Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

mymacsux

macrumors newbie
Original poster
Hi all. Long term mac user but was recently gifted a new machine which I've had nothing but problems with since day one if anyone can help. Specs are as follows:

13" Macbook Air M4 / 256gb SSD / 16gb RAM / Sequoia 15.7.7

The laptop is not not entirely my main use computer so I only really use it for a few movies/games and apps that wont run on my older day-to-day mac; and because not much ever changes on it, I know every time I switch it on I should always have ~60GB free SSD.

However, all of a sudden, at some random point, even if the laptop is totally idle, my SSD will instantly go from ~60GB free to ~45GB free. It does this every day at least once. No idea why, and I'm certain it never used to do it as I would have noticed.


Don't know if it's relevant but a short while back I upgraded to Tahoe, didn't like it, so did a full erase and Sequoia reinstall. Since then I've done several clean installs trying/failing to get fix the issue. Can't say for sure if its connected to downgrading as I don't recall it happening right away.

As you can see from the screenshots, from the General > Storage tab in Settings, my MacOS balloons from the normal ~25GB to ~40GB with System Data rocketing from ~2GB to ~7GB.

I do not use any Time Machine backups yet from Disk Utility something is making multiple 5.66GB snapshots on one of the segmented drive sections.

Restarting the computer does nothing to delete these snapshots or give me back my missing 15-20GB. The only solution I've found it booting in Safe Mode, which does fix the issue, however within a day my ~60GB drops back to ~45GB again.

I should not have to keep booting into safe mode every few hours to fix an issue that never used to exist, so any help or advice to fix this would be much appreciated.


Sorry for long post. Many thanks in advance.
 

Attachments

  • Storage-WTF-1.png
    Storage-WTF-1.png
    30.7 KB · Views: 101
  • Storage-Normal-1.png
    Storage-Normal-1.png
    31.6 KB · Views: 81
  • Storage-Normal-2.png
    Storage-Normal-2.png
    191.6 KB · Views: 80
  • Storage-WTF-2.png
    Storage-WTF-2.png
    270.8 KB · Views: 81
  • Unknown Snapshots.png
    Unknown Snapshots.png
    512.8 KB · Views: 72
It’s a bug. I have the same on Tahoe, brand new MacBook Air. System Data will balloon to 70 gb , i boot it in safe mode and restart it and it’s like 9gb. I tried everything, had Claude help me diagnose it and the safe boot mode was the only thing i could tie it to. It’s annoying for sure.
 
Can you select them and click the delete (-) button….?
Have you done software updates recently, they could be created for that, to save the previous state.
 
  • Like
Reactions: mymacsux
My only suggestion would be to use GrandPerspective/DiskDaisy/OmniDiskSweeper to find out where exactly the size is coming from. Maybe there's a runaway processes writing too much data somewhere.
 
It’s a bug. I have the same on Tahoe, brand new MacBook Air. System Data will balloon to 70 gb , i boot it in safe mode and restart it and it’s like 9gb. I tried everything, had Claude help me diagnose it and the safe boot mode was the only thing i could tie it to. It’s annoying for sure.

Can you select them and click the delete (-) button….?
Have you done software updates recently, they could be created for that, to save the previous state.

My only suggestion would be to use GrandPerspective/DiskDaisy/OmniDiskSweeper to find out where exactly the size is coming from. Maybe there's a runaway processes writing too much data somewhere.

Thanks all for the replies.

@ry-guy I didn't use Tahoe long enough to notice if this issue happened with that OS too, so for me it's really only a new thing in Sequoia but it never used to happen which is odd.

@MarkC426 I tried to delete them but I just got an error message as per the attached screenshot. I haven't done any software updates per se as I've done several full erase/resets, so it's a fresh install, all apps from the App store, with Sequoia 15.7.7 being the default version. The only "update" is a ~200mb Safari update but would be surprised if thats the cause. I've tried terminal commands to maybe stop mac doing/prompting updates in the background but -so far- it doesn't feel like they are a fix.

@!!! I've downloaded all three of those and will give them a try soon as I'm going to try and leave the mac idle/off for a day or two just to see if somehow not using it maybe resets the issue, or if it doesn't, perhaps I can pinpoint why it seems to keep happening at certain times of the day and not others.

Thanks all for the suggestions, very much appreciated indeed. Any further suggestions are welcome. Will update with any relevant info over the weekend.
 

