{"id":90,"date":"2024-12-16T11:00:46","date_gmt":"2024-12-16T11:00:46","guid":{"rendered":"https:\/\/lawrencetechservices.com\/?p=90"},"modified":"2026-08-18T01:59:34","modified_gmt":"2026-08-18T01:59:34","slug":"transferring-data-from-an-apple-filesystem-apfs-partition-with-linux","status":"publish","type":"post","link":"https:\/\/lawrencetechservices.com\/index.php\/2024\/12\/16\/transferring-data-from-an-apple-filesystem-apfs-partition-with-linux\/","title":{"rendered":"Transferring data from an Apple Filesystem (APFS) Partition with Linux"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Preface<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We needed to pull data from a Macbook hard drive without having access to another Mac device. We decided to use Linux using the&nbsp;<a href=\"https:\/\/github.com\/sgan81\/apfs-fuse\">APFS-Fuse<\/a>&nbsp;by sgan81.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Definitions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>APFS(Apple File System)<\/strong>: This the organizational system Apple uses to organize files on Mac OS storage drives (Hard Disk Drives, Solid State Drives\u2026).<br><strong>Virtual Machine (VM)<\/strong>: Virtual Machines are guest operating systems running on an application inside of another operating system.<br><strong>Package<\/strong>: Software\/Resources.<br><strong>Package Manager<\/strong>: Software to control to installation\/updating\/removal of packages.<br><strong>Repository<\/strong>: A location containing a project\/code.<br><strong>Path (Terminal)<\/strong>: A file with a list of all the locations terminal will look for to find the application\/command you type in.<br><strong>Superuser<\/strong>: Elevated User (Administrator is the Windows equivalent to Superuser).<br><strong>Mount (Mount Point)<\/strong>: Location where a drive&#8217;s files are displayed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>sudo<\/strong>: the user is in the \u201cSudoers\u201d group this command will elevate the command written behind it.<br><strong>apt<\/strong>: Advanced Package Tool, Debian based package manager. \u201capt install\u201d is used to install packages.<br><strong>ls<\/strong>: List files in the request directory. If no path is given it will list files in the current directory.<br><strong>cp<\/strong>: Copy command, copies the given the entered file to the given path. If a folder was targeted the recursive flag must be used.<br><strong>git<\/strong>: Version control software. This is for managing repositories and in this writeup will only be used for preparing a repository to be build.<br><strong>cmake<\/strong>: Software used for building\/compiling code into software.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">System<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Because I don&#8217;t expect to see many APFS recoveries I opted to create a Linux Mint VM to install APFS-Fuse onto. For the VM, I created a restore drive to hold the recovered data. However, I did not create a drive for the OS, as the live environment will work just fine.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Setup<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sgan81&#8217;s APFS-Fuse installation instructions are great and make it easy to follow.<br>The first step was to update the system, and then install the required packages. Since I was using a live environment, I chose not to do the update. The next command was for the packages:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt install fuse libfuse3-dev bzip2 libbz2-dev cmake gcc-c++ git libattr1-dev zlib1g-dev<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">I was unable to install gcc-c++ which would have been used with cmake for building the project folder. However, because g++ was working I knew cmake would work and moved on.<br>After installing the required packages, I needed to use git clone to copy the&nbsp;<a href=\"https:\/\/github.com\/sgan81\/apfs-fuse\">repository<\/a>. Once it had finished downloading, I went into the directory and ran the following commands:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git submodule init\ngit submodule update<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">From there we are ready to build to package. We made a folder to build the package in and went into it and ran &#8216;cmake ..&#8217;. This run compiles project in the folder above, but have it dump the files in the build folder. After it finished, we then ran &#8216;make&#8217; to build out the rest of the software. From there we are ready to open the APFS filesystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From there we are ready to build to package. We made a folder to build the package in and went into it and ran &#8216;cmake ..&#8217;. This run compiles project in the folder above, but have it dump the files in the build folder. After it finished, we then ran &#8216;make&#8217; to build out the rest of the software. From there we are ready to open the APFS filesystem.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Opening APFS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Because the APFS-Fuse folder is not in terminal&#8217;s path, we will have to run the software by appending &#8216;.\/&#8217; so our command should look like:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.\/apfs-fuse &#91;device-location] &#91;mount-point]<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">In my case the partition was at \/dev\/sdb2, and I want to send it to \/mnt. To send it to \/mnt I will need to have superuser permissions. My command was:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo .\/apfs-fuse \/dev\/sdb2 \/mnt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">When I opened a file explorer, and went to \/mnt the drive stopped responding. This meant I had to unmount the drive using:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo umount \/mnt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">I then had to remount using the same apfs command as above. The file explorer didn&#8217;t work. I then tried to use &#8216;ls&#8217; in terminal, but it replied back saying I didn&#8217;t have permission to access that folder. I then ran &#8216;ls&#8217; as a superuser and did not have any issues. I started looking into the drive. Whenever I pushed the drive to much, the transport layer would close forcing me to unmount and remount the drive again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Copying the data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With the drive now mounted, I am able to explore the drive. I took the restore drive and formatted it as a FAT filesystem to make sure that any OS would be able to access the drive. I then had to slowly try to copy each folder in the users root directory. If it failed, then I had to go into the failed directory and copy each file individually. The cycle of commands looked as follows:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ls \/mnt\/path-to-user\nsudo cp \/mnt\/path-to-user\/subdirectory \/media\/mint\/recovery-drive<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">and if there was a failure:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ls \/mnt\/path-to-user\/subdirectory\nsudo cp \/mnt\/path-to-user\/subdirectory\/FileorFolder \/media\/mint\/recovery-drive\/subdirectory<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Once the data was recovered, it was copied to an external hard drive. Then it was ready for delivery.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Preface We needed to pull data from a Macbook hard drive without having access to another Mac device. We decided to use Linux using the&nbsp;APFS-Fuse&nbsp;by sgan81. Definitions APFS(Apple File System): This the organizational system Apple uses to organize files on Mac OS storage drives (Hard Disk Drives, Solid State Drives\u2026).Virtual Machine (VM): Virtual Machines are [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-90","post","type-post","status-publish","format-standard","hentry","category-knowledge-base"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"_links":{"self":[{"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/posts\/90","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/comments?post=90"}],"version-history":[{"count":3,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/posts\/90\/revisions"}],"predecessor-version":[{"id":94,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/posts\/90\/revisions\/94"}],"wp:attachment":[{"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/media?parent=90"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/categories?post=90"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawrencetechservices.com\/index.php\/wp-json\/wp\/v2\/tags?post=90"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}