron_init()) /* initialize periodic events */
+        fatal("Cron initialization failed");
+    options_defaults();
+    options_apply();
+#ifndef USE_FORK
+    get_limits(); /* required by setup_fd() */
+#endif
+    fds=s_poll_alloc();
+    if(signal_pipe_init())
+        fatal("Signal pipe initialization failed: "
+            "check your personal firewall");
+    stunnel_info(LOG_NOTICE);
+}
+
+    /* configuration-dependent initialization */
+int main_configure(char *arg1, char *arg2) {
+    if(options_cmdline(arg1, arg2))
+        return 1;
+    options_apply();
+    str_canary_init(); /* needs prng initialization from options_cmdline */
+#if !defined(USE_WIN32) && !defined(__vms)
+    /* syslog_open() must be called before change_root()
+     * to be able to access /dev/log socket */
+    syslog_open();
+#endif /* !defined(USE_WIN32) && !defined(__vms) */
+    if(bind_ports())
+        return 1;
+
+#ifdef HAVE_CHROOT
+    /* change_root() must be called before drop_privileges()
+     * since chroot() needs root privileges */
+    if(change_root())
+        return 1;
+#endif /* HAVE_CHROOT */
+
+    if(drop_privileges(1))
+        return 1;
+
+    /* log_open() must be be called after drop_privileges()
+     * or logfile rotation won't be possible */
+    /* log_open() must be be called before daemonize()
+     * since daemonize() invalidates stderr */
+    if(log_open())
+        return 1;
+#ifndef USE_FORK
+    num_clients=0; /* the first valid config */
+#endif
+    return 0;
+}
+
+int drop_privileges(int critical) {
+#if defined(USE_WIN32) || defined(__vms) || defined(USE_OS2)
+    (void)critical; /* skip warning about unused parameter */
+#else
+#ifdef HAVE_SETGROUPS
+    gid_t gr_list[1];
+#endif
+
+    /* set uid and gid */
+    if(global_options.gid) {
+        if(setgid(global_options.gid) && critical) {
+            sockerror("setgid");
+            return 1;
+        }
+#ifdef HAVE_SETGROUPS
+        gr_list[0]=global_options.gid;
+        if(setgroups(1, gr_list) && critical) {
+            sockerror("setgroups");
+            return 1;
+        }
+#endif
+    }
+    if(global_options.uid) {
+        if(setuid(global_options.uid) && critical) {
+            sockerror("setuid");
+            return 1;
+        }
+    }
+#endif /* standard Unix */
+    return 0;
+}
+
+void main_cleanup() {
+    unbind_ports();
+    s_poll_free(fds);
+    fds=NULL;
+#if 0
+    str_stats(); /* main thread allocation tracking */
+#endif
+    log_flush(LOG_MODE_ERROR);
+}
+
+/**************************************** Unix-specific initialization */
+
+#ifndef USE_WIN32
+
+#ifdef USE_FORK
+NOEXPORT void client_status(void) { /* dead children detected */
+    int pid, status;
+    char *sig_name;
+
+#ifdef HAVE_WAIT_FOR_PID
+    while((pid=wait_for_pid(-1, &status, WNOHANG))>0) {
+#else
+    if((pid=wait(&status))>0) {
+#endif
+#ifdef WIFSIGNALED
+        if(WIFSIGNALED(status)) {
+            sig_name=signal_name(WTERMSIG(status));
+            s_log(LOG_DEBUG, "Process %d terminated on %s",
+                pid, sig_name);
+            str_free(sig_name);
+        } else {
+            s_log(LOG_DEBUG, "Process %d finished with code %d",
+                pid, WEXITSTATUS(status));
+        }
+    }
+#else
+        s_log(LOG_DEBUG, "Process %d finished with code %d",
+            pid, status);
+    }
+#endif
+}
+#endif /* defined USE_FORK */
+
+#ifndef USE_OS2
+
+void child_status(void) { /* dead libwrap or 'exec' process detected */
+    int pid, status;
+    char *sig_name;
+
+#ifdef HAVE_WAIT_FOR_PID
+    while((pid=wait_for_pid(-1, &status, WNOHANG))>0) {
+#else
+    if((pid=wait(&status))>0) {
+#endif
+#ifdef WIFSIGNALED
+        if(WIFSIGNALED(status)) {
+            sig_name=signal_name(WTERMSIG(status));
+            s_log(LOG_INFO, "Child process %d terminated on %s",
+                pid, sig_name);
+            str_free(sig_name);
+        } else {
+            s_log(LOG_INFO, "Child process %d finished with code %d",
+                pid, WEXITSTATUS(status));
+        }
+#else
+        s_log(LOG_INFO, "Child process %d finished with status %d",
+            pid, status);
+#endif
+    }
+}
+
+#endif /* !defined(USE_OS2) */
+
+#endif /* !defined(USE_WIN32) */
+
+/**************************************** main loop accepting connections */
+
+void daemon_loop(void) {
+    while(1) {
+        int temporary_lack_of_resources=0;
+        int num=s_poll_wait(fds, -1, -1);
+        if(num>=0) {
+            SERVICE_OPTIONS *opt;
+            s_log(LOG_DEBUG, "Found %d ready file descriptor(s)", num);
+            if(service_options.log_level>=LOG_DEBUG) /* performance optimization */
+                s_poll_dump(fds, LOG_DEBUG);
+            if(s_poll_canread(fds, signal_pipe[0]))
+                if(signal_pipe_dispatch()) /* SIGNAL_TERMINATE or error */
+                    break; /* terminate daemon_loop */
+            for(opt=service_options.next; opt; opt=opt->next)
+                if(opt->option.accept && s_poll_canread(fds, opt->fd))
+                    if(accept_connection(opt))
+                        temporary_lack_of_resources=1;
+        } else {
+            log_error(LOG_NOTICE, get_last_socket_error(),
+                "daemon_loop: s_poll_wait");
+            temporary_lack_of_resources=1;
+        }
+        if(temporary_lack_of_resources) {
+            s_log(LOG_NOTICE,
+                "Accepting new connections suspended for 1 second");
+            sleep(1); /* to avoid log trashing */
+        }
+    }
+}
+
+    /* return 1 when a short delay is needed before another try */
+NOEXPORT int accept_connection(SERVICE_OPTIONS *opt) {
+    SOCKADDR_UNION addr;
+    char *from_address;
+    SOCKET s;
+    socklen_t addrlen;
+
+    addrlen=sizeof addr;
+    for(;;) {
+        s=s_accept(opt->fd, &addr.sa, &addrlen, 1, "local socket");
+        if(s!=INVALID_SOCKET) /* success! */
+            break;
+        switch(get_last_socket_error()) {
+            case S_EINTR: /* interrupted by a signal */
+                break; /* retry now */
+            case S_EMFILE:
+#ifdef S_ENFILE
+            case S_ENFILE:
+#endif
+#ifdef S_ENOBUFS
+            case S_ENOBUFS:
+#endif
+#ifdef S_ENOMEM
+            case S_ENOMEM:
+#endif
+                return 1; /* temporary lack of resources */
+            default:
+                return 0; /* any other error */
+        }
+    }
+    from_address=s_ntop(&addr, addrlen);
+    s_log(LOG_DEBUG, "Service [%s] accepted (FD=%d) from %s",
+        opt->servname, s, from_address);
+    str_free(from_address);
+#ifdef USE_FORK
+    RAND_add("", 1, 0.0); /* each child needs a unique entropy pool */
+#else
+    if(max_clients && num_clients>=max_clients) {
+        s_log(LOG_WARNING, "Connection rejected: too many clients (>=%ld)",
+            max_clients);
+        closesocket(s);
+        return 0;
+    }
+#endif
+    if(create_client(opt->fd, s,
+            alloc_client_session(opt, s, s), client_thread)) {
+        s_log(LOG_ERR, "Connection rejected: create_client failed");
+        closesocket(s);
+        return 0;
+    }
+    return 0;
+}
+
+/**************************************** initialization helpers */
+
+/* clear fds, close old ports */
+void unbind_ports(void) {
+    SERVICE_OPTIONS *opt;
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+    struct stat sb; /* buffer for stat */
+#endif
+
+    s_poll_init(fds);
+    s_poll_add(fds, signal_pipe[0], 1, 0);
+
+    for(opt=service_options.next; opt; opt=opt->next) {
+        s_log(LOG_DEBUG, "Closing service [%s]", opt->servname);
+        if(opt->option.accept && opt->fd!=INVALID_SOCKET) {
+            if(opt->fd<(SOCKET)listen_fds_start ||
+                    opt->fd>=(SOCKET)(listen_fds_start+systemd_fds))
+                closesocket(opt->fd);
+            s_log(LOG_DEBUG, "Service [%s] closed (FD=%d)",
+                opt->servname, opt->fd);
+            opt->fd=INVALID_SOCKET;
+#ifdef HAVE_STRUCT_SOCKADDR_UN
+            if(opt->local_addr.sa.sa_family==AF_UNIX) {
+                if(lstat(opt->local_addr.un.sun_path, &sb))
+                    sockerror(opt->local_addr.un.sun_path);
+                else if(!S_ISSOCK(sb.st_mode))
+                    s_log(LOG_ERR, "Not a socket: %s",
+                        opt->local_addr.un.sun_path);
+                else if(unlink(opt->local_addr.un.sun_path))
+                    sockerror(opt->local_addr.un.sun_path);
+                else
+                    s_log(LOG_DEBUG, "Socket removed: %s",
+                        opt->local_addr.un.sun_path);
+            }
+#endif
+        } else if(opt->exec_name && opt->connect_addr.names) {
+            /* create exec+connect services             */
+            /* FIXME: this is just a crude workaround   */
+            /*        is it better to kill the service? */
+            opt->option.retry=0;
+        }
+        /* purge session cache of the old SSL_CTX object */
+        /* this workaround won't be needed anymore after */
+        /* delayed deallocation calls SSL_CTX_free()     */
+        if(opt->ctx)
+            SSL_CTX_flush_sessions(opt->ctx,
+                (long)time(NULL)+opt->session_timeout+1);
+        s_log(LOG_DEBUG, "Service [%s] closed", opt->servname);
+    }
+}
+
+/* open new ports, update fds */
+int bind_ports(void) {
+    SERVICE_OPTIONS *opt;
+    char *local_address;
+    int listening_section;
+
+#ifdef USE_LIBWRAP
+    /* execute after options_cmdline() to know service_options.next,
+     * but as early as possible to avoid leaking file descriptors */
+    /* retry on each bind_ports() in case stunnel.conf was reloaded
+       without "libwrap = no" */
+    libwrap_init();
+#endif /* USE_LIBWRAP */
+
+    s_poll_init(fds);
+    s_poll_add(fds, signal_pipe[0], 1, 0);
+
+    /* allow clean unbind_ports() even though
+       bind_ports() was not fully performed */
+    for(opt=service_options.next; opt; opt=opt->next)
+        if(opt->option.accept)
+            opt->fd=INVALID_SOCKET;
+
+    listening_section=0;
+    for(opt=service_options.next; opt; opt=opt->next) {
+        if(opt->option.accept) {
+            if(listening_section<systemd_fds) {
+                opt->fd=(SOCKET)(listen_fds_start+listening_section);
+                s_log(LOG_DEBUG,
+                    "Listening file descriptor received from systemd (FD=%d)",
+                    opt->fd);
+            } else {
+                opt->fd=s_socket(opt->local_addr.sa.sa_family,
+                    SOCK_STREAM, 0, 1, "accept socket");
+                if(opt->fd==INVALID_SOCKET)
+                    return 1;
+                s_log(LOG_DEBUG, "Listening file descriptor created (FD=%d)",
+                    opt->fd);
+            }
+            if(set_socket_options(opt->fd, 0)<0) {
+                closesocket(opt->fd);
+                opt->fd=INVALID_SOCKET;
+                return 1;
+            }
+            /* local socket can't be unnamed */
+            local_address=s_ntop(&opt->local_addr, addr_len(&opt->local_addr));
+            /* we don't bind or listen on a socket inherited from systemd */
+            if(listening_section>=systemd_fds) {
+                if(bind(opt->fd, &opt->local_addr.sa, addr_len(&opt->local_addr))) {
+                    s_log(LOG_ERR, "Error binding service [%s] to %s",
+                        opt->servname, local_address);
+                    sockerror("bind");
+                    closesocket(opt->fd);
+                    opt->fd=INVALID_SOCKET;
+                    str_free(local_address);
+                    return 1;
+                }
+                if(listen(opt->fd, SOMAXCONN)) {
+                    sockerror("listen");
+                    closesocket(opt->fd);
+                    opt->fd=INVALID_SOCKET;
+                    str_free(local_address);
+                    return 1;
+                }
+            }
+            s_poll_add(fds, opt->fd, 1, 0);
+            s_log(LOG_DEBUG, "Service [%s] (FD=%d) bound to %s",
+                opt->servname, opt->fd, local_address);
+            str_free(local_address);
+            ++listening_section;
+        } else if(opt->exec_name && opt->connect_addr.names) {
+            /* create exec+connect services */
+            /* FIXME: needs to be delayed on reload with opt->option.retry set */
+            create_client(INVALID_SOCKET, INVALID_SOCKET,
+                alloc_client_session(opt, INVALID_SOCKET, INVALID_SOCKET),
+                client_thread);
+        }
+    }
+    if(listening_section<systemd_fds) {
+        s_log(LOG_ERR,
+            "Too many listening file descriptors received from systemd, got %d",
+            systemd_fds);
+        return 1;
+    }
+    return 0; /* OK */
+}
+
+#ifdef HAVE_CHROOT
+NOEXPORT int change_root(void) {
+    if(!global_options.chroot_dir)
+        return 0;
+    if(chroot(global_options.chroot_dir)) {
+        sockerror("chroot");
+        return 1;
+    }
+    if(chdir("/")) {
+        sockerror("chdir");
+        return 1;
+    }
+    return 0;
+}
+#endif /* HAVE_CHROOT */
+
+/**************************************** signal pipe handling */
+
+NOEXPORT int signal_pipe_init(void) {
+#ifdef USE_WIN32
+    if(make_sockets(signal_pipe))
+        return 1;
+#elif defined(__INNOTEK_LIBC__)
+    /* Innotek port of GCC can not use select on a pipe:
+     * use local socket instead */
+    struct sockaddr_un un;
+    fd_set set_pipe;
+    int pipe_in;
+
+    FD_ZERO(&set_pipe);
+    signal_pipe[0]=s_socket(PF_OS2, SOCK_STREAM, 0, 0, "socket#1");
+    signal_pipe[1]=s_socket(PF_OS2, SOCK_STREAM, 0, 0, "socket#2");
+
+    /* connect the two endpoints */
+    memset(&un, 0, sizeof un);
+    un.sun_len=sizeof un;
+    un.sun_family=AF_OS2;
+    sprintf(un.sun_path, "\\socket\\stunnel-%u", getpid());
+    /* make the first endpoint listen */
+    bind(signal_pipe[0], (struct sockaddr *)&un, sizeof un);
+    listen(signal_pipe[0], 1);
+    connect(signal_pipe[1], (struct sockaddr *)&un, sizeof un);
+    FD_SET(signal_pipe[0], &set_pipe);
+    if(select(signal_pipe[0]+1, &set_pipe, NULL, NULL, NULL)>0) {
+        pipe_in=signal_pipe[0];
+        signal_pipe[0]=s_accept(signal_pipe[0], NULL, 0, 0, "accept");
+        closesocket(pipe_in);
+    } else {
+        sockerror("select");
+        return 1;
+    }
+#else /* Unix */
+    if(s_pipe(signal_pipe, 1, "signal_pipe"))
+        return 1;
+#endif /* USE_WIN32 */
+    return 0;
+}
+
+#ifdef __GNUC__
+#pragma GCC diagnostic push
+#pragma GCC diagnostic ignored "-Wunused-result"
+#endif /* __GNUC__ */
+void signal_post(int sig) {
+    /* no meaningful way here to handle the result */
+    writesocket(signal_pipe[1], (char *)&sig, sizeof sig);
+}
+#ifdef __GNUC__
+#pragma GCC diagnostic pop
+#endif /* __GNUC__ */
+
+NOEXPORT int signal_pipe_dispatch(void) {
+    static int sig;
+    static size_t ptr=0;
+    ssize_t num;
+    char *sig_name;
+
+    s_log(LOG_DEBUG, "Dispatching signals from the signal pipe");
+    for(;;) {
+        num=readsocket(signal_pipe[0], (char *)&sig+ptr, sizeof sig-ptr);
+        if(num==-1 && get_last_socket_error()==S_EWOULDBLOCK) {
+            s_log(LOG_DEBUG, "Signal pipe is empty");
+            return 0;
+        }
+        if(num==-1 || num==0) {
+            if(num)
+                sockerror("signal pipe read");
+            else
+                s_log(LOG_ERR, "Signal pipe closed");
+            s_poll_remove(fds, signal_pipe[0]);
+            closesocket(signal_pipe[0]);
+            closesocket(signal_pipe[1]);
+            if(signal_pipe_init()) {
+                s_log(LOG_ERR,
+                    "Signal pipe reinitialization failed; terminating");
+                return 1;
+            }
+            s_poll_add(fds, signal_pipe[0], 1, 0);
+            s_log(LOG_ERR, "Signal pipe reinitialized");
+            return 0;
+        }
+        ptr+=(size_t)num;
+        if(ptr<sizeof sig) {
+            s_log(LOG_DEBUG, "Incomplete signal pipe read (ptr=%ld)",
+                (long)ptr);
+            return 0;
+        }
+        ptr=0;
+        switch(sig) {
+#ifndef USE_WIN32
+        case SIGCHLD:
+            s_log(LOG_DEBUG, "Processing SIGCHLD");
+#ifdef USE_FORK
+            client_status(); /* report status of client process */
+#else /* USE_UCONTEXT || USE_PTHREAD */
+            child_status();  /* report status of libwrap or 'exec' process */
+#endif /* defined USE_FORK */
+            break;
+#endif /* !defind USE_WIN32 */
+        case SIGNAL_RELOAD_CONFIG:
+            s_log(LOG_DEBUG, "Processing SIGNAL_RELOAD_CONFIG");
+            if(options_parse(CONF_RELOAD)) {
+                s_log(LOG_ERR, "Failed to reload the configuration file");
+            } else {
+                unbind_ports();
+                log_close();
+                options_apply();
+                log_open();
+                ui_config_reloaded();
+                if(bind_ports()) {
+                    /* FIXME: handle the error */
+                }
+            }
+            break;
+        case SIGNAL_REOPEN_LOG:
+            s_log(LOG_DEBUG, "Processing SIGNAL_REOPEN_LOG");
+            log_close();
+            log_open();
+            s_log(LOG_NOTICE, "Log file reopened");
+            break;
+        case SIGNAL_TERMINATE:
+            s_log(LOG_DEBUG, "Processing SIGNAL_TERMINATE");
+            s_log(LOG_NOTICE, "Terminated");
+            return 1;
+        default:
+            sig_name=signal_name(sig);
+            s_log(LOG_ERR, "Received %s; terminating", sig_name);
+            str_free(sig_name);
+            return 1;
+        }
+    }
+}
+
+/**************************************** signal name decoding */
+
+#define check_signal(s) if(signum==s) return str_dup(#s);
+
+NOEXPORT char *signal_name(int signum) {
+#ifdef SIGHUP
+    check_signal(SIGHUP)
+#endif
+#ifdef SIGINT
+    check_signal(SIGINT)
+#endif
+#ifdef SIGQUIT
+    check_signal(SIGQUIT)
+#endif
+#ifdef SIGILL
+    check_signal(SIGILL)
+#endif
+#ifdef SIGTRAP
+    check_signal(SIGTRAP)
+#endif
+#ifdef SIGABRT
+    check_signal(SIGABRT)
+#endif
+#ifdef SIGIOT
+    check_signal(SIGIOT)
+#endif
+#ifdef SIGBUS
+    check_signal(SIGBUS)
+#endif
+#ifdef SIGFPE
+    check_signal(SIGFPE)
+#endif
+#ifdef SIGKILL
+    check_signal(SIGKILL)
+#endif
+#ifdef SIGUSR1
+    check_signal(SIGUSR1)
+#endif
+#ifdef SIGSEGV
+    check_signal(SIGSEGV)
+#endif
+#ifdef SIGUSR2
+    check_signal(SIGUSR2)
+#endif
+#ifdef SIGPIPE
+    check_signal(SIGPIPE)
+#endif
+#ifdef SIGALRM
+    check_signal(SIGALRM)
+#endif
+#ifdef SIGTERM
+    check_signal(SIGTERM)
+#endif
+#ifdef SIGSTKFLT
+    check_signal(SIGSTKFLT)
+#endif
+#ifdef SIGCHLD
+    check_signal(SIGCHLD)
+#endif
+#ifdef SIGCONT
+    check_signal(SIGCONT)
+#endif
+#ifdef SIGSTOP
+    check_signal(SIGSTOP)
+#endif
+#ifdef SIGTSTP
+    check_signal(SIGTSTP)
+#endif
+#ifdef SIGTTIN
+    check_signal(SIGTTIN)
+#endif
+#ifdef SIGTTOU
+    check_signal(SIGTTOU)
+#endif
+#ifdef SIGURG
+    check_signal(SIGURG)
+#endif
+#ifdef SIGXCPU
+    check_signal(SIGXCPU)
+#endif
+#ifdef SIGXFSZ
+    check_signal(SIGXFSZ)
+#endif
+#ifdef SIGVTALRM
+    check_signal(SIGVTALRM)
+#endif
+#ifdef SIGPROF
+    check_signal(SIGPROF)
+#endif
+#ifdef SIGWINCH
+    check_signal(SIGWINCH)
+#endif
+#ifdef SIGIO
+    check_signal(SIGIO)
+#endif
+#ifdef SIGPOLL
+    check_signal(SIGPOLL)
+#endif
+#ifdef SIGLOST
+    check_signal(SIGLOST)
+#endif
+#ifdef SIGPWR
+    check_signal(SIGPWR)
+#endif
+#ifdef SIGSYS
+    check_signal(SIGSYS)
+#endif
+#ifdef SIGUNUSED
+    check_signal(SIGUNUSED)
+#endif
+    return str_printf("signal %d", signum);
+}
+
+/**************************************** log build details */
+
+void stunnel_info(int level) {
+    s_log(level, "stunnel " STUNNEL_VERSION " on " HOST " platform");
+    if(strcmp(OPENSSL_VERSION_TEXT, SSLeay_version(SSLEAY_VERSION))) {
+        s_log(level, "Compiled with " OPENSSL_VERSION_TEXT);
+        s_log(level, "Running  with %s", SSLeay_version(SSLEAY_VERSION));
+        s_log(level, "Update OpenSSL shared libraries or rebuild stunnel");
+    } else {
+        s_log(level, "Compiled/running with " OPENSSL_VERSION_TEXT);
+    }
+    s_log(level,
+
+        "Threading:"
+#ifdef USE_UCONTEXT
+        "UCONTEXT"
+#endif
+#ifdef USE_PTHREAD
+        "PTHREAD"
+#endif
+#ifdef USE_WIN32
+        "WIN32"
+#endif
+#ifdef USE_FORK
+        "FORK"
+#endif
+
+        " Sockets:"
+#ifdef USE_POLL
+        "POLL"
+#else /* defined(USE_POLL) */
+        "SELECT"
+#endif /* defined(USE_POLL) */
+        ",IPv%c"
+#ifdef USE_SYSTEMD
+        ",SYSTEMD"
+#endif /* defined(USE_SYSTEMD) */
+
+        " TLS:"
+#ifndef OPENSSL_NO_ENGINE
+#define TLS_FEATURE_FOUND
+        "ENGINE"
+#endif /* !defined(OPENSSL_NO_ENGINE) */
+#ifdef USE_FIPS
+#ifdef TLS_FEATURE_FOUND
+        ","
+#else
+#define TLS_FEATURE_FOUND
+#endif
+        "FIPS"
+#endif /* defined(USE_FIPS) */
+#ifndef OPENSSL_NO_OCSP
+#ifdef TLS_FEATURE_FOUND
+        ","
+#else
+#define TLS_FEATURE_FOUND
+#endif
+        "OCSP"
+#endif /* !defined(OPENSSL_NO_OCSP) */
+#ifndef OPENSSL_NO_PSK
+#ifdef TLS_FEATURE_FOUND
+        ","
+#else
+#define TLS_FEATURE_FOUND
+#endif
+        "PSK"
+#endif /* !defined(OPENSSL_NO_PSK) */
+#ifndef OPENSSL_NO_TLSEXT
+#ifdef TLS_FEATURE_FOUND
+        ","
+#else
+#define TLS_FEATURE_FOUND
+#endif
+        "SNI"
+#endif /* !defined(OPENSSL_NO_TLSEXT) */
+#ifndef TLS_FEATURE_FOUND
+        "NONE"
+#endif /* !defined(TLS_FEATURE_FOUND) */
+
+#ifdef USE_LIBWRAP
+        " Auth:LIBWRAP"
+#endif
+
+        , /* supported IP version parameter */
+#if defined(USE_WIN32) && !defined(_WIN32_WCE)
+        s_getaddrinfo ? '6' : '4'
+#else /* defined(USE_WIN32) */
+#if defined(USE_IPv6)
+        '6'
+#else /* defined(USE_IPv6) */
+        '4'
+#endif /* defined(USE_IPv6) */
+#endif /* defined(USE_WIN32) */
+        );
+#ifdef errno
+#define xstr(a) str(a)
+#define str(a) #a
+    s_log(LOG_DEBUG, "errno: " xstr(errno));
+#endif /* errno */
+}
+
+/* end of stunnel.c */
diff --git a/src/stunnel.ico b/src/stunnel.ico
new file mode 100644
index 0000000..ba56e9c
--- /dev/null
+++ b/src/stunnel.ico
Binary files differ
diff --git a/src/stunnel3.in b/src/stunnel3.in
new file mode 100755
index 0000000..eebbdcd
--- /dev/null
+++ b/src/stunnel3.in
@@ -0,0 +1,75 @@
+#!/usr/bin/perl
+#
+# stunnel3      Perl wrapper to use stunnel 3.x syntax in stunnel >=4.05
+# Copyright (C) 2004-2012 Michal Trojnara <Michal.Trojnara@mirt.net>
+# Version:      2.03
+# Date:         2011.10.22
+#
+# This program is free software; you can redistribute it and/or modify it
+# under the terms of the GNU General Public License as published by the
+# Free Software Foundation; either version 2 of the License, or (at your
+# option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+# See the GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License along
+# with this program; if not, see <http://www.gnu.org/licenses>.
+
+use POSIX;
+use Getopt::Std;
+
+# Configuration - path to stunnel (version >=4.05)
+$stunnel_bin='@bindir@/stunnel';
+
+# stunnel3 script body begins here
+($read_fd, $write_fd)=POSIX::pipe();
+$pid=fork;
+die "Can't fork" unless defined $pid;
+if($pid) { # parent
+    POSIX::close($write_fd);
+    exec "$stunnel_bin -fd $read_fd";
+    die "$stunnel_bin exec failed";
+}
+# child
+POSIX::close($read_fd);
+open(STUNNEL, ">&$write_fd");
+# comment out the next line to see the config file
+select(STUNNEL);
+
+getopts('cTWfD:O:o:C:p:v:a:A:t:N:u:n:E:R:B:I:d:s:g:P:r:L:l:');
+
+print("client = yes\n") if defined $opt_c;
+print("transparent = yes\n") if defined $opt_T;
+print("RNDoverwrite = yes\n") if defined $opt_W;
+print("foreground = yes\n") if defined $opt_f;
+print("debug = $opt_D\n") if defined $opt_D;
+print("socket = $opt_O\n") if defined $opt_O;
+print("output = $opt_o\n") if defined $opt_o;
+print("ciphers = $opt_C\n") if defined $opt_C;
+print("cert = $opt_p\n") if defined $opt_p;
+print("verify = $opt_v\n") if defined $opt_v;
+print("CApath = $opt_a\n") if defined $opt_a;
+print("CAfile = $opt_A\n") if defined $opt_A;
+print("session = $opt_t\n") if defined $opt_t;
+print("service = $opt_N\n") if defined $opt_N;
+print("ident = $opt_u\n") if defined $opt_u;
+print("protocol = $opt_n\n") if defined $opt_n;
+print("EGD = $opt_E\n") if defined $opt_E;
+print("RNDfile = $opt_R\n") if defined $opt_R;
+print("RNDbytes = $opt_B\n") if defined $opt_B;
+print("local = $opt_I\n") if defined $opt_I;
+print("accept = $opt_d\n") if defined $opt_d;
+print("setuid = $opt_s\n") if defined $opt_s;
+print("setgid = $opt_g\n") if defined $opt_g;
+print("pid = $opt_P\n") if defined $opt_P;
+print("connect = $opt_r\n") if defined $opt_r;
+print("pty = yes\n"), $opt_l=$opt_L if defined $opt_L;
+print("exec = $opt_l\nexecArgs = " . join(' ', $opt_l, @ARGV) . "\n") if defined $opt_l;
+print("[stunnel3]\n") if defined $opt_d;
+
+close(STUNNEL);
+
+# stunnel3 script body ends here
diff --git a/src/tls.c b/src/tls.c
new file mode 100644
index 0000000..40cc4e8
--- /dev/null
+++ b/src/tls.c
@@ -0,0 +1,186 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+volatile int tls_initialized=0;
+
+NOEXPORT void tls_platform_init();
+NOEXPORT void free_function(void *);
+
+/**************************************** thread local storage */
+
+/* this has to be the first function called from ui_*.c */
+void tls_init() {
+    tls_platform_init();
+    tls_initialized=1;
+    ui_tls=tls_alloc(NULL, NULL, "ui");
+    CRYPTO_set_mem_ex_functions(str_alloc_detached_debug,
+        str_realloc_debug, free_function);
+}
+
+/* this has to be the first function called by a new thread */
+TLS_DATA *tls_alloc(CLI *c, TLS_DATA *inherited, char *txt) {
+    TLS_DATA *tls_data;
+
+    if(inherited) { /* reuse the thread-local storage after fork() */
+        tls_data=inherited;
+        str_free(tls_data->id);
+    } else {
+        tls_data=calloc(1, sizeof(TLS_DATA));
+        if(!tls_data)
+            fatal("Out of memory");
+        if(c)
+            c->tls=tls_data;
+        str_init(tls_data);
+        tls_data->c=c;
+        tls_data->opt=c?c->opt:&service_options;
+    }
+    tls_data->id="unconfigured";
+    tls_set(tls_data);
+
+    /* str.c functions can be used below this point */
+    if(txt) {
+        tls_data->id=str_dup(txt);
+        str_detach(tls_data->id); /* it is deallocated after str_stats() */
+    } else if(c) {
+        tls_data->id=log_id(c);
+        str_detach(tls_data->id); /* it is deallocated after str_stats() */
+    }
+
+    return tls_data;
+}
+
+/* per-thread thread-local storage cleanup */
+void tls_cleanup() {
+    TLS_DATA *tls_data;
+
+    tls_data=tls_get();
+    if(!tls_data)
+        return;
+    str_cleanup(tls_data);
+    str_free(tls_data->id); /* detached allocation */
+    tls_set(NULL);
+    free(tls_data);
+}
+
+#ifdef USE_UCONTEXT
+
+static TLS_DATA *global_tls=NULL;
+
+NOEXPORT void tls_platform_init() {
+}
+
+void tls_set(TLS_DATA *tls_data) {
+    if(ready_head)
+        ready_head->tls=tls_data;
+    else /* ucontext threads not initialized */
+        global_tls=tls_data;
+}
+
+TLS_DATA *tls_get() {
+    if(ready_head)
+        return ready_head->tls;
+    else /* ucontext threads not initialized */
+        return global_tls;
+}
+
+#endif /* USE_UCONTEXT */
+
+#ifdef USE_FORK
+
+static TLS_DATA *global_tls=NULL;
+
+NOEXPORT void tls_platform_init() {
+}
+
+void tls_set(TLS_DATA *tls_data) {
+    global_tls=tls_data;
+}
+
+TLS_DATA *tls_get() {
+    return global_tls;
+}
+
+#endif /* USE_FORK */
+
+#ifdef USE_PTHREAD
+
+static pthread_key_t pthread_key;
+
+NOEXPORT void tls_platform_init() {
+    pthread_key_create(&pthread_key, NULL);
+}
+
+void tls_set(TLS_DATA *tls_data) {
+    pthread_setspecific(pthread_key, tls_data);
+}
+
+TLS_DATA *tls_get() {
+    return pthread_getspecific(pthread_key);
+}
+
+#endif /* USE_PTHREAD */
+
+#ifdef USE_WIN32
+
+static DWORD tls_index;
+
+NOEXPORT void tls_platform_init() {
+    tls_index=TlsAlloc();
+}
+
+void tls_set(TLS_DATA *tls_data) {
+    TlsSetValue(tls_index, tls_data);
+}
+
+TLS_DATA *tls_get() {
+    return TlsGetValue(tls_index);
+}
+
+#endif /* USE_WIN32 */
+
+/**************************************** OpenSSL allocator hook */
+
+NOEXPORT void free_function(void *ptr) {
+    /* CRYPTO_set_mem_ex_functions() needs a function rather than a macro */
+    /* unfortunately, OpenSSL provides no file:line information here */
+    str_free_debug(ptr, "OpenSSL", 0);
+}
+
+/* end of tls.c */
diff --git a/src/ui_unix.c b/src/ui_unix.c
new file mode 100644
index 0000000..9b80be3
--- /dev/null
+++ b/src/ui_unix.c
@@ -0,0 +1,263 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+NOEXPORT int main_unix(int, char*[]);
+#if !defined(__vms) && !defined(USE_OS2)
+NOEXPORT int daemonize(int);
+NOEXPORT int create_pid(void);
+NOEXPORT void delete_pid(void);
+#endif
+#ifndef USE_OS2