Attachments

  • Cant Delete.png
    Cant Delete.png
    534.9 KB · Views: 76
a few random thoughts:

- if nothing else helps, you should do the nuclear option: a full DFU restore with a fresh Sequoia .ipsw. That's the ONLY option that will completely wipe all the Tahoe traces from your system.

- Have you Carbon Copy Cloner installed? It can also create Snapshots. (It can also delete them. Pretty helpful.)

- Does the System Data keep growing? (like 5 GB per day?) Or will it stay at a certain point?

- Please note, that there is a certain amount of System Data, that is needed for daily use. (Caches, Indices, etc.) These are deleted when you boot into SafeMode, but are recreated during normal use, because the Mac needs them. (System Data on my Sequoia M2 MacStudio is 49 GB for example, after almost 3 years of use. So 7 GB of System Data - like in your case - seems pretty reasonable to me. At least as long as it doesn't increase by 5 GB per day.)
 
a few random thoughts:

- if nothing else helps, you should do the nuclear option: a full DFU restore with a fresh Sequoia .ipsw. That's the ONLY option that will completely wipe all the Tahoe traces from your system.

- Have you Carbon Copy Cloner installed? It can also create Snapshots. (It can also delete them. Pretty helpful.)

- Does the System Data keep growing? (like 5 GB per day?) Or will it stay at a certain point?

- Please note, that there is a certain amount of System Data, that is needed for daily use. (Caches, Indices, etc.) These are deleted when you boot into SafeMode, but are recreated during normal use, because the Mac needs them. (System Data on my Sequoia M2 MacStudio is 49 GB for example, after almost 3 years of use. So 7 GB of System Data - like in your case - seems pretty reasonable to me. At least as long as it doesn't increase by 5 GB per day.)
Thanks for the info. So far I haven't had the issue in the last couple of days (perhaps because it's been left either off or more idle than usual, not that its a great fix). I do not have CCC installed but if the issue happens again I will definitely give it a try as well as explore how to do the full wipe you mentioned. FWIW in the few months I've been frequently using this mac (with a few resets) I don't recall my system data going beyond 4-5GB, but when this issue occurs it does go up 0.01GB virtually every second and you can watch your storage gradually disappear until a safe boot. Appreciate the input, will see if my mac can go a week and then try those options.
 
a 15-20GB overnight drop with almost no user activity has a pretty short list of usual suspects on Apple Silicon. the fact that safe boot resets it (per ry-guy) is the clue — safe boot skips creating local snapshots and clears caches. some things to check on the actual machine:

`tmutil listlocalsnapshots /` in Terminal will show you every APFS local Time Machine snapshot. even without a TM destination configured, macOS keeps 24 hours of hourly local snapshots on the system volume, and if your working set has any churn (Photos library, mail, browser cache) those snapshots reserve that space until they age out. `tmutil deletelocalsnapshots <date>` clears them individually if you want to test.

second, `sudo mdutil -s /` — if Spotlight indexing is stuck in a loop (common after a version change like the Tahoe → Sequoia round-trip you did), mds_stores can write a huge index temp file overnight and never finalize it. `sudo mdutil -E /` erases and rebuilds the index cleanly, which sometimes gets the daemon unstuck.

third, sleepimage in /private/var/vm/ — 16GB of RAM means that file can be 16GB when the machine hibernates. it should be reused, but I've seen edge cases where it doesn't get overwritten cleanly.

if none of those pan out, GrandPerspective + comparing snapshots morning/night will show you exactly where the delta is.
 

 
  • Like
Reactions: mymacsux
a 15-20GB overnight drop with almost no user activity has a pretty short list of usual suspects on Apple Silicon. the fact that safe boot resets it (per ry-guy) is the clue — safe boot skips creating local snapshots and clears caches. some things to check on the actual machine:

`tmutil listlocalsnapshots /` in Terminal will show you every APFS local Time Machine snapshot. even without a TM destination configured, macOS keeps 24 hours of hourly local snapshots on the system volume, and if your working set has any churn (Photos library, mail, browser cache) those snapshots reserve that space until they age out. `tmutil deletelocalsnapshots <date>` clears them individually if you want to test.

second, `sudo mdutil -s /` — if Spotlight indexing is stuck in a loop (common after a version change like the Tahoe → Sequoia round-trip you did), mds_stores can write a huge index temp file overnight and never finalize it. `sudo mdutil -E /` erases and rebuilds the index cleanly, which sometimes gets the daemon unstuck.

third, sleepimage in /private/var/vm/ — 16GB of RAM means that file can be 16GB when the machine hibernates. it should be reused, but I've seen edge cases where it doesn't get overwritten cleanly.

if none of those pan out, GrandPerspective + comparing snapshots morning/night will show you exactly where the delta is.



