Aggregated disk writes

i have found the text below in iPhone analytics data. What does it mean please?

{"app_name":"aggregated","app_version":"","bug_type":"145","timestamp":"2020-02-06 08:20:33.14 +0300","os_version":"iPhone OS 13.3.1 (17D50)","incident_id":"34880E87-9A67-4A16-A17A-94D0369275CF","slice_uuid":"B722CBE6-961A-3300-80E4-2CC18CCFC143","build_version":"","is_first_party":true,"share_with_app_devs":true,"name":"aggregated"}

Date/Time: 2020-02-05 21:01:20 +0300

End time: 2020-02-06 08:20:32 +0300

OS Version: iPhone OS 13.3.1 (Build 17D50)

Architecture: arm64e

Report Version: 29

Incident Identifier: 34880E87-9A67-4A16-A17A-94D0369275CF


Data Source: Microstackshots

Shared Cache: 0x1a4e8000 A77981DC-1632-354B-978B-380DC657D1E6

Shared Cache: 0x24988000 A77981DC-1632-354B-978B-380DC657D1E6


Command: aggregated

Path: /System/Library/PrivateFrameworks/AggregateDictionary.framework/Support/aggregated

Version: ??? (???)

PID: 1811


Event: disk writes

Action taken: none

Writes: 1073.75 MB of file backed memory dirtied over 40752 seconds (26.35 KB per second average), exceeding limit of 12.43 KB per second over 86400 seconds

Writes limit: 1073.74 MB

Limit duration: 86400s

Writes caused: 1073.75 MB

Writes duration: 40752s

Duration: 40752.35s

Duration Sampled: 40679.60s

Steps: 263 ( (10.49 MB/step))


Hardware model: iPhone12,1

Active cpus: 6

iPhone 11, iOS 13

Posted on Feb 7, 2020 5:50 PM

Reply

Similar questions

95 replies

May 29, 2020 1:53 PM in response to DARKG8R

UPDATE : Important recollection during 13.4 when my Apple Trusted certificates changed and the Nvram OTA after - In March, my location somehow was fixed and correctly showed Boston, MA. It stayed that way for a few weeks until the 13.4 update, when it changed to a different State again. This is so major, I can't believe I didn't post it. But I Support did do a screenshare and enhanced log. They CHANGED my iphone IMEI !!!! This was of the 2-3 logs that generated after an 'unknown' restore completed. I recall this in thinking back a few weeks ago when I asked cell co. to redo the sim. She said would but nothing ever happened.


As of today, I am completely unable to change my location from the State it is in. I received a manadarin call today and two Stacks logs generated immediately during when the call came in.


Bottom line: Someone fixed my location and the criminals needed and were able to access my phone remotely to send a rogue update that must have restored my device using someone else's system which is why IMEI is wrong. Looking in General all is good but certain if my device was checked forensically, IMEI won't match. And they also have access to my icloud because since 13.0 end Dec, my backups were turned off or deleted after Apple restore. Including last month. There are also both Provisioning amd MDM. Multiple of each. Added note. No ios updates should be coming from carrier since phone purchased from Apple Store. See short video proving I am no longer able to correct or use location in Safari. Taken today


Edited to insert correct screen video


May 29, 2020 5:10 PM in response to Cr21h

Another thing I notice. Today is Friday May 29. It occurred last night. Reinstalled H--ulu from appstore last night. Twice.

1) Size of app doesn't match what is posted in appstore but version says correct. The app generated a crash log Thread 4 "AVaudiosession notify thread" amongst other thin it says.


2) G---oogl--e Ch--romeC---a--st is installed on my iphone??? see pic. Why would this be installed if I downloaded app from Apple appstore onto iphone? And why is not all arm64e? Some is just arm64.

Apr 28, 2020 11:18 PM in response to DARKG8R

Interesting that I found this post here. I just posted earlier regarding Certs validation. My Certs changed recently. And, i'm going through the same thing. I have a disk writes log in my phone and generated last night.

problem started at the end of September beginning of October. After every Apple update someone is remotely restoring my device. Effectively downgrading my device. I've contacted Apple multiple times since I also noticed managed configuration and remote management. This was listed numerous times and logs. logs have changed now, then not the standard logs I've always had.