+NOEXPORT void signal_handler(int);
+#endif
+
+int main(int argc, char* argv[]) { /* execution begins here 8-) */
+    int retval;
+
+#ifdef M_MMAP_THRESHOLD
+    mallopt(M_MMAP_THRESHOLD, 4096);
+#endif
+    tls_init(); /* initialize thread-local storage */
+    retval=main_unix(argc, argv);
+    main_cleanup();
+    return retval;
+}
+
+NOEXPORT int main_unix(int argc, char* argv[]) {
+#if !defined(__vms) && !defined(USE_OS2)
+    int fd;
+
+    fd=open("/dev/null", O_RDWR); /* open /dev/null before chroot */
+    if(fd==INVALID_SOCKET)
+        fatal("Could not open /dev/null");
+#endif
+    main_init();
+    if(main_configure(argc>1 ? argv[1] : NULL, argc>2 ? argv[2] : NULL)) {
+        close(fd);
+        return 1;
+    }
+    if(service_options.next) { /* there are service sections -> daemon mode */
+#if !defined(__vms) && !defined(USE_OS2)
+        if(daemonize(fd)) {
+            close(fd);
+            return 1;
+        }
+        close(fd);
+        /* create_pid() must be called after drop_privileges()
+         * or it won't be possible to remove the file on exit */
+        /* create_pid() must be called after daemonize()
+         * since the final pid is not known beforehand */
+        if(create_pid())
+            return 1;
+#endif
+#ifndef USE_OS2
+        signal(SIGCHLD, signal_handler); /* handle dead children */
+        signal(SIGHUP, signal_handler); /* configuration reload */
+        signal(SIGUSR1, signal_handler); /* log reopen */
+        signal(SIGPIPE, SIG_IGN); /* ignore broken pipe */
+        if(signal(SIGTERM, SIG_IGN)!=SIG_IGN)
+            signal(SIGTERM, signal_handler); /* fatal */
+        if(signal(SIGQUIT, SIG_IGN)!=SIG_IGN)
+            signal(SIGQUIT, signal_handler); /* fatal */
+        if(signal(SIGINT, SIG_IGN)!=SIG_IGN)
+            signal(SIGINT, signal_handler); /* fatal */
+#endif
+        daemon_loop();
+    } else { /* inetd mode */
+#if !defined(__vms) && !defined(USE_OS2)
+        close(fd);
+#endif /* standard Unix */
+#ifndef USE_OS2
+        signal(SIGCHLD, SIG_IGN); /* ignore dead children */
+        signal(SIGPIPE, SIG_IGN); /* ignore broken pipe */
+#endif
+        set_nonblock(0, 1); /* stdin */
+        set_nonblock(1, 1); /* stdout */
+        client_main(alloc_client_session(&service_options, 0, 1));
+    }
+    return 0;
+}
+
+#ifndef USE_OS2
+NOEXPORT void signal_handler(int sig) {
+    int saved_errno;
+
+    saved_errno=errno;
+    signal_post(sig);
+    signal(sig, signal_handler);
+    errno=saved_errno;
+}
+#endif
+
+#if !defined(__vms) && !defined(USE_OS2)
+
+NOEXPORT int daemonize(int fd) { /* go to background */
+    if(global_options.option.foreground)
+        return 0;
+    dup2(fd, 0);
+    dup2(fd, 1);
+    dup2(fd, 2);
+#if defined(HAVE_DAEMON) && !defined(__BEOS__)
+    /* set noclose option when calling daemon() function,
+     * so it does not require /dev/null device in the chrooted directory */
+    if(daemon(0, 1)==-1) {
+        ioerror("daemon");
+        return 1;
+    }
+#else
+    chdir("/");
+    switch(fork()) {
+    case -1:    /* fork failed */
+        ioerror("fork");
+        return 1;
+    case 0:     /* child */
+        break;
+    default:    /* parent */
+        exit(0);
+    }
+#endif
+    tls_alloc(NULL, ui_tls, "main"); /* reuse thread-local storage */
+#ifdef HAVE_SETSID
+    setsid(); /* ignore the error */
+#endif
+    return 0;
+}
+
+NOEXPORT int create_pid(void) {
+    int pf;
+    char *pid;
+
+    if(!global_options.pidfile) {
+        s_log(LOG_DEBUG, "No pid file being created");
+        return 0;
+    }
+    if(global_options.pidfile[0]!='/') {
+        /* to prevent creating pid file relative to '/' after daemonize() */
+        s_log(LOG_ERR, "Pid file (%s) must be full path name", global_options.pidfile);
+        return 1;
+    }
+    global_options.dpid=(unsigned long)getpid();
+
+    /* silently remove old pid file */
+    unlink(global_options.pidfile);
+    pf=open(global_options.pidfile, O_WRONLY|O_CREAT|O_TRUNC|O_EXCL, 0644);
+    if(pf==-1) {
+        s_log(LOG_ERR, "Cannot create pid file %s", global_options.pidfile);
+        ioerror("create");
+        return 1;
+    }
+    pid=str_printf("%lu\n", global_options.dpid);
+    if(write(pf, pid, strlen(pid))<(int)strlen(pid)) {
+        s_log(LOG_ERR, "Cannot write pid file %s", global_options.pidfile);
+        ioerror("write");
+        return 1;
+    }
+    str_free(pid);
+    close(pf);
+    s_log(LOG_DEBUG, "Created pid file %s", global_options.pidfile);
+    atexit(delete_pid);
+    return 0;
+}
+
+NOEXPORT void delete_pid(void) {
+    if((unsigned long)getpid()!=global_options.dpid)
+        return; /* current process is not main daemon process */
+    s_log(LOG_DEBUG, "removing pid file %s", global_options.pidfile);
+    if(unlink(global_options.pidfile)<0)
+        ioerror(global_options.pidfile); /* not critical */
+}
+
+#endif /* standard Unix */
+
+/**************************************** options callbacks */
+
+void ui_config_reloaded(void) {
+    /* no action */
+}
+
+#ifdef ICON_IMAGE
+
+ICON_IMAGE load_icon_default(ICON_TYPE icon) {
+    (void)icon; /* skip warning about unused parameter */
+    return (ICON_IMAGE)0;
+}
+
+ICON_IMAGE load_icon_file(const char *file) {
+    (void)file; /* skip warning about unused parameter */
+    return (ICON_IMAGE)0;
+}
+
+#endif
+
+/**************************************** client callbacks */
+
+void ui_new_chain(const unsigned section_number) {
+    (void)section_number; /* skip warning about unused parameter */
+}
+
+void ui_clients(const long num) {
+    (void)num; /* skip warning about unused parameter */
+}
+
+/**************************************** s_log callbacks */
+
+void ui_new_log(const char *line) {
+    fprintf(stderr, "%s\n", line);
+}
+
+/**************************************** ctx callbacks */
+
+int passwd_cb(char *buf, int size, int rwflag, void *userdata) {
+    (void)buf; /* skip warning about unused parameter */
+    (void)size; /* skip warning about unused parameter */
+    (void)rwflag; /* skip warning about unused parameter */
+    (void)userdata; /* skip warning about unused parameter */
+    return 0; /* not implemented */
+}
+
+#ifndef OPENSSL_NO_ENGINE
+int pin_cb(UI *ui, UI_STRING *uis) {
+    (void)ui; /* skip warning about unused parameter */
+    (void)uis; /* skip warning about unused parameter */
+    return 0; /* not implemented */
+}
+#endif
+
+/* end of ui_unix.c */
diff --git a/src/ui_win_cli.c b/src/ui_win_cli.c
new file mode 100644
index 0000000..760b319
--- /dev/null
+++ b/src/ui_win_cli.c
@@ -0,0 +1,137 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+int main(int argc, char *argv[]) {
+    static struct WSAData wsa_state;
+    TCHAR *c, stunnel_exe_path[MAX_PATH];
+
+    tls_init(); /* initialize thread-local storage */
+
+    /* set current working directory and engine path */
+    GetModuleFileName(0, stunnel_exe_path, MAX_PATH);
+    c=_tcsrchr(stunnel_exe_path, TEXT('\\')); /* last backslash */
+    if(c) /* found */
+        c[1]=TEXT('\0'); /* truncate program name */
+#ifndef _WIN32_WCE
+    if(!SetCurrentDirectory(stunnel_exe_path)) {
+        /* log to stderr, as s_log() is not initialized */
+        _ftprintf(stderr, TEXT("Cannot set directory to %s"),
+            stunnel_exe_path);
+        return 1;
+    }
+#endif
+    _tputenv(str_tprintf(TEXT("OPENSSL_ENGINES=%s"), stunnel_exe_path));
+
+    if(WSAStartup(MAKEWORD(1, 1), &wsa_state))
+        return 1;
+    resolver_init();
+    main_init();
+    if(!main_configure(argc>1 ? argv[1] : NULL, argc>2 ? argv[2] : NULL))
+        daemon_loop();
+    main_cleanup();
+    return 0;
+}
+
+/**************************************** options callbacks */
+
+void ui_config_reloaded(void) {
+    /* no action */
+}
+
+ICON_IMAGE load_icon_default(ICON_TYPE type) {
+    (void)type; /* skip warning about unused parameter */
+    return NULL;
+}
+
+ICON_IMAGE load_icon_file(const char *name) {
+    (void)name; /* skip warning about unused parameter */
+    return NULL;
+}
+
+/**************************************** client callbacks */
+
+void ui_new_chain(const unsigned section_number) {
+    (void)section_number; /* skip warning about unused parameter */
+}
+
+void ui_clients(const long num) {
+    (void)num; /* skip warning about unused parameter */
+}
+
+/**************************************** s_log callbacks */
+
+void message_box(LPCTSTR text, const UINT type) {
+    MessageBox(NULL, text, TEXT("stunnel"), type);
+}
+
+void ui_new_log(const char *line) {
+    LPTSTR tstr;
+
+    tstr=str2tstr(line);
+#ifdef _WIN32_WCE
+    /* log to Windows CE debug output stream */
+    RETAILMSG(TRUE, (TEXT("%s\r\n"), tstr));
+#else
+    /* use UTF-16 or native codepage rather than UTF-8 */
+    _ftprintf(stderr, TEXT("%s\r\n"), tstr);
+    fflush(stderr);
+#endif
+    str_free(tstr);
+}
+
+/**************************************** ctx callbacks */
+
+int passwd_cb(char *buf, int size, int rwflag, void *userdata) {
+    (void)buf; /* skip warning about unused parameter */
+    (void)size; /* skip warning about unused parameter */
+    (void)rwflag; /* skip warning about unused parameter */
+    (void)userdata; /* skip warning about unused parameter */
+    return 0; /* not implemented */
+}
+
+#ifndef OPENSSL_NO_ENGINE
+int pin_cb(UI *ui, UI_STRING *uis) {
+    (void)ui; /* skip warning about unused parameter */
+    (void)uis; /* skip warning about unused parameter */
+    return 0; /* not implemented */
+}
+#endif
+
+/* end of ui_win_cli.c */
diff --git a/src/ui_win_gui.c b/src/ui_win_gui.c
new file mode 100644
index 0000000..fcda2c8
--- /dev/null
+++ b/src/ui_win_gui.c
@@ -0,0 +1,1537 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+#include <commdlg.h>
+#include <commctrl.h>
+#ifndef _WIN32_WCE
+#include <psapi.h>
+#endif
+#include "resources.h"
+
+#define LOG_LINES 1000
+
+#ifdef _WIN32_WCE
+#define STUNNEL_PLATFORM "WinCE"
+#else
+#ifdef _WIN64
+#define STUNNEL_PLATFORM "Win64"
+#else /* MSDN claims that _WIN32 is always defined */
+#define STUNNEL_PLATFORM "Win32"
+#endif
+#define SERVICE_NAME TEXT("stunnel")
+#define SERVICE_DISPLAY_NAME TEXT("Stunnel SSL wrapper")
+#endif
+
+/* mingw-Patches-1825044 is missing in Debian Squeeze */
+WINBASEAPI BOOL WINAPI CheckTokenMembership(HANDLE, PSID, PBOOL);
+
+/* prototypes */
+NOEXPORT BOOL CALLBACK enum_windows(HWND, LPARAM);
+NOEXPORT void gui_cmdline();
+NOEXPORT int initialize_winsock(void);
+NOEXPORT int gui_loop();
+
+NOEXPORT void CALLBACK timer_proc(HWND, UINT, UINT_PTR, DWORD);
+NOEXPORT LRESULT CALLBACK window_proc(HWND, UINT, WPARAM, LPARAM);
+NOEXPORT LRESULT CALLBACK about_proc(HWND, UINT, WPARAM, LPARAM);
+NOEXPORT LRESULT CALLBACK pass_proc(HWND, UINT, WPARAM, LPARAM);
+
+NOEXPORT void save_log(void);
+NOEXPORT void win_log(LPCTSTR);
+NOEXPORT int save_text_file(LPTSTR, char *);
+NOEXPORT void update_logs(void);
+NOEXPORT LPTSTR log_txt(void);
+
+NOEXPORT void daemon_thread(void *);
+
+NOEXPORT void valid_config(void);
+NOEXPORT void invalid_config(void);
+NOEXPORT void update_peer_menu(void);
+NOEXPORT void tray_update(const int);
+NOEXPORT void tray_delete(void);
+NOEXPORT void error_box(LPCTSTR);
+NOEXPORT void edit_config(HWND);
+NOEXPORT BOOL is_admin(void);
+
+/* NT Service related function */
+#ifndef _WIN32_WCE
+NOEXPORT int service_initialize(void);
+NOEXPORT int service_install(void);
+NOEXPORT int service_uninstall(void);
+NOEXPORT int service_start(void);
+NOEXPORT int service_stop(void);
+NOEXPORT int service_user(DWORD);
+NOEXPORT void WINAPI service_main(DWORD, LPTSTR *);
+NOEXPORT void WINAPI control_handler(DWORD);
+#endif /* !defined(_WIN32_WCE) */
+
+/* other functions */
+NOEXPORT LPTSTR get_params();
+
+/* global variables */
+static struct LIST {
+  struct LIST *next;
+  size_t len;
+  TCHAR txt[1]; /* single character for trailing '\0' */
+} *head=NULL, *tail=NULL;
+
+static unsigned number_of_sections=0;
+
+static HINSTANCE ghInst;
+static HWND edit_handle=NULL;
+static HMENU tray_menu_handle=NULL;
+#ifndef _WIN32_WCE
+static HMENU main_menu_handle=NULL;
+#endif
+static HWND hwnd=NULL; /* main window handle */
+#ifdef _WIN32_WCE
+static HWND command_bar_handle; /* command bar handle */
+#endif
+    /* win32_name is needed for any error_box(), message_box(),
+     * and the initial main window title */
+static TCHAR *win32_name=TEXT("stunnel ") TEXT(STUNNEL_VERSION)
+    TEXT(" on ") TEXT(STUNNEL_PLATFORM) TEXT(" (not configured)");
+
+#ifndef _WIN32_WCE
+static SERVICE_STATUS serviceStatus;
+static SERVICE_STATUS_HANDLE serviceStatusHandle=0;
+#define SERVICE_CONTROL_USER 128
+#endif
+
+static BOOL visible=FALSE;
+static HANDLE main_initialized=NULL; /* global initialization performed */
+static HANDLE config_ready=NULL; /* reload without a valid configuration */
+static LONG new_logs=0;
+
+static UI_DATA *ui_data=NULL;
+
+static struct {
+    char *config_file;
+    unsigned service:1, install:1, uninstall:1, start:1, stop:1,
+        quiet:1, exit:1, reload:1, reopen:1;
+} cmdline;
+
+/**************************************** initialization */
+
+int WINAPI WinMain(HINSTANCE this_instance, HINSTANCE prev_instance,
+#ifdef _WIN32_WCE
+        LPWSTR lpCmdLine,
+#else
+        LPSTR lpCmdLine,
+#endif
+        int nCmdShow) {
+    TCHAR stunnel_exe_path[MAX_PATH];
+    LPTSTR c;
+#ifndef _WIN32_WCE
+    LPTSTR errmsg;
+#endif
+
+    (void)prev_instance; /* skip warning about unused parameter */
+    (void)lpCmdLine; /* skip warning about unused parameter */
+    (void)nCmdShow; /* skip warning about unused parameter */
+
+    tls_init(); /* initialize thread-local storage */
+    ghInst=this_instance;
+    gui_cmdline(); /* setup global cmdline structure */
+    GetModuleFileName(0, stunnel_exe_path, MAX_PATH);
+
+#ifndef _WIN32_WCE
+    /* find previous instances of the same executable */
+    if(!cmdline.service && !cmdline.install && !cmdline.uninstall &&
+            !cmdline.reload && !cmdline.reopen &&
+            !cmdline.start && !cmdline.stop) {
+        EnumWindows(enum_windows, (LPARAM)stunnel_exe_path);
+        if(cmdline.exit)
+            return 0; /* in case EnumWindows didn't find a previous instance */
+    }
+#endif
+
+    /* set current working directory and engine path */
+    c=_tcsrchr(stunnel_exe_path, TEXT('\\')); /* last backslash */
+    if(c) /* found */
+        c[1]=TEXT('\0'); /* truncate program name */
+#ifndef _WIN32_WCE
+    if(!SetCurrentDirectory(stunnel_exe_path)) {
+        errmsg=str_tprintf(TEXT("Cannot set directory to %s"),
+            stunnel_exe_path);
+        message_box(errmsg, MB_ICONERROR);
+        str_free(errmsg);
+        return 1;
+    }
+#endif
+    _tputenv(str_tprintf(TEXT("OPENSSL_ENGINES=%s"), stunnel_exe_path));
+
+    if(initialize_winsock())
+        return 1;
+
+#ifndef _WIN32_WCE
+    if(cmdline.service) /* "-service" must be processed before "-install" */
+        return service_initialize();
+    if(cmdline.install)
+        return service_install();
+    if(cmdline.uninstall)
+        return service_uninstall();
+    if(cmdline.start)
+        return service_start();
+    if(cmdline.stop)
+        return service_stop();
+    if(cmdline.reload)
+        return service_user(SIGNAL_RELOAD_CONFIG);
+    if(cmdline.reopen)
+        return service_user(SIGNAL_REOPEN_LOG);
+#endif
+    return gui_loop();
+}
+
+#ifndef _WIN32_WCE
+
+NOEXPORT BOOL CALLBACK enum_windows(HWND other_window_handle, LPARAM lParam) {
+    DWORD pid;
+    HINSTANCE hInstance;
+    HANDLE process_handle;
+    TCHAR window_exe_path[MAX_PATH];
+    LPTSTR stunnel_exe_path=(LPTSTR)lParam;
+
+    if(!other_window_handle)
+        return TRUE;
+    hInstance=(HINSTANCE)GetWindowLong(other_window_handle, GWL_HINSTANCE);
+    GetWindowThreadProcessId(other_window_handle, &pid);
+    process_handle=OpenProcess(SYNCHRONIZE|         /* WaitForSingleObject() */
+        PROCESS_TERMINATE|                          /* TerminateProcess()    */
+        PROCESS_QUERY_INFORMATION|PROCESS_VM_READ,  /* GetModuleFileNameEx() */
+        FALSE, pid);
+    if(!process_handle)
+        return TRUE;
+    if(!GetModuleFileNameEx(process_handle,
+            hInstance, window_exe_path, MAX_PATH)) {
+        CloseHandle(process_handle);
+        return TRUE;
+    }
+    if(_tcscmp(stunnel_exe_path, window_exe_path)) {
+        CloseHandle(process_handle);
+        return TRUE;
+    }
+    if(cmdline.exit) {
+        PostMessage(other_window_handle, WM_COMMAND, IDM_EXIT, 0);
+        if(WaitForSingleObject(process_handle, 3000)==WAIT_TIMEOUT) {
+            TerminateProcess(process_handle, 0);
+            WaitForSingleObject(process_handle, 3000);
+        }
+    } else {
+        ShowWindow(other_window_handle, SW_SHOWNORMAL); /* show window */
+        SetForegroundWindow(other_window_handle); /* bring on top */
+    }
+    CloseHandle(process_handle);
+    exit(0);
+    return FALSE; /* should never be executed */
+}
+
+#endif
+
+NOEXPORT void gui_cmdline() {
+    char *line, *c, *opt;
+
+    line=tstr2str(get_params());
+    memset(&cmdline, 0, sizeof cmdline);
+    c=line;
+    while(*c && (*c=='/' || *c=='-')) {
+        opt=c;
+        while(*c && !isspace(*c)) /* skip non-whitespaces */
+            c++;
+        while(*c && isspace(*c)) /* replace whitespaces with '\0' */
+            *c++='\0';
+        if(!strcasecmp(opt+1, "install"))
+            cmdline.install=1;
+        else if(!strcasecmp(opt+1, "uninstall"))
+            cmdline.uninstall=1;
+        else if(!strcasecmp(opt+1, "reload"))
+            cmdline.reload=1;
+        else if(!strcasecmp(opt+1, "reopen"))
+            cmdline.reopen=1;
+        else if(!strcasecmp(opt+1, "start"))
+            cmdline.start=1;
+        else if(!strcasecmp(opt+1, "stop"))
+            cmdline.stop=1;
+        else if(!strcasecmp(opt+1, "service"))
+            cmdline.service=1;
+        else if(!strcasecmp(opt+1, "quiet"))
+            cmdline.quiet=1;
+        else if(!strcasecmp(opt+1, "exit"))
+            cmdline.exit=1;
+        else { /* an option to be processed in options.c */
+            c=opt;
+            break;
+        }
+    }
+    if(*c=='\"') { /* the option is within double quotes */
+        c++;
+        opt=c;
+        while(*c && *c!='\"') /* find the closing double quote */
+            c++;
+        *c='\0';
+    } else /* the option is simply the rest of the line */
+        opt=c;
+    cmdline.config_file=*opt ? str_dup(opt) : NULL;
+    str_free(line);
+}
+
+/* try to load winsock2 resolver functions from a specified dll name */
+NOEXPORT int initialize_winsock() {
+    static struct WSAData wsa_state;
+
+    if(WSAStartup(MAKEWORD( 2, 2 ), &wsa_state)) {
+        message_box(TEXT("Failed to initialize winsock"), MB_ICONERROR);
+        return 1; /* error */
+    }
+    resolver_init();
+    return 0; /* IPv4 detected -> OK */
+}
+
+/**************************************** GUI thread */
+
+NOEXPORT int gui_loop() {
+#ifdef _WIN32_WCE
+    WNDCLASS wc;
+#else
+    WNDCLASSEX wc;
+#endif
+    MSG msg;
+    LPTSTR classname=TEXT("stunnel_main_window_class");
+
+    /* register the class */
+#ifndef _WIN32_WCE
+    wc.cbSize=sizeof wc;
+#endif
+    wc.style=CS_VREDRAW|CS_HREDRAW;
+    wc.lpfnWndProc=window_proc;
+    wc.cbClsExtra=wc.cbWndExtra=0;
+    wc.hInstance=ghInst;
+    wc.hIcon=LoadIcon(ghInst, MAKEINTRESOURCE(IDI_STUNNEL_MAIN));
+    wc.hCursor=LoadCursor(NULL, IDC_ARROW);
+    wc.hbrBackground=(HBRUSH)(COLOR_WINDOW+1);
+    wc.lpszMenuName=NULL;
+    wc.lpszClassName=classname;
+#ifdef _WIN32_WCE
+    RegisterClass(&wc);
+#else
+    /* load 16x16 icon */
+    wc.hIconSm=LoadImage(ghInst, MAKEINTRESOURCE(IDI_STUNNEL_MAIN), IMAGE_ICON,
+        GetSystemMetrics(SM_CXSMICON), GetSystemMetrics(SM_CYSMICON), 0);
+    RegisterClassEx(&wc);
+#endif
+
+    /* create main window */
+#ifdef _WIN32_WCE
+    hwnd=CreateWindow(classname, win32_name, 0,
+        CW_USEDEFAULT, CW_USEDEFAULT, CW_USEDEFAULT, CW_USEDEFAULT,
+        NULL, NULL, ghInst, NULL);
+#else
+    main_menu_handle=LoadMenu(ghInst, MAKEINTRESOURCE(IDM_MAINMENU));
+    if(main_menu_handle && cmdline.service) {
+        /* block unsafe operations in the service mode */
+        EnableMenuItem(main_menu_handle, IDM_EDIT_CONFIG, MF_GRAYED);
+        EnableMenuItem(main_menu_handle, IDM_SAVE_LOG, MF_GRAYED);
+    }
+    hwnd=CreateWindow(classname, win32_name, WS_TILEDWINDOW,
+        CW_USEDEFAULT, CW_USEDEFAULT, CW_USEDEFAULT, CW_USEDEFAULT,
+        NULL, main_menu_handle, ghInst, NULL);
+#endif
+
+    /* auto-reset, non-signaled events */
+    main_initialized=CreateEvent(NULL, FALSE, FALSE, NULL);
+    config_ready=CreateEvent(NULL, FALSE, FALSE, NULL);
+    /* hwnd needs to be initialized before _beginthread() */
+    _beginthread(daemon_thread, DEFAULT_STACK_SIZE, NULL);
+    WaitForSingleObject(main_initialized, INFINITE);
+    /* logging subsystem is now available */
+
+    /* setup periodic event to trigger update_logs() */
+    SetTimer(NULL, 0, 1000, timer_proc); /* run callback once per second */
+
+    s_log(LOG_DEBUG, "GUI message loop initialized");
+    for(;;)
+        switch(GetMessage(&msg, NULL, 0, 0)) {
+        case -1:
+            ioerror("GetMessage");
+            return 0;
+        case 0:
+            s_log(LOG_DEBUG, "GUI message loop terminated");
+            return (int)msg.wParam;
+        default:
+            TranslateMessage(&msg);
+            DispatchMessage(&msg);
+        }
+}
+
+NOEXPORT void CALLBACK timer_proc(HWND hwnd, UINT msg, UINT_PTR id, DWORD t) {
+    (void)hwnd; /* skip warning about unused parameter */
+    (void)msg; /* skip warning about unused parameter */
+    (void)id; /* skip warning about unused parameter */
+    (void)t; /* skip warning about unused parameter */
+    if(visible)
+        update_logs();
+    tray_update(num_clients); /* needed when explorer.exe (re)starts */
+}
+
+NOEXPORT LRESULT CALLBACK window_proc(HWND main_window_handle,
+        UINT message, WPARAM wParam, LPARAM lParam) {
+    POINT pt;
+    RECT rect;
+    PAINTSTRUCT ps;
+    SERVICE_OPTIONS *section;
+    unsigned section_number;
+    LPTSTR txt;
+
+#if 0
+    switch(message) {
+    case WM_CTLCOLORSTATIC:
+    case WM_TIMER:
+    case WM_LOG:
+        break;
+    default:
+        s_log(LOG_DEBUG, "Window message: 0x%x(0x%hx,0x%lx)",
+            message, wParam, lParam);
+    }
+#endif
+    switch(message) {
+    case WM_CREATE:
+#ifdef _WIN32_WCE
+        /* create command bar */
+        command_bar_handle=CommandBar_Create(ghInst, main_window_handle, 1);
+        if(!command_bar_handle)
+            error_box(TEXT("CommandBar_Create"));
+        if(!CommandBar_InsertMenubar(command_bar_handle, ghInst, IDM_MAINMENU, 0))
+            error_box(TEXT("CommandBar_InsertMenubar"));
+        if(!CommandBar_AddAdornments(command_bar_handle, 0, 0))
+            error_box(TEXT("CommandBar_AddAdornments"));
+#endif
+
+        /* create child edit window */
+        edit_handle=CreateWindowEx(WS_EX_STATICEDGE, TEXT("EDIT"), NULL,
+            WS_CHILD|WS_VISIBLE|WS_HSCROLL|WS_VSCROLL|ES_MULTILINE|ES_READONLY,
+            0, 0, 0, 0, main_window_handle, (HMENU)IDE_EDIT, ghInst, NULL);
+#ifndef _WIN32_WCE
+        SendMessage(edit_handle, WM_SETFONT,
+            (WPARAM)CreateFont(-12, 0, 0, 0, FW_DONTCARE, FALSE, FALSE, FALSE,
+                DEFAULT_CHARSET, OUT_RASTER_PRECIS, CLIP_DEFAULT_PRECIS,
+                PROOF_QUALITY, DEFAULT_PITCH, TEXT("Courier")),
+            MAKELPARAM(FALSE, 0)); /* no need to redraw right now */
+#endif
+        /* NOTE: there's no return statement here -> proceeding with resize */
+
+    case WM_SIZE:
+        GetClientRect(main_window_handle, &rect);
+#ifdef _WIN32_WCE
+        MoveWindow(edit_handle, 0, CommandBar_Height(command_bar_handle),
+            rect.right, rect.bottom-CommandBar_Height(command_bar_handle),
+            TRUE);
+        SendMessage(command_bar_handle, TB_AUTOSIZE, 0L, 0L);
+        CommandBar_AlignAdornments(command_bar_handle);
+#else
+        MoveWindow(edit_handle, 0, 0, rect.right, rect.bottom, TRUE);
+#endif
+        UpdateWindow(edit_handle);
+        /* CommandBar_Show(command_bar_handle, TRUE); */
+        return 0;
+
+    case WM_SETFOCUS:
+        SetFocus(edit_handle);
+        return 0;
+
+    case WM_PAINT:
+        BeginPaint(hwnd, &ps);
+        EndPaint(hwnd, &ps);
+        break;
+
+    case WM_CLOSE:
+        ShowWindow(main_window_handle, SW_HIDE);
+        return 0;
+
+#ifdef WM_SHOWWINDOW
+    case WM_SHOWWINDOW:
+        visible=(BOOL)wParam;
+#else /* this works for Pierre Delaage, but not for me... */
+    case WM_WINDOWPOSCHANGED:
+        visible=IsWindowVisible(main_window_handle);
+#endif
+        if(tray_menu_handle)
+            CheckMenuItem(tray_menu_handle, IDM_SHOW_LOG,
+                visible ? MF_CHECKED : MF_UNCHECKED);
+        if(visible)
+            update_logs();
+#ifdef WM_SHOWWINDOW
+        return 0;
+#else
+        break; /* proceed to DefWindowProc() */
+#endif
+
+    case WM_DESTROY:
+#ifdef _WIN32_WCE
+        CommandBar_Destroy(command_bar_handle);
+#else
+        if(main_menu_handle) {
+            if(!DestroyMenu(main_menu_handle))
+                ioerror("DestroyMenu");
+            main_menu_handle=NULL;
+        }
+#endif
+        tray_delete(); /* remove the taskbark icon if exists */
+        PostQuitMessage(0);
+        return 0;
+
+    case WM_COMMAND:
+        if(wParam>=IDM_PEER_MENU && wParam<IDM_PEER_MENU+number_of_sections) {
+            for(section=service_options.next, section_number=0;
+                    section && wParam!=IDM_PEER_MENU+section_number;
+                    section=section->next, ++section_number)
+                ;
+            if(!section)
+                return 0;
+            if(save_text_file(section->file, section->chain))
+                return 0;
+#ifndef _WIN32_WCE
+            if(main_menu_handle)
+                CheckMenuItem(main_menu_handle, wParam, MF_CHECKED);
+#endif
+            if(tray_menu_handle)
+                CheckMenuItem(tray_menu_handle, wParam, MF_CHECKED);
+            message_box(section->help, MB_ICONINFORMATION);
+            return 0;
+        }
+        switch(wParam) {
+        case IDM_ABOUT:
+            DialogBox(ghInst, TEXT("AboutBox"), main_window_handle,
+                (DLGPROC)about_proc);
+            break;
+        case IDM_SHOW_LOG:
+            if(visible) {
+                ShowWindow(main_window_handle, SW_HIDE); /* hide window */
+            } else {
+                ShowWindow(main_window_handle, SW_SHOWNORMAL); /* show window */
+                SetForegroundWindow(main_window_handle); /* bring on top */
+            }
+            break;
+        case IDM_CLOSE:
+            ShowWindow(main_window_handle, SW_HIDE); /* hide window */
+            break;
+        case IDM_EXIT:
+            if(num_clients>=0) /* signal_pipe is active */
+                signal_post(SIGNAL_TERMINATE);
+            DestroyWindow(main_window_handle);
+            break;
+        case IDM_SAVE_LOG:
+            if(!cmdline.service) /* security */
+                save_log();
+            break;
+        case IDM_EDIT_CONFIG:
+#ifndef _WIN32_WCE
+            if(!cmdline.service) /* security */
+                edit_config(main_window_handle);
+#endif
+            break;
+        case IDM_RELOAD_CONFIG:
+            if(num_clients>=0) /* signal_pipe is active */
+                signal_post(SIGNAL_RELOAD_CONFIG);
+            else
+                SetEvent(config_ready); /* unlock daemon_thread() */
+            break;
+        case IDM_REOPEN_LOG:
+            signal_post(SIGNAL_REOPEN_LOG);
+            break;
+        case IDM_MANPAGE:
+#ifndef _WIN32_WCE
+            if(!cmdline.service) /* security */
+                ShellExecute(main_window_handle, TEXT("open"),
+                    TEXT("stunnel.html"), NULL, NULL, SW_SHOWNORMAL);
+#endif
+            break;
+        case IDM_HOMEPAGE:
+#ifndef _WIN32_WCE
+            if(!cmdline.service) /* security */
+                ShellExecute(main_window_handle, TEXT("open"),
+                    TEXT("http://www.stunnel.org/"), NULL, NULL, SW_SHOWNORMAL);
+#endif
+            break;
+        }
+        return 0;
+
+    case WM_SYSTRAY: /* a taskbar event */
+        switch(lParam) {
+#ifdef _WIN32_WCE
+        case WM_LBUTTONDOWN: /* no right mouse button on Windows CE */
+            GetWindowRect(GetDesktopWindow(), &rect); /* no cursor position */
+            pt.x=rect.right;
+            pt.y=rect.bottom-25;
+#else
+        case WM_RBUTTONDOWN:
+            GetCursorPos(&pt);
+#endif
+            SetForegroundWindow(main_window_handle);
+            if(tray_menu_handle)
+                TrackPopupMenuEx(GetSubMenu(tray_menu_handle, 0),
