Zond modified engine sources, 0.9.32
Toolchain: Go 1.27.2; CGO_ENABLED=0; GOARCH=amd64; GOOS=windows or linux.
Xray: go build -mod=readonly -trimpath -buildvcs=false -ldflags="-s -w -X github.com/xtls/xray-core/core.build=Zond-security-2" ./main
sing-box: go build -mod=readonly -trimpath -buildvcs=false -tags with_clash_api -ldflags="-s -w -X github.com/sagernet/sing-box/constant.Version=1.14.2-zond.2" ./cmd/sing-box
Run the commands inside the corresponding source tree. Modified go.mod/go.sum are included in each tree. sing-box uses the adjacent patched sing source tree through a local replace directive.
Zond's Xray DNS patch retries a transient DNS transport failure once against the same selected resolver, retaining the original per-attempt timeout and caller cancellation. Successful answers, NXDOMAIN and empty answers are not retried. The patch recipe and regression tests are in zond-build; the patched source is app/dns/nameserver.go.
Zond's sing patch declares an unknown client UDP endpoint (0.0.0.0:0) for SOCKS5 UDP ASSOCIATE, as specified by RFC 1928 section 6. It fixes IPv4 UDP DNS forwarding into Xray without relaxing Xray's client source validation. The patch recipe and regression test are in zond-build, with the resulting source in sing/protocol/socks/handshake.go.
module-cache contains source ZIPs, metadata, checksums and original license files for every module used by both builds. It can serve as a Go file module proxy. The Go compiler and standard library are available at https://go.dev/dl/ .
The reusable source-fetch/build/audit recipe is in zond-build. Scanning happens BEFORE stripping symbols, using govulncheck 1.8.0.
These are Zond builds, not upstream release binaries. Xray's source tag is marked prerelease upstream. Geo-data and third-party native UI/runtime binaries are outside this engine-source archive.