I contacted support again after the update because I noticed an OTA nvram wipe as 'stale'.This after an update. The interesting things is what I viewed in the log. And why I noticed the Trust Certificates date changed. there were numerous exceptions and regarding Certs it was saying no name and to pull a name from a specific file I won't mention here. I am 110% certain, it blacklisted com...apple..os..software...update... or something along that layout. Ditto for Apple's own Certs. it also did things to hardware which I do not know. But since I contacted support and they screen shared with me they should certainly have that particular log question. all the times I've contacted them in the last months of all pertained to managed configuration and remote management. Also, that it appeared a system restore was taking place after each Apple update. I was never more certain than this last update a few weeks ago. A white screen with black letters said restore completed it was hidden behind the black login screen with the Apple.


contacted support again today regarding MDM and remote management because of the disk writes I saw. as always I am told it's not possible unless it says profile. Also it is not possible to do a restore unless it is I that's doing it. While I beg to differ, hey, they are the experts. It's been a trust factor in the Mojo I feel for Apple. But I have three devices that I'm not feeling confident about at the moment.


I do believe developer certificates are being used. I wonder if it Is coming from my cable company since they also sell the same products and offer the same service for said products. My home network and phone are using excess data.


This is definitely at least for myself not happening for the benefit of Apple or reputation. Consider black listing them from their own products, inserting rogue Certs, downgrading ios and other Apple product systems. Plus, from what I've seen in the last four or five updates since end of September they appear to know the schedule of these updates that are not publicly shared. Because something funky always occurs prior to the update release. but with the big transformations I saw the other week I'm not sure that will be necessary at all anymore.


Hopefully Apple sees this here and can fix it. because, as of today, I'm simply told the MDM cannot happen without a profile and remote restores not possible. I have received no answers regarding nvram, certs and the screenshare either. advisers tell me they have no record of any of it. Including today I was told there was no record of screenshare or data all the data and proof of mdm, I submitted to the gigabyte site. He wants me to send more data saying I have to prove it as if I already haven't. I'm done. I'd like it fixed now.

May 4, 2020 3:59 PM in response to DARKG8R

I want to post an update on my situation. I have an Disk Writes occurring today. This time, it is Safari Disk Writes and references power, sql, etc. I've shut down cable service already so this, is not a result of that. Three Apple devices are being controlled by someone who has access to my AppleId which I never share, and access to unique device information which I have never shared with anyone. Additionally, it appears they have not only downgraded ios version, but they have ALSO downgraded my device to an iphone 7 plus! Multiple indicators, for example AppleTv on phone now is a small screen as if I have the white band on top and bottom where fingerprint and Home would be.


Also, prevalent in all these months, when my device was only 8 months, is, there is

1) schedule callback taking place, importantly, 2) CommCenterEntitlementRequest that consistently appears to be changing my location or routing my service.

3) Something to do Sqllite3

To add further to the nvram ota I spoke of in my other post on this thread, there was another mount volume created.


Atop my initial Q's I want to know where my icloud server is based. What state, do my files reside? Is it supposed to be close and in region where one lives? Opened it?.....






May 4, 2020 7:37 PM in response to Jagcresmur

See, the problem here is one thing seems to affect the other. AND I think there are at least two seperate things going on. Cable co appears to be doing MITM too. I paid for additional security from them too until they began giving it free. My question, is what device info can a cable co get? Did they take the phone number, route it in their service, link to my AppleId and create an MDM since they also sell Apple products and then downgrade the OS and ios? I rarely ever connected to wifi too. But that doesn't explain the nvram ota. Also, in my case, I think a neighbor who has Apple prods too, might have major issues. She showed me a slew of phone numbers in her contacts she said she didnt put there. Apple needs to find a way to not allow priveluge access into any devixe info. It should not be granted as it appears it was to I don't know who. Bottom line, I think there is monitoring as well as illegal phone/internet activity taking place, using my device. Consider, it has to be placed somehow and if the phone has never been left alone and only connected for a restore and hardware check at Apple, and the ither devices are minths old and barely used, I cannot decipher it quite yet but have a reasonable sequence of things. I have to check receipt dates.