+                    TPM_BOTTOMALIGN, pt.x, pt.y, main_window_handle, NULL);
+            PostMessage(main_window_handle, WM_NULL, 0, 0);
+            break;
+#ifndef _WIN32_WCE
+        case WM_LBUTTONDBLCLK: /* switch log window visibility */
+            if(visible) {
+                ShowWindow(main_window_handle, SW_HIDE); /* hide window */
+            } else {
+                ShowWindow(main_window_handle, SW_SHOWNORMAL); /* show window */
+                SetForegroundWindow(main_window_handle); /* bring on top */
+            }
+            break;
+#endif
+        }
+        return 0;
+
+    case WM_VALID_CONFIG:
+        valid_config();
+        return 0;
+
+    case WM_INVALID_CONFIG:
+        invalid_config();
+        return 0;
+
+    case WM_LOG:
+        txt=(LPTSTR)wParam;
+        win_log(txt);
+        str_free(txt);
+        return 0;
+
+    case WM_NEW_CHAIN:
+#ifndef _WIN32_WCE
+        if(main_menu_handle)
+            EnableMenuItem(main_menu_handle, IDM_PEER_MENU+wParam, MF_ENABLED);
+#endif
+        if(tray_menu_handle)
+            EnableMenuItem(tray_menu_handle, IDM_PEER_MENU+wParam, MF_ENABLED);
+        return 0;
+
+    case WM_CLIENTS:
+        tray_update((int)wParam);
+        return 0;
+    }
+
+    return DefWindowProc(main_window_handle, message, wParam, lParam);
+}
+
+NOEXPORT LRESULT CALLBACK about_proc(HWND dialog_handle, UINT message,
+        WPARAM wParam, LPARAM lParam) {
+    (void)lParam; /* skip warning about unused parameter */
+
+    switch(message) {
+        case WM_INITDIALOG:
+            return TRUE;
+        case WM_COMMAND:
+            switch(wParam) {
+                case IDOK:
+                case IDCANCEL:
+                    EndDialog(dialog_handle, TRUE);
+                    return TRUE;
+            }
+    }
+    return FALSE;
+}
+
+NOEXPORT LRESULT CALLBACK pass_proc(HWND dialog_handle, UINT message,
+        WPARAM wParam, LPARAM lParam) {
+    LPTSTR titlebar;
+    union {
+        TCHAR txt[PEM_BUFSIZE];
+        WORD len;
+    } pass_dialog;
+    WORD pass_len;
+    char* pass_txt;
+    LPTSTR key_file_name;
+
+    switch(message) {
+    case WM_INITDIALOG:
+        /* set the default push button to "Cancel" */
+        SendMessage(dialog_handle, DM_SETDEFID, (WPARAM)IDCANCEL, (LPARAM)0);
+
+        key_file_name=str2tstr(ui_data->section->key);
+        titlebar=str_tprintf(TEXT("Private key: %s"), key_file_name);
+        str_free(key_file_name);
+        SetWindowText(dialog_handle, titlebar);
+        str_free(titlebar);
+        return TRUE;
+
+    case WM_COMMAND:
+        /* set the default push button to "OK" when the user enters text */
+        if(HIWORD(wParam)==EN_CHANGE && LOWORD(wParam)==IDE_PASSEDIT)
+            SendMessage(dialog_handle, DM_SETDEFID, (WPARAM)IDOK, (LPARAM)0);
+        switch(wParam) {
+        case IDOK:
+            /* get number of characters */
+            pass_len=(WORD)SendDlgItemMessage(dialog_handle,
+                IDE_PASSEDIT, EM_LINELENGTH, (WPARAM)0, (LPARAM)0);
+            if(!pass_len || pass_len>=PEM_BUFSIZE) {
+                EndDialog(dialog_handle, FALSE);
+                return FALSE;
+            }
+
+            /* put the number of characters into first word of buffer */
+            pass_dialog.len=pass_len;
+
+            /* get the characters */
+            SendDlgItemMessage(dialog_handle, IDE_PASSEDIT, EM_GETLINE,
+                (WPARAM)0 /* line 0 */, (LPARAM)pass_dialog.txt);
+            pass_dialog.txt[pass_len]='\0'; /* null-terminate the string */
+
+            /* convert input password to UTF-8 string (as ui_data->pass) */
+            pass_txt=tstr2str(pass_dialog.txt);
+            strcpy(ui_data->pass, pass_txt);
+            str_free(pass_txt);
+
+            EndDialog(dialog_handle, TRUE);
+            return TRUE;
+
+        case IDCANCEL:
+            EndDialog(dialog_handle, FALSE);
+            return TRUE;
+        }
+        return 0;
+    }
+    return FALSE;
+
+    UNREFERENCED_PARAMETER(lParam);
+}
+
+int passwd_cb(char *buf, int size, int rwflag, void *userdata) {
+    (void)rwflag; /* skip warning about unused parameter */
+
+    ui_data=userdata;
+    if(size<0) /* just in case */
+        return 0;
+    if(!DialogBox(ghInst, TEXT("PassBox"), hwnd, (DLGPROC)pass_proc))
+        return 0; /* error */
+    strncpy(buf, ui_data->pass, (size_t)size);
+    buf[size-1]='\0';
+    return (int)strlen(buf);
+}
+
+#ifndef OPENSSL_NO_ENGINE
+int pin_cb(UI *ui, UI_STRING *uis) {
+    ui_data=UI_get0_user_data(ui); /* was: ui_data=UI_get_app_data(ui); */
+    if(!ui_data) {
+        s_log(LOG_ERR, "INTERNAL ERROR: user data data pointer");
+        return 0;
+    }
+    if(!DialogBox(ghInst, TEXT("PassBox"), hwnd, (DLGPROC)pass_proc))
+        return 0; /* error */
+    UI_set_result(ui, uis, ui_data->pass);
+    return 1;
+}
+#endif
+
+/**************************************** log handling */
+
+NOEXPORT void save_log() {
+    TCHAR file_name[MAX_PATH];
+    OPENFILENAME ofn;
+    LPTSTR txt;
+    LPSTR str;
+
+    ZeroMemory(&ofn, sizeof ofn);
+    file_name[0]='\0';
+
+    ofn.lStructSize=sizeof ofn;
+    ofn.hwndOwner=hwnd;
+    ofn.lpstrFilter=TEXT("Log Files (*.log)\0*.log\0All Files (*.*)\0*.*\0\0");
+    ofn.lpstrFile=file_name;
+    ofn.nMaxFile=MAX_PATH;
+    ofn.lpstrDefExt=TEXT("LOG");
+    ofn.lpstrInitialDir=TEXT(".");
+
+    ofn.lpstrTitle=TEXT("Save Log");
+    ofn.Flags=OFN_EXPLORER|OFN_PATHMUSTEXIST|OFN_HIDEREADONLY|
+        OFN_OVERWRITEPROMPT;
+    if(!GetSaveFileName(&ofn))
+        return;
+
+    txt=log_txt(); /* need to convert the result to UTF-8 */
+    str=tstr2str(txt);
+    str_free(txt);
+    save_text_file(file_name, str);
+    str_free(str);
+}
+
+NOEXPORT int save_text_file(LPTSTR file_name, char *str) {
+    HANDLE file_handle;
+    DWORD ignore;
+
+    file_handle=CreateFile(file_name, GENERIC_WRITE, 0, NULL,
+        CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
+    if(file_handle==INVALID_HANDLE_VALUE) {
+        error_box(TEXT("CreateFile"));
+        return 1;
+    }
+    if(!WriteFile(file_handle, str, strlen(str), &ignore, NULL)) {
+        CloseHandle(file_handle);
+        error_box(TEXT("WriteFile"));
+        return 1;
+    }
+    CloseHandle(file_handle);
+    return 0;
+}
+
+NOEXPORT void win_log(LPCTSTR txt) {
+    struct LIST *curr;
+    size_t txt_len;
+    static size_t log_len=0;
+
+    txt_len=_tcslen(txt);
+    curr=str_alloc(sizeof(struct LIST)+txt_len*sizeof(TCHAR));
+    curr->len=txt_len;
+    _tcscpy(curr->txt, txt);
+    curr->next=NULL;
+    if(tail)
+        tail->next=curr;
+    tail=curr;
+    if(!head)
+        head=tail;
+    log_len++;
+    while(log_len>LOG_LINES) {
+        curr=head;
+        head=head->next;
+        str_free(curr);
+        log_len--;
+    }
+    new_logs=1;
+}
+
+NOEXPORT void update_logs(void) {
+    LPTSTR txt;
+
+    if(!InterlockedExchange(&new_logs, 0))
+        return;
+    txt=log_txt();
+    SetWindowText(edit_handle, txt);
+    str_free(txt);
+    SendMessage(edit_handle, WM_VSCROLL, (WPARAM)SB_BOTTOM, (LPARAM)0);
+}
+
+NOEXPORT LPTSTR log_txt(void) {
+    LPTSTR buff;
+    unsigned ptr=0, len=0;
+    struct LIST *curr;
+
+    for(curr=head; curr; curr=curr->next)
+        len+=curr->len+2; /* +2 for trailing '\r\n' */
+    buff=str_alloc((len+1)*sizeof(TCHAR)); /* +1 for trailing '\0' */
+    for(curr=head; curr; curr=curr->next) {
+        memcpy(buff+ptr, curr->txt, curr->len*sizeof(TCHAR));
+        ptr+=curr->len;
+        if(curr->next) {
+            buff[ptr++]=TEXT('\r');
+            buff[ptr++]=TEXT('\n');
+        }
+    }
+    buff[ptr]=TEXT('\0');
+    return buff;
+}
+
+/**************************************** worker thread */
+
+NOEXPORT void daemon_thread(void *arg) {
+    (void)arg; /* skip warning about unused parameter */
+
+    tls_alloc(NULL, NULL, "main"); /* new thread-local storage */
+    main_init();
+    SetEvent(main_initialized); /* unlock the GUI thread */
+    /* get a valid configuration */
+    while(main_configure(cmdline.config_file, NULL)) {
+        cmdline.config_file=NULL; /* don't retry commandline switches */
+        unbind_ports(); /* in case initialization failed after bind_ports() */
+        log_flush(LOG_MODE_ERROR); /* otherwise logs are buffered */
+        PostMessage(hwnd, WM_INVALID_CONFIG, 0, 0); /* display error */
+        WaitForSingleObject(config_ready, INFINITE);
+        log_close(); /* prevent main_configure() from logging in error mode */
+    }
+    PostMessage(hwnd, WM_VALID_CONFIG, 0, 0);
+
+    /* start the main loop */
+    daemon_loop();
+    main_cleanup();
+    _endthread(); /* SIGNAL_TERMINATE received */
+}
+
+/**************************************** helper functions */
+
+NOEXPORT void invalid_config() {
+    /* update the main window title */
+    win32_name=TEXT("stunnel ") TEXT(STUNNEL_VERSION) TEXT(" on ")
+        TEXT(STUNNEL_PLATFORM) TEXT(" (invalid configuration file)");
+    SetWindowText(hwnd, win32_name);
+
+    /* log window is hidden by default */
+    ShowWindow(hwnd, SW_SHOWNORMAL); /* show window */
+    SetForegroundWindow(hwnd); /* bring on top */
+
+    tray_update(-1); /* error icon */
+    update_peer_menu(); /* purge the list of sections */
+
+    win_log(TEXT(""));
+    s_log(LOG_ERR, "Server is down");
+    message_box(TEXT("Stunnel server is down due to an error.\n")
+        TEXT("You need to exit and correct the problem.\n")
+        TEXT("Click OK to see the error log window."),
+        MB_ICONERROR);
+}
+
+NOEXPORT void valid_config() {
+    /* update the main window title */
+    win32_name=TEXT("stunnel ") TEXT(STUNNEL_VERSION) TEXT(" on ")
+        TEXT(STUNNEL_PLATFORM);
+    SetWindowText(hwnd, win32_name);
+
+    tray_update(num_clients); /* idle or busy icon (on reload) */
+    update_peer_menu(); /* one menu item per section */
+
+    /* enable IDM_REOPEN_LOG menu if a log file is used, disable otherwise */
+#ifndef _WIN32_WCE
+    EnableMenuItem(main_menu_handle, IDM_REOPEN_LOG,
+        (UINT)(global_options.output_file ? MF_ENABLED : MF_GRAYED));
+#endif
+    if(tray_menu_handle)
+        EnableMenuItem(tray_menu_handle, IDM_REOPEN_LOG,
+            (UINT)(global_options.output_file ? MF_ENABLED : MF_GRAYED));
+}
+
+NOEXPORT void update_peer_menu(void) {
+    SERVICE_OPTIONS *section;
+#ifndef _WIN32_WCE
+    HMENU main_peer_list=NULL;
+#endif
+    HMENU tray_peer_list=NULL;
+    unsigned section_number;
+    LPTSTR servname;
+
+    /* purge menu peer lists */
+#ifndef _WIN32_WCE
+    if(main_menu_handle)
+        main_peer_list=GetSubMenu(main_menu_handle, 2); /* 3rd submenu */
+    if(main_peer_list)
+        while(GetMenuItemCount(main_peer_list)) /* purge old menu */
+            DeleteMenu(main_peer_list, 0, MF_BYPOSITION);
+#endif
+    if(tray_menu_handle)
+        tray_peer_list=GetSubMenu(GetSubMenu(tray_menu_handle, 0), 2);
+    if(tray_peer_list)
+        while(GetMenuItemCount(tray_peer_list)) /* purge old menu */
+            DeleteMenu(tray_peer_list, 0, MF_BYPOSITION);
+
+    /* initialize data structures */
+    number_of_sections=0;
+    for(section=service_options.next; section; section=section->next)
+        section->section_number=number_of_sections++;
+
+    section_number=0;
+    for(section=service_options.next; section; section=section->next) {
+        servname=str2tstr(section->servname);
+
+        /* setup LPTSTR section->file */
+        section->file=str_tprintf(TEXT("peer-%s.pem"), servname);
+
+        /* setup section->help */
+        section->help=str_tprintf(
+            TEXT("Peer certificate chain has been saved.\n")
+            TEXT("Add the following lines to section [%s]:\n")
+            TEXT("\tCAfile = peer-%s.pem\n")
+            TEXT("\tverify = 3\n")
+            TEXT("to enable cryptographic authentication.\n")
+            TEXT("Then reload stunnel configuration file."),
+            servname, servname);
+
+        str_free(servname);
+
+        /* setup section->chain */
+        section->chain=NULL;
+
+        /* insert new menu item */
+#ifndef _WIN32_WCE
+        if(main_peer_list)
+            if(!InsertMenu(main_peer_list, section_number,
+                    MF_BYPOSITION|MF_STRING|MF_GRAYED,
+                    IDM_PEER_MENU+section_number, section->file))
+                ioerror("InsertMenu");
+#endif
+        if(tray_peer_list)
+            if(!InsertMenu(tray_peer_list, section_number,
+                    MF_BYPOSITION|MF_STRING|MF_GRAYED,
+                    IDM_PEER_MENU+section_number, section->file))
+                ioerror("InsertMenu");
+
+        ++section_number;
+    }
+    if(hwnd)
+        DrawMenuBar(hwnd);
+}
+
+ICON_IMAGE load_icon_default(ICON_TYPE type) {
+    WORD idi;
+    ICON_IMAGE img;
+
+    switch(type) {
+    case ICON_ACTIVE:
+        idi=IDI_STUNNEL_ACTIVE;
+        break;
+    case ICON_ERROR:
+        idi=IDI_STUNNEL_ERROR;
+        break;
+    case ICON_IDLE:
+        idi=IDI_STUNNEL_IDLE;
+        break;
+    default:
+        return NULL;
+    }
+    img=LoadImage(ghInst, MAKEINTRESOURCE(idi), IMAGE_ICON,
+        GetSystemMetrics(SM_CXSMICON), GetSystemMetrics(SM_CYSMICON), 0);
+    return DuplicateIcon(NULL, img);
+}
+
+ICON_IMAGE load_icon_file(const char *name) {
+    LPTSTR tname;
+    ICON_IMAGE icon;
+
+    tname=str2tstr((LPSTR)name);
+#ifndef _WIN32_WCE
+    icon=LoadImage(NULL, tname, IMAGE_ICON, GetSystemMetrics(SM_CXSMICON),
+        GetSystemMetrics(SM_CYSMICON), LR_LOADFROMFILE);
+#else
+    /* TODO: Implement a WCE version of LoadImage() */
+    /* icon=wceLoadIconFromFile(tname); */
+    s_log(LOG_ERR, "Loading image from file not implemented on WCE");
+    icon=NULL;
+#endif
+    str_free(tname);
+    return icon;
+}
+
+NOEXPORT void tray_update(const int num) {
+    NOTIFYICONDATA nid;
+    static ICON_TYPE previous_icon=ICON_NONE;
+    ICON_TYPE current_icon;
+    LPTSTR tip;
+
+    if(!global_options.option.taskbar) { /* currently disabled */
+        tray_delete(); /* remove the taskbark icon if exists */
+        return;
+    }
+    if(!tray_menu_handle) /* initialize taskbar */
+        tray_menu_handle=LoadMenu(ghInst, MAKEINTRESOURCE(IDM_TRAYMENU));
+    if(!tray_menu_handle) {
+        ioerror("LoadMenu");
+        return;
+    }
+    if(cmdline.service)
+        EnableMenuItem(tray_menu_handle, IDM_EDIT_CONFIG, MF_GRAYED);
+
+    ZeroMemory(&nid, sizeof nid);
+    nid.cbSize=sizeof nid;
+    nid.uID=1; /* application-defined icon ID */
+    nid.uFlags=NIF_MESSAGE|NIF_TIP;
+    nid.uCallbackMessage=WM_SYSTRAY; /* notification message */
+    nid.hWnd=hwnd; /* window to receive notifications */
+    if(num<0) {
+        tip=str_tprintf(TEXT("Server is down"));
+        current_icon=ICON_ERROR;
+    } else if(num>0) {
+        tip=str_tprintf(TEXT("%d active session(s)"), num);
+        current_icon=ICON_ACTIVE;
+    } else {
+        tip=str_tprintf(TEXT("Server is idle"));
+        current_icon=ICON_IDLE;
+    }
+    _tcsncpy(nid.szTip, tip, 63);
+    nid.szTip[63]=TEXT('\0');
+    str_free(tip);
+    nid.hIcon=global_options.icon[current_icon];
+    if(current_icon!=previous_icon) {
+        nid.uFlags|=NIF_ICON;
+        previous_icon=current_icon;
+    }
+    if(Shell_NotifyIcon(NIM_MODIFY, &nid)) /* modify tooltip */
+        return; /* OK: taskbar icon exists */
+    /* tooltip update failed - try to create the icon */
+    nid.uFlags|=NIF_ICON;
+    Shell_NotifyIcon(NIM_ADD, &nid);
+}
+
+NOEXPORT void tray_delete(void) {
+    NOTIFYICONDATA nid;
+
+    if(tray_menu_handle) {
+        ZeroMemory(&nid, sizeof nid);
+        nid.cbSize=sizeof nid;
+        nid.uID=1; /* application-defined icon ID */
+        nid.hWnd=hwnd; /* window to receive notifications */
+        nid.uFlags=NIF_TIP; /* not really sure what to put here, but it works */
+        Shell_NotifyIcon(NIM_DELETE, &nid); /* this removes the icon */
+        if(!DestroyMenu(tray_menu_handle)) /* release menu resources */
+            ioerror("DestroyMenu");
+        tray_menu_handle=NULL;
+    }
+}
+
+NOEXPORT void error_box(LPCTSTR text) {
+    LPTSTR errmsg, fullmsg;
+    DWORD dw;
+
+    dw=GetLastError();
+    FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER|FORMAT_MESSAGE_FROM_SYSTEM,
+        NULL, dw, MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT),
+        (LPTSTR)&errmsg, 0, NULL);
+    fullmsg=str_tprintf(TEXT("%s: error %ld: %s"), text, dw, errmsg);
+    LocalFree(errmsg);
+    message_box(fullmsg, MB_ICONERROR);
+    str_free(fullmsg);
+}
+
+void message_box(LPCTSTR text, const UINT type) {
+    if(cmdline.quiet)
+        return;
+    MessageBox(hwnd, text, win32_name, type);
+}
+
+void ui_new_chain(const unsigned section_number) {
+    PostMessage(hwnd, WM_NEW_CHAIN, section_number, 0);
+}
+
+void ui_new_log(const char *line) {
+    LPTSTR txt;
+    txt=str2tstr(line);
+    str_detach(txt); /* this allocation will be freed in the GUI thread */
+    PostMessage(hwnd, WM_LOG, (WPARAM)txt, 0);
+}
+
+void ui_config_reloaded(void) {
+    PostMessage(hwnd, WM_VALID_CONFIG, 0, 0);
+}
+
+void ui_clients(const long num) {
+    PostMessage(hwnd, WM_CLIENTS, (WPARAM)num, 0);
+}
+
+    /* TODO: port it to WCE */
+NOEXPORT void edit_config(HWND main_window_handle) {
+    TCHAR cwd[MAX_PATH];
+    LPTSTR conf_file, conf_path;
+
+    conf_file=str2tstr(configuration_file);
+    if(*conf_file==TEXT('\"')) {
+        conf_path=conf_file;
+    } else if(_tcschr(conf_file, TEXT('\\'))) {
+        conf_path=str_tprintf(TEXT("\"%s\""), conf_file);
+        str_free(conf_file);
+    } else {
+        GetCurrentDirectory(MAX_PATH, cwd);
+        conf_path=str_tprintf(TEXT("\"%s\\%s\""), cwd, conf_file);
+        str_free(conf_file);
+    }
+
+    if(is_admin()) {
+        ShellExecute(main_window_handle, TEXT("open"),
+            TEXT("notepad.exe"), conf_path,
+            NULL, SW_SHOWNORMAL);
+    } else { /* UAC workaround */
+        ShellExecute(main_window_handle, TEXT("runas"),
+            TEXT("notepad.exe"), conf_path,
+            NULL, SW_SHOWNORMAL);
+    }
+    str_free(conf_path);
+}
+
+NOEXPORT BOOL is_admin(void) {
+#ifndef _WIN32_WCE
+    SID_IDENTIFIER_AUTHORITY NtAuthority={SECURITY_NT_AUTHORITY};
+    PSID admin_group;
+    BOOL retval;
+
+    retval=AllocateAndInitializeSid(&NtAuthority, 2,
+        SECURITY_BUILTIN_DOMAIN_RID, DOMAIN_ALIAS_RID_ADMINS,
+        0, 0, 0, 0, 0, 0, &admin_group);
+    if(retval) {
+        if(!CheckTokenMembership(NULL, admin_group, &retval))
+            retval=FALSE;
+        FreeSid(admin_group);
+    }
+    return retval;
+#else
+    return TRUE; /* always an admin on WCE */
+#endif
+}
+
+/**************************************** windows service */
+
+#ifndef _WIN32_WCE
+
+NOEXPORT int service_initialize(void) {
+    SERVICE_TABLE_ENTRY serviceTable[]={{0, 0}, {0, 0}};
+
+    serviceTable[0].lpServiceName=SERVICE_NAME;
+    serviceTable[0].lpServiceProc=service_main;
+    /* disable taskbar for security */
+    /* global_options.option.taskbar=0; */
+    if(!StartServiceCtrlDispatcher(serviceTable)) {
+        error_box(TEXT("StartServiceCtrlDispatcher"));
+        return 1;
+    }
+    return 0; /* NT service started */
+}
+
+#define DESCR_LEN 256
+
+NOEXPORT int service_install() {
+    SC_HANDLE scm, service;
+    TCHAR stunnel_exe_path[MAX_PATH];
+    LPTSTR service_path;
+    TCHAR descr_str[DESCR_LEN];
+    SERVICE_DESCRIPTION descr;
+
+    scm=OpenSCManager(0, 0, SC_MANAGER_CREATE_SERVICE);
+    if(!scm) {
+        error_box(TEXT("OpenSCManager"));
+        return 1;
+    }
+    GetModuleFileName(0, stunnel_exe_path, MAX_PATH);
+    service_path=str_tprintf(TEXT("\"%s\" -service %s"),
+        stunnel_exe_path, get_params());
+    service=CreateService(scm, SERVICE_NAME, SERVICE_DISPLAY_NAME,
+        SERVICE_ALL_ACCESS,
+        SERVICE_WIN32_OWN_PROCESS|SERVICE_INTERACTIVE_PROCESS,
+        SERVICE_AUTO_START, SERVICE_ERROR_NORMAL, service_path,
+        NULL, NULL, TEXT("TCPIP\0"), NULL, NULL);
+    if(!service) {
+        error_box(TEXT("CreateService"));
+        str_free(service_path);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    str_free(service_path);
+    if(LoadString(ghInst, IDS_SERVICE_DESC, descr_str, DESCR_LEN)) {
+        descr.lpDescription=descr_str;
+        ChangeServiceConfig2(service, SERVICE_CONFIG_DESCRIPTION, &descr);
+    }
+    message_box(TEXT("Service installed"), MB_ICONINFORMATION);
+    CloseServiceHandle(service);
+    CloseServiceHandle(scm);
+    return 0;
+}
+
+NOEXPORT int service_uninstall(void) {
+    SC_HANDLE scm, service;
+    SERVICE_STATUS serviceStatus;
+
+    scm=OpenSCManager(0, 0, SC_MANAGER_CONNECT);
+    if(!scm) {
+        error_box(TEXT("OpenSCManager"));
+        return 1;
+    }
+    service=OpenService(scm, SERVICE_NAME, SERVICE_QUERY_STATUS|DELETE);
+    if(!service) {
+        error_box(TEXT("OpenService"));
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!QueryServiceStatus(service, &serviceStatus)) {
+        error_box(TEXT("QueryServiceStatus"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(serviceStatus.dwCurrentState!=SERVICE_STOPPED) {
+        message_box(TEXT("The service is still running"), MB_ICONERROR);
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!DeleteService(service)) {
+        error_box(TEXT("DeleteService"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    message_box(TEXT("Service uninstalled"), MB_ICONINFORMATION);
+    CloseServiceHandle(service);
+    CloseServiceHandle(scm);
+    return 0;
+}
+
+NOEXPORT int service_start(void) {
+    SC_HANDLE scm, service;
+    SERVICE_STATUS serviceStatus;
+
+    scm=OpenSCManager(0, 0, SC_MANAGER_CONNECT);
+    if(!scm) {
+        error_box(TEXT("OpenSCManager"));
+        return 1;
+    }
+    service=OpenService(scm, SERVICE_NAME, SERVICE_QUERY_STATUS|SERVICE_START);
+    if(!service) {
+        error_box(TEXT("OpenService"));
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!StartService(service, 0, NULL)) {
+        error_box(TEXT("StartService"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    do {
+        Sleep(1000);
+        if(!QueryServiceStatus(service, &serviceStatus)) {
+            error_box(TEXT("QueryServiceStatus"));
+            CloseServiceHandle(service);
+            CloseServiceHandle(scm);
+            return 1;
+        }
+    } while(serviceStatus.dwCurrentState==SERVICE_START_PENDING);
+    if(serviceStatus.dwCurrentState!=SERVICE_RUNNING) {
+        message_box(TEXT("Failed to start service"), MB_ICONERROR);
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    message_box(TEXT("Service started"), MB_ICONINFORMATION);
+    CloseServiceHandle(service);
+    CloseServiceHandle(scm);
+    return 0;
+}
+
+NOEXPORT int service_stop(void) {
+    SC_HANDLE scm, service;
+    SERVICE_STATUS serviceStatus;
+
+    scm=OpenSCManager(0, 0, SC_MANAGER_CONNECT);
+    if(!scm) {
+        error_box(TEXT("OpenSCManager"));
+        return 1;
+    }
+    service=OpenService(scm, SERVICE_NAME, SERVICE_QUERY_STATUS|SERVICE_STOP);
+    if(!service) {
+        error_box(TEXT("OpenService"));
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!QueryServiceStatus(service, &serviceStatus)) {
+        error_box(TEXT("QueryServiceStatus"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(serviceStatus.dwCurrentState==SERVICE_STOPPED) {
+        message_box(TEXT("The service is already stopped"), MB_ICONERROR);
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!ControlService(service, SERVICE_CONTROL_STOP, &serviceStatus)) {
+        error_box(TEXT("ControlService"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    do {
+        Sleep(1000);
+        if(!QueryServiceStatus(service, &serviceStatus)) {
+            error_box(TEXT("QueryServiceStatus"));
+            CloseServiceHandle(service);
+            CloseServiceHandle(scm);
+            return 1;
+        }
+    } while(serviceStatus.dwCurrentState!=SERVICE_STOPPED);
+    message_box(TEXT("Service stopped"), MB_ICONINFORMATION);
+    CloseServiceHandle(service);
+    CloseServiceHandle(scm);
+    return 0;
+}
+
+NOEXPORT int service_user(DWORD sig) {
+    SC_HANDLE scm, service;
+    SERVICE_STATUS serviceStatus;
+
+    scm=OpenSCManager(0, 0, SC_MANAGER_CONNECT);
+    if(!scm) {
+        error_box(TEXT("OpenSCManager"));
+        return 1;
+    }
+    service=OpenService(scm, SERVICE_NAME,
+        SERVICE_QUERY_STATUS|SERVICE_USER_DEFINED_CONTROL);
+    if(!service) {
+        error_box(TEXT("OpenService"));
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!QueryServiceStatus(service, &serviceStatus)) {
+        error_box(TEXT("QueryServiceStatus"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(serviceStatus.dwCurrentState==SERVICE_STOPPED) {
+        message_box(TEXT("The service is stopped"), MB_ICONERROR);
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    if(!ControlService(service, SERVICE_CONTROL_USER+sig, &serviceStatus)) {
+        error_box(TEXT("ControlService"));
+        CloseServiceHandle(service);
+        CloseServiceHandle(scm);
+        return 1;
+    }
+    switch(sig) {
+        case SIGNAL_RELOAD_CONFIG:
+            message_box(TEXT("Service configuration reloaded"),
+                MB_ICONINFORMATION);
+            break;
+        case SIGNAL_REOPEN_LOG:
+            message_box(TEXT("Service log file reopened"),
+                MB_ICONINFORMATION);
+            break;
+        default:
+            message_box(TEXT("Undefined operation requested"),
+                MB_ICONINFORMATION);
+    }
+    CloseServiceHandle(service);
+    CloseServiceHandle(scm);
+    return 0;
+}
+
+NOEXPORT void WINAPI service_main(DWORD argc, LPTSTR* argv) {
+    (void)argc; /* skip warning about unused parameter */
+    (void)argv; /* skip warning about unused parameter */
+
+    tls_alloc(NULL, NULL, "service"); /* new thread-local storage */
+
+    /* initialise service status */
+    serviceStatus.dwServiceType=SERVICE_WIN32;
+    serviceStatus.dwCurrentState=SERVICE_STOPPED;
+    serviceStatus.dwControlsAccepted=0;
+    serviceStatus.dwWin32ExitCode=NO_ERROR;
+    serviceStatus.dwServiceSpecificExitCode=NO_ERROR;
+    serviceStatus.dwCheckPoint=0;
+    serviceStatus.dwWaitHint=0;
+
+    serviceStatusHandle=
+        RegisterServiceCtrlHandler(SERVICE_NAME, control_handler);
+
+    if(serviceStatusHandle) {
+        /* service is starting */
+        serviceStatus.dwCurrentState=SERVICE_START_PENDING;
+        SetServiceStatus(serviceStatusHandle, &serviceStatus);
+
+        /* running */
+        serviceStatus.dwControlsAccepted|=
+            (SERVICE_ACCEPT_STOP|SERVICE_ACCEPT_SHUTDOWN);
+        serviceStatus.dwCurrentState=SERVICE_RUNNING;
+        SetServiceStatus(serviceStatusHandle, &serviceStatus);
+
+        gui_loop();
+
+        /* service was stopped */
+        serviceStatus.dwCurrentState=SERVICE_STOP_PENDING;
+        SetServiceStatus(serviceStatusHandle, &serviceStatus);
+
+        /* service is now stopped */
+        serviceStatus.dwControlsAccepted&=
+            (DWORD)~(SERVICE_ACCEPT_STOP|SERVICE_ACCEPT_SHUTDOWN);
+        serviceStatus.dwCurrentState=SERVICE_STOPPED;
+        SetServiceStatus(serviceStatusHandle, &serviceStatus);
+    }
+}
+
+NOEXPORT void WINAPI control_handler(DWORD controlCode) {
+    switch(controlCode) {
+    case SERVICE_CONTROL_INTERROGATE:
+        break;
+    case SERVICE_CONTROL_SHUTDOWN:
+    case SERVICE_CONTROL_STOP:
+        serviceStatus.dwCurrentState=SERVICE_STOP_PENDING;
+        SetServiceStatus(serviceStatusHandle, &serviceStatus);
+        PostMessage(hwnd, WM_COMMAND, IDM_EXIT, 0);
+        return;
+    case SERVICE_CONTROL_PAUSE:
+        break;
+    case SERVICE_CONTROL_CONTINUE:
+        break;
+    case SERVICE_CONTROL_USER+SIGNAL_RELOAD_CONFIG:
+        signal_post(SIGNAL_RELOAD_CONFIG);
+        break;
+    case SERVICE_CONTROL_USER+SIGNAL_REOPEN_LOG:
+        signal_post(SIGNAL_REOPEN_LOG);
+        break;
+    default:
+        if(controlCode >= 128 && controlCode <= 255)
+            break; /* user defined control code */
+        else
+            break; /* unrecognised control code */
+    }
+    SetServiceStatus(serviceStatusHandle, &serviceStatus);
+}
+
+#endif /* !defined(_WIN32_WCE) */
+
+/**************************************** other functions */
+
+NOEXPORT LPTSTR get_params() {
+    LPTSTR c;
+    TCHAR s;
+
+    c=GetCommandLine();
+    if(*c==TEXT('\"')) {
+        s=TEXT('\"');
+        ++c;
+    } else {
+        s=TEXT(' ');
+    }
+    for(; *c; ++c)
+        if(*c==s) {
+            ++c;
+            break;
+        }
+    while(*c==TEXT(' '))
+        ++c;
+    return c;
+}
+
+/* end of ui_win_gui.c */
diff --git a/src/vc.mak b/src/vc.mak
new file mode 100644
index 0000000..0c505c8
--- /dev/null
+++ b/src/vc.mak
@@ -0,0 +1,105 @@
+# vc.mak by Michal Trojnara 1998-2015