@benholt I'd tried to look up snapshots in Terminal, but it didn't list any at all even though they'd show in Disk Utility. My Spotlight seems to be forever either reindexing itself or always on pause, but I think the sudo command has fixed that now. My sleep image was only ~1GB and GrandPerspective didn't show anything unusual but the issue hasn't happened for almost a week now, so hopefully it's fixed. Thanks for the info, much appreciated.

@MacCheetah3 thanks for those links, very useful to get an understanding of what might be happening. I'm hopeful the issue is now resolved but will keep them handy and see how it goes over the next few days just to be sure. Appreciate the info.
 
third, sleepimage in /private/var/vm/ — 16GB of RAM means that file can be 16GB when the machine hibernates. it should be reused, but I've seen edge cases where it doesn't get overwritten cleanly.
Correction; if hibernate mode is on, 3 or 25, 16GB of RAM means that sleepimage file is always 16GB whether the machine hibernates or not.
pmset -g --- Shows the sleep settings you have set now.
This will make the 16GB sleepimage a zero byte file and save that 16GB of Disk Space.
I have used this for years and never had any related issues.
The following 4 commands should be done in order as one set.
sudo pmset -a hibernatemode 0
sudo rm /var/vm/sleepimage --- Ignore any message saying there is no such file
sudo touch /var/vm/sleepimage --- Make a blanked zero-byte file
sudo chflags uchg /var/vm/sleepimage --- Make the file immutable (non-changable)
(use <sudo chflags nouchg /var/vm/sleepimage> to revert if necessary)
 
Last edited:
I second LeVan's reply above about "shrinking" the sleepimage file to "0" and "turning it off".

Remember to use the sudo commands "one at a time" -- a "4-step" process.
You'll be asked for your password after the first entry (that's what "sudo" requires).
But not for the next 3.
 
  • Like
Reactions: mymacsux and LeVan
Correction; if hibernate mode is on, 3 or 25, 16GB of RAM means that sleepimage file is always 16GB whether the machine hibernates or not.
pmset -g --- Shows the sleep settings you have set now.
This will make the 16GB sleepimage a zero byte file and save that 16GB of Disk Space.
I have used this for years and never had any related issues.
The following 4 commands should be done in order as one set.
sudo pmset -a hibernatemode 0
sudo rm /var/vm/sleepimage --- Ignore any message saying there is no such file
sudo touch /var/vm/sleepimage --- Make a blanked zero-byte file
sudo chflags uchg /var/vm/sleepimage --- Make the file immutable (non-changable)
(use <sudo chflags nouchg /var/vm/sleepimage> to revert if necessary)
I second LeVan's reply above about "shrinking" the sleepimage file to "0" and "turning it off".

Remember to use the sudo commands "one at a time" -- a "4-step" process.
You'll be asked for your password after the first entry (that's what "sudo" requires).
But not for the next 3.
Thanks for the info. It's not happening as much now, although it may be because I'm not using the laptop as much and also do a safe boot start every now and then just to clean it out. Will use those commands if it becomes an issue again.

Are you sure it's not just osx gobbling up storage as VM having only 16GB ram?
I don't know. System Settings tells me the OS is still a fraction under 25GB as it was on the clean install, with System Data generally being around 5-7GB which doesn't seem overly large or unusual. My sleep image is also not a huge file size, so it's probably just the way the OS is. A safe boot once a week seems to have the issue under control for now thanks.
 
Thanks for the info. It's not happening as much now, although it may be because I'm not using the laptop as much and also do a safe boot start every now and then just to clean it out. Will use those commands if it becomes an issue again.


I don't know. System Settings tells me the OS is still a fraction under 25GB as it was on the clean install, with System Data generally being around 5-7GB which doesn't seem overly large or unusual. My sleep image is also not a huge file size, so it's probably just the way the OS is. A safe boot once a week seems to have the issue under control for now thanks.
How do you know the size of the sleepimage file is "not a huge file size"? If the hibernate mode is 3 (the default), the slleepimage file will be the size of the RAM installed, and it is not dynamic (does not change size). Run the "pmset -g" Terminal code to see what the hibernation mode is set at now.
 
OP:

Once again, I'll recommend that you disable the sleep image, and then delete the existing image and replace it with one that will remain "0" in size.

This will take you about 1 minute to complete.

The 4 terminal commands to do this are up above in the thread...
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.