Package
com.google.android.networkstack.overlay
GoogleNetworkStackResOverlay
Guidance
A small resource package in Google's namespace whose label varies by device: this site records GoogleNetworkStackResOverlay, NetworkStackOverlay, NetworkStackGoogleResOverlay, or the bare package name in place of a label. It has no launcher entry, no observation here is user-facing, none is Play-eligible, its aggregated permission set holds a single entry, POST_NOTIFICATIONS, and builds are recorded between roughly 8.5 KB and 74.1 KB. This site aggregates permissions across observations rather than per build, so which builds request that permission cannot be established. The name and labels describe a Runtime Resource Overlay (RRO), which AOSP defines as a package that changes the resource values of a target package at runtime, and which cannot carry code. The labels point at the Google-signed NetworkStack module, which this site records as com.google.android.networkstack with the label "Network manager". On 34 of the 36 devices that record this overlay, this site also records that module, which is consistent with it being the overlay's target, though the target is inferred from naming rather than confirmed. On 30 of the 36 devices it is recorded alongside the AOSP-keyed overlay com.android.networkstack.overlay, so on those devices the two overlays coexist rather than one replacing the other. What an overlay of NetworkStack may set is published by the module itself. AOSP describes Network Stack as an updatable Mainline module that ensures Android can adapt to evolving network standards, naming captive portal detection and login code as an example, and its components include the DHCP client and NetworkMonitor, which tests for internet reachability, detects captive portals and validates networks. The module declares an overlayable named NetworkStackConfig, whose entries include the captive portal HTTP and HTTPS probe URLs and their list and fallback forms, the DNS probe timeout, the regular expressions used to judge whether a validation probe succeeded or failed, the default DNS servers, and DHCP client hostname options. Which of these values this package sets on any build could not be sourced. Provenance: despite the Google namespace, none of the signing certificates recorded for it here is classified as Google's. Among the observations that carry signing data, 10 distinct certificates are recorded, each classified as the device maker's own key, covering Motorola, Lenovo, OPPO, vivo, Xiaomi, NUU, OUKITEL and ANT DAO TECHNOLOGY LIMITED; eight of the ten are recorded as also signing the Android framework, a platform-level key. The package is seen across 20 device make names in this sample, including TCL, OnePlus, realme, Infinix and Blackview. Version note. Observations here run from API 30 to API 36, version names run from 12 to 15, and this site's target SDK roll-up reports 31 to 35. Those are independent roll-ups across observations rather than a per-build pairing, so they cannot say which target SDK a given device carries. AOSP documents the module it appears to accompany as updatable through Mainline. Whether the values this overlay sets have changed across Android releases could not be sourced. For Android Enterprise, EMM and kiosk use it has no identified enrolment or policy role in the sources cited here and nothing a user interacts with. If it overlays NetworkStack as its name indicates, the captive portal probe URLs are the entries worth knowing about on a managed or filtered network, since they decide which endpoint the device contacts when judging whether a network has internet access. If this package overrides them, disabling it could change the endpoints used for validation; the resulting values would depend on the module defaults and any other enabled overlays, and this package's actual overrides could not be sourced. No hardening benefit from disabling it is established by the cited sources. Where kiosk mode is stopping a captive portal login from appearing, the documented fix is to allow the captive portal login package in the EMM policy rather than to touch this package.
- Network Stack - Android Open Source Project →
- Change the value of an app's resources at runtime (RROs) - Android Open Source Project →
- NetworkStack overlayable.xml (packages/modules/NetworkStack) - Android source →
- Kiosk devices and captive portals - Android Enterprise FAQ →
- Package provenance for com.google.android.networkstack.overlay - Android System App Database →
- Package provenance for com.google.android.networkstack - Android System App Database →
- Package provenance for com.android.networkstack.overlay - Android System App Database →
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Re-signed by each device maker with its own platform key - 10 different certificates appear across 8 device makers in our sample. That is the signature of a stock AOSP/system package every OEM builds and signs itself, not a single maker's or a third party's preinstall. These are platform-level keys: they also sign the Android framework itself.
- Its largest observed manifest declares 1 permissions: 1 runtime (user-granted).
