iCloud SH!

Introduction

iCloud is Apple’s cloud-based services for storage, application data and files, and synchronization between devices.

General

First, ‘iCloud’ can be a bit confusing as not too seldomly very much depend on in which context it’s discussed.

  • It IS cloud-based – i.e. data servers accessible on the Internet, Internet-based servers). And in the case of iCloud all by Apple Inc.
  • But then, people can be talking about all sorts of synchronization – of data between apps (like Calendar, Contacts,…), files – then it’s technically iCloud Drive and not just iCloud, or even accounts.
  • An Apple ID (older name), Apple Account (newer name) is required for using any iCloud services.
    • And is THE critical detail for synchronization of all your devices – every device must be logged in using same Apple ID/Account [user].
  • Essentially everyone that has Apple devices both
    • Has an Apple Account – you create(d) it with your first Apple device.
    • Also has iCloud services, at least some, including iCloud Drive storage (though small amount).

The table below provide an overview and introduction of some iCloud services, with Dropbox as example of another common product (family) with both having file synchronization as a common feature.

iCloud by Apple Dropbox in comparison
Common capabilities
* Cloud-based file system ✅ Called iCloud Drive, introduced in macOS 10.7 (2011) ✅ The real, original, core feature of Dropbox (2007) class-leader for many years
* Free plan 5 GB storage (iCloud+ plans) 2 GB (dropbox.com/basic)
** Integration in maOS Finder, macOS file management ✅ ‘As good as it gets’ nowadays, Apple is (of course) using their File Provide framework so it is what it is. ✅ Has been absolutely excellent, at least up to Apple’s File Provider framework ###
*** Synchronization tech(s) * Older kernel extensions has been completely replaced by File Provider framework since macOS Sonoma 2023. Continue to support using both older kernel extensions and File Provider framework. AND this is where I have mixed experiences of using the latter. But, time will tell, as techs and products evolve.
** Multi-OS support ⚠️ Primarily Apple devices. Not researched any details on how well supports *NIX, Windows, Android, … ✅ Yes, absolutely, great.
** Sharing files amongst Apple users ### ✅ Easy. Just select a folder/item and select Share...-menu in Finder.
** Sharing file with anyone ### ✅ Easy. As above (Share...) but also Copy Dropbox Link-menu.
* Sync data among your own Apple devices ✅ ✅ All sorts of data from apps, including files, photos, addresses, … ✅ Files-focus only.
* Photos – handling ✅ But so-so in my meaning, as synchronization in not on files-level but inside Apple-managed databases that  Photos.apps are using, and which becomes huge over time. ✅ Great in my meaning, as can automatically upload files into Dropbox ecosystem from devices.
* Scan documents ✅ Got functionality.
⚠️ Docs are named ‘Scanned Document.pdf’ – changeable?!
👷  Not yet sorted out all details for a good workflow.
✅ Got functionality.
✅ Docs are named ‘YYYY-MM-DD hh.mm.ss.pdf’
✅ Got good workflow sorted out.
* For advanced users… Command Line Tools, tricks for scripting, etc ### placeholder, still need to document here (to learn more, some adaption of scripts is needed) ### placeholder, still need to document here (got a fair amount of experiences and scripts)
* ‘Transitional’-user comments, J Aug-Sep 2026. Moving more into iCloud (2TB) .. … from Dropbox-based (had 3TB)
Used 2.97 TB of 3.01 TB for
1 661 045 items
Aug 2026 (had 3 TB plan, changed to 2 TB once below that volume; from $19.99 to $11.99/mon,+tax)
Use 1.1 TB of 2 TB, incl. Photos Use 1.77 TB of 2.01 TB per 2026-09-28, Plan usage
573.6 GB, for some 811 726 items 1.77 TB, for 325 917 items per 2026-09-28, Files usages
After using Dropbox since 2010 (… yeah), start migrating primary cloud-files use from Dropbox to iCloud Drive, for a number of reasons.
* Been struggling with “Preparing to “… dialogs when using Dropbox-based locations, up to 50 seconds delays (NOT when on VPN…. very weird problems), since macOS 26.4 update Apr 2026.
* Fed up with Dropbox complaining about ‘No supporting 500,000 files’ (dealing with 1.6 million or so items)
* Apple iCloud Drive seems ‘good enough’, works ok.
* Personally basically only Apple-devices/ecosystem nowadays (no Windows, limited *NIX)
The difference between the 1 661 045 items in Dropbox in August to
811 726 (iCloud)
+ 325 917 (still Dropbox)
=1 137 643 (in cloud services ‘now’) is some 523 402 items of which
* some still handled locally, and/or
* shifted out to external disks/off-line backups, AND
* files zipped together and still in cloud (as good backups location).
Saved to iCloud, examples: iCloud/Apple Any similar in Dropbox
* Addresses, Contacts, Contacts.app(s) ✅ – (no)
* Calendar, Calendar.app(s) ✅ – (no)
* Drive, shared file system ✅ iCloud Drive ✅ Yes (the Dropbox core functionality)
* Mail.app(s), emails ✅ – (no)
* Messages, Messages.app(s) ✅ – (no)
* Notes, Notes.app ✅ – (no)
* Passwords, Passwords.app(s) ✅ – ###
* Wallet, Wallet.app(s) ✅ – (no)
iCloud+ Features iCloud/Apple Any similar in Dropbox
* Plans – different plans one can subscribe to (at cost) (5 GB storage (iCloud+ plans))
E.g. 2 TB $9.99/mo,
(50 GB, 200 GB, … 6 TB, 12 TB)
2 GB free (dropbox.com/basic)
E.g. 2 TB $9.99/mo
dropbox.com/buy
Apple’s free plan does not include all + features.
* Family sharing ✅ –
* Apple Invites ✅ – (no##)
* Private Relay ✅ – (no)
* Hide My Email ✅ – (no)
* Custom Email ✅ – (no)

