How do I recover data from the HD portion of a failing Fusion Drive?

I have a 2017 27" iMac with a 2 TB Fusion Drive running Mojave. The Fusion Drive is not encrypted, no Bootcamp, no extra partitions. Aside from the migrated data from my old MB Pro, it looks like a regular factory installation of Mojave on a Fusion Drive.


While re-compressing some large jpg's, my iMac spontaneously rebooted leaving me with the flashing-question-mark-folder icon.


I do have Time Machine but, for various, completely unjustifiable reasons, I have not had Time Machine running for a couple of months. Obviously a terrible mistake.


I installed Mojave on an External drive. The system will now boot to the external but, though the external is selected as the boot drive, there is a kernel panic at about 60% progress, spontaneously reboots, then gets to the log in screen on this second go-round. This is consistent behaviour. Once booted, the machine runs normally—perhaps slower as it's running off of an external drive.


Running diskutil on a healthy system should look like this:

$ diskutil list
/dev/disk0 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *2.0 TB     disk0
   1:                        EFI EFI                     209.7 MB   disk0s1
   2:          Apple_CoreStorage Macintosh HD            2.0 TB     disk0s2
   3:                 Apple_Boot Recovery HD             650.0 MB   disk0s3
/dev/disk1 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *121.3 GB   disk1
   1:                        EFI EFI                     209.7 MB   disk1s1
   2:          Apple_CoreStorage Macintosh HD            121.0 GB   disk1s2
   3:                 Apple_Boot Boot OS X               650.0 MB   disk1s3
/dev/disk2 (internal, virtual):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:                  Apple_HFS Macintosh HD              2.1 TB.  disk2
                                 Logical Volume on disk1s2, disk0s2
                                 SOME-LONG-IDENTIFIER-NUMBER
                                 Unencrypted Fusion Drive


These are my results:

$ diskutil list
/dev/disk0 (internal, physical):
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *2.0 TB     disk0
   1:                        EFI EFI                     209.7 MB   disk0s1
   2:                 Apple_APFS                         2.0 TB     disk0s2


Disk0s3, disk1and disk2 are all completely gone.


Disk1 is the SSD of a Fusion Drive. It's not showing up at all. Naturally, the virtual disk2 can't really be built as one of the components is completely missing.


When I run diskutil cs list, this is what is returned:


diskutil cs list
No CoreStorage logical volume groups found


Running "gpt show" returns what I think are promising results but my knowledge of such commands is weak and I really, really don't want to make things worse.

Any ideas on how I can recover the data with some semblance of a structure? Looking at PhotoRec it seems like it might be able to recover a lot of my files but not with any file structure and without the original file names. Helpful, but not optimal.


Does anyone here have experience trying to recover data from a malfunctioning Fusion Drive? Any help is, of course, greatly appreciated.

iMac Line (2012 and Later)

Posted on Mar 1, 2020 3:42 PM

Reply

Similar questions

9 replies

Mar 1, 2020 6:16 PM in response to HWTech

Thanks for the answers. I did make a clone with DDRescue. I'm running PhotoRec on it now. At this point, it's found roughly 85,000 files. Flipping through the recovery folders, it seems to have found every possible GUI element gif and png from the system folders and rescued them first.


Awesome, lol.


I was wondering about what could be done with GPT but I haven't been able to find something that is easy for me to understand. I'm really not that great with Terminal. It's too easy for me to mangle the image and have to start over—which is really time intensive. Also, I need to get the iMac fixed sooner or later so I can continue on with my life. Once I send it in, I won't have the original drive any more to clone from.

Mar 1, 2020 4:47 PM in response to tripleman

You should make a bit for bit clone of the hard drive and work from the clone. That way if you make a critical mistake you will still have the original drive intact. Of course you will need a 2TB or larger external drive for the clone and it will most likely a day to clone it over USB. The command line utility GNU ddresue is good for cloning a drive since it doesn't require a mounted drive and if you use the logging feature you can resume an interrupted clone (just make sure the source, destination, and logging files referenced are correct since their location may change especially after a reboot).