+# with help of David Gillingham <dgillingham@gmail.com>

+# with help of Pierre Delaage <delaage.pierre@free.fr>

+

+# the compilation requires:

+# - Visual C++ 2005 Express Edition with Platform SDK

+#   http://social.msdn.microsoft.com/forums/en-US/Vsexpressvc/thread/c5c3afad-f4c6-4d27-b471-0291e099a742/

+# - Visual C++ 2005 Professional Edition

+# - Visual C++ 2008 Express Edition

+

+!IF [ml64.exe /help >NUL 2>&1]

+TARGET=win32

+!ELSE

+TARGET=win64

+!ENDIF

+!MESSAGE Detected target: $(TARGET)

+!MESSAGE

+

+# modify this to point to your OpenSSL directory

+# either install a precompiled version (*not* the "Light" one) from

+# http://www.slproweb.com/products/Win32OpenSSL.html

+#SSLDIR=C:\OpenSSL-Win32

+#INCDIR=$(SSLDIR)\include

+#LIBDIR=$(SSLDIR)\lib

+# or compile one yourself

+SSLDIR=..\..\openssl-1.0.2d-$(TARGET)

+INCDIR=$(SSLDIR)\inc32

+LIBDIR=$(SSLDIR)\out32dll

+# or simply install with "nmake -f ms\ntdll.mak install"

+#SSLDIR=\usr\local\ssl

+#INCDIR=$(SSLDIR)\include

+#LIBDIR=$(SSLDIR)\lib

+

+SRC=..\src

+OBJROOT=..\obj

+OBJ=$(OBJROOT)\$(TARGET)

+BINROOT=..\bin

+BIN=$(BINROOT)\$(TARGET)

+

+SHAREDOBJS=$(OBJ)\stunnel.obj $(OBJ)\ssl.obj $(OBJ)\ctx.obj \

+	$(OBJ)\verify.obj $(OBJ)\file.obj $(OBJ)\client.obj \

+	$(OBJ)\protocol.obj $(OBJ)\sthreads.obj $(OBJ)\log.obj \

+	$(OBJ)\options.obj $(OBJ)\network.obj $(OBJ)\resolver.obj \

+	$(OBJ)\str.obj $(OBJ)\tls.obj $(OBJ)\fd.obj $(OBJ)\dhparam.obj \

+	$(OBJ)\cron.obj

+GUIOBJS=$(OBJ)\ui_win_gui.obj $(OBJ)\resources.res

+CLIOBJS=$(OBJ)\ui_win_cli.obj

+

+CC=cl

+LINK=link

+

+UNICODEFLAGS=/DUNICODE /D_UNICODE

+CFLAGS=/MD /W3 /O2 /nologo /I"$(INCDIR)" $(UNICODEFLAGS)

+LDFLAGS=/NOLOGO /DEBUG

+

+SHAREDLIBS=ws2_32.lib user32.lib shell32.lib

+GUILIBS=advapi32.lib comdlg32.lib crypt32.lib gdi32.lib psapi.lib

+CLILIBS=

+SSLLIBS=/LIBPATH:"$(LIBDIR)" libeay32.lib ssleay32.lib

+# static linking:

+#	/LIBPATH:"$(LIBDIR)\VC\static" libeay32MD.lib ssleay32MD.lib

+

+{$(SRC)\}.c{$(OBJ)\}.obj:

+	$(CC) $(CFLAGS) -Fo$@ -c $<

+

+{$(SRC)\}.rc{$(OBJ)\}.res:

+	$(RC) -fo$@ -r $<

+

+all: build

+

+build: makedirs $(BIN)\stunnel.exe $(BIN)\tstunnel.exe

+

+clean:

+	-@ del $(SHAREDOBJS) >NUL 2>&1

+	-@ del $(GUIOBJS) >NUL 2>&1

+	-@ del $(CLIOBJS) >NUL 2>&1

+#	-@ del *.manifest >NUL 2>&1

+	-@ del $(BIN)\stunnel.exe >NUL 2>&1

+	-@ del $(BIN)\stunnel.exe.manifest >NUL 2>&1

+	-@ del $(BIN)\tstunnel.exe >NUL 2>&1

+	-@ del $(BIN)\tstunnel.exe.manifest >NUL 2>&1

+	-@ rmdir $(OBJ) >NUL 2>&1

+	-@ rmdir $(BIN) >NUL 2>&1

+

+makedirs:

+	-@ IF NOT EXIST $(OBJROOT) mkdir $(OBJROOT) >NUL 2>&1

+	-@ IF NOT EXIST $(OBJ) mkdir $(OBJ) >NUL 2>&1

+	-@ IF NOT EXIST $(BINROOT) mkdir $(BINROOT) >NUL 2>&1

+	-@ IF NOT EXIST $(BIN) mkdir $(BIN) >NUL 2>&1

+

+$(SHAREDOBJS): *.h vc.mak

+$(GUIOBJS): *.h vc.mak

+$(CLIOBJS): *.h vc.mak

+

+$(BIN)\stunnel.exe: $(SHAREDOBJS) $(GUIOBJS)

+	$(LINK) $(LDFLAGS) $(SHAREDLIBS) $(GUILIBS) $(SSLLIBS) /OUT:$@ $**

+	IF EXIST $@.manifest \

+		mt -nologo -manifest $@.manifest -outputresource:$@;1

+

+$(BIN)\tstunnel.exe: $(SHAREDOBJS) $(CLIOBJS)