 

Apple

Other

Synchronizing

Apple’s File Provider framework

  • jandp.biz/?s=file+provider
  • search.brave.com/search?q=apple+File+Provider+framework+history
    • The File Provider framework was first introduced by Apple for iOS 11 to allow apps to present remote files to users via a standardized interface. It was later added to macOS 10.15 Catalina (with broader support in macOS 11 Big Sur) to replace the need for third-party kernel extensions, which posed security and reliability risks.

      Adoption accelerated significantly starting in 2021, with iCloud Drive fully migrating to the framework in macOS Sonoma (2023). Major cloud services including Dropbox, Google Drive, Microsoft OneDrive, and Box have since transitioned from custom kernel extensions to this Apple-approved, user-space extension model to integrate cloud storage directly into the Finder and APFS file system. 

Older (here) Stuff

From What is iCloud? https://support.apple.com/guide/mac-help/what-is-icloud-mh36832/mac:

Here are some ways you can use iCloud on your Mac.

iCloud feature

Description

Photos icon
All your photos and videos. Always available.

iCloud Photos securely stores your photos and videos and lets you access them on all your devices and on the web at iCloud.com. With Shared Albums, it’s easy to share photos and videos with the people you choose and invite them to add photos, videos, and comments to your shared albums. Learn more about Photos.

With iCloud Shared Photo Library, you can collaborate with up to five family members or friends on a shared collection of photos and videos and enjoy more complete memories all in one place.

iCloud Drive icon
Keep all your files securely stored in iCloud Drive

Securely store and organize your files in iCloud Drive. Access and keep them up to date across all your devices and on iCloud.com. You can also add your Mac Desktop and Documents folders to iCloud Drive so they’re available everywhere. Learn more about iCloud Drive.

You can share items stored in iCloud and collaborate on them with others. You decide who can view your content and who can make changes. If participants make edits to the content, everyone sees them in real time. See Use iCloud to share and collaborate on files and folders.

Family Sharing icon
Share music, books, apps, subscriptions, and more with your family

With Family Sharing, you and up to five other family members can share access to amazing Apple services like Apple Music, Apple TV+, iCloud+, Apple Fitness+, Apple News+, and Apple Arcade. Your group can also share iTunes, Apple Books, and App Store purchases, an iCloud storage plan, and a family photo album. You can even help locate each other’s missing devices. When you subscribe to iCloud+, you can also share all the iCloud+ features and included storage with your family. Learn more about Family Sharing.

iCloud Private Relay icon
iCloud Private Relay

Hide your IP address and browsing activity in Safari and protect your unencrypted internet traffic so that no one—including Apple—can see who you are or what sites you visit. Available with iCloud+. Learn more about Private Relay.