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (1)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
POST_NOTIFICATIONS |
Allows the app to show notifications |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Ant Dao Technology Limited | B3 | Android 14 | OEM ANT DAO TECHNOLOGY LIMITED | 1 | 18 Aug 2026 |
| Blackview | VARG | Android 11 | - | 1 | 1 Sep 2025 |
| DOOGEE | S41 Max | Android 13 | - | 2 | 3 Oct 2025 |
| Fezawio | F11_V_US | Android 15 | - | 1 | 14 Jul 2026 |
| Hotwav | TAB R9 Pro | Android 14 | - | 1 | 18 Sep 2025 |
| Infinix | Infinix X6871 | Android 14 | - | 1 | 21 May 2025 |
| Lenovo | Lenovo TB-7306F | Android 11 | - | 1 | 19 Jul 2025 |
| Lenovo | Lenovo TB-X6C6NBF | Android 12 | - | 1 | 15 May 2025 |
| Lenovo | TB132FU | Android 14 | - | 1 | 16 Jun 2025 |
| Lenovo | TB328FU | Android 12 | - | 1 | 15 Sep 2025 |
| Lenovo | TB352FU | Android 15 | OEM LENOVO | 1 | 6 Sep 2026 |
| Lenovo | TB570FU | Android 15 | - | 1 | 17 Jun 2025 |
| Motorola | moto g - 2025 | Android 16 | OEM Motorola | 1 | 14 Dec 2025 |
| Motorola | moto g14 | Android 13 | OEM Motorola | 1 | 19 Dec 2025 |
| Motorola | moto g24 | Android 14 | OEM Motorola | 1 | 19 Dec 2025 |
| NUU | S6707X | Android 14 | OEM NUU | 1 | 12 Jan 2026 |
| OnePlus | CPH2465 | Android 14 | - | 1 | 17 Jun 2025 |
| OnePlus | CPH2653 | Android 16 | - | 1 | 24 Nov 2025 |
| OnePlus | HD1903 | Android 12 | - | 1 | 10 Sep 2025 |
| OnePlus | KB2005 | Android 14 | - | 1 | 17 Sep 2025 |
| OPPO | CPH2591 | Android 15 | - | 1 | 10 Jul 2025 |
| OPPO | CPH2637 | Android 15 | OEM OPPO | 1 | 2 Feb 2026 |
| OUKITEL | C59 Pro | Android 15 | - | 1 | 6 Nov 2025 |
| OUKITEL | WP28 E | Android 14 | OEM OUKITEL | 1 | 24 Aug 2026 |
| realme | RMX2001 | Android 11 | - | 1 | 21 Aug 2025 |
| realme | RMX3627 | Android 12 | - | 1 | 20 Sep 2025 |
| Rhino | T8 | Android 14 | - | 1 | 17 May 2025 |
| Smt_hk | Helium Pro | Android 12 | - | 1 | 19 Jul 2025 |
| TCL | 6025D_EEA | Android 11 | - | 1 | 17 Sep 2025 |
| TCL | 6165H | Android 13 | - | 1 | 16 Sep 2025 |
| TCL | 9466X | Android 13 | - | 1 | 13 Jan 2026 |
| TCL | 9491G | Android 14 | - | 1 | 26 Aug 2025 |
| Ulefone | Power Armor X11 Pro | Android 12 | - | 1 | 15 Sep 2025 |
| vivo | V2550 | Android 16 | OEM vivo | 1 | 21 Jul 2026 |
| Xiaomi | 21091116UI | Android 13 | - | 1 | 8 Sep 2025 |
| Xiaomi | 24117RN76O | Android 15 | OEM Xiaomi | 1 | 28 Dec 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| GoogleNetworkStackResOverlay | en-gb | 6 |
| GoogleNetworkStackResOverlay | en-us | 4 |
| NetworkStackOverlay | en-us | 4 |
| com.google.android.networkstack.overlay | en-us | 3 |
| GoogleNetworkStackResOverlay | es-es | 2 |
| GoogleNetworkStackResOverlay | en-US | 2 |
| NetworkStackOverlay | en-GB | 2 |
| NetworkStackOverlay | en-gb | 2 |
| com.google.android.networkstack.overlay | 2 | |
| GoogleNetworkStackResOverlay | 1 | |
| GoogleNetworkStackResOverlay | en | 1 |
| GoogleNetworkStackResOverlay | en-GB | 1 |
| GoogleNetworkStackResOverlay | en-in | 1 |
| GoogleNetworkStackResOverlay | en-za-u-fw-mon-mu-celsius | 1 |
| GoogleNetworkStackResOverlay | es-US | 1 |
| GoogleNetworkStackResOverlay | es-us | 1 |
| GoogleNetworkStackResOverlay | vi-VN | 1 |
| GoogleNetworkStackResOverlay | vi-vn | 1 |
| NetworkStackGoogleResOverlay | ru-ru | 1 |
| NetworkStackOverlay | ja-jp | 1 |
| NetworkStackOverlay | ru-ru | 1 |
| NetworkStackOverlay | en | 1 |
| NetworkStackOverlay | it-it | 1 |
| com.google.android.networkstack.overlay | es-MX | 1 |
| com.google.android.networkstack.overlay | es-mx | 1 |
| com.google.android.networkstack.overlay | fr-fr | 1 |
| com.google.android.networkstack.overlay | de-de | 1 |
| com.google.android.networkstack.overlay | en | 1 |
| com.google.android.networkstack.overlay | en-lk | 1 |
| com.google.android.networkstack.overlay | en-pk | 1 |