As soon as my device turned one year, all **** broke loose. Just before, there were numerous queries in log for Account info and queries also came from Appstore? I did inform Support. Wasn't completely sure if it had anything to do with connecting to our Appletv.

May 11, 2020 5:47 AM in response to Community User

One more thing. When I log in to my AppleId on my phone, I no longer receive verification codes. It just logs me right in. And, in calling Apple support at the mid April, it also stopped sending me device verification. So since my phone was 8 months old til now, it's all good???? I hate being lied to. That to me is the worst of human character traits.

May 12, 2020 1:19 AM in response to Cr21h

DarkG8r, thanks for your reply. Pinpointed yes. I am a female, mother, victim, witness, not criminal.


Update: Appears my iphone has two seperate accounts going on mine and another with my initials.


Q for all: I want to reset my end to end encryption but absolutely none of the various ways, work. Nothing is allowing me to reset end to end encryption. How else can I get this done?


Thanks in advance.

May 26, 2020 3:57 PM in response to Cr21h

Update on my situation. More happened but this is just for yesterday on my phone. Four stacks logs generated. Three in the afternoon during in the middle of a phone call and the fourth around 8p. Some explanation from what I know occurred described after examples. Logs heavy for throttling Sflags throttlng, camera, voice, video, Camin, mail, something called utune, all forms network, VM, skywalk doorbells and if_nets and controllers. Some regarding Apple account.


Example: ifnet_start_utune1, much regarding wifi and vm.

Example: vm_io_reprioritize thread, hardware, vm_swapfile_create, many skywalk doorbells


Example: skywalk_doorbell_en0_tx, skywalk_doorbell_pdo_ip2_tx, AppleICA60, ioAccelFenceMachine, AppleEmbeddedGPSControl


Saturday installed H--ulu app. Login as normal shows location of login. It shows me out if state. Multiple logins to other accounts unrelated also show me out of state (I'm not in that state). This has been a problem for at least 8 months. Someone changed my service to be routed through specific network servers coming from west coast while I am in the northeast. From there, they can manipulate anything sunce they clearly cobtrol said servers. Contracts, devices, Apple accounts and usage all opened/purchases in Boston, MA area.

Saturday - Notified Apple of wrong state situation again.

Yesterday, Monday, log into the H app again, this time it sends my FULL ip and NO location. Security issue. I contact H via chat and explain my account was changed between Saturday evening- Monday afternoon. This occurs on backend. Customer can't do it. This is a security issue aka hackers. They fix it to report as normal. Then after, I made a call, these Stacks logs occurred. In less than 1 1/2 hrs of me discovering my H account was altered to send my full ip to sit on an unencrypted Apple server, and me contacting them, the Stacks occurred.


The reason ut has me un a dufferant State, is because they MOVED both Cell and icloud server to west coast. Clearly shown by my billing cycle being changed from 11:59p to 2:59am AND previously having done Trace Routes a few times. Each time same route from west coast to TX or Chicago then Rhode Island. Rhode Island towers used by ATT no my service and owned by individuals in the west coast. I've checked and all major cell networks less than 2 miles of my location. My service will not use any of them.


Bottom line: I think the criminal needed my new ip address and used an insider in H. Really, what are the chances of me downloading H, all normal, changes made, then an hour adter I login again and get email notice, I get these Stacks that have extensive throttling and promotions when I'm just on a phone call?

May 29, 2020 2:10 PM in response to Community User

Correction: since 13.0 end of September beginning October 2019, someone has been turning off or deleting my backups from icloud server. Noticed backup deletions or turned off, after 13.0 when I saw a restore done after I updated and before Apple removed signing. Unable to restore device to know good. Then again after Apple restored iphone and again after 13.4 when they changed root certificates. They also must be using the esim which, how could they get that info?

Jun 4, 2020 3:59 PM in response to Cr21h

Update: Today. Someone turned on my settings for Handoff automatic settings.