+	$(LINK) $(LDFLAGS) $(SHAREDLIBS) $(CLILIBS) $(SSLLIBS) /OUT:$@ $**

+	IF EXIST $@.manifest \

+		mt -nologo -manifest $@.manifest -outputresource:$@;1

+

+# end of vc.mak

diff --git a/src/verify.c b/src/verify.c
new file mode 100644
index 0000000..bf761ed
--- /dev/null
+++ b/src/verify.c
@@ -0,0 +1,835 @@
+/*
+ *   stunnel       TLS offloading and load-balancing proxy
+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>
+ *
+ *   This program is free software; you can redistribute it and/or modify it
+ *   under the terms of the GNU General Public License as published by the
+ *   Free Software Foundation; either version 2 of the License, or (at your
+ *   option) any later version.
+ *
+ *   This program is distributed in the hope that it will be useful,
+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of
+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
+ *   See the GNU General Public License for more details.
+ *
+ *   You should have received a copy of the GNU General Public License along
+ *   with this program; if not, see <http://www.gnu.org/licenses>.
+ *
+ *   Linking stunnel statically or dynamically with other modules is making
+ *   a combined work based on stunnel. Thus, the terms and conditions of
+ *   the GNU General Public License cover the whole combination.
+ *
+ *   In addition, as a special exception, the copyright holder of stunnel
+ *   gives you permission to combine stunnel with free software programs or
+ *   libraries that are released under the GNU LGPL and with code included
+ *   in the standard release of OpenSSL under the OpenSSL License (or
+ *   modified versions of such code, with unchanged license). You may copy
+ *   and distribute such a system following the terms of the GNU GPL for
+ *   stunnel and the licenses of the other code concerned.
+ *
+ *   Note that people who make modified versions of stunnel are not obligated
+ *   to grant this special exception for their modified versions; it is their
+ *   choice whether to do so. The GNU General Public License gives permission
+ *   to release a modified version without this exception; this exception
+ *   also makes it possible to release a modified version which carries
+ *   forward this exception.
+ */
+
+#include "common.h"
+#include "prototypes.h"
+
+/**************************************** prototypes */
+
+/* verify initialization */
+NOEXPORT void set_client_CA_list(SERVICE_OPTIONS *section);
+NOEXPORT void auth_warnings(SERVICE_OPTIONS *);
+NOEXPORT int load_file_lookup(X509_STORE *, char *);
+NOEXPORT int add_dir_lookup(X509_STORE *, char *);
+
+/* verify callback */
+NOEXPORT int verify_callback(int, X509_STORE_CTX *);
+NOEXPORT int verify_checks(CLI *, int, X509_STORE_CTX *);
+NOEXPORT int cert_check(CLI *, X509_STORE_CTX *, int);
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+NOEXPORT int cert_check_subject(CLI *, X509_STORE_CTX *);
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+NOEXPORT int cert_check_local(X509_STORE_CTX *);
+NOEXPORT int compare_pubkeys(X509 *, X509 *);
+NOEXPORT int crl_check(CLI *, X509_STORE_CTX *);
+#ifndef OPENSSL_NO_OCSP
+NOEXPORT int ocsp_check(CLI *, X509_STORE_CTX *);
+NOEXPORT int ocsp_request(CLI *, X509_STORE_CTX *, OCSP_CERTID *, char *);
+NOEXPORT OCSP_RESPONSE *ocsp_get_response(CLI *, OCSP_REQUEST *, char *);
+#endif
+
+/* utility functions */
+#ifndef OPENSSL_NO_OCSP
+NOEXPORT X509 *get_current_issuer(X509_STORE_CTX *);
+#endif
+NOEXPORT void log_time(const int, const char *, ASN1_TIME *);
+
+/**************************************** verify initialization */
+
+int verify_init(SERVICE_OPTIONS *section) {
+    int verify_mode=0;
+
+    /* revocation store initialization */
+    section->revocation_store=X509_STORE_new();
+    if(!section->revocation_store) {
+        sslerror("X509_STORE_new");
+        return 1; /* FAILED */
+    }
+
+    /* CA initialization */
+    if(section->ca_file) {
+        if(!SSL_CTX_load_verify_locations(section->ctx,
+                section->ca_file, NULL)) {
+            s_log(LOG_ERR, "Error loading verify certificates from %s",
+                section->ca_file);
+            sslerror("SSL_CTX_load_verify_locations");
+            return 1; /* FAILED */
+        }
+        /* revocation store needs CA certificates for CRL validation */
+        if(load_file_lookup(section->revocation_store, section->ca_file))
+            return 1; /* FAILED */
+        if(!section->option.client) /* only performed on server */
+            set_client_CA_list(section);
+    }
+    if(section->ca_dir) {
+        if(!SSL_CTX_load_verify_locations(section->ctx,
+                NULL, section->ca_dir)) {
+            s_log(LOG_ERR, "Error setting verify directory to %s",
+                section->ca_dir);
+            sslerror("SSL_CTX_load_verify_locations");
+            return 1; /* FAILED */
+        }
+        s_log(LOG_INFO, "Verify directory set to %s", section->ca_dir);
+        /* revocation store needs CA certificates for CRL validation */
+        add_dir_lookup(section->revocation_store, section->ca_dir);
+    }
+
+    /* CRL initialization */
+    if(section->crl_file)
+        if(load_file_lookup(section->revocation_store, section->crl_file))
+            return 1; /* FAILED */
+    if(section->crl_dir) {
+        section->revocation_store->cache=0; /* don't cache CRLs */
+        add_dir_lookup(section->revocation_store, section->crl_dir);
+    }
+
+    /* verify callback setup */
+    if(section->verify_level>=0)
+        verify_mode|=SSL_VERIFY_PEER;
+    if(section->verify_level>=2 && !section->redirect_addr.names)
+        verify_mode|=SSL_VERIFY_FAIL_IF_NO_PEER_CERT;
+    SSL_CTX_set_verify(section->ctx, verify_mode, verify_callback);
+    auth_warnings(section);
+
+    return 0; /* OK */
+}
+
+/* trusted CA names sent to clients for client cert selection */
+NOEXPORT void set_client_CA_list(SERVICE_OPTIONS *section) {
+    STACK_OF(X509_NAME) *ca_dn;
+    char *ca_name;
+    int i;
+
+    s_log(LOG_DEBUG, "Client CA list: %s", section->ca_file);
+    ca_dn=SSL_load_client_CA_file(section->ca_file);
+    for(i=0; i<sk_X509_NAME_num(ca_dn); ++i) {
+        ca_name=X509_NAME2text(sk_X509_NAME_value(ca_dn, i));
+        s_log(LOG_INFO, "Client CA: %s", ca_name);
+        str_free(ca_name);
+    }
+    SSL_CTX_set_client_CA_list(section->ctx, ca_dn);
+}
+
+/* issue warnings on insecure/missing authentication */
+NOEXPORT void auth_warnings(SERVICE_OPTIONS *section) {
+#ifndef OPENSSL_NO_PSK
+    if(section->psk_keys)
+        return;
+#endif /* !defined(OPENSSL_NO_PSK) */
+    /* for servers it is usually okay to accept all client
+       certificates signed by a specified certificate authority */
+    if(!section->option.client)
+        return;
+    if(section->verify_level<2) {
+        s_log(LOG_WARNING,
+            "Service [%s] needs authentication to prevent MITM attacks",
+            section->servname);
+        return;
+    }
+    if(section->verify_level>=3) /* levels>=3 don't rely on PKI */
+        return;
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+    if(section->check_email || section->check_host || section->check_ip)
+        return;
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+    s_log(LOG_WARNING,
+        "Service [%s] uses \"verify = 2\" without subject checks",
+        section->servname);
+#if OPENSSL_VERSION_NUMBER<0x10002000L
+    s_log(LOG_WARNING,
+        "Rebuild your stunnel against OpenSSL version 1.0.2 or higher");
+#endif /* OPENSSL_VERSION_NUMBER<0x10002000L */
+    s_log(LOG_WARNING,
+        "Use \"checkHost\" or \"checkIP\" to restrict trusted certificates");
+}
+
+NOEXPORT int load_file_lookup(X509_STORE *store, char *name) {
+    X509_LOOKUP *lookup;
+
+    lookup=X509_STORE_add_lookup(store, X509_LOOKUP_file());
+    if(!lookup) {
+        sslerror("X509_STORE_add_lookup");
+        return 1; /* FAILED */
+    }
+    if(!X509_LOOKUP_load_file(lookup, name, X509_FILETYPE_PEM)) {
+        s_log(LOG_ERR, "Failed to load %s revocation lookup file", name);
+        sslerror("X509_LOOKUP_load_file");
+        return 1; /* FAILED */
+    }
+    s_log(LOG_DEBUG, "Loaded %s revocation lookup file", name);
+    return 0; /* OK */
+}
+
+NOEXPORT int add_dir_lookup(X509_STORE *store, char *name) {
+    X509_LOOKUP *lookup;
+
+    lookup=X509_STORE_add_lookup(store, X509_LOOKUP_hash_dir());
+    if(!lookup) {
+        sslerror("X509_STORE_add_lookup");
+        return 1; /* FAILED */
+    }
+    if(!X509_LOOKUP_add_dir(lookup, name, X509_FILETYPE_PEM)) {
+        s_log(LOG_ERR, "Failed to add %s revocation lookup directory", name);
+        sslerror("X509_LOOKUP_add_dir");
+        return 1; /* FAILED */
+    }
+    s_log(LOG_DEBUG, "Added %s revocation lookup directory", name);
+    return 0; /* OK */
+}
+
+/**************************************** verify callback */
+
+NOEXPORT int verify_callback(int preverify_ok, X509_STORE_CTX *callback_ctx) {
+        /* our verify callback function */
+    SSL *ssl;
+    CLI *c;
+
+    /* retrieve application specific data */
+    ssl=X509_STORE_CTX_get_ex_data(callback_ctx,
+        SSL_get_ex_data_X509_STORE_CTX_idx());
+    c=SSL_get_ex_data(ssl, index_cli);
+
+    if(c->opt->verify_level<1) {
+        s_log(LOG_INFO, "Certificate verification disabled");
+        return 1; /* accept */
+    }
+    if(verify_checks(c, preverify_ok, callback_ctx))
+        return 1; /* accept */
+    if(c->opt->option.client || c->opt->protocol)
+        return 0; /* reject */
+    if(c->opt->redirect_addr.names) {
+        c->redirect=REDIRECT_ON;
+        return 1; /* accept */
+    }
+    return 0; /* reject */
+}
+
+NOEXPORT int verify_checks(CLI *c,
+        int preverify_ok, X509_STORE_CTX *callback_ctx) {
+    X509 *cert;
+    int depth;
+    char *subject;
+
+    cert=X509_STORE_CTX_get_current_cert(callback_ctx);
+    depth=X509_STORE_CTX_get_error_depth(callback_ctx);
+    subject=X509_NAME2text(X509_get_subject_name(cert));
+
+    s_log(LOG_DEBUG, "Verification started at depth=%d: %s", depth, subject);
+
+    if(!cert_check(c, callback_ctx, preverify_ok)) {
+        s_log(LOG_WARNING, "Rejected by CERT at depth=%d: %s", depth, subject);
+        str_free(subject);
+        return 0; /* reject */
+    }
+    if((c->opt->crl_file || c->opt->crl_dir) &&
+            !crl_check(c, callback_ctx)) {
+        s_log(LOG_WARNING, "Rejected by CRL at depth=%d: %s", depth, subject);
+        str_free(subject);
+        return 0; /* reject */
+    }
+#ifndef OPENSSL_NO_OCSP
+    if((c->opt->ocsp_url || c->opt->option.aia) &&
+            !ocsp_check(c, callback_ctx)) {
+        s_log(LOG_WARNING, "Rejected by OCSP at depth=%d: %s", depth, subject);
+        str_free(subject);
+        return 0; /* reject */
+    }
+#endif /* !defined(OPENSSL_NO_OCSP) */
+
+    s_log(depth ? LOG_INFO : LOG_NOTICE,
+        "Certificate accepted at depth=%d: %s", depth, subject);
+    str_free(subject);
+    return 1; /* accept */
+}
+
+/**************************************** certificate checking */
+
+NOEXPORT int cert_check(CLI *c, X509_STORE_CTX *callback_ctx,
+        int preverify_ok) {
+    int depth=X509_STORE_CTX_get_error_depth(callback_ctx);
+
+    if(preverify_ok) {
+        s_log(LOG_DEBUG, "CERT: Pre-verification succeeded");
+    } else { /* remote site sent an invalid certificate */
+        if(c->opt->verify_level>=4 && depth>0) {
+            s_log(LOG_INFO, "CERT: Invalid CA certificate ignored");
+            return 1; /* accept */
+        }
+        s_log(LOG_WARNING, "CERT: Pre-verification error: %s",
+            X509_verify_cert_error_string(
+                X509_STORE_CTX_get_error(callback_ctx)));
+        /* retain the STORE_CTX error produced by pre-verification */
+        return 0; /* reject */
+    }
+
+    if(depth==0) { /* additional peer certificate checks */
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+        if(!cert_check_subject(c, callback_ctx))
+            return 0; /* reject */
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+        if(c->opt->verify_level>=3 && !cert_check_local(callback_ctx))
+            return 0; /* reject */
+    }
+
+    return 1; /* accept */
+}
+
+#if OPENSSL_VERSION_NUMBER>=0x10002000L
+NOEXPORT int cert_check_subject(CLI *c, X509_STORE_CTX *callback_ctx) {
+    X509 *cert=X509_STORE_CTX_get_current_cert(callback_ctx);
+    NAME_LIST *ptr;
+    char *peername=NULL;
+
+    if(c->opt->check_host) {
+        for(ptr=c->opt->check_host; ptr; ptr=ptr->next)
+            if(X509_check_host(cert, ptr->name, 0, 0, &peername)>0)
+                break;
+        if(!ptr) {
+            s_log(LOG_WARNING, "CERT: No matching host name found");
+            return 0; /* reject */
+        }
+        s_log(LOG_INFO, "CERT: Host name \"%s\" matched with \"%s\"",
+            ptr->name, peername);
+        OPENSSL_free(peername);
+    }
+
+    if(c->opt->check_email) {
+        for(ptr=c->opt->check_email; ptr; ptr=ptr->next)
+            if(X509_check_email(cert, ptr->name, 0, 0)>0)
+                break;
+        if(!ptr) {
+            s_log(LOG_WARNING, "CERT: No matching email address found");
+            return 0; /* reject */
+        }
+        s_log(LOG_INFO, "CERT: Email address \"%s\" matched", ptr->name);
+    }
+
+    if(c->opt->check_ip) {
+        for(ptr=c->opt->check_ip; ptr; ptr=ptr->next)
+            if(X509_check_ip_asc(cert, ptr->name, 0)>0)
+                break;
+        if(!ptr) {
+            s_log(LOG_WARNING, "CERT: No matching IP address found");
+            return 0; /* reject */
+        }
+        s_log(LOG_INFO, "CERT: IP address \"%s\" matched", ptr->name);
+    }
+
+    return 1; /* accept */
+}
+#endif /* OPENSSL_VERSION_NUMBER>=0x10002000L */
+
+NOEXPORT int cert_check_local(X509_STORE_CTX *callback_ctx) {
+    X509 *cert;
+    X509_NAME *subject;
+#if OPENSSL_VERSION_NUMBER>=0x10000000L
+    STACK_OF(X509) *sk;
+    int i;
+#endif
+    X509_OBJECT obj;
+    int success;
+
+    cert=X509_STORE_CTX_get_current_cert(callback_ctx);
+    subject=X509_get_subject_name(cert);
+
+#if OPENSSL_VERSION_NUMBER>=0x10000000L
+    /* modern API allows retrieving multiple matching certificates */
+    sk=X509_STORE_get1_certs(callback_ctx, subject);
+    if(sk) {
+        for(i=0; i<sk_X509_num(sk); i++)
+            if(compare_pubkeys(cert, sk_X509_value(sk, i))) {
+                sk_X509_pop_free(sk, X509_free);
+                return 1; /* accept */
+            }
+        sk_X509_pop_free(sk, X509_free);
+    }
+#endif
+
+    /* pre-1.0.0 API only returns a single matching certificate */
+    memset((char *)&obj, 0, sizeof obj);
+    if(X509_STORE_get_by_subject(callback_ctx, X509_LU_X509,
+            subject, &obj)<=0) {
+        s_log(LOG_WARNING,
+            "CERT: Certificate not found in local repository");
+        return 0; /* reject */
+    }
+    success=compare_pubkeys(cert, obj.data.x509);
+    X509_OBJECT_free_contents(&obj);
+    if(!success) {
+        s_log(LOG_WARNING, "CERT: Public keys do not match");
+        X509_STORE_CTX_set_error(callback_ctx, X509_V_ERR_CERT_REJECTED);
+    }
+    return success;
+}
+
+NOEXPORT int compare_pubkeys(X509 *c1, X509 *c2) {
+    ASN1_BIT_STRING *k1=X509_get0_pubkey_bitstr(c1);
+    ASN1_BIT_STRING *k2=X509_get0_pubkey_bitstr(c2);
+    if(!k1 || !k2 || k1->length!=k2->length || k1->length<0 ||
+            safe_memcmp(k1->data, k2->data, (size_t)k1->length))
+        return 0; /* reject */
+    s_log(LOG_INFO, "CERT: Locally installed certificate matched");
+    return 1; /* accept */
+}
+
+/**************************************** CRL checking */
+
+/* based on the BSD-style licensed code of mod_ssl */
+NOEXPORT int crl_check(CLI *c, X509_STORE_CTX *callback_ctx) {
+    X509_STORE_CTX store_ctx;
+    X509_OBJECT obj;
+    X509_NAME *subject;
+    X509_NAME *issuer;
+    X509 *cert;
+    X509_CRL *crl;
+    X509_REVOKED *revoked;
+    EVP_PKEY *pubkey;
+    long serial;
+    int i, n, rc;
+    char *cp;
+    ASN1_TIME *last_update=NULL, *next_update=NULL;
+
+    cert=X509_STORE_CTX_get_current_cert(callback_ctx);
+    subject=X509_get_subject_name(cert);
+    issuer=X509_get_issuer_name(cert);
+
+    /* try to retrieve a CRL corresponding to the _subject_ of
+     * the current certificate in order to verify it's integrity */
+    X509_STORE_CTX_init(&store_ctx, c->opt->revocation_store, NULL, NULL);
+    memset((char *)&obj, 0, sizeof obj);
+    rc=X509_STORE_get_by_subject(&store_ctx, X509_LU_CRL, subject, &obj);
+    X509_STORE_CTX_cleanup(&store_ctx);
+    crl=obj.data.crl;
+    if(rc>0 && crl) {
+        cp=X509_NAME2text(subject);
+        s_log(LOG_INFO, "CRL: issuer: %s", cp);
+        str_free(cp);
+        last_update=X509_CRL_get_lastUpdate(crl);
+        next_update=X509_CRL_get_nextUpdate(crl);
+        log_time(LOG_INFO, "CRL: last update", last_update);
+        log_time(LOG_INFO, "CRL: next update", next_update);
+
+        /* verify the signature on this CRL */
+        pubkey=X509_get_pubkey(cert);
+        if(X509_CRL_verify(crl, pubkey)<=0) {
+            s_log(LOG_WARNING, "CRL: Invalid signature");
+            X509_STORE_CTX_set_error(callback_ctx,
+                X509_V_ERR_CRL_SIGNATURE_FAILURE);
+            X509_OBJECT_free_contents(&obj);
+            if(pubkey)
+                EVP_PKEY_free(pubkey);
+            return 0; /* reject */
+        }
+        if(pubkey)
+            EVP_PKEY_free(pubkey);
+
+        /* check date of CRL to make sure it's not expired */
+        if(!next_update) {
+            s_log(LOG_WARNING, "CRL: Invalid nextUpdate field");
+            X509_STORE_CTX_set_error(callback_ctx,
+                X509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD);
+            X509_OBJECT_free_contents(&obj);
+            return 0; /* reject */
+        }
+        if(X509_cmp_current_time(next_update)<0) {
+            s_log(LOG_WARNING, "CRL: CRL Expired - revoking all certificates");
+            X509_STORE_CTX_set_error(callback_ctx, X509_V_ERR_CRL_HAS_EXPIRED);
+            X509_OBJECT_free_contents(&obj);
+            return 0; /* reject */
+        }
+        X509_OBJECT_free_contents(&obj);
+    }
+
+    /* try to retrieve a CRL corresponding to the _issuer_ of
+     * the current certificate in order to check for revocation */
+    memset((char *)&obj, 0, sizeof obj);
+    X509_STORE_CTX_init(&store_ctx, c->opt->revocation_store, NULL, NULL);
+    rc=X509_STORE_get_by_subject(&store_ctx, X509_LU_CRL, issuer, &obj);
+    X509_STORE_CTX_cleanup(&store_ctx);
+    crl=obj.data.crl;
+    if(rc>0 && crl) {
+        /* check if the current certificate is revoked by this CRL */
+        n=sk_X509_REVOKED_num(X509_CRL_get_REVOKED(crl));
+        for(i=0; i<n; i++) {
+            revoked=sk_X509_REVOKED_value(X509_CRL_get_REVOKED(crl), i);
+            if(ASN1_INTEGER_cmp(revoked->serialNumber,
+                    X509_get_serialNumber(cert))==0) {
+                serial=ASN1_INTEGER_get(revoked->serialNumber);
+                cp=X509_NAME2text(issuer);
+                s_log(LOG_WARNING, "CRL: Certificate with serial %ld (0x%lX) "
+                    "revoked per CRL from issuer %s", serial, serial, cp);
+                str_free(cp);
+                X509_STORE_CTX_set_error(callback_ctx, X509_V_ERR_CERT_REVOKED);
+                X509_OBJECT_free_contents(&obj);
+                return 0; /* reject */
+            }
+        }
+        X509_OBJECT_free_contents(&obj);
+    }
+    return 1; /* accept */
+}
+
+#ifndef OPENSSL_NO_OCSP
+
+/**************************************** OCSP checking */
+
+/* type checks not available -- use generic functions */
+#ifndef sk_OPENSSL_STRING_num
+#define sk_OPENSSL_STRING_num(st) sk_num(st)
+#endif
+#ifndef sk_OPENSSL_STRING_value
+#define sk_OPENSSL_STRING_value(st, i) sk_value((st),(i))
+#endif
+
+NOEXPORT int ocsp_check(CLI *c, X509_STORE_CTX *callback_ctx) {
+    X509 *cert;
+    OCSP_CERTID *cert_id;
+    STACK_OF(OPENSSL_STRING) *aia;
+    int i, ocsp_status=V_OCSP_CERTSTATUS_UNKNOWN, saved_error;
+
+    /* the original error code is restored unless we report our own error */
+    saved_error=X509_STORE_CTX_get_error(callback_ctx);
+
+    /* get the current certificate ID */
+    cert=X509_STORE_CTX_get_current_cert(callback_ctx);
+    if(!cert) {
+        s_log(LOG_ERR, "OCSP: Failed to get the current certificate");
+        X509_STORE_CTX_set_error(callback_ctx,
+            X509_V_ERR_APPLICATION_VERIFICATION);
+        return 0; /* reject */
+    }
+    if(!X509_NAME_cmp(X509_get_subject_name(cert),
+            X509_get_issuer_name(cert))) {
+        s_log(LOG_DEBUG, "OCSP: Ignoring root certificate");
+        return 1; /* accept */
+    }
+    cert_id=OCSP_cert_to_id(NULL, cert, get_current_issuer(callback_ctx));
+    if(!cert_id) {
+        sslerror("OCSP: OCSP_cert_to_id");
+        X509_STORE_CTX_set_error(callback_ctx,
+            X509_V_ERR_APPLICATION_VERIFICATION);
+        return 0; /* reject */
+    }
+
+    /* use the responder specified in the configuration file */
+    if(c->opt->ocsp_url) {
+        s_log(LOG_NOTICE, "OCSP: Connecting configured responder \"%s\"",
+            c->opt->ocsp_url);
+        if(ocsp_request(c, callback_ctx, cert_id, c->opt->ocsp_url)!=
+                V_OCSP_CERTSTATUS_GOOD) {
+            OCSP_CERTID_free(cert_id);
+            return 0; /* reject */
+        }
+    }
+
+    /* use the responder from AIA (Authority Information Access) */
+    if(c->opt->option.aia && (aia=X509_get1_ocsp(cert))) {
+        for(i=0; i<sk_OPENSSL_STRING_num(aia); i++) {
+            s_log(LOG_NOTICE, "OCSP: Connecting AIA responder \"%s\"",
+                sk_OPENSSL_STRING_value(aia, i));
+            ocsp_status=ocsp_request(c, callback_ctx, cert_id,
+                sk_OPENSSL_STRING_value(aia, i));
+            if(ocsp_status!=V_OCSP_CERTSTATUS_UNKNOWN)
+                break; /* we received a definitive response */
+        }
+        X509_email_free(aia);
+        if(ocsp_status!=V_OCSP_CERTSTATUS_GOOD) {
+            OCSP_CERTID_free(cert_id);
+            return 0; /* reject */
+        }
+    }
+
+    OCSP_CERTID_free(cert_id);
+    X509_STORE_CTX_set_error(callback_ctx, saved_error);
+    return 1; /* accept */
+}
+
+/* returns one of:
+ * V_OCSP_CERTSTATUS_GOOD
+ * V_OCSP_CERTSTATUS_REVOKED
+ * V_OCSP_CERTSTATUS_UNKNOWN */
+NOEXPORT int ocsp_request(CLI *c, X509_STORE_CTX *callback_ctx,
+        OCSP_CERTID *cert_id, char *url) {
+    int ocsp_status=V_OCSP_CERTSTATUS_UNKNOWN;
+    int response_status;
+    int reason;
+    int ctx_err=X509_V_ERR_APPLICATION_VERIFICATION;
+    OCSP_REQUEST *request=NULL;
+    OCSP_RESPONSE *response=NULL;
+    OCSP_BASICRESP *basic_response=NULL;
+    ASN1_GENERALIZEDTIME *revoked_at=NULL,
+        *this_update=NULL, *next_update=NULL;
+
+    /* build request */
+    request=OCSP_REQUEST_new();
+    if(!request) {
+        sslerror("OCSP: OCSP_REQUEST_new");
+        goto cleanup;
+    }
+    if(!OCSP_request_add0_id(request, OCSP_CERTID_dup(cert_id))) {
+        sslerror("OCSP: OCSP_request_add0_id");
+        goto cleanup;
+    }
+#if 0
+    OCSP_request_add1_nonce(request, NULL, -1);
+#endif
+
+    /* send the request and get a response */
+    response=ocsp_get_response(c, request, url);
+    if(!response)
+        goto cleanup;
+    response_status=OCSP_response_status(response);
+    if(response_status!=OCSP_RESPONSE_STATUS_SUCCESSFUL) {
+        s_log(LOG_WARNING, "OCSP: Responder error: %d: %s",
+            response_status, OCSP_response_status_str(response_status));
+        goto cleanup;
+    }
+
+    /* verify the response */
+    basic_response=OCSP_response_get1_basic(response);
+    if(!basic_response) {
+        sslerror("OCSP: OCSP_response_get1_basic");
+        goto cleanup;
+    }
+#if 0
+    if(OCSP_check_nonce(request, basic_response)<=0) {
+        s_log(LOG_WARNING, "OCSP: Invalid nonce");
+        goto cleanup;
+    }
+#endif
+    if(OCSP_basic_verify(basic_response, X509_STORE_CTX_get_chain(callback_ctx),
+            c->opt->revocation_store, c->opt->ocsp_flags)<=0) {
+        sslerror("OCSP: OCSP_basic_verify");
+        goto cleanup;
+    }
+    if(!OCSP_resp_find_status(basic_response, cert_id, &ocsp_status, &reason,
+            &revoked_at, &this_update, &next_update)) {
+        sslerror("OCSP: OCSP_resp_find_status");
+        goto cleanup;
+    }
+    s_log(LOG_INFO, "OCSP: Status: %s", OCSP_cert_status_str(ocsp_status));
+    log_time(LOG_INFO, "OCSP: This update", this_update);
+    log_time(LOG_INFO, "OCSP: Next update", next_update);
+    /* check if the response is valid for at least one minute */
+    if(!OCSP_check_validity(this_update, next_update, 60, -1)) {
+        sslerror("OCSP: OCSP_check_validity");
+        ocsp_status=V_OCSP_CERTSTATUS_UNKNOWN;
+        goto cleanup;
+    }
+    switch(ocsp_status) {
+    case V_OCSP_CERTSTATUS_GOOD:
+        s_log(LOG_NOTICE, "OCSP: Certificate accepted");
+        break;
+    case V_OCSP_CERTSTATUS_REVOKED:
+        if(reason==-1)
+            s_log(LOG_WARNING, "OCSP: Certificate revoked");
+        else
+            s_log(LOG_WARNING, "OCSP: Certificate revoked: %d: %s",
+                reason, OCSP_crl_reason_str(reason));
+        log_time(LOG_NOTICE, "OCSP: Revoked at", revoked_at);
+        ctx_err=X509_V_ERR_CERT_REVOKED;
+        break;
+    case V_OCSP_CERTSTATUS_UNKNOWN:
+        s_log(LOG_WARNING, "OCSP: Unknown verification status");
+    }
+cleanup:
+    if(request)
+        OCSP_REQUEST_free(request);
+    if(response)
+        OCSP_RESPONSE_free(response);
+    if(basic_response)
+        OCSP_BASICRESP_free(basic_response);
+    if(ocsp_status!=V_OCSP_CERTSTATUS_GOOD)
+        X509_STORE_CTX_set_error(callback_ctx, ctx_err);
+    return ocsp_status;
+}
+
+NOEXPORT OCSP_RESPONSE *ocsp_get_response(CLI *c,
+        OCSP_REQUEST *req, char *url) {
+    BIO *bio=NULL;
+    OCSP_REQ_CTX *req_ctx=NULL;
+    OCSP_RESPONSE *resp=NULL;
+    int err;
+    char *host=NULL, *port=NULL, *path=NULL;
+    SOCKADDR_UNION addr;
+    int ssl;
+
+    /* parse the OCSP URL */
+    if(!OCSP_parse_url(url, &host, &port, &path, &ssl)) {
+        s_log(LOG_ERR, "OCSP: Failed to parse the OCSP URL");
+        goto cleanup;
+    }
+    if(ssl) {
+        s_log(LOG_ERR, "OCSP: SSL not supported for OCSP"
+            " - additional stunnel service needs to be defined");
+        goto cleanup;
+    }
+    memset(&addr, 0, sizeof addr);
+    addr.in.sin_family=AF_INET;
+    if(!hostport2addr(&addr, host, port, 0)) {
+        s_log(LOG_ERR, "OCSP: Failed to resolve the OCSP server address");
+        goto cleanup;
+    }
+
+    /* connect specified OCSP server (responder) */
+    c->fd=s_socket(addr.sa.sa_family, SOCK_STREAM, 0, 1, "OCSP: socket");
+    if(c->fd==INVALID_SOCKET)
+        goto cleanup;
+    if(s_connect(c, &addr, addr_len(&addr)))
+        goto cleanup;
+    bio=BIO_new_socket((int)c->fd, BIO_NOCLOSE);
+    if(!bio)
+        goto cleanup;
+    s_log(LOG_DEBUG, "OCSP: Connected %s:%s", host, port);
+
+    /* OCSP protocol communication loop */
+    req_ctx=OCSP_sendreq_new(bio, path, NULL, -1);
+    if(!req_ctx) {
+        sslerror("OCSP: OCSP_sendreq_new");
+        goto cleanup;
+    }
+    if(!OCSP_REQ_CTX_add1_header(req_ctx, "Host", host)) {
+        sslerror("OCSP: OCSP_REQ_CTX_add1_header");
+        goto cleanup;
+    }
+    if(!OCSP_REQ_CTX_set1_req(req_ctx, req))
+        goto cleanup;
+    while(OCSP_sendreq_nbio(&resp, req_ctx)==-1) {
+        s_poll_init(c->fds);
+        s_poll_add(c->fds, c->fd, BIO_should_read(bio), BIO_should_write(bio));
+        err=s_poll_wait(c->fds, c->opt->timeout_busy, 0);
+        if(err==-1)
+            sockerror("OCSP: s_poll_wait");
+        if(err==0)
+            s_log(LOG_INFO, "OCSP: s_poll_wait: TIMEOUTbusy exceeded");
+        if(err<=0)
+            goto cleanup;
+    }
+#if 0
+    s_log(LOG_DEBUG, "OCSP: context state: 0x%x", *(int *)req_ctx);
+#endif
+    /* http://www.mail-archive.com/openssl-users@openssl.org/msg61691.html */
+    if(resp) {
+        s_log(LOG_DEBUG, "OCSP: Response received");
+    } else {
+        if(ERR_peek_error())
+            sslerror("OCSP: OCSP_sendreq_nbio");
+        else /* OpenSSL error: OCSP_sendreq_nbio does not use OCSPerr */
+            s_log(LOG_ERR, "OCSP: OCSP_sendreq_nbio: OpenSSL internal error");
+    }
+
+cleanup:
+    if(req_ctx)
+        OCSP_REQ_CTX_free(req_ctx);
+    if(bio)
+        BIO_free_all(bio);
+    if(c->fd!=INVALID_SOCKET) {
+        closesocket(c->fd);
+        c->fd=INVALID_SOCKET; /* avoid double close on cleanup */
+    }
+    if(host)
+        OPENSSL_free(host);
+    if(port)
+        OPENSSL_free(port);
+    if(path)
+        OPENSSL_free(path);
+    return resp;
+}
+
+/* find the issuer certificate without lookups */
+NOEXPORT X509 *get_current_issuer(X509_STORE_CTX *callback_ctx) {
+    STACK_OF(X509) *chain;
+    int depth;
+
+    chain=X509_STORE_CTX_get_chain(callback_ctx);
+    depth=X509_STORE_CTX_get_error_depth(callback_ctx);
+    if(depth<sk_X509_num(chain)-1) /* not the root CA cert */
+        ++depth; /* index of the issuer cert */
+    return sk_X509_value(chain, depth);
+}
+
+#endif /* !defined(OPENSSL_NO_OCSP) */
+
+char *X509_NAME2text(X509_NAME *name) {
+    char *text;
+    BIO *bio;
+    int n;
+
+    bio=BIO_new(BIO_s_mem());
+    if(!bio)
+        return str_dup("BIO_new() failed");
+    X509_NAME_print_ex(bio, name, 0,
+        XN_FLAG_ONELINE & ~ASN1_STRFLGS_ESC_MSB & ~XN_FLAG_SPC_EQ);
+    n=BIO_pending(bio);
+    text=str_alloc((size_t)n+1);
+    n=BIO_read(bio, text, n);
+    if(n<0) {
+        BIO_free(bio);
+        str_free(text);
+        return str_dup("BIO_read() failed");
+    }
+    text[n]='\0';
+    BIO_free(bio);
+    return text;
+}
+
+NOEXPORT void log_time(const int level, const char *txt, ASN1_TIME *t) {
+    char *cp;
+    BIO *bio;
+    int n;
+
+    if(!t)
+        return;
+    bio=BIO_new(BIO_s_mem());
+    if(!bio)
+        return;
+    ASN1_TIME_print(bio, t);
+    n=BIO_pending(bio);
+    cp=str_alloc((size_t)n+1);
+    n=BIO_read(bio, cp, n);
+    if(n<0) {
+        BIO_free(bio);
+        str_free(cp);
+        return;
+    }
+    cp[n]='\0';
+    BIO_free(bio);
+    s_log(level, "%s: %s", txt, cp);
+    str_free(cp);
+}
+
+/* end of verify.c */
diff --git a/src/version.h b/src/version.h
new file mode 100644
index 0000000..67d72bb
--- /dev/null
+++ b/src/version.h
@@ -0,0 +1,95 @@
+/*

