Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
← All case files // case file · Mac & MacBook

One volume on the desktop. Two devices underneath it.

An iMac Fusion Drive that stopped mounting. macOS presents one icon, which hides the thing that decides the recovery: the files are spread across two physically separate devices with completely different failure behaviour.

DeviceiMac Fusion · SSD + HDD
FaultHead failure, mechanical half
Turnaround10 days
Outcome94% recovered
MethodClean-air · CoreStorage rebuild

What arrived

An iMac that had been slowing noticeably for a fortnight, then failed to boot and showed the flashing question-mark folder. The owner assumed the SSD had worn out, which is the common guess and was wrong. On the machine were a working photographic archive and several years of business documents. A Time Machine backup existed and had stopped running eight months earlier without anyone noticing.

What a Fusion Drive actually is

Apple pairs a small SSD — 24 GB, 32 GB or 128 GB depending on model and year — with a conventional 3.5″ or 2.5″ hard disk, and joins the two into a single logical volume. On pre-APFS machines that join is CoreStorage; on later ones the same two devices sit in an APFS container spanning both. Either way the desktop shows one drive and there are two.

The tiering is automatic and continuous. Frequently read data and recent writes live on the flash; colder data migrates down to the mechanical disk in the background. Apple also reserves a write buffer of a few gigabytes on the SSD so new data lands on flash first and is relocated later, which is why these machines felt so much quicker than a plain hard disk for everyday use.

The consequence for recovery is the part almost everyone misses. A given file may sit entirely on the SSD, entirely on the hard disk, or be split across both, with no relationship between where a file lives and what it is. Only the volume metadata knows the mapping. Recover one device in isolation and you get fragments: readable blocks with no reliable way to determine what they belong to or in what order.

Diagnosis

The SSD was healthy, with wear indicators low and no reallocation activity — unsurprising, since the flash half of a Fusion pair sees heavy but well-distributed traffic and these are not small-cell consumer parts.

The hard disk was the problem. It had a failing head and light circumferential scoring in a band near the outer diameter, which is where a drive lays down data first and therefore where the oldest and most-migrated material sits. Reallocated sector count was high and pending sectors were climbing.

That explains the fortnight of gradual slowing precisely, and it explains why it was misread as an SSD problem. As the mechanical half deteriorated, every read of migrated data stalled while the drive exhausted its retry budget before returning either the sector or an error. Because macOS presents a single volume, the user experiences that as the entire machine becoming sluggish rather than as one device failing. The tiering that makes a Fusion Drive fast is the same mechanism that disguises which half is dying.

Bench work

Both devices were imaged read-only, and the SSD went first because it was quick and because losing it later would have been fatal to the whole job. It completed in under an hour with no errors.

The hard disk was opened under filtered air and given a matched donor head stack assembly — matched on family, head count and firmware revision, since the preamplifier characteristics differ between revisions and a mismatch reads nothing at all. The scored band was mapped before imaging began and deliberately deprioritised: bulk passes ran around it at large block sizes, and only once everything else was secured were short targeted attempts made at the damaged zone, with the drive rested between them. Repeatedly hammering a scored surface generates debris and turns a partial loss into a total one.

Rejoining two devices into one volume

With both images secured, the logical structure was rebuilt from the metadata rather than inferred. CoreStorage records the volume group, the physical volumes belonging to it and the extent map describing which ranges on which device back which logical addresses; those structures were parsed from the images and the mapping reconstructed in software.

The volume was then assembled from the two images together, outside the iMac entirely, and the APFS structures rebuilt on top of the result — container superblock, checkpoint descriptors, the object map and the file-system B-trees, walked back to the most recent checkpoint that resolved cleanly against readable data.

This is the step that cannot be skipped and cannot be done by connecting the good half to another Mac. Half a Fusion volume is not a volume.

Verification

Documents were opened in the applications that created them. Photographs were decoded rather than listed, with raw files demosaiced end to end and checked against their embedded previews, because a raw file can present a valid header and a clean thumbnail while the sensor payload behind it is damaged.

Anything that failed verification was named in the manifest handed over before payment, rather than returned in the file count as though it were intact.

Outcome

About 94%. The shortfall was blocks that had been resident in the scored band on the mechanical half.

Those losses were scattered across older material rather than concentrated in any one folder, and that is a direct consequence of how tiering works: data migrates down by access frequency, not by folder or by date, so what ends up in a damaged region of the hard disk is simply whatever had gone cold. A recovery from a conventional single drive tends to lose contiguous things. A Fusion recovery loses a statistical sample of everything you had stopped opening.

// ready when you are

Facing something similar? Let's help.

Start with an instant online quote, or call and talk it through with us first. You'll have a clear, fixed price before any work begins.

Peter House, Oxford Street, Manchester M1 5AN · Mon–Fri 9am–5:30pm · No fix, no fee on most jobs