You can try running Disk Utilty First Aid on the clone to see if it can repair the drive partitions and volumes. Unfortunately if First Aid cannot repair the drive/volume, then you may not have any success since there are no third party utilities yet which can repair an APFS volume since Apple has not released the necessary APFS documentation.


I'm not sure if PhotoRec will work on an APFS volume, but it is worth a try. You could try using a paid data recovery app such as Data Rescue. Stellaris is another data recovery app I've seen suggested on these forums (I've never used it though). I believe both of them have a free download so you can see if they can locate your files. You will need to pay for the apps if you actually want to save any of the files they find.


You should consider contacting a professional data recovery service such as Drive Savers or Ontrack. Both vendors provide free estimates and are recommended by Apple and other OEMs.


I've never tried to recover anything from a broken Fusion Drive so I don't know if there is anything else to know or to do, but I don't think there is much else you can do


Mar 1, 2020 6:45 PM in response to tripleman

Yeah it is horrifying how many files are on a drive when you are trying to recover lost files! So many cache & temp files from the OS and the web browsers as well. Even the paid data recovery apps can be like this too.


As far as restoring the the GPT tables from the backup copy, see if any of these links help:

http://www.rodsbooks.com/gdisk/repairing.html


(See the section about half way down):

https://theducks.org/2010/12/fixing-gpt-partition-tables-for-osx/


I believe using "gdisk" is how I restored a restored the partition table from the backup copy. Just use the following command making sure to replace the "diskN" with the correct drive identifier for your drive:

sudo  gdisk  /dev/diskN


It should automatically see the main partition table is damaged and load the backup copy automatically. If you exit the utility with "q", it should not apply the backup copy and leave your drive untouched (in theory). If you exit "gdisk" by pressing "w", it will write the backup copy to the main header on the drive which hopefully will restore access to your drive and the data. It should be just that simple.


I can certainly understand your hesitation. I've been there many times myself when trying to recover data for other people. Data recovery is a painful and time consuming process especially if you do it the right way by being cautious. It is nice to know PhotoRec can find items on an APFS file system as I wasn't sure.


Good luck and please keep us informed on how you make out.

Mar 11, 2020 2:19 PM in response to HWTech

So, in the end, I ran PhotoRec a second time—limiting the types of files that it would search for to only ones that I might need—and it completed without crashing.


It grabbed about 1.5 million files. Some corruption, no real structure, no original file names. Most likely* this is actually not much different from what I would get from a paid service.


Trying gdisk did not work for me.


I spent some time trying a terminal app called Afro (just search for Afro apfs) on GitHub that is specifically built for APFS drives. I was hoping that it could parse the file system and maybe recover my files with some sort of structure. But, it's a forensics tool first and, as far as I can tell, it's not necessarily meant for drive failure situations. Or, more probable, the damage to my file system was simply too much for it to work.


DiskDrill showed a list of files that was very similar to what I already had recovered with PhotoRec so I didn't spend the hundred bucks that it costs. IBoysoft (I avoided trying this until the very last possible moment simply because of the terrible name) took so amazingly long (it estimated more than 80 hours compared to DiskDrill, TestDisk and PhotoRec all needing ~10 hours) that I bailed out. From what it was listing before I bailed on it, it would not have been able to restore my files with a better structure than PhotoRec so, again, I saved myself the $100.


A Fusion Drive CoreStorage setup is basically a raid 0 type of situation. When my SSD failed, there was no recovering from that in any sort of a graceful manner. I could have saved myself a lot of time and aggravation if:


Moral of the story: keep good backups.


*Don't take my word for it folks, look around on your own, you might be luckier—or your situation could simply be different than mine.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How do I recover data from the HD portion of a failing Fusion Drive?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.