Hide My Email icon
Hide My Email

Keep your personal email address private by creating unique, random addresses that forward to your personal inbox and can be deleted at any time. Available with iCloud+. Learn more about Hide My Email.

Mail, Calendar, Notes, Contacts, Reminders, Messages, Home, and News icons
Your favorite apps are even better with iCloud

Keep your mail, calendars, notes, contacts, reminders, messages, and more in sync across all your devices. Learn more about the apps included on your Mac.

Safari icon
Safari bookmarks, open tabs, Reading List, and Tab Groups

Sync your open browser tabs across all your devices, access the same bookmarks, and read articles from your Reading List, even when you’re offline. Plus, keep your Tab Groups up to date on all your devices, and collaborate on Tab Groups with others. Learn more about Safari.

iCloud Keychain icon
iCloud Keychain

Securely store your passwords, credit cards, and more in iCloud. Autofill your information in Safari and other supported web browsers. Learn more about iCloud Keychain.

J&P: THIS IS THE ONE TO TURN OFF TO AVOID Wi-Fi hotspots to be shared among devices. AND being the reason for struggling with getting hotspots/networks in any working order…..

See also Wi-Fi Settings Changes Orders – Problems (/is/apps/macos/wi-fi-settings-changes-orders-problems/)

iCloud icon
iCloud storage

Everyone gets 5 GB of free iCloud storage to get started and it’s easy to upgrade at any time. Your apps and iTunes Store purchases don’t count toward your iCloud storage space, so you only need it for things like photos, videos, files, and device backups. Data stored in iCloud is encrypted, and with two-factor authentication, your account can only be accessed on devices you trust. Learn more about iCloud storage.

 

macOS – Specifics

Finder – General Use

iCloud Drive in SideBar (Command-Control-S hide/show)

  • Desktop
  • Documents
  • TextEdit
  • Automator
  • Downloads
  • …

More Hidden-Away, ~/Library/…

~/Library/Mobile Documents/

  • -JohanWasHere
  • Automator
    • ~/Library/Mobile Documents/com~apple~Automator/Documents/
  • Desktop
  • Documents
    • ~/Library/Mobile Documents/com~apple~CloudDocs/Documents/
    • ~/Library/Mobile Documents/com~apple~CloudDocs/Documents/gpxparser/
  • Downloads
  • FileExplorer
  • GarageBand for iOS
  • iMovie
  • Map Plus
  • Pages
  • Preview
  • Shortcuts
  • TextEdit
    • ~/Library/Mobile Documents/com~apple~TextEdit/Documents/

 

mac:~ bob$ ls -ld ~/Library/Mobile\ Documents
drwxr-xr-x@ 114 bob  staff  3648 May  7 07:14 /Users/bob/Library/Mobile Documents

mb1422:~ johan$ ls ~/Library/Mobile\ Documents/
2792V3BKH6~net~mrbin~historymapsofworld
2BUA8C4S2C~com~agilebits~onepassword
2BUA8C4S2C~com~agilebits~onepassword-ios
57T9237FN3~net~whatsapp~WhatsApp
....
com~apple~Automator
com~apple~CloudDocs
com~apple~Keynote
com~apple~Numbers
com~apple~Pages
com~apple~Preview
...
com~apple~ScriptEditor2
com~apple~TextEdit
com~apple~TextInput
com~apple~iBooks~cloudData
com~apple~mail
com~apple~mobilemail
com~apple~notes
com~apple~shoebox
com~apple~system~spotlight
...
iCloud~com~agilebits~onepassword-ios
...

Processes and Commands – more Low-Level, iCloud (macOS)

Q> iCloud processes on macOS, I would love to see some overview of relevant processes and their purposes
Private-access-only: chatgpt.com/c/6a89771e-501c-83ea-8c7a-99def635669f

A)

ID: 20260822051700

Yes. On modern macOS, iCloud Drive is no longer one single “iCloud process.” It is a stack involving CloudKit, File Provider, Finder integration, metadata/indexing, and background transfer services.

