ZN-hostsredirect is an ARM64 Zygisk Next module that makes Android's netd service read hosts entries from /data/adb/hostsredirect/hosts instead of the standard system file.
Redirect netd to a Writable Hosts File
A focused native hook for Android's network daemon, without replacing /system/etc/hosts on the read-only system image.
netd Hook
Intercepts the network daemon when it opens the default hosts path and substitutes a descriptor for the custom file.
External Rule File
Keeps the user-maintained hosts list under /data/adb, separate from protected system partitions.
Native ARM64 Module
Version 1 is built only for ARM64 and declares Android 10 as its minimum platform.
How the Native Redirection Works
The module registers netd as its Zygisk Next target. Before the daemon's main executable begins normal operation, the native library locates the C library's __openat function and installs an inline hook.
When netd requests /system/etc/hosts, a companion process opens /data/adb/hostsredirect/hosts and passes the file descriptor across a local socket. Requests for other paths continue to the original function. If the custom file is missing or cannot be opened, the hook falls back to the normal system hosts file.
Requirements and Setup
- Use an ARM64 device running Android 10 or later.
- Install through Magisk or a KernelSU-compatible manager; recovery installation is explicitly rejected.
- Provide an active Zygisk Next environment because the module uses the Zygisk Next native module and companion APIs.
- Create
/data/adb/hostsredirect/hostswith standard hosts syntax, for example an IP address followed by one or more hostnames. - Do not run multiple root implementations together; the installer explicitly treats that setup as unsupported.
Practical Scope
A hosts file maps exact names before ordinary DNS resolution. It can block a hostname by mapping it to a non-routable local address or redirect it to another IP. It does not support wildcard domains, URL paths, encrypted DNS performed inside an app, or applications that connect directly to an IP address.
After changing the file, restart the affected process or reboot if cached name resolution remains. Validate each entry carefully: a malformed or overly broad list can prevent sign-in, media delivery, captive-portal detection, or other dependent services.
netd and grants it access to an alternate file. Keep a recovery path available and avoid combining it with other modules that hook the same function or replace hosts handling in an incompatible way.