The sealed system volume and the space you will never get back

Since Big Sur, macOS doesn’t live on the same volume as your files. It sits on its own read-only volume with a cryptographic seal, and what you think of as “the disk” is really the data volume with the system grafted onto it through a set of links called firmlinks. That arrangement explains where the first 15 GB of a fresh install goes, and it’s why a whole family of older cleanup advice can no longer be followed at all.

You can see both halves:

diskutil apfs list
df -h / /System/Volumes/Data

/ is the system volume: read-only, sealed, typically 10 to 15 GB depending on the macOS version. /System/Volumes/Data holds everything else, meaning your home folder, the apps you installed and everything you’ve ever made.

Diagram: the single folder tree you see at / is built from two volumes; /System and /usr come from the sealed read-only system volume, while /Users, /Applications, /Library, /private and /System/Library/AssetsV2 are firmlinked to the writable data volume
One folder tree, two volumes: firmlinks decide which paths are yours to change.

What the seal means for space

The seal is a hash over every file on the system volume, checked as the system reads it. Change one byte and the hash no longer matches. That’s why you can’t delete a language pack, a wallpaper or an unused printer driver from the system volume, even as root with SIP turned off: the volume is mounted read-only and anything that altered it would break the seal.

There is also nothing to gain. The system volume is exactly as big as the operating system it holds, and it doesn’t accumulate. Each update replaces it wholesale. People sometimes turn off the seal (csrutil authenticated-root disable, from Recovery) hoping to slim it down, and get nothing back but a Mac that can’t install updates normally.

Time Machine doesn’t back it up either, and doesn’t need to. It backs up the data volume, and a restore reinstalls the system from Apple.

Why your files seem to be counted twice

The paths the two volumes share are listed in a plain text file:

cat /usr/share/firmlinks

Because /Users, /Applications and the rest appear in both namespaces, a naive du -sh / walks from the system volume straight into the data volume and counts your home folder as part of the system. The total can come out larger than the disk. Keep du on one file system:

sudo du -xh -d 1 / 2>/dev/null | sort -h | tail

-x makes du stop at the volume boundary. Forgetting it is the most common reason a du total doesn’t match df, alongside the deleted-but-open file covered in why df, du and the Finder disagree.

Old advice that no longer applies

Guides written before 2020 assumed one writable volume. On a current Mac, a lot of that advice is dead:

Old adviceStatus now
Delete unused language files from appsBreaks code signing; system apps are read-only anyway
Remove printer drivers from /Library/PrintersAlmost nothing ships there any more; drivers are downloaded
Trim /System/LibraryImpossible: sealed volume
Delete system fonts you do not useImpossible, and see font caches
Clear /private/var/foldersStill possible, still a bad idea; the system manages it

Everything still reclaimable is on the data volume: caches, developer build products, container images, model weights, old backups. The useful work was always in your home folder.

The snapshot macOS boots from

macOS doesn’t boot from the live system volume. It boots from a snapshot of it, and during an upgrade there are briefly two system snapshots. That’s part of why an update asks for far more free space than the download size; why a macOS update needs more space than it says goes through the rest of it.

diskutil apfs listSnapshots /

You can’t delete the current one, since the Mac is running from it. It’s a different thing from the local snapshots on the data volume, which belong to Time Machine and can be thinned freely. Mixing the two up leads to deletions that fail with permission errors. What APFS snapshots are separates them.

What a fresh install costs before you add anything

Roughly, on a current release:

  • 10 to 15 GB for the sealed system volume.
  • 1 to 2 GB for Recovery, and several gigabytes for Preboot, which since macOS 13 also holds the system’s cryptexes.
  • A few gigabytes of caches, dictionaries and Spotlight index built during first use.
  • Whatever swap and sleep image the machine ends up needing.

So a new 256 GB MacBook with nothing installed shows well under 256 GB available, and all of the difference is accounted for. It isn’t a defect and no procedure reduces it. The recovery volume and the others sharing your container covers the smaller volumes.

Keep reading