Opens an install session so several APKs — a base plus its splits — are installed as one atomic unit.
pm install-create [-r] [-g] [-d] [-t] [-S <total bytes>]
pm install-write [-S <bytes>] <session> <name> <path or ->
pm install-commit <session>
pm install-abandon <session>| Token | Meaning |
|---|---|
| -S <bytes> | On `install-create`, the total size of the whole set, so the installer can reserve space and fail early. On `install-write`, the exact size of this file — and it is mandatory when the bytes come from stdin, because the reader has no other way to know where they end. |
| - | As the path argument of `install-write`, read the APK bytes from stdin. |
| -r -g -d -t | The install options, and they belong on `install-create`. `install-commit` takes no install parameters at all, so a flag appended there is silently dropped. |
pm install-create -r -S 82345678Open a session for an 82 MB set. The reply carries the session id.
pm install-write -S 41000000 1234567 base.apk /data/local/tmp/base.apkAdd one already-pushed file to the session.
pm install-commit 1234567Install everything in the session as one operation.
pm install-abandon 1234567Throw the session away and release the staged bytes.
Sample output
Success: created install session [1234567]`install-create` replies with the session id in square brackets, and that number is the argument for every later step. Each `install-write` answers `Success` or a `Failure [INSTALL_FAILED_…]`, and `install-commit` is the one whose failure matters most — that is where signature, split-set and verification problems surface, because until then nothing has been checked against the installed app.
| Field | Meaning |
|---|---|
| Success: created install session [<id>] | The session id for install-write and install-commit. |
| Success | That write, or the commit, was accepted. |
| Error: must specify a APK size | An `install-write` reading from stdin without -S. |
| INSTALL_FAILED_INVALID_APK | The set does not hold together — a duplicate split, a mismatched base. |
| INSTALL_FAILED_ABORTED | The session was abandoned, or an on-device prompt was not answered. |
The install itself replaces the app that is there, exactly as `pm install` does. The session-specific hazard is leaving one open: a created session holds staged bytes on the device until it is committed or abandoned, so `pm install-abandon <session>` is the cleanup step, not an optional one.
APK Installer runs this command over USB and parses what comes back — a Chromium browser, no SDK, nothing uploaded.
Commands that turn up in the same session as pm install-create.
| Command | What it does |
|---|---|
| pm install | Installs one APK that is already on the device, which is what `adb install` does under the hood. |
| pm path | Prints the absolute paths of the APK files that make up an installed package. |
| pm uninstall | Removes a package, or removes it for one Android user only — which is how a preinstalled app is disposed of without root. |
| Command | What it does |
|---|---|
| pm list packages | Lists installed packages, optionally with the APK path, uid, version code and installer. |
| pm disable-user | Switches a package off for one Android user without removing it — the reversible alternative to uninstalling. |
| pm clear | Wipes an app's data — or, on Android 13 and later, only its cache. |
| pm trim-caches | Asks the system to drop cached files until the given amount of free space exists. |
Checked against AOSP, toybox and kernel sources while writing the parsers behind our Web ADB tools. Where a behaviour genuinely varies by Android version or manufacturer, this page says so instead of giving a number that would be wrong on half the phones out there.
Switch on developer options and USB debugging on the phone, plug it in, then run `adb shell <command>` from a machine with platform-tools installed — or run `adb shell` on its own to get an interactive prompt and type the command without the prefix. If the command produces binary output, such as a screenshot, use `adb exec-out` instead of `adb shell`: the plain shell service attaches a terminal, which rewrites newline bytes and corrupts the data.
Not the ones on this reference. They run as the `shell` user, which can manage packages for its own Android user, read most `dumpsys` services, write the settings provider, inject input and read shared storage. Root is only needed for things this reference deliberately avoids — reading another app's private data (except through `run-as` on a debuggable build), writing system partitions, or reading `/data/anr` directly.
Either the Android version or the manufacturer. Some flags and fields arrived in a specific release, and those are noted per command. The rest is OEM patching, which hits `dumpsys` hardest: a dump is debug output whose text is whatever the service author last printed, and manufacturers change it and backport their changes. Read fields by name rather than by position, and treat an unfamiliar shape as a difference rather than as a failure.
For many commands, yes — the Web ADB tools on this site talk to a phone over WebUSB from a Chromium-based desktop browser, with no SDK installed and nothing uploaded. Each page links to the tool that runs its command, when one exists. Two limits are worth knowing: only one program can hold the ADB interface at a time, so a desktop `adb server` has to be stopped first, and `adb forward` and `adb reverse` cannot work in a browser at all.
Would rather click than type? The Web ADB Toolkit runs commands like this from a browser over USB. Or browse every command.