Android高版本Root安装APK的/data/local/tmp/路径限制问题问询
Hey there, let's dive into your APK installation problem on Android P and break down solutions based on what you've already tried.
Quick Background Recap
Before Android P, with root access, you could install APKs directly from your app using:
pm install -t -f fullPathToApkFile
Or for SD card installs:
pm install -t -s fullPathToApkFile
The Core Problem
Starting with Android P Beta, these commands fail because system_server (the core system process handling package installs) no longer has permission to read APKs from sdcardfs paths. The system recommends using /data/local/tmp/ instead, and even popular tools like Titanium Backup Pro were hit by this change.
Your Attempted Fixes (Recap)
chmod 777on the APK: No impact- Granting storage +
REQUEST_INSTALL_PACKAGESpermissions: Didn't help - Symlinks to
/data/local/tmp/(via APIs orln -sf): Symlinks aren't recognized for installation - Copying/moving APK to
/data/local/tmp/: Works, but has annoying downsides (original file hidden temporarily, timestamp changes, extra storage usage, slow copies) - Hard links with
cp -p -r -l: Fails with "Cross-device link" error - Comparing other methods: IDE installs use
/data/local/tmp/, but Play Store, Intent-based installs, and adb installs don't require it - Filed a report with Google's Issue Tracker
Answers to Your Questions
1. How to avoid /data/local/tmp/'s downsides, or skip it entirely?
Here are three solid workarounds that let you keep the original APK intact:
Use Bind Mounts (Root Required)
Instead of copying the file, use a bind mount to create a filesystem-level mirror of your APK in /data/local/tmp/. This doesn't duplicate any data, so your original file stays exactly as it was (no timestamp changes, no extra storage used).
Run these commands as root:
# Mount the original APK to a temp path mount --bind fullPathToApkFile /data/local/tmp/temp_install.apk # Install from the mounted path pm install -t -f /data/local/tmp/temp_install.apk # Clean up after installation umount /data/local/tmp/temp_install.apk
Use the PackageInstaller API with Root
Skip direct pm install calls entirely and use Android's official PackageInstaller API with root privileges. Since you have root, you can bypass normal storage restrictions to read the APK directly from its original path:
- Open a file descriptor to the original APK (using root to get around sandbox limits)
- Create a
PackageInstaller.Session - Pass the file descriptor to the session (no need to copy the entire APK)
- Commit the session to trigger installation
This method works within the system's official flow and avoids /data/local/tmp/ completely.
Run pm install as the System User (Advanced)
If your root setup allows it, try running the install command as the system user (which owns system_server). This might grant the necessary permission to read sdcardfs paths directly:
run-as system pm install -t -f fullPathToApkFile
Note: This doesn't work on all devices, but it's worth testing if bind mounts aren't an option.
2. Why does the system force /data/local/tmp/ now, but other methods don't need it?
This is part of Android P's stricter security sandboxing:
system_serverPermission Lockdown: Android P tightened filesystem access forsystem_server. It can't read from sdcardfs paths anymore because those are part of app-specific storage sandboxes, andsystem_serverdoesn't hold the app's storage permissions.- Alternative Install Channels Use Special Permissions:
- Play Store installs are handled by a dedicated system service with trusted access to APK sources.
- Intent-based installs use
ACTION_INSTALL_PACKAGE, which routes through the system's package installer app—this app has explicit permission to read sdcardfs paths on behalf of the user. - adb installs run in a separate shell with elevated privileges (not as
system_server), so they can access sdcardfs paths directly.
/data/local/tmp/ is a world-writable temp directory that system_server can access, which is why it's the recommended fallback.
内容的提问来源于stack exchange,提问作者android developer