+ *   stunnel       TLS offloading and load-balancing proxy

+ *   Copyright (C) 1998-2015 Michal Trojnara <Michal.Trojnara@mirt.net>

+ *

+ *   This program is free software; you can redistribute it and/or modify it

+ *   under the terms of the GNU General Public License as published by the

+ *   Free Software Foundation; either version 2 of the License, or (at your

+ *   option) any later version.

+ * 

+ *   This program is distributed in the hope that it will be useful,

+ *   but WITHOUT ANY WARRANTY; without even the implied warranty of

+ *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

+ *   See the GNU General Public License for more details.

+ * 

+ *   You should have received a copy of the GNU General Public License along

+ *   with this program; if not, see <http://www.gnu.org/licenses>.

+ * 

+ *   Linking stunnel statically or dynamically with other modules is making

+ *   a combined work based on stunnel. Thus, the terms and conditions of

+ *   the GNU General Public License cover the whole combination.

+ * 

+ *   In addition, as a special exception, the copyright holder of stunnel

+ *   gives you permission to combine stunnel with free software programs or

+ *   libraries that are released under the GNU LGPL and with code included

+ *   in the standard release of OpenSSL under the OpenSSL License (or

+ *   modified versions of such code, with unchanged license). You may copy

+ *   and distribute such a system following the terms of the GNU GPL for

+ *   stunnel and the licenses of the other code concerned.

+ * 

+ *   Note that people who make modified versions of stunnel are not obligated

+ *   to grant this special exception for their modified versions; it is their

+ *   choice whether to do so. The GNU General Public License gives permission

+ *   to release a modified version without this exception; this exception

+ *   also makes it possible to release a modified version which carries

+ *   forward this exception.

+ */

+

+#ifndef VERSION_MAJOR

+

+#ifdef HAVE_CONFIG_H

+#include "config.h"

+#endif /* HAVE_CONFIG_H */

+

+/* HOST may be undefined on Win32 platform */

+#ifndef HOST

+#if defined(_WIN64)

+#define PLATFORM "x64"

+#elif defined(_WIN32)

+#define PLATFORM "x86"

+#else /* although MSDN claims that _WIN32 is always defined */

+#define PLATFORM "unknown"

+#endif

+#ifdef __MINGW32__

+#define HOST PLATFORM "-pc-mingw32-gnu"

+#else /* __MINGW32__ */

+#ifdef _MSC_VER

+#define xstr(a) str(a)

+#define str(a) #a

+#define HOST PLATFORM "-pc-msvc-" xstr(_MSC_VER)

+#else /* _MSC_VER */

+#define HOST PLATFORM "-pc-unknown"

+#endif /* _MSC_VER */

+#endif /* __MINGW32__ */

+#endif /* HOST */

+

+/* START CUSTOMIZE */

+#define VERSION_MAJOR 5

+#define VERSION_MINOR 22

+/* END CUSTOMIZE */

+

+/* all the following macros are ABSOLUTELY NECESSARY to have proper string

+ * construction with VARIOUS C preprocessors (EVC, VC, BCC, GCC) */

+#define STRINGIZE0(x) #x

+#define STRINGIZE(x) STRINGIZE0(x)

+#define STRZCONCAT30(a,b,c) a##b##c

+#define STRZCONCAT3(a,b,c) STRZCONCAT30(a,b,c)

+ 

+/* for resource.rc, stunnel.c, gui.c */

+#define STUNNEL_VERSION0 STRZCONCAT3(VERSION_MAJOR, . , VERSION_MINOR)

+#define STUNNEL_VERSION STRINGIZE(STUNNEL_VERSION0)

+

+/* for resources.rc */

+#define STUNNEL_VERSION_FIELDS VERSION_MAJOR,VERSION_MINOR,0,0

+#define STUNNEL_PRODUCTNAME "stunnel " STUNNEL_VERSION " for " HOST

+

+/* some useful tricks for preprocessing debugging */

+#if 0

+#pragma message ( "VERSION.H: STUNNEL_VERSION is " STUNNEL_VERSION )

+#pragma message ( "VERSION.H: HOST is " HOST )

+#pragma message ( "VERSION.H: STUNNEL_PRODUCTNAME is " STUNNEL_PRODUCTNAME )