A useful overview—especially when troubleshooting files that are stuck downloading/uploading—is:

Process / daemon Main purpose Why you might care
bird iCloud Drive synchronization daemon Historically the core iCloud Drive sync process; coordinates local files with iCloud
cloudd CloudKit daemon Handles communication with Apple’s CloudKit infrastructure; many Apple apps/services use it
fileproviderd File Provider framework daemon Very important on current macOS. Manages File Provider domains, file materialization, placeholders, downloads, uploads, etc.
fileproviderctl File Provider diagnostic/control CLI Not normally a persistent process; useful for inspecting File Provider state
brctl iCloud Drive diagnostic/control CLI Older but still useful diagnostic interface associated with the “Bird”/Documents-in-the-Cloud infrastructure
nsurlsessiond Background network transfers Performs background upload/download activity for apps and system services
accountsd Internet/iCloud account management Handles account information and credentials used by Apple services
appleaccountd Apple Account services Modern Apple Account/Apple ID account infrastructure
apsd Apple Push Notification service Push notifications can tell cloud services that remote data has changed
mds / mdworker* Spotlight metadata indexing Not iCloud sync itself, but heavily involved when cloud files appear/disappear/change locally
Finder User-facing filesystem integration Requests downloads, displays cloud state/icons, invokes File Provider operations
sharingd Sharing/AirDrop/iCloud-related sharing services Relevant primarily for sharing rather than ordinary iCloud Drive synchronization

The most important relationship

For an iCloud Drive file, I’d visualize the modern architecture roughly like this:

                         APPLE / iCLOUD
                              │
                              │ CloudKit / network
                              ▼
                         ┌──────────┐
                         │  cloudd  │
                         └──────────┘
                              │
                     cloud coordination
                              │
             ┌────────────────┴───────────────┐
             │                                │
          ┌──────┐                    ┌───────────────┐
          │ bird │                    │ fileproviderd │
          └──────┘                    └───────────────┘
             │                                │
             │                         File Provider
             │                         domains/items
             │                                │
             └──────────────┬─────────────────┘
                            │
                            ▼
              ~/Library/Mobile Documents/
                    com~apple~CloudDocs/
                            │
                 ┌──────────┴─────────┐
                 ▼                    ▼
              Finder              applications
                 │
                 ▼
          user opens/copies/
          downloads/evicts file

One complication is that Apple is in a transition from the older Documents-in-the-Cloud/Bird architecture toward File Provider infrastructure, so you can encounter both old and new terminology and components. That is one reason logs can be confusing.

For the troubleshooting you’ve been doing

I’d divide the processes into four layers:

Layer Processes What failure here looks like
1. Account/authentication accountsd, appleaccountd Account/login/token problems; iCloud services broadly affected
2. Cloud communication cloudd, nsurlsessiond, apsd Server requests, network errors, CloudKit errors
3. File synchronization bird, fileproviderd Files stuck as placeholders, downloads don’t start, changes aren’t propagated
4. Local filesystem/UI Finder, mds, mdworker* Wrong/stale status indicators, indexing problems, Finder not reflecting actual state

For your purposes, I would pay by far the most attention to these three:

cloudd
fileproviderd
bird

They answer somewhat different questions:

cloudd — “Can macOS talk to Apple’s cloud database/services?”

You have already seen entries such as:

cloudd[...] [com.apple.cloudkit:Request]

Those are CloudKit operations. A request ending with:

Finishing with error (null)

normally means that particular CloudKit request completed without an error.

fileproviderd — “What should this file look like locally, and should it be downloaded?”

This is especially interesting when investigating things such as:

cloud file exists
       │
       ▼
placeholder exists locally
       │
       ▼
download requested
       │
       ▼
materialization
       │
       ▼
actual bytes exist locally

And importantly, fileproviderd isn’t just iCloud. It is also involved with providers such as Dropbox. That’s why your logs contain things like:

[com.apple.FileProvider:com.getdropbox.dropbox.fileprovider/...]

So when reading fileproviderd logs, the File Provider domain/provider identifier matters enormously. An error from fileproviderd is not automatically an iCloud error.

bird — “Is the iCloud Drive synchronization state consistent?”

bird is worth watching when the problem appears specifically limited to iCloud Drive rather than File Provider generally.

