命令行工具/usr/sbin/installer安装失败但GUI版Installer.app成功的排障咨询——日志解读与排障方向
Hey there, let's dig into your logs and map out clear troubleshooting steps based on what you've shared: you're seeing PKInstallErrorDomain Code=100 failures when using the command-line /usr/sbin/installer tool (but the GUI Installer.app works), the issue only hits a subset of machines, and removing MDM profiles doesn't fix it.
First, let's break down those log entries—they hold the key to why this is happening:
Log Interpretation
2024-01-29 installd[1605]: PackageKit: request (at * PKTrustLevelAppleDeveloperID) not compatible with right(s) system.install.apple-software, system.install.software.iap
This is the critical line. It's telling you that your package is signed with an Apple Developer ID (PKTrustLevelAppleDeveloperID), but the system's permission rules don't allow this signature level to use the installation rights it needs:
system.install.apple-software: This right is reserved exclusively for official Apple-signed software (like macOS updates, App Store apps)system.install.software.iap: For installations tied to in-app purchases
The two subsequent error messages are just the end result of this permission mismatch—they're the generic "authorization required" alert that hides the underlying signature/permission conflict.
Troubleshooting Starting Points
Let's start with the most actionable checks first:
- Confirm the package's signature: Run this command to verify exactly how your package is signed:
Look for thecodesign -dv --verbose=4 /path/to/your/package.pkgAuthorityfield to confirm it's a Developer ID signature (not an official Apple-signed package). - Double-check sudo usage: The command-line
installertool needs root privileges for most system-level installs. Make sure you're running it with:
The GUI Installer.app runs under a different permission context that's more lenient with Developer ID-signed packages, which is why it works.sudo /usr/sbin/installer -pkg /path/to/your/package.pkg -target / - Adjust system security policies:
- For newer macOS versions (Ventura/Sonoma), try temporarily relaxing the security policy to allow Developer ID installs:
This lets you install software from "Any Source" (you can re-enable it later withsudo spctl --master-disablesudo spctl --master-enable). Note that managed environments might block this command. - Inspect the system authorization database to check if Developer ID installs are restricted:
Look for references tosecurity authorizationdb read system.install.softwarePKTrustLevelAppleDeveloperID—if it's missing or set to deny, that's a problem.
- For newer macOS versions (Ventura/Sonoma), try temporarily relaxing the security policy to allow Developer ID installs:
- Rule out third-party interference: Since only some machines are affected, check those devices for third-party security tools (antivirus, endpoint protection) or leftover system tweaks that might be overriding default permission rules. These tools often restrict Developer ID package installs.
- Check macOS version alignment: Ensure the problematic machines are on the same macOS version as the working ones. Some OS updates introduced stricter rules for Developer ID-signed software that could cause this mismatch.
备注:内容来源于stack exchange,提问作者Phatmandrake