+#endif

+

+#endif /* VERSION_MAJOR */

+

+/* end of version.h */

diff --git a/tools/Makefile.am b/tools/Makefile.am
new file mode 100644
index 0000000..3104e06
--- /dev/null
+++ b/tools/Makefile.am
@@ -0,0 +1,55 @@
+## Process this file with automake to produce Makefile.in
+
+EXTRA_DIST = ca.html ca.pl importCA.html importCA.sh script.sh \
+	stunnel.spec stunnel.cnf stunnel.nsi stunnel.license stunnel.conf \
+	stunnel.conf-sample.in stunnel.init.in stunnel.service.in
+
+confdir = $(sysconfdir)/stunnel
+conf_DATA = stunnel.conf-sample
+
+docdir = $(datadir)/doc/stunnel
+examplesdir = $(docdir)/examples
+examples_DATA = stunnel.spec stunnel.init stunnel.service
+examples_DATA += ca.html ca.pl importCA.html importCA.sh script.sh
+
+CLEANFILES = stunnel.conf-sample stunnel.init stunnel.service
+
+install-data-local:
+	${INSTALL} -d -m 1770 $(DESTDIR)$(localstatedir)/lib/stunnel
+	-chgrp $(DEFAULT_GROUP) $(DESTDIR)$(localstatedir)/lib/stunnel
+
+OPENSSL=$(SSLDIR)/bin/openssl
+
+cert:
+	@if test -r $(DESTDIR)$(confdir)/stunnel.pem; \
+	then \
+		echo "$(DESTDIR)$(confdir)/stunnel.pem already exists"; \
+	else \
+		if test -r "$(RANDOM_FILE)"; then \
+			dd if="$(RANDOM_FILE)" of=stunnel.rnd bs=256 count=1; \
+			RND="-rand stunnel.rnd"; \
+		else \
+			RND=""; \
+		fi; \
+		$(OPENSSL) req -new -x509 -days 365 $$RND \
+			-config $(srcdir)/stunnel.cnf \
+			-out stunnel.pem -keyout stunnel.pem; \
+		$(OPENSSL) x509 -subject -dates -fingerprint -noout -in stunnel.pem; \
+		${INSTALL} -m 600 stunnel.pem $(DESTDIR)$(confdir)/stunnel.pem; \
+		rm stunnel.pem; \
+		rm -f stunnel.rnd; \
+	fi
+
+edit = sed \
+	-e 's|@prefix[@]|$(prefix)|g' \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@localstatedir[@]|$(localstatedir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g' \
+	-e 's|@DEFAULT_GROUP[@]|$(DEFAULT_GROUP)|g'
+
+stunnel.conf-sample stunnel.init stunnel.service: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.conf-sample: $(srcdir)/stunnel.conf-sample.in
+stunnel.init: $(srcdir)/stunnel.init.in
+stunnel.service: $(srcdir)/stunnel.service.in
diff --git a/tools/Makefile.in b/tools/Makefile.in
new file mode 100644
index 0000000..3bff28f
--- /dev/null
+++ b/tools/Makefile.in
@@ -0,0 +1,563 @@
+# Makefile.in generated by automake 1.14.1 from Makefile.am.
+# @configure_input@
+
+# Copyright (C) 1994-2013 Free Software Foundation, Inc.
+
+# This Makefile.in is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+@SET_MAKE@
+
+VPATH = @srcdir@
+am__is_gnu_make = test -n '$(MAKEFILE_LIST)' && test -n '$(MAKELEVEL)'
+am__make_running_with_option = \
+  case $${target_option-} in \
+      ?) ;; \
+      *) echo "am__make_running_with_option: internal error: invalid" \
+              "target option '$${target_option-}' specified" >&2; \
+         exit 1;; \
+  esac; \
+  has_opt=no; \
+  sane_makeflags=$$MAKEFLAGS; \
+  if $(am__is_gnu_make); then \
+    sane_makeflags=$$MFLAGS; \
+  else \
+    case $$MAKEFLAGS in \
+      *\\[\ \	]*) \
+        bs=\\; \
+        sane_makeflags=`printf '%s\n' "$$MAKEFLAGS" \
+          | sed "s/$$bs$$bs[$$bs $$bs	]*//g"`;; \
+    esac; \
+  fi; \
+  skip_next=no; \
+  strip_trailopt () \
+  { \
+    flg=`printf '%s\n' "$$flg" | sed "s/$$1.*$$//"`; \
+  }; \
+  for flg in $$sane_makeflags; do \
+    test $$skip_next = yes && { skip_next=no; continue; }; \
+    case $$flg in \
+      *=*|--*) continue;; \
+        -*I) strip_trailopt 'I'; skip_next=yes;; \
+      -*I?*) strip_trailopt 'I';; \
+        -*O) strip_trailopt 'O'; skip_next=yes;; \
+      -*O?*) strip_trailopt 'O';; \
+        -*l) strip_trailopt 'l'; skip_next=yes;; \
+      -*l?*) strip_trailopt 'l';; \
+      -[dEDm]) skip_next=yes;; \
+      -[JT]) skip_next=yes;; \
+    esac; \
+    case $$flg in \
+      *$$target_option*) has_opt=yes; break;; \
+    esac; \
+  done; \
+  test $$has_opt = yes
+am__make_dryrun = (target_option=n; $(am__make_running_with_option))
+am__make_keepgoing = (target_option=k; $(am__make_running_with_option))
+pkgdatadir = $(datadir)/@PACKAGE@
+pkgincludedir = $(includedir)/@PACKAGE@
+pkglibdir = $(libdir)/@PACKAGE@
+pkglibexecdir = $(libexecdir)/@PACKAGE@
+am__cd = CDPATH="$${ZSH_VERSION+.}$(PATH_SEPARATOR)" && cd
+install_sh_DATA = $(install_sh) -c -m 644
+install_sh_PROGRAM = $(install_sh) -c
+install_sh_SCRIPT = $(install_sh) -c
+INSTALL_HEADER = $(INSTALL_DATA)
+transform = $(program_transform_name)
+NORMAL_INSTALL = :
+PRE_INSTALL = :
+POST_INSTALL = :
+NORMAL_UNINSTALL = :
+PRE_UNINSTALL = :
+POST_UNINSTALL = :
+build_triplet = @build@
+host_triplet = @host@
+subdir = tools
+DIST_COMMON = $(srcdir)/Makefile.in $(srcdir)/Makefile.am
+ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
+am__aclocal_m4_deps = $(top_srcdir)/m4/ax_append_compile_flags.m4 \
+	$(top_srcdir)/m4/ax_append_flag.m4 \
+	$(top_srcdir)/m4/ax_append_link_flags.m4 \
+	$(top_srcdir)/m4/ax_check_compile_flag.m4 \
+	$(top_srcdir)/m4/ax_check_link_flag.m4 \
+	$(top_srcdir)/m4/ax_pthread.m4 \
+	$(top_srcdir)/m4/ax_require_defined.m4 \
+	$(top_srcdir)/m4/libtool.m4 $(top_srcdir)/m4/ltoptions.m4 \
+	$(top_srcdir)/m4/ltsugar.m4 $(top_srcdir)/m4/ltversion.m4 \
+	$(top_srcdir)/m4/lt~obsolete.m4 $(top_srcdir)/configure.ac
+am__configure_deps = $(am__aclocal_m4_deps) $(CONFIGURE_DEPENDENCIES) \
+	$(ACLOCAL_M4)
+mkinstalldirs = $(install_sh) -d
+CONFIG_HEADER = $(top_builddir)/src/config.h
+CONFIG_CLEAN_FILES =
+CONFIG_CLEAN_VPATH_FILES =
+AM_V_P = $(am__v_P_@AM_V@)
+am__v_P_ = $(am__v_P_@AM_DEFAULT_V@)
+am__v_P_0 = false
+am__v_P_1 = :
+AM_V_GEN = $(am__v_GEN_@AM_V@)
+am__v_GEN_ = $(am__v_GEN_@AM_DEFAULT_V@)
+am__v_GEN_0 = @echo "  GEN     " $@;
+am__v_GEN_1 = 
+AM_V_at = $(am__v_at_@AM_V@)
+am__v_at_ = $(am__v_at_@AM_DEFAULT_V@)
+am__v_at_0 = @
+am__v_at_1 = 
+SOURCES =
+DIST_SOURCES =
+am__can_run_installinfo = \
+  case $$AM_UPDATE_INFO_DIR in \
+    n|no|NO) false;; \
+    *) (install-info --version) >/dev/null 2>&1;; \
+  esac
+am__vpath_adj_setup = srcdirstrip=`echo "$(srcdir)" | sed 's|.|.|g'`;
+am__vpath_adj = case $$p in \
+    $(srcdir)/*) f=`echo "$$p" | sed "s|^$$srcdirstrip/||"`;; \
+    *) f=$$p;; \
+  esac;
+am__strip_dir = f=`echo $$p | sed -e 's|^.*/||'`;
+am__install_max = 40
+am__nobase_strip_setup = \
+  srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*|]/\\\\&/g'`
+am__nobase_strip = \
+  for p in $$list; do echo "$$p"; done | sed -e "s|$$srcdirstrip/||"
+am__nobase_list = $(am__nobase_strip_setup); \
+  for p in $$list; do echo "$$p $$p"; done | \
+  sed "s| $$srcdirstrip/| |;"' / .*\//!s/ .*/ ./; s,\( .*\)/[^/]*$$,\1,' | \
+  $(AWK) 'BEGIN { files["."] = "" } { files[$$2] = files[$$2] " " $$1; \
+    if (++n[$$2] == $(am__install_max)) \
+      { print $$2, files[$$2]; n[$$2] = 0; files[$$2] = "" } } \
+    END { for (dir in files) print dir, files[dir] }'
+am__base_list = \
+  sed '$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;$$!N;s/\n/ /g' | \
+  sed '$$!N;$$!N;$$!N;$$!N;s/\n/ /g'
+am__uninstall_files_from_dir = { \
+  test -z "$$files" \
+    || { test ! -d "$$dir" && test ! -f "$$dir" && test ! -r "$$dir"; } \
+    || { echo " ( cd '$$dir' && rm -f" $$files ")"; \
+         $(am__cd) "$$dir" && rm -f $$files; }; \
+  }
+am__installdirs = "$(DESTDIR)$(confdir)" "$(DESTDIR)$(examplesdir)"
+DATA = $(conf_DATA) $(examples_DATA)
+am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) $(LISP)
+DISTFILES = $(DIST_COMMON) $(DIST_SOURCES) $(TEXINFOS) $(EXTRA_DIST)
+ACLOCAL = @ACLOCAL@
+AMTAR = @AMTAR@
+AM_DEFAULT_VERBOSITY = @AM_DEFAULT_VERBOSITY@
+AR = @AR@
+AUTOCONF = @AUTOCONF@
+AUTOHEADER = @AUTOHEADER@
+AUTOMAKE = @AUTOMAKE@
+AWK = @AWK@
+CC = @CC@
+CCDEPMODE = @CCDEPMODE@
+CFLAGS = @CFLAGS@
+CPP = @CPP@
+CPPFLAGS = @CPPFLAGS@
+CYGPATH_W = @CYGPATH_W@
+DEFAULT_GROUP = @DEFAULT_GROUP@
+DEFS = @DEFS@
+DEPDIR = @DEPDIR@
+DLLTOOL = @DLLTOOL@
+DSYMUTIL = @DSYMUTIL@
+DUMPBIN = @DUMPBIN@
+ECHO_C = @ECHO_C@
+ECHO_N = @ECHO_N@
+ECHO_T = @ECHO_T@
+EGREP = @EGREP@
+EXEEXT = @EXEEXT@
+FGREP = @FGREP@
+GREP = @GREP@
+INSTALL = @INSTALL@
+INSTALL_DATA = @INSTALL_DATA@
+INSTALL_PROGRAM = @INSTALL_PROGRAM@
+INSTALL_SCRIPT = @INSTALL_SCRIPT@
+INSTALL_STRIP_PROGRAM = @INSTALL_STRIP_PROGRAM@
+LD = @LD@
+LDFLAGS = @LDFLAGS@
+LIBOBJS = @LIBOBJS@
+LIBS = @LIBS@
+LIBTOOL = @LIBTOOL@
+LIBTOOL_DEPS = @LIBTOOL_DEPS@
+LIPO = @LIPO@
+LN_S = @LN_S@
+LTLIBOBJS = @LTLIBOBJS@
+MAKEINFO = @MAKEINFO@
+MANIFEST_TOOL = @MANIFEST_TOOL@
+MKDIR_P = @MKDIR_P@
+NM = @NM@
+NMEDIT = @NMEDIT@
+OBJDUMP = @OBJDUMP@
+OBJEXT = @OBJEXT@
+OTOOL = @OTOOL@
+OTOOL64 = @OTOOL64@
+PACKAGE = @PACKAGE@
+PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
+PACKAGE_NAME = @PACKAGE_NAME@
+PACKAGE_STRING = @PACKAGE_STRING@
+PACKAGE_TARNAME = @PACKAGE_TARNAME@
+PACKAGE_URL = @PACKAGE_URL@
+PACKAGE_VERSION = @PACKAGE_VERSION@
+PATH_SEPARATOR = @PATH_SEPARATOR@
+PTHREAD_CC = @PTHREAD_CC@
+PTHREAD_CFLAGS = @PTHREAD_CFLAGS@
+PTHREAD_LIBS = @PTHREAD_LIBS@
+RANDOM_FILE = @RANDOM_FILE@
+RANLIB = @RANLIB@
+SED = @SED@
+SET_MAKE = @SET_MAKE@
+SHELL = @SHELL@
+SSLDIR = @SSLDIR@
+STRIP = @STRIP@
+VERSION = @VERSION@
+abs_builddir = @abs_builddir@
+abs_srcdir = @abs_srcdir@
+abs_top_builddir = @abs_top_builddir@
+abs_top_srcdir = @abs_top_srcdir@
+ac_ct_AR = @ac_ct_AR@
+ac_ct_CC = @ac_ct_CC@
+ac_ct_DUMPBIN = @ac_ct_DUMPBIN@
+am__include = @am__include@
+am__leading_dot = @am__leading_dot@
+am__quote = @am__quote@
+am__tar = @am__tar@
+am__untar = @am__untar@
+ax_pthread_config = @ax_pthread_config@
+bindir = @bindir@
+build = @build@
+build_alias = @build_alias@
+build_cpu = @build_cpu@
+build_os = @build_os@
+build_vendor = @build_vendor@
+builddir = @builddir@
+datadir = @datadir@
+datarootdir = @datarootdir@
+docdir = $(datadir)/doc/stunnel
+dvidir = @dvidir@
+exec_prefix = @exec_prefix@
+host = @host@
+host_alias = @host_alias@
+host_cpu = @host_cpu@
+host_os = @host_os@
+host_vendor = @host_vendor@
+htmldir = @htmldir@
+includedir = @includedir@
+infodir = @infodir@
+install_sh = @install_sh@
+libdir = @libdir@
+libexecdir = @libexecdir@
+localedir = @localedir@
+localstatedir = @localstatedir@
+mandir = @mandir@
+mkdir_p = @mkdir_p@
+oldincludedir = @oldincludedir@
+pdfdir = @pdfdir@
+prefix = @prefix@
+program_transform_name = @program_transform_name@
+psdir = @psdir@
+sbindir = @sbindir@
+sharedstatedir = @sharedstatedir@
+srcdir = @srcdir@
+sysconfdir = @sysconfdir@
+target_alias = @target_alias@
+top_build_prefix = @top_build_prefix@
+top_builddir = @top_builddir@
+top_srcdir = @top_srcdir@
+EXTRA_DIST = ca.html ca.pl importCA.html importCA.sh script.sh \
+	stunnel.spec stunnel.cnf stunnel.nsi stunnel.license stunnel.conf \
+	stunnel.conf-sample.in stunnel.init.in stunnel.service.in
+
+confdir = $(sysconfdir)/stunnel
+conf_DATA = stunnel.conf-sample
+examplesdir = $(docdir)/examples
+examples_DATA = stunnel.spec stunnel.init stunnel.service ca.html \
+	ca.pl importCA.html importCA.sh script.sh
+CLEANFILES = stunnel.conf-sample stunnel.init stunnel.service
+OPENSSL = $(SSLDIR)/bin/openssl
+edit = sed \
+	-e 's|@prefix[@]|$(prefix)|g' \
+	-e 's|@bindir[@]|$(bindir)|g' \
+	-e 's|@localstatedir[@]|$(localstatedir)|g' \
+	-e 's|@sysconfdir[@]|$(sysconfdir)|g' \
+	-e 's|@DEFAULT_GROUP[@]|$(DEFAULT_GROUP)|g'
+
+all: all-am
+
+.SUFFIXES:
+$(srcdir)/Makefile.in:  $(srcdir)/Makefile.am  $(am__configure_deps)
+	@for dep in $?; do \
+	  case '$(am__configure_deps)' in \
+	    *$$dep*) \
+	      ( cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh ) \
+	        && { if test -f $@; then exit 0; else break; fi; }; \
+	      exit 1;; \
+	  esac; \
+	done; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu tools/Makefile'; \
+	$(am__cd) $(top_srcdir) && \
+	  $(AUTOMAKE) --gnu tools/Makefile
+.PRECIOUS: Makefile
+Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
+	@case '$?' in \
+	  *config.status*) \
+	    cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh;; \
+	  *) \
+	    echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe)'; \
+	    cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe);; \
+	esac;
+
+$(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+
+$(top_srcdir)/configure:  $(am__configure_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(ACLOCAL_M4):  $(am__aclocal_m4_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(am__aclocal_m4_deps):
+
+mostlyclean-libtool:
+	-rm -f *.lo
+
+clean-libtool:
+	-rm -rf .libs _libs
+install-confDATA: $(conf_DATA)
+	@$(NORMAL_INSTALL)
+	@list='$(conf_DATA)'; test -n "$(confdir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(confdir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(confdir)" || exit 1; \
+	fi; \
+	for p in $$list; do \
+	  if test -f "$$p"; then d=; else d="$(srcdir)/"; fi; \
+	  echo "$$d$$p"; \
+	done | $(am__base_list) | \
+	while read files; do \
+	  echo " $(INSTALL_DATA) $$files '$(DESTDIR)$(confdir)'"; \
+	  $(INSTALL_DATA) $$files "$(DESTDIR)$(confdir)" || exit $$?; \
+	done
+
+uninstall-confDATA:
+	@$(NORMAL_UNINSTALL)
+	@list='$(conf_DATA)'; test -n "$(confdir)" || list=; \
+	files=`for p in $$list; do echo $$p; done | sed -e 's|^.*/||'`; \
+	dir='$(DESTDIR)$(confdir)'; $(am__uninstall_files_from_dir)
+install-examplesDATA: $(examples_DATA)
+	@$(NORMAL_INSTALL)
+	@list='$(examples_DATA)'; test -n "$(examplesdir)" || list=; \
+	if test -n "$$list"; then \
+	  echo " $(MKDIR_P) '$(DESTDIR)$(examplesdir)'"; \
+	  $(MKDIR_P) "$(DESTDIR)$(examplesdir)" || exit 1; \
+	fi; \
+	for p in $$list; do \
+	  if test -f "$$p"; then d=; else d="$(srcdir)/"; fi; \
+	  echo "$$d$$p"; \
+	done | $(am__base_list) | \
+	while read files; do \
+	  echo " $(INSTALL_DATA) $$files '$(DESTDIR)$(examplesdir)'"; \
+	  $(INSTALL_DATA) $$files "$(DESTDIR)$(examplesdir)" || exit $$?; \
+	done
+
+uninstall-examplesDATA:
+	@$(NORMAL_UNINSTALL)
+	@list='$(examples_DATA)'; test -n "$(examplesdir)" || list=; \
+	files=`for p in $$list; do echo $$p; done | sed -e 's|^.*/||'`; \
+	dir='$(DESTDIR)$(examplesdir)'; $(am__uninstall_files_from_dir)
+tags TAGS:
+
+ctags CTAGS:
+
+cscope cscopelist:
+
+
+distdir: $(DISTFILES)
+	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	list='$(DISTFILES)'; \
+	  dist_files=`for file in $$list; do echo $$file; done | \
+	  sed -e "s|^$$srcdirstrip/||;t" \
+	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
+	case $$dist_files in \
+	  */*) $(MKDIR_P) `echo "$$dist_files" | \
+			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sort -u` ;; \
+	esac; \
+	for file in $$dist_files; do \
+	  if test -f $$file || test -d $$file; then d=.; else d=$(srcdir); fi; \
+	  if test -d $$d/$$file; then \
+	    dir=`echo "/$$file" | sed -e 's,/[^/]*$$,,'`; \
+	    if test -d "$(distdir)/$$file"; then \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    if test -d $(srcdir)/$$file && test $$d != $(srcdir); then \
+	      cp -fpR $(srcdir)/$$file "$(distdir)$$dir" || exit 1; \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    cp -fpR $$d/$$file "$(distdir)$$dir" || exit 1; \
+	  else \
+	    test -f "$(distdir)/$$file" \
+	    || cp -p $$d/$$file "$(distdir)/$$file" \
+	    || exit 1; \
+	  fi; \
+	done
+check-am: all-am
+check: check-am
+all-am: Makefile $(DATA)
+installdirs:
+	for dir in "$(DESTDIR)$(confdir)" "$(DESTDIR)$(examplesdir)"; do \
+	  test -z "$$dir" || $(MKDIR_P) "$$dir"; \
+	done
+install: install-am
+install-exec: install-exec-am
+install-data: install-data-am
+uninstall: uninstall-am
+
+install-am: all-am
+	@$(MAKE) $(AM_MAKEFLAGS) install-exec-am install-data-am
+
+installcheck: installcheck-am
+install-strip:
+	if test -z '$(STRIP)'; then \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	      install; \
+	else \
+	  $(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	    install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	    "INSTALL_PROGRAM_ENV=STRIPPROG='$(STRIP)'" install; \
+	fi
+mostlyclean-generic:
+
+clean-generic:
+	-test -z "$(CLEANFILES)" || rm -f $(CLEANFILES)
+
+distclean-generic:
+	-test -z "$(CONFIG_CLEAN_FILES)" || rm -f $(CONFIG_CLEAN_FILES)
+	-test . = "$(srcdir)" || test -z "$(CONFIG_CLEAN_VPATH_FILES)" || rm -f $(CONFIG_CLEAN_VPATH_FILES)
+
+maintainer-clean-generic:
+	@echo "This command is intended for maintainers to use"
+	@echo "it deletes files that may require special tools to rebuild."
+clean: clean-am
+
+clean-am: clean-generic clean-libtool mostlyclean-am
+
+distclean: distclean-am
+	-rm -f Makefile
+distclean-am: clean-am distclean-generic
+
+dvi: dvi-am
+
+dvi-am:
+
+html: html-am
+
+html-am:
+
+info: info-am
+
+info-am:
+
+install-data-am: install-confDATA install-data-local \
+	install-examplesDATA
+
+install-dvi: install-dvi-am
+
+install-dvi-am:
+
+install-exec-am:
+
+install-html: install-html-am
+
+install-html-am:
+
+install-info: install-info-am
+
+install-info-am:
+
+install-man:
+
+install-pdf: install-pdf-am
+
+install-pdf-am:
+
+install-ps: install-ps-am
+
+install-ps-am:
+
+installcheck-am:
+
+maintainer-clean: maintainer-clean-am
+	-rm -f Makefile
+maintainer-clean-am: distclean-am maintainer-clean-generic
+
+mostlyclean: mostlyclean-am
+
+mostlyclean-am: mostlyclean-generic mostlyclean-libtool
+
+pdf: pdf-am
+
+pdf-am:
+
+ps: ps-am
+
+ps-am:
+
+uninstall-am: uninstall-confDATA uninstall-examplesDATA
+
+.MAKE: install-am install-strip
+
+.PHONY: all all-am check check-am clean clean-generic clean-libtool \
+	cscopelist-am ctags-am distclean distclean-generic \
+	distclean-libtool distdir dvi dvi-am html html-am info info-am \
+	install install-am install-confDATA install-data \
+	install-data-am install-data-local install-dvi install-dvi-am \
+	install-examplesDATA install-exec install-exec-am install-html \
+	install-html-am install-info install-info-am install-man \
+	install-pdf install-pdf-am install-ps install-ps-am \
+	install-strip installcheck installcheck-am installdirs \
+	maintainer-clean maintainer-clean-generic mostlyclean \
+	mostlyclean-generic mostlyclean-libtool pdf pdf-am ps ps-am \
+	tags-am uninstall uninstall-am uninstall-confDATA \
+	uninstall-examplesDATA
+
+
+install-data-local:
+	${INSTALL} -d -m 1770 $(DESTDIR)$(localstatedir)/lib/stunnel
+	-chgrp $(DEFAULT_GROUP) $(DESTDIR)$(localstatedir)/lib/stunnel
+
+cert:
+	@if test -r $(DESTDIR)$(confdir)/stunnel.pem; \
+	then \
+		echo "$(DESTDIR)$(confdir)/stunnel.pem already exists"; \
+	else \
+		if test -r "$(RANDOM_FILE)"; then \
+			dd if="$(RANDOM_FILE)" of=stunnel.rnd bs=256 count=1; \
+			RND="-rand stunnel.rnd"; \
+		else \
+			RND=""; \
+		fi; \
+		$(OPENSSL) req -new -x509 -days 365 $$RND \
+			-config $(srcdir)/stunnel.cnf \
+			-out stunnel.pem -keyout stunnel.pem; \
+		$(OPENSSL) x509 -subject -dates -fingerprint -noout -in stunnel.pem; \
+		${INSTALL} -m 600 stunnel.pem $(DESTDIR)$(confdir)/stunnel.pem; \
+		rm stunnel.pem; \
+		rm -f stunnel.rnd; \
+	fi
+
+stunnel.conf-sample stunnel.init stunnel.service: Makefile
+	$(edit) '$(srcdir)/$@.in' >$@
+
+stunnel.conf-sample: $(srcdir)/stunnel.conf-sample.in
+stunnel.init: $(srcdir)/stunnel.init.in
+stunnel.service: $(srcdir)/stunnel.service.in
+
+# Tell versions [3.59,3.63) of GNU make to not export all variables.
+# Otherwise a system limit (for SysV at least) may be exceeded.
+.NOEXPORT:
diff --git a/tools/ca.html b/tools/ca.html
new file mode 100644
index 0000000..cf25736
--- /dev/null
+++ b/tools/ca.html
@@ -0,0 +1,56 @@
+<HTML>
+<HEAD>
+   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
+   <TITLE>Make your own certificate</TITLE>
+</HEAD>
+<BODY TEXT="#000000" BGCOLOR="#FFFFCC" LINK="#0000EF" VLINK="#51188E" ALINK="#FF0000">
+<FORM ACTION="http://localhost/cgi-bin/ca.pl" METHOD=POST>
+<TABLE>
+
+<TR>
+<TD>Key bits:</TD>
+<TD><KEYGEN NAME="SPKAC"></TD>
+</TR>
+
+<TR>
+<TD>Your name:</TD>
+
+<TD><INPUT NAME="who" SIZE="40" MAXLENGTH=60 ALIGN=middle></TD>
+</TR>
+
+<TR>
+<TD>Your e-mail address:</TD>
+
+<TD><INPUT NAME="email" SIZE="40" MAXLENGTH=40 ALIGN=middle></TD>
+</TR>
+
+<TR>
+<TD>Country name:</TD>
+
+<TD><INPUT NAME="country" SIZE="40" MAXLENGTH=150 ALIGN=middle></TD>
+</TR>
+
+<TR>
+<TD>State or province name:</TD>
+
+<TD><INPUT NAME="state" SIZE="40" MAXLENGTH=40 ALIGN=middle></TD>
+</TR>
+
+<TR>
+<TD>Organization:</TD>
+
+<TD><INPUT NAME="organization" SIZE="40" MAXLENGTH=60 ALIGN=middle></TD>
+</TR>
+
+<TR>
+<TD>Comment:</TD>
+
+<TD><INPUT NAME="comment" SIZE="40" MAXLENGTH=40 ALIGN=middle></TD>
+</TR>
+</TABLE>
+
+<H3>
+<INPUT TYPE=submit VALUE="   Submit  ">&nbsp;<INPUT TYPE=reset VALUE="   Reset All   "></H3>
+</FORM>
+</BODY>
+</HTML>
diff --git a/tools/ca.pl b/tools/ca.pl
new file mode 100755
index 0000000..cea08f4
--- /dev/null
+++ b/tools/ca.pl
@@ -0,0 +1,65 @@
+#!/usr/bin/perl
+
+$config   = "/var/openssl/openssl.cnf";
+$capath   = "/usr/bin/openssl ca";
+$certpass = "mypassword";
+$tempca   = "/tmp/ssl/cli".rand 10000;
+$tempout  = "/tmp/ssl/certtmp".rand 10000;
+$caout    = "/tmp/ssl/certout.txt";
+$CAcert   = "/var/openssl/localCA/cacert.pem";
+$spkac	  = "";
+
+&ReadForm;
+
+$spkac = $FIELDS{'SPKAC'};
+$spkac =~ s/\n//g;
+
+open(TEMPCE,">$tempca") || die &Error;
+print TEMPCE "C = $FIELDS{'country'}\n";
+print TEMPCE "ST = $FIELDS{'state'}\n";
+print TEMPCE "O = $FIELDS{'organization'}\n";
+print TEMPCE "Email = $FIELDS{'email'}\n";
+print TEMPCE "CN = $FIELDS{'who'}\n";
+print TEMPCE "SPKAC = $spkac\n";
+close(TEMPCE);                         
+
+system("$capath -batch -config $config -spkac $tempca -out $tempout -key $certpass -cert $CAcert>> $caout 2>&1"); 
+open(CERT,"$tempout") || die &Error;
+@certificate = <CERT>;
+close(CERT);
+
+#system("rm -f $tempca");
+#system("rm -f $tempout");
+
+print "Content-type: application/x-x509-user-cert\n\n";
+print @certificate;
+
+##############################################################
+####
+####     Procedures
+####
+
+sub ReadForm {
+
+   if ($ENV{'REQUEST_METHOD'} eq 'GET') {
+      @pairs = split(/&/, $ENV{'QUERY_STRING'});
+   }
+   elsif ($ENV{'REQUEST_METHOD'} eq 'POST') {
+      read(STDIN, $buffer, $ENV{'CONTENT_LENGTH'});
+      @pairs = split(/&/, $buffer);
+   }
+   foreach $pair (@pairs) {
+      ($name, $value) = split(/=/, $pair);
+      $name =~ tr/+/ /;
+      $name =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg;
+      $value =~ tr/+/ /;
+      $value =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg;
+      $value =~ s/<!--(.|\n)*-->//g;
+      $FIELDS{$name} = $value;
+      }
+}
+
+sub Error {
+    print "Content-type: text/html\n\n";
+    print "<P><P><center><H1>Can't open file</H1></center>\n";
+}
diff --git a/tools/importCA.html b/tools/importCA.html
new file mode 100644
index 0000000..dd1feab
--- /dev/null
+++ b/tools/importCA.html
@@ -0,0 +1,16 @@
+<HTML>
+<HEAD>
+   <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
+   <TITLE>Import CA root certificate</TITLE>
+</HEAD>
+<BODY TEXT="#000000" BGCOLOR="#FFFFCC" LINK="#0000EF" VLINK="#51188E" ALINK="#FF0000">
+&nbsp;
+<BR>&nbsp;
+<BR>&nbsp;
+<BR>&nbsp;
+<BR>&nbsp;
+<CENTER><FONT SIZE=+2><A HREF="http://localhost/cgi-bin/importCA.sh">Import
+CA certificate</A></FONT></CENTER>
+
+</BODY>
+</HTML>
diff --git a/tools/importCA.sh b/tools/importCA.sh
new file mode 100755
index 0000000..e492fe2
--- /dev/null
+++ b/tools/importCA.sh
@@ -0,0 +1,5 @@
+#!/bin/bash
+
+echo "Content-type: application/x-x509-ca-cert"
+echo
+cat /var/lib/httpds/cgi-bin/cacert.pem
diff --git a/tools/script.sh b/tools/script.sh
new file mode 100755
index 0000000..d362c23
--- /dev/null
+++ b/tools/script.sh
@@ -0,0 +1,11 @@
+#!/bin/bash
+
+REMOTE_HOST="www.mirt.net:443"
+echo "client script connecting $REMOTE_HOST"
+/usr/local/bin/stunnel -fd 10 \
+    11<&0 <<EOT 10<&0 0<&11 11<&-
+client=yes
+connect=$REMOTE_HOST
+EOT
+echo "client script finished"
+
diff --git a/tools/stunnel.cnf b/tools/stunnel.cnf
new file mode 100644
index 0000000..5398221
--- /dev/null
+++ b/tools/stunnel.cnf
@@ -0,0 +1,47 @@
+# OpenSSL configuration file to create a server certificate

+# by Michal Trojnara 1998-2015

+

+[ req ]

+# comment out the next line to protect the private key with a passphrase

+encrypt_key                     = no

+# the default key length is secure and quite fast - do not change it

+default_bits                    = 2048

+default_md                      = sha1

+x509_extensions                 = stunnel_extensions

+distinguished_name              = stunnel_dn

+

+[ stunnel_extensions ]

+nsCertType                      = server

+basicConstraints                = CA:TRUE,pathlen:0

+keyUsage                        = keyCertSign

+extendedKeyUsage                = serverAuth

+nsComment                       = "stunnel self-signed certificate"

+

+[ stunnel_dn ]

+countryName = Country Name (2 letter code)

+countryName_default             = PL

+countryName_min                 = 2

+countryName_max                 = 2

+

+stateOrProvinceName             = State or Province Name (full name)

+stateOrProvinceName_default     = Mazovia Province

+

+localityName                    = Locality Name (eg, city)

+localityName_default            = Warsaw

+

+organizationName                = Organization Name (eg, company)

+organizationName_default        = Stunnel Developers

+

+organizationalUnitName          = Organizational Unit Name (eg, section)

+organizationalUnitName_default  = Provisional CA

+

+0.commonName                    = Common Name (FQDN of your server)

+0.commonName_default            = localhost

+

+# To create a certificate for more than one name uncomment:

+# 1.commonName                  = DNS alias of your server

+# 2.commonName                  = DNS alias of your server

+# ...

+# See http://home.netscape.com/eng/security/ssl_2.0_certificate.html

+# to see how Netscape understands commonName.

+

diff --git a/tools/stunnel.conf b/tools/stunnel.conf
new file mode 100644
index 0000000..934f78f
--- /dev/null
+++ b/tools/stunnel.conf
@@ -0,0 +1,116 @@
+; Sample stunnel configuration file for Win32 by Michal Trojnara 2002-2015

+; Some options used here may be inadequate for your particular configuration

+; This sample file does *not* represent stunnel.conf defaults

+; Please consult the manual for detailed description of available options

+

+; **************************************************************************

+; * Global options                                                         *

+; **************************************************************************

+

+; Debugging stuff (may be useful for troubleshooting)

+;debug = info

+;output = stunnel.log

+

+; Enable FIPS 140-2 mode if needed for compliance

+;fips = yes

+

+; Microsoft CryptoAPI engine allows for authentication with private keys

+; stored in the Windows certificate store

+; Each section using this feature also needs the "engineId = capi" option

+;engine = capi

+

+; **************************************************************************

+; * Service defaults may also be specified in individual service sections  *

+; **************************************************************************

+

+; Enable support for the insecure SSLv3 protocol

+;options = -NO_SSLv3

+

+; These options provide additional security at some performance degradation

+;options = SINGLE_ECDH_USE

+;options = SINGLE_DH_USE

+

+; **************************************************************************

+; * Include all configuration file fragments from the specified folder     *

+; **************************************************************************

+

+;include = conf.d

+

+; **************************************************************************

+; * Service definitions (at least one service has to be defined)           *

+; **************************************************************************

+

+; ***************************************** Example TLS client mode services

+

+[gmail-pop3]

+client = yes

+accept = 127.0.0.1:110

+connect = pop.gmail.com:995

+verify = 2

+CAfile = ca-certs.pem

+checkHost = pop.gmail.com

+OCSPaia = yes

+

+[gmail-imap]

+client = yes

+accept = 127.0.0.1:143

+connect = imap.gmail.com:993

+verify = 2

+CAfile = ca-certs.pem

+checkHost = imap.gmail.com

+OCSPaia = yes

+

+[gmail-smtp]

+client = yes

+accept = 127.0.0.1:25

+connect = smtp.gmail.com:465

+verify = 2

+CAfile = ca-certs.pem

+checkHost = smtp.gmail.com

+OCSPaia = yes

+

+; Encrypted HTTP proxy authenticated with a client certificate

+; located in the Windows certificate store

+;[example-proxy]

+;client = yes

+;accept = 127.0.0.1:8080

+;connect = example.com:8443

+;engineId = capi

+

+; ***************************************** Example TLS server mode services

+

+;[pop3s]

+;accept  = 995

+;connect = 110

+;cert = stunnel.pem

+

+;[imaps]

+;accept  = 993

+;connect = 143

+;cert = stunnel.pem

+

+;[ssmtp]

+;accept  = 465

+;connect = 25

+;cert = stunnel.pem

+

+; TLS front-end to a web server

+;[https]

+;accept  = 443

+;connect = 80

+;cert = stunnel.pem

+; "TIMEOUTclose = 0" is a workaround for a design flaw in Microsoft SChannel

+; Microsoft implementations do not use TLS close-notify alert and thus they

+; are vulnerable to truncation attacks

+;TIMEOUTclose = 0

+

+; Remote cmd.exe protected with PSK-authenticated TLS

+; Create "secrets.txt" containing IDENTITY:KEY pairs

+;[cmd]

