Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Mac & Apple Systems · Space Gets Reclaimed

A Versioned Backup Prunes Its Own Oldest Content When the Destination Fills

His enquiry asks a question and half-answers it himself. A laptop backed up by the platform's versioned system, where "after purchasing a newer model, the snapshot of the old machine is missing" — and he wonders whether he has let the system overwrite it. He is very likely right, and the mechanism is worth setting out, because it is designed behaviour rather than a fault.

MediaVersioned backup destination holding histories for two machines — the earlier machine's backup set no longer present following the introduction of a replacement
Reported situationLaptop backed up using the platform's versioned backup system · replacement machine purchased · replacement machine backed up to the same destination · backup set for the previous machine no longer present · owner uncertain whether the system reclaimed the space · content from the previous machine sought
Fault classBackup retention pruning on a shared destination — oldest sets removed as capacity is required; removed content unreferenced rather than necessarily overwritten
Equipment usedRetention behaviour identified as the probable cause before any device fault was investigated · destination removed from backup service before assessment · imaged write-blocked at the block level before any interpretation · backup structure examined for removed set references and retained content · recovered content validated by opening

The decode: what the system does when space runs short

How a versioned backup works: it keeps many points in time rather than one copy. Hourly, daily and weekly states accumulate, sharing unchanged content between them, so the destination fills gradually with history.

What happens as it approaches capacity: it deletes the oldest material to make room. Pruning old states is designed behaviour and it happens without prompting, because a backup system that stopped when full would protect nothing.

Why introducing a second machine accelerates that sharply: the new machine's first backup is a complete copy of everything on it. A large initial backup arriving on a destination already holding years of history forces a great deal of pruning at once.

Why the old machine's history is what gets pruned: it is the oldest material and it is no longer being added to. A retired machine's backups stop being current the day it stops being used, and the system treats them accordingly.

Why the whole set can disappear rather than just its oldest parts: pruning works through from the oldest, and a retired machine's states are all older than the new machine's. Once pruning starts on that set it can consume all of it before reaching anything newer.

Why that is designed rather than broken: the system is protecting the machine currently in use. It has no way of knowing that the retired machine's history is the part he cares about, and nothing asked him.

Why the situation is nonetheless not hopeless: pruning is deletion. Removed content remains where it was written until new backups occupy those regions, exactly as with any deleted file.

Why the destination must therefore come out of service immediately: it is still receiving backups from the new machine. Every scheduled run writes into the space the pruned history occupied, and that is the only variable he controls.

What determines how much survives: how long the new machine has been backing up, and how full the destination is. A few weeks of use may leave a great deal; months of it will not.

What the practical lesson is: a retired machine's backup should be taken off the shared destination before a replacement is introduced. A final copy set aside separately costs a fraction of the destination and is not subject to pruning at all.

On the bench

Retention behaviour was identified as the probable cause before any device fault was investigated — versioned backup accumulating many points in time sharing unchanged content, and deleting the oldest material as capacity is required, which is designed behaviour. A replacement machine's initial backup is a complete copy, forcing substantial pruning at once, and a retired machine's states being uniformly oldest can be consumed entirely. Pruning is deletion, so removed content persists pending overwriting. The destination was removed from service.

The outcome

Retention behaviour identified before any fault was investigated, the destination removed from backup service, and the structure examined for removed set references and retained content. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your suspicion is right and it was not a mistake. The system prunes its oldest material to make room, your new machine's first backup demanded a great deal of room, and the retired machine's history was the oldest thing there.

Before you point a new machine at an old backup drive

Take the retired machine's backup off that destination first and keep it separately — a final copy set aside isn't subject to pruning at all, and it costs a fraction of the drive. Versioned backup keeps many points in time and deletes the oldest to make room as it fills, which is designed behaviour rather than a fault. A new machine's first backup is a complete copy of everything on it, so it forces a lot of pruning at once, and a retired machine's states are uniformly the oldest thing present. If it's already happened, stop the scheduled backups now.

Old machine's backup gone after adding a new one?
Stop the scheduled backups — call Manchester Data Recovery on 0161 871 0788; retention identified as the cause, destination removed from service, structure examined for removed sets and retained content.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.