Also, they are coming through the downloaded apps and turning on downloads up to 200mb. Recently they used A-zon app. They are altering app personal account information to get other details and from there shifting service. They duplicated purchases. These dupe purchases came from west coast. Also added a phone number, removed OTP, login notifications and location, etc. THIS is how they're doing it. Something very fish with u--ps definately. I won't go into. Phoned my carrier today. A---azon got my number immediately did a memory corruption? Microstackshots with kernal calls, while interacting with them regarding an unknown west coast number attached to my account. Can't explain all here. Tried to resolve by removal if erroneuous number and dupe charges. Within minutes I phone Cell Co. and Agent from west coast region picks up. Not my regular region. Ask why. Tells me matter of factly they they will be managing our account from now on and carrier divided all accounts up evenly and ours was transferred to west coast. I said no we do not want that and should not be happening at all. Why would we pass 49 states and get service and mive our account in a region we want nothing to do with. We opened account and purchased devices in Boston, MA not west coast. As I said previously billing was changed from EST time to west coast time. Also when I called carrier recording spoke of west coast time also. Coming up to that, within the last number of days, I received at least six calls from west coast. Same State. Most no message except for two. Yesterday someone wiped my entire call log and VM's. This is calculated. It clearly shows. Consider during that one statement by carrier at least 10,000 people got new service. And carrier has it sorted by regions so why would they illegally try to take us iff our region? It is illegal to move our service. Or alter our service in the way that it has occurred. This is so criminal. ps: The number attched to A-zon acct is also that same State in issue.


Additional notes: Accessibility is being used.

Jun 4, 2020 4:17 PM in response to Cr21h

Update: Today. Someone turned on my settings for Handoff automatic settings.


Also, they are coming through the downloaded apps by using personal info WITHIN said app. In other words, you sign up for acct, then they use an insider to slightly alter your personal info then it gors from there to get the service. Today, for me, the also turned on downloads up to 200mb along eith Handoff. Recently, again, in my situation, they used A-zon app. They are altering app personal account information to get other details and from there shifting service. They duplicated a few of my purchases. These dupe purchases came from west coast. Also added a phone number fron same, removed OTP, login notifications and location, etc. THIS is how they're doing it. Something very fish with u--ps also. I won't go into.


A---azon, while interacting and trying to resolve, their app did a memory corruption. It was Microstackshots with kernal calls, while interacting with them regarding the unknown west coast number attached to my account. Tried to resolve by removal if erroneuous number and dupe charges.


Within minutes after, I phone Cell Co. and Agent from west coast region picks up. Not my regular region office. Ask why. Tells me matter of factly they will be managing our account from now on. That carrier divided all accounts up evenly and ours was transferred to west coast. Of course we were adamant and refused any change like that. We want in our area. Not across the world. I said they shouldn't be moving our account at all. Whatsoever. Why would we pass 49 states and get service and move our account in a region when we're here. Plus, account was opened and devices purchased MA not west coast. Consider during that one statement Agent made, at least 10,000 people got new service. And carrier has it sorted by regions so why would they illegally try to take us off our region? As I said previously billing was changed from EST time to west coast time. Also when I called carrier recording spoke of west coast time also. This is calculated and everything shows it.


Coming up to that, within the last number of days, I received at least six calls from west coast. Same State. Most no message except for two. Yesterday someone wiped my entire call log and VM's. It is illegal to move our service from where we signed contract, live and never left. This is so criminal. ps: The number attched to A-zon acct is also that same State in issue.


Additional notes: Accessibility is being used.

Jun 4, 2020 4:52 PM in response to Community User

Just want to clarify because, in what I posted was initially jumbled. Much has happened and I'm at my wits end. I want to be more clear in my last post above.


For my situation, it is coming from a few directions. But all paths lead to same issue.


For me, as I know and in short, my number and account were acquired, it was altered via MDm, managed configuarion, mobile configuration and MS intunes? from the beginning. With utunes/intunes (not itunes), they are able to alter device further away from Apple configuration and, I believe alter the certificates. By not using Apple's Configurator. Hence, someone illegally put device in utunes/intunes. Good luck trying to get help no way to contact that co at all.


Also, apps I downloaded were used. So Apple might see app as clean in appstore. But criminals want account access to those apps installed so they set out to alter the account info to the app. In my case two different well-known apps.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Aggregated disk writes

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.