+;accept = 1337

+;exec = c:\windows\system32\cmd.exe

+;execArgs = cmd.exe

+;ciphers = PSK

+;PSKsecrets = secrets.txt

+

+; vim:ft=dosini

diff --git a/tools/stunnel.conf-sample.in b/tools/stunnel.conf-sample.in
new file mode 100644
index 0000000..dc98200
--- /dev/null
+++ b/tools/stunnel.conf-sample.in
@@ -0,0 +1,116 @@
+; Sample stunnel configuration file for Unix by Michal Trojnara 2002-2015
+; Some options used here may be inadequate for your particular configuration
+; This sample file does *not* represent stunnel.conf defaults
+; Please consult the manual for detailed description of available options
+
+; **************************************************************************
+; * Global options                                                         *
+; **************************************************************************
+
+; It is recommended to drop root privileges if stunnel is started by root
+;setuid = nobody
+;setgid = @DEFAULT_GROUP@
+
+; PID file is created inside the chroot jail (if enabled)
+;pid = @localstatedir@/run/stunnel.pid
+
+; Debugging stuff (may be useful for troubleshooting)
+;foreground = yes
+;debug = info
+;output = @localstatedir@/log/stunnel.log
+
+; Enable FIPS 140-2 mode if needed for compliance
+;fips = yes
+
+; **************************************************************************
+; * Service defaults may also be specified in individual service sections  *
+; **************************************************************************
+
+; Enable support for the insecure SSLv3 protocol
+;options = -NO_SSLv3
+
+; These options provide additional security at some performance degradation
+;options = SINGLE_ECDH_USE
+;options = SINGLE_DH_USE
+
+; **************************************************************************
+; * Include all configuration file fragments from the specified folder     *
+; **************************************************************************
+
+;include = @sysconfdir@/stunnel/conf.d
+
+; **************************************************************************
+; * Service definitions (remove all services for inetd mode)               *
+; **************************************************************************
+
+; ***************************************** Example TLS client mode services
+
+; The following examples use /etc/ssl/certs, which is the common location
+; of a hashed directory containing trusted CA certificates.  This is not
+; a hardcoded path of the stunnel package, as it is not related to the
+; stunnel configuration in @sysconfdir@/stunnel/.
+
+[gmail-pop3]
+client = yes
+accept = 127.0.0.1:110
+connect = pop.gmail.com:995
+verify = 2
+CApath = /etc/ssl/certs
+checkHost = pop.gmail.com
+OCSPaia = yes
+
+[gmail-imap]
+client = yes
+accept = 127.0.0.1:143
+connect = imap.gmail.com:993
+verify = 2
+CApath = /etc/ssl/certs
+checkHost = imap.gmail.com
+OCSPaia = yes
+
+[gmail-smtp]
+client = yes
+accept = 127.0.0.1:25
+connect = smtp.gmail.com:465
+verify = 2
+CApath = /etc/ssl/certs
+checkHost = smtp.gmail.com
+OCSPaia = yes
+
+; ***************************************** Example TLS server mode services
+
+;[pop3s]
+;accept  = 995
+;connect = 110
+;cert = @sysconfdir@/stunnel/stunnel.pem
+
+;[imaps]
+;accept  = 993
+;connect = 143
+;cert = @sysconfdir@/stunnel/stunnel.pem
+
+;[ssmtp]
+;accept  = 465
+;connect = 25
+;cert = @sysconfdir@/stunnel/stunnel.pem
+
+; TLS front-end to a web server
+;[https]
+;accept  = 443
+;connect = 80
+;cert = @sysconfdir@/stunnel/stunnel.pem
+; "TIMEOUTclose = 0" is a workaround for a design flaw in Microsoft SChannel
+; Microsoft implementations do not use TLS close-notify alert and thus they
+; are vulnerable to truncation attacks
+;TIMEOUTclose = 0
+
+; Remote shell protected with PSK-authenticated TLS
+; Create "@sysconfdir@/stunnel/secrets.txt" containing IDENTITY:KEY pairs
+;[shell]
+;accept = 1337
+;exec = /bin/sh
+;execArgs = sh -i
+;ciphers = PSK
+;PSKsecrets = @sysconfdir@/stunnel/secrets.txt
+
+; vim:ft=dosini
diff --git a/tools/stunnel.init.in b/tools/stunnel.init.in
new file mode 100644
index 0000000..8909635
--- /dev/null
+++ b/tools/stunnel.init.in
@@ -0,0 +1,204 @@
+#! /bin/sh -e
+### BEGIN INIT INFO
+# Provides:          stunnel
+# Required-Start:    $local_fs $remote_fs
+# Required-Stop:     $local_fs $remote_fs
+# Should-Start:      $syslog
+# Should-Stop:       $syslog
+# Default-Start:     2 3 4 5
+# Default-Stop:      0 1 6
+# Short-Description: Start or stop stunnel 4.x (SSL tunnel for network daemons)
+# Description:       Starts or stops all configured SSL network tunnels. Each *.conf file in
+#                    /etc/stunnel/ will spawn a separate stunnel process. The list of files
+#                    can be overriden in /etc/default/stunnel, and that same file can be used
+#                    to completely disable *all* tunnels.
+### END INIT INFO
+
+. /lib/lsb/init-functions
+
+DEFAULTPIDFILE="/var/run/stunnel.pid"
+DAEMON=@bindir@/stunnel
+NAME=stunnel
+DESC="SSL tunnels"
+OPTIONS=""
+ENABLED=0
+
+get_opt() {
+  sed -e "s;^[[:space:]]*;;" -e "s;[[:space:]]*$;;" \
+    -e "s;[[:space:]]*=[[:space:]]*;=;" "$1" |
+    grep -i "^$2=" | sed -e "s;^[^=]*=;;"
+}
+
+get_pidfile() {
+  local file=$1
+  if [ -f $file ]; then
+    CHROOT=`get_opt $file chroot`
+    PIDFILE=`get_opt $file pid`
+    if [ "$PIDFILE" = "" ]; then
+      PIDFILE=$DEFAULTPIDFILE
+    fi
+    echo "$CHROOT/$PIDFILE"
+  fi
+}
+
+startdaemons() {
+  local res file args pidfile warn status
+
+  if ! [ -d /var/run/stunnel ]; then
+    rm -rf /var/run/stunnel
+    install -d -o stunnel -g stunnel /var/run/stunnel
+  fi
+  if [ -n "$RLIMITS" ]; then
+    ulimit $RLIMITS
+  fi
+  res=0
+  for file in $FILES; do 
+    if [ -f $file ]; then
+      echo -n " $file: "
+      args="$file $OPTIONS"
+      pidfile=`get_pidfile $file`
+      if egrep -qe '^pid[[:space:]]*=' "$file"; then
+        warn=''
+      else
+        warn=' (no pid=pidfile specified!)'
+      fi
+      status=0
+      start_daemon -p "$pidfile" "$DAEMON" $args || status=$?
+      if [ "$status" -eq 0 ]; then
+        echo -n "started$warn"
+      else
+        echo "failed$warn"
+        echo "You should check that you have specified the pid= in you configuration file"
+        res=1
+      fi
+    fi
+  done;
+  echo ''
+  return "$res"
+}
+
+killdaemons()
+{
+  local sig file pidfile status
+
+  sig=${1:-TERM}
+  res=0
+  for file in $FILES; do
+    echo -n " $file: "
+    pidfile=`get_pidfile $file`
+    if [ ! -e "$pidfile" ]; then
+      echo -n "no pid file"
+    else
+      status=0
+      killproc -p "$pidfile" "$DAEMON" "$sig" || status=$?
+      if [ "$status" -eq 0 ]; then
+        echo -n 'stopped'
+      else
+        echo -n 'failed'
+        res=1
+      fi
+    fi
+  done
+  echo ''
+  return "$res"
+}
+
+querydaemons()
+{
+  local res file pidfile status
+
+  res=0
+  for file in $FILES; do
+    echo -n " $file: "
+    pidfile=`get_pidfile "$file"`
+    if [ ! -e "$pidfile" ]; then
+      echo -n 'no pid file'
+      res=1
+    else
+      status=0
+      pidofproc -p "$pidfile" "$DAEMON" >/dev/null || status="$?"
+      if [ "$status" = 0 ]; then
+        echo -n 'running'
+      elif [ "$status" = 4 ]; then
+        echo "cannot access the pid file $pidfile"
+        res=1
+      else
+        echo -n 'stopped'
+        res=1
+      fi
+    fi
+  done
+  echo ''
+  exit "$res"
+}
+
+if [ "x$OPTIONS" != "x" ]; then
+  OPTIONS="-- $OPTIONS"
+fi
+
+[ -f @sysconfdir@/default/stunnel ] && . /etc/default/stunnel
+if [ "$ENABLED" = "0" ] ; then
+  echo "$DESC disabled, see @sysconfdir@/default/stunnel"
+  exit 0
+fi
+
+# If the user want to manage a single tunnel, the conf file's name
+# is in $2. Otherwise, respect /etc/default/stunnel4 setting. If no
+# setting there, use /etc/stunnel/*.conf
+if [ -n "${2:-}" ]; then
+  if [ -e "@sysconfdir@/stunnel/$2.conf" ]; then
+    FILES="@sysconfdir@/stunnel/$2.conf"
+  else
+    echo >&2 "@sysconfdir@/stunnel/$2.conf does not exist."
+    exit 1
+  fi
+else
+  if [ -z "$FILES" ]; then
+    FILES="@sysconfdir@/stunnel/*.conf"
+  fi
+fi
+
+[ -x $DAEMON ] || exit 0
+
+set -e
+
+res=0
+case "$1" in
+  start)
+    echo -n "Starting $DESC:"
+    startdaemons
+    res=$?
+    ;;
+  stop)
+    echo -n "Stopping $DESC:"
+    killdaemons
+    res=$?
+    ;;
+  reopen-logs)
+    echo -n "Reopening log files $DESC:"
+    killdaemons USR1
+    res=$?
+    ;;
+  force-reload|reload)
+    echo -n "Reloading configuration $DESC:"
+    killdaemons HUP
+    res=$?
+    ;;  
+  restart)
+    echo -n "Restarting $DESC:"
+    killdaemons && startdaemons
+    res=$?
+    ;;
+  status)
+    echo -n "$DESC status:"
+    querydaemons
+    res=$?
+    ;;
+  *)
+    N=@sysconfdir@/init.d/$NAME
+    echo "Usage: $N {start|stop|status|reload|reopen-logs|restart} [<stunnel instance>]" >&2
+    res=1
+    ;;
+esac
+
+exit "$res"
diff --git a/tools/stunnel.license b/tools/stunnel.license
new file mode 100644
index 0000000..102739a
--- /dev/null
+++ b/tools/stunnel.license
@@ -0,0 +1,13 @@
+Copyright (C) 1998-2015 Michal Trojnara
+
+This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
+
+This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
+
+You should have received a copy of the GNU General Public License along with this program; if not, see <http://www.gnu.org/licenses>.
+
+Linking stunnel statically or dynamically with other modules is making a combined work based on stunnel. Thus, the terms and conditions of the GNU General Public License cover the whole combination.
+
+In addition, as a special exception, the copyright holder of stunnel gives you permission to combine stunnel with free software programs or libraries that are released under the GNU LGPL and with code included in the standard release of OpenSSL under the OpenSSL License (or modified versions of such code, with unchanged license). You may copy and distribute such a system following the terms of the GNU GPL for stunnel and the licenses of the other code concerned.
+
+Note that people who make modified versions of stunnel are not obligated to grant this special exception for their modified versions; it is their choice whether to do so. The GNU General Public License gives permission to release a modified version without this exception; this exception also makes it possible to release a modified version which carries forward this exception.
diff --git a/tools/stunnel.nsi b/tools/stunnel.nsi
new file mode 100644
index 0000000..a7df5e3
--- /dev/null
+++ b/tools/stunnel.nsi
@@ -0,0 +1,423 @@
+# NSIS stunnel installer by Michal Trojnara 1998-2015

+

+!include "Sections.nsh"

+

+!ifndef VERSION

+!define VERSION 5.22

+!endif

+

+!ifndef ZLIBDIR

+!define ZLIBDIR zlib-1.2.8-win32

+!endif

+

+!ifndef OPENSSLDIR

+!define OPENSSLDIR openssl-1.0.2d-win32

+!endif

+

+!addplugindir "plugins/SimpleFC"

+!addplugindir "plugins/ShellLink/Plugins"

+

+Name "stunnel ${VERSION}"

+OutFile "stunnel-${VERSION}-installer.exe" 

+InstallDir "$PROGRAMFILES\stunnel"

+BrandingText "Author: Michal Trojnara" 

+LicenseData "stunnel.license"

+SetCompressor /SOLID LZMA

+InstallDirRegKey HKLM "Software\NSIS_stunnel" "Install_Dir"

+

+RequestExecutionLevel admin

+

+Page license

+Page components

+Page directory

+Page instfiles

+

+UninstPage uninstConfirm

+UninstPage instfiles

+

+Section "Stunnel Core Files (required)"

+  SectionIn RO

+  SetOutPath "$INSTDIR"

+

+  # stop the service, exit stunnel

+  Var /GLOBAL service

+  StrCpy $service 1

+  ReadRegStr $R0 HKLM \

+    "Software\Microsoft\Windows NT\CurrentVersion" CurrentVersion

+  IfErrors skip_service_stop

+  ExecWait '"$INSTDIR\stunnel.exe" -stop -quiet' $service

+skip_service_stop:

+  ExecWait '"$INSTDIR\stunnel.exe" -exit -quiet'

+

+  # write files

+  SetOverwrite off

+  File "stunnel.conf"

+  File "ca-certs.pem"

+  SetOverwrite on

+  !cd ".."

+  !cd "doc"

+  File "stunnel.html"

+  !cd ".."

+  !cd "bin"

+  !cd "win32"

+  File "stunnel.exe"

+  File "stunnel.exe.manifest"

+  !cd ".."

+  !cd ".."

+  !cd ".."

+  !cd "${ZLIBDIR}"

+  File "zlib1.dll"

+  File "zlib1.dll.manifest"

+  !cd ".."

+  !cd "${OPENSSLDIR}"

+  !cd "out32dll"

+  File "libeay32.dll"

+  File "libeay32.dll.manifest"

+  File "ssleay32.dll"

+  File "ssleay32.dll.manifest"

+  File "4758cca.dll"

+  File "4758cca.dll.manifest"

+  File "aep.dll"

+  File "aep.dll.manifest"

+  File "atalla.dll"

+  File "atalla.dll.manifest"

+  File "capi.dll"

+  File "capi.dll.manifest"

+  File "chil.dll"

+  File "chil.dll.manifest"

+  File "cswift.dll"

+  File "cswift.dll.manifest"

+  File "gmp.dll"

+  File "gmp.dll.manifest"

+  File "gost.dll"

+  File "gost.dll.manifest"

+  File "nuron.dll"

+  File "nuron.dll.manifest"

+  File "padlock.dll"

+  File "padlock.dll.manifest"

+  File "sureware.dll"

+  File "sureware.dll.manifest"

+  File "ubsec.dll"

+  File "ubsec.dll.manifest"

+

+  !cd ".."

+  !cd ".."

+  !cd "redist"

+  File "msvcr90.dll"

+  File "Microsoft.VC90.CRT.manifest"

+  !cd ".."

+  !cd "stunnel"

+  !cd "tools"

+  # MINGW builds requires libssp-0.dll instead of msvcr90.dll

+

+  # add firewall rule

+  SimpleFC::AddApplication "stunnel (GUI Version)" \

+    "$INSTDIR\stunnel.exe" 0 2 "" 1

+  Pop $0 # returns error(1)/success(0)

+  DetailPrint "SimpleFC::AddApplication: $0"

+

+  # write uninstaller and its registry entries

+  WriteUninstaller "uninstall.exe"

+  WriteRegStr HKLM "Software\NSIS_stunnel" "Install_Dir" "$INSTDIR"

+  WriteRegStr HKLM \

+    "Software\Microsoft\Windows\CurrentVersion\Uninstall\stunnel" \

+    "DisplayName" "stunnel"

+  WriteRegStr HKLM \

+    "Software\Microsoft\Windows\CurrentVersion\Uninstall\stunnel" \

+    "UninstallString" '"$INSTDIR\uninstall.exe"'

+  WriteRegDWORD HKLM \

+    "Software\Microsoft\Windows\CurrentVersion\Uninstall\stunnel" \

+    "NoModify" 1

+  WriteRegDWORD HKLM \

+    "Software\Microsoft\Windows\CurrentVersion\Uninstall\stunnel" \

+    "NoRepair" 1

+

+  # start the service

+  IntCmp $service 0 lbl_start_service lbl_skip_service lbl_skip_service

+lbl_start_service:

+  ExecWait '"$INSTDIR\stunnel.exe" -start -quiet'

+lbl_skip_service:

+SectionEnd

+

+Section "Self-signed Certificate Tools" sectionCA

+  SetOutPath "$INSTDIR"

+  !cd ".."

+  !cd ".."

+  !cd "${OPENSSLDIR}"

+  !cd "out32dll"

+  File "openssl.exe"

+  File "openssl.exe.manifest"

+  !cd ".."

+  !cd ".."

+  !cd "stunnel"

+  !cd "tools"

+  File "stunnel.cnf"

+  IfSilent lbl_skip_new_pem

+  IfFileExists "$INSTDIR\stunnel.pem" lbl_skip_new_pem

+  ReadEnvStr $0 "HOME"

+  StrCmp $0 "" lbl_home_defined 0

+  System::Call 'Kernel32::SetEnvironmentVariable(t, t) i("HOME", "$INSTDIR").r0'

+lbl_home_defined:

+  ExecWait '"$INSTDIR\openssl.exe" req -new -x509 -days 365 -config stunnel.cnf -out stunnel.pem -keyout stunnel.pem'

+lbl_skip_new_pem:

+SectionEnd

+

+Section "Terminal Version of stunnel" sectionTERM

+  SetOutPath "$INSTDIR"

+  !cd ".."

+  !cd "bin"

+  !cd "win32"

+  File "tstunnel.exe"

+  File "tstunnel.exe.manifest"

+  !cd ".."

+  !cd ".."

+  !cd "tools"

+  # add firewall rule

+  SimpleFC::AddApplication "stunnel (Terminal Version)" \

+    "$INSTDIR\tstunnel.exe" 0 2 "" 1

+  Pop $0 # returns error(1)/success(0)

+  DetailPrint "SimpleFC::AddApplication: $0"

+SectionEnd

+

+Section "Start Menu Shortcuts"

+  SetShellVarContext all

+  CreateDirectory "$SMPROGRAMS\stunnel"

+

+  # remove old links

+  Delete "$SMPROGRAMS\stunnel\*.lnk"

+  Delete "$SMPROGRAMS\stunnel\*.url"

+

+  # main link

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel GUI Start.lnk" \

+    "$INSTDIR\stunnel.exe" "" "$INSTDIR\stunnel.exe" 0

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel GUI Stop.lnk" \

+    "$INSTDIR\stunnel.exe" "-exit" "$INSTDIR\stunnel.exe" 0

+

+  # tstunnel

+  SectionGetFlags ${sectionTERM} $0

+  IntOp $0 $0 & ${SF_SELECTED}

+  IntCmp $0 0 lbl_noTERM

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Terminal Start.lnk" \

+    "$INSTDIR\tstunnel.exe" "" "$INSTDIR\tstunnel.exe" 0

+lbl_noTERM:

+

+  # NT service

+  ClearErrors

+  ReadRegStr $R0 HKLM \

+    "Software\Microsoft\Windows NT\CurrentVersion" CurrentVersion

+  IfErrors skip_service_links

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Install.lnk" \

+    "$INSTDIR\stunnel.exe" "-install" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Install.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Uninstall.lnk" \

+    "$INSTDIR\stunnel.exe" "-uninstall" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Uninstall.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Start.lnk" \

+    "$INSTDIR\stunnel.exe" "-start" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Start.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Stop.lnk" \

+    "$INSTDIR\stunnel.exe" "-stop" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Stop.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Configuration File Reload.lnk" \

+    "$INSTDIR\stunnel.exe" "-reload" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Configuration File Reload.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  CreateShortCut "$SMPROGRAMS\stunnel\stunnel Service Log File Reopen.lnk" \

+    "$INSTDIR\stunnel.exe" "-reopen" "$INSTDIR\stunnel.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\stunnel Service Log File Reopen.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+skip_service_links:

+

+  # edit config file

+  CreateShortCut "$SMPROGRAMS\stunnel\Edit stunnel.conf.lnk" \

+    "notepad.exe" "$INSTDIR\stunnel.conf" "notepad.exe" 0

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\Edit stunnel.conf.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+  SectionGetFlags ${sectionCA} $0

+  IntOp $0 $0 & ${SF_SELECTED}

+  IntCmp $0 0 lbl_noCA

+

+  # OpenSSL shell

+  CreateShortCut "$SMPROGRAMS\stunnel\OpenSSL Shell.lnk" \

+    "$INSTDIR\openssl.exe" "" "$INSTDIR\openssl.exe" 0

+

+  # make stunnel.pem

+  CreateShortCut "$SMPROGRAMS\stunnel\Build Self-signed stunnel.pem.lnk" \

+    "$INSTDIR\openssl.exe" \

+    "req -new -x509 -days 365 -config stunnel.cnf -out stunnel.pem -keyout stunnel.pem"

+  ShellLink::SetRunAsAdministrator \

+    "$SMPROGRAMS\stunnel\\Build Self-signed stunnel.pem.lnk"

+  Pop $0 # returns error(-1)/success(0)

+  DetailPrint "ShellLink::SetRunAsAdministrator: $0"

+

+lbl_noCA:

+

+  # help/uninstall

+  WriteINIStr "$SMPROGRAMS\stunnel\Manual.url" "InternetShortcut" \

+    "URL" "file://$INSTDIR/stunnel.html"

+  CreateShortCut "$SMPROGRAMS\stunnel\Uninstall stunnel.lnk" \

+    "$INSTDIR\uninstall.exe" "" "$INSTDIR\uninstall.exe" 0

+SectionEnd

+

+Section "Desktop Shortcut"

+  SetShellVarContext all

+  Delete "$DESKTOP\stunnel.lnk"

+  CreateShortCut "$DESKTOP\stunnel.lnk" \

+    "$INSTDIR\stunnel.exe" "" "$INSTDIR\stunnel.exe" 0

+SectionEnd

+

+Section /o "Debugging Symbols"

+  SetOutPath "$INSTDIR"

+  !cd ".."

+  !cd "bin"

+  !cd "win32"

+  File "stunnel.pdb"

+  File "tstunnel.pdb"

+  !cd ".."

+  !cd ".."

+  !cd ".."

+  !cd "${ZLIBDIR}"

+  File "zlib1.pdb"

+  !cd ".."

+  !cd "${OPENSSLDIR}"

+  !cd "out32dll"

+  File "libeay32.pdb"

+  File "ssleay32.pdb"

+  File "openssl.pdb"

+  File "4758cca.pdb"

+  File "aep.pdb"

+  File "atalla.pdb"

+  File "capi.pdb"

+  File "chil.pdb"

+  File "cswift.pdb"

+  File "gmp.pdb"

+  File "gost.pdb"

+  File "nuron.pdb"

+  File "padlock.pdb"

+  File "sureware.pdb"

+  File "ubsec.pdb"

+  !cd ".."

+  !cd ".."

+  !cd "stunnel"

+  !cd "tools"

+SectionEnd

+

+Section "Uninstall"

+  ClearErrors

+

+  # stop and remove the service, exit stunnel

+  ReadRegStr $R0 HKLM \

+    "Software\Microsoft\Windows NT\CurrentVersion" CurrentVersion

+  IfErrors skip_service_uninstall

+  ExecWait '"$INSTDIR\stunnel.exe" -stop -quiet'

+  ExecWait '"$INSTDIR\stunnel.exe" -uninstall -quiet'

+skip_service_uninstall:

+  ExecWait '"$INSTDIR\stunnel.exe" -exit -quiet'

+

+  # remove stunnel folder

+  Delete "$INSTDIR\stunnel.conf"

+  Delete "$INSTDIR\ca-certs.pem"

+  Delete "$INSTDIR\stunnel.pem"

+  Delete "$INSTDIR\stunnel.exe"

+  Delete "$INSTDIR\stunnel.exe.manifest"

+  Delete "$INSTDIR\stunnel.pdb"

+  Delete "$INSTDIR\tstunnel.exe"

+  Delete "$INSTDIR\tstunnel.exe.manifest"

+  Delete "$INSTDIR\stunnel.cnf"

+  Delete "$INSTDIR\openssl.exe"

+  Delete "$INSTDIR\openssl.exe.manifest"

+  Delete "$INSTDIR\openssl.pdb"

+  Delete "$INSTDIR\Microsoft.VC90.CRT.manifest"

+  Delete "$INSTDIR\libeay32.dll"

+  Delete "$INSTDIR\libeay32.dll.manifest"

+  Delete "$INSTDIR\libeay32.pdb"

+  Delete "$INSTDIR\ssleay32.dll"

+  Delete "$INSTDIR\ssleay32.dll.manifest"

+  Delete "$INSTDIR\ssleay32.pdb"

+  Delete "$INSTDIR\4758cca.dll"

+  Delete "$INSTDIR\4758cca.dll.manifest"

+  Delete "$INSTDIR\4758cca.pdb"

+  Delete "$INSTDIR\aep.dll"

+  Delete "$INSTDIR\aep.dll.manifest"

+  Delete "$INSTDIR\aep.pdb"

+  Delete "$INSTDIR\atalla.dll"

+  Delete "$INSTDIR\atalla.dll.manifest"

+  Delete "$INSTDIR\atalla.pdb"

+  Delete "$INSTDIR\capi.dll"

+  Delete "$INSTDIR\capi.dll.manifest"

+  Delete "$INSTDIR\capi.pdb"

+  Delete "$INSTDIR\chil.dll"

+  Delete "$INSTDIR\chil.dll.manifest"

+  Delete "$INSTDIR\chil.pdb"

+  Delete "$INSTDIR\cswift.dll"

+  Delete "$INSTDIR\cswift.dll.manifest"

+  Delete "$INSTDIR\cswift.pdb"

+  Delete "$INSTDIR\gmp.dll"

+  Delete "$INSTDIR\gmp.dll.manifest"

+  Delete "$INSTDIR\gmp.pdb"

+  Delete "$INSTDIR\gost.dll"

+  Delete "$INSTDIR\gost.dll.manifest"

+  Delete "$INSTDIR\gost.pdb"

+  Delete "$INSTDIR\nuron.dll"

+  Delete "$INSTDIR\nuron.dll.manifest"

+  Delete "$INSTDIR\nuron.pdb"

+  Delete "$INSTDIR\padlock.dll"

+  Delete "$INSTDIR\padlock.dll.manifest"

+  Delete "$INSTDIR\padlock.pdb"

+  Delete "$INSTDIR\sureware.dll"

+  Delete "$INSTDIR\sureware.dll.manifest"

+  Delete "$INSTDIR\sureware.pdb"

+  Delete "$INSTDIR\ubsec.dll"

+  Delete "$INSTDIR\ubsec.dll.manifest"

+  Delete "$INSTDIR\ubsec.pdb"

+  Delete "$INSTDIR\stunnel.html"

+  Delete "$INSTDIR\uninstall.exe"

+  RMDir "$INSTDIR"

+

+  # remove menu shortcuts

+  SetShellVarContext all

+  Delete "$DESKTOP\stunnel.lnk"

+  Delete "$SMPROGRAMS\stunnel\*.lnk"

+  Delete "$SMPROGRAMS\stunnel\*.url"

+  RMDir "$SMPROGRAMS\stunnel"

+

+  # remove firewall rules

+  SimpleFC::RemoveApplication "$INSTDIR\stunnel.exe"

+  Pop $0 # returns error(1)/success(0)

+  DetailPrint "SimpleFC::RemoveApplication: $0"

+  SimpleFC::RemoveApplication "$INSTDIR\tstunnel.exe"

+  Pop $0 # returns error(1)/success(0)

+  DetailPrint "SimpleFC::RemoveApplication: $0"

+

+  # remove uninstaller registry entires

+  DeleteRegKey HKLM \

+    "Software\Microsoft\Windows\CurrentVersion\Uninstall\stunnel"

+  DeleteRegKey HKLM "Software\NSIS_stunnel"

+SectionEnd

+

+# end of stunnel.nsi

diff --git a/tools/stunnel.service.in b/tools/stunnel.service.in
new file mode 100644
index 0000000..7776364
--- /dev/null
+++ b/tools/stunnel.service.in
@@ -0,0 +1,10 @@
+[Unit]
+Description=SSL tunnel for network daemons
+After=syslog.target
+
+[Service]
+ExecStart=@bindir@/stunnel
+Type=forking
+
+[Install]
+WantedBy=multi-user.target
diff --git a/tools/stunnel.spec b/tools/stunnel.spec
new file mode 100644
index 0000000..245aa70
--- /dev/null
+++ b/tools/stunnel.spec
@@ -0,0 +1,97 @@
+%define _prefix /usr
+%define _sysconfdir /etc
+
+Summary: Program that wraps normal socket connections with SSL/TLS
+Name: stunnel
+Version: 5.22
+Release: 1
+License: GPL with an OpenSSL exception
+Group: Applications/Networking
+Source: stunnel-%{version}.tar.gz
+Packager: Bill Quayle <Bill.Quayle@citadel.com>
+Requires: openssl >= 0.9.7
+BuildRequires: openssl-devel >= 0.9.7
+Buildroot: /var/tmp/stunnel-%{version}-root
+
+%description
+The stunnel program is designed to work as SSL encryption wrapper
+between remote clients and local (inetd-startable) or remote
+servers. The concept is that having non-SSL aware daemons running on
+your system you can easily set them up to communicate with clients over
+secure SSL channels.
+stunnel can be used to add SSL functionality to commonly used inetd
+daemons like POP-2, POP-3, and IMAP servers, to standalone daemons like
+NNTP, SMTP and HTTP, and in tunneling PPP over network sockets without
+changes to the source code.
+
+%prep
+%setup -n stunnel-%{version}
+
+
+%build
+if [ ! -x ./configure ]; then
+    autoconf
+    autoheader
+fi
+
+CFLAGS="%{optflags}" ./configure --prefix=%{_prefix} --sysconfdir=%{_sysconfdir}
+
+%{__make}
+
+%install
+%{__rm} -rf %{buildroot}
+%{__mkdir} -p %{buildroot}%{_sysconfdir}/stunnel
+%{__mkdir} -p %{buildroot}%{_sbindir}
+%{__mkdir} -p %{buildroot}%{_libdir}
+%{__mkdir} -p %{buildroot}%{_mandir}/man8
+%{__mkdir} -p %{buildroot}%{_initrddir}
+
+%{__install} -m755 -s src/stunnel %{buildroot}%{_sbindir}
+%{__install} -m755 src/.libs/libstunnel.so %{buildroot}%{_libdir}
+%{__install} -m755 src/.libs/libstunnel.la %{buildroot}%{_libdir}
+%{__install} -m644 doc/stunnel.8 %{buildroot}%{_mandir}/man8/stunnel.8
+%{__install} -m644 tools/stunnel.conf-sample %{buildroot}%{_sysconfdir}/stunnel
+%{__install} -m500 tools/stunnel.init %{buildroot}%{_initrddir}/stunnel
+
+%clean
+%{__rm} -rf %{buildroot}
+
+%post
+ldconfig
+
+%postun
+ldconfig
+
+%files
+%defattr(-,root,root)
+%doc COPYING COPYRIGHT.GPL README ChangeLog doc/stunnel.html
+%doc tools/ca.html tools/ca.pl tools/importCA.html tools/importCA.sh tools/stunnel.cnf
+%dir %{_sysconfdir}/stunnel
+%config %{_sysconfdir}/stunnel/*
+%{_sbindir}/stunnel
+%{_libdir}/libstunnel.so
+%{_libdir}/libstunnel.la
+%{_mandir}/man8/stunnel.8.gz
+%{_initrddir}/stunnel
+
+%changelog
+* Tue May 26 2015 Bill Quayle <Bill.Quayle@citadel.com>
+- updated license specification
+- the manual page is no longer marked as compressed
+- removed outdated documentation files
+- updated minimum required version of OpenSSL
+
+* Fri Sep 09 2005 neeo <neeo@irc.pl>
+- lots of changes and cleanups
+
+* Wed Mar 17 2004 neeo <neeo@irc.pl>
+- updated for 4.05
+
+* Sun Jun 24 2000 Brian Hatch <bri@stunnel.org>
+- updated for 3.8p3
+
+* Wed Jul 14 1999 Dirk O. Siebnich <dok@vossnet.de>
+- updated for 3.5.
+
+* Mon Jun 07 1999 Dirk O. Siebnich <dok@vossnet.de>
+- adapted from sslwrap RPM spec file