A practical live troubleshooting command is therefore:

log stream --style compact \
  --predicate 'process == "bird" OR process == "cloudd" OR process == "fileproviderd"'

For a broader picture:

log stream --style compact \
  --predicate 'process == "bird" OR
               process == "cloudd" OR
               process == "fileproviderd" OR
               process == "nsurlsessiond" OR
               process == "accountsd" OR
               process == "appleaccountd"'

And when troubleshooting iCloud versus Dropbox, I would actually treat fileproviderd as the common middle layer:

                    macOS
                      │
               fileproviderd
                /           \
               /             \
        iCloud domain      Dropbox domain
             │                  │
          iCloud              Dropbox
        infrastructure      infrastructure

That distinction is particularly useful because a fileproviderd problem affecting multiple providers points toward macOS/File Provider itself, while a problem seen only in the Dropbox domain points much more strongly toward Dropbox’s File Provider implementation.

If you’d like, I can next make a much more detailed “macOS Cloud Process Map”, including bird, cloudd, fileproviderd, nsurlsessiond, accountsd, apsd, Spotlight, Finder, and the relevant command-line tools, with a column for “safe to kill/restart?” and exactly what happens when you do.

troubleshooting cloudd process

ID: 20260826112200

For cloudd troubleshooting, I would work from observation → isolate CloudKit errors → restart → investigate account/cache only if necessary. cloudd is used by more than iCloud Drive, so simply seeing lots of cloudd activity does not mean iCloud Drive itself is malfunctioning.

1. Establish whether cloudd is actually unhealthy

Check that it is running:

pgrep -lf cloudd

and resource consumption:

ps -axo pid,%cpu,%mem,etime,command | grep '[c]loudd'

For a better live view:

top -pid "$(pgrep -x cloudd)"

Things I’d consider suspicious are sustained high CPU, rapidly increasing memory, repeated crashes/restarts, or the same CloudKit request/error repeating continuously.

2. Watch cloudd alone

This is my preferred starting point:

log stream --style compact \
    --info \
    --predicate 'process == "cloudd"'

For historical activity, for example the last hour:

log show --last 1h \
    --style compact \
    --info \
    --predicate 'process == "cloudd"'

Because the output can be enormous, look first for errors:

log show --last 1h \
    --style compact \
    --predicate 'process == "cloudd" AND messageType == error'

But be careful: Apple’s unified logging uses “error” fairly liberally. An error-level log entry is not necessarily evidence that the operation failed.

3. Search for genuinely interesting patterns

I’d use:

log show --last 1h --style compact \
    --predicate 'process == "cloudd"' |
egrep -i 'error|failed|failure|timeout|timed out|network|account|auth|token|retry|throttl|quota'

A particularly important distinction is between an intermediate scary-looking message and the final result of the CloudKit request.

For example, the entry you showed previously:

[com.apple.cloudkit:Request]
req: 4E4AE6DA-...
"Finishing with error (null)"

is actually reassuring:

error (null)
      ↑
      no error object

So I would not treat that line itself as evidence of failure.

4. Follow one CloudKit request from beginning to end

This is much more useful than grepping random cloudd errors.

If you see:

req: 4E4AE6DA-1E8E-42D8-B545-9242FD801CBB

take that UUID and run:

log show --last 1h --style compact \
    --predicate 'process == "cloudd"' |
grep '4E4AE6DA-1E8E-42D8-B545-9242FD801CBB'

You can then reconstruct:

request created
      ↓
request scheduled
      ↓
network transaction
      ↓
CloudKit response
      ↓
retry / processing
      ↓
Finishing with error (...)

That gives us considerably better evidence than individual log lines.

5. Correlate cloudd with the other cloud processes

For an iCloud Drive problem, I’d normally run:

log stream --style compact --info \
    --predicate 'process == "cloudd" OR
                 process == "bird" OR
                 process == "fileproviderd"'

Then deliberately trigger the problem—for example:

icloud status "/path/to/problem-file"

or request that the file download in Finder.

We can then see whether the chain looks like:

Finder / user action
        ↓
fileproviderd
        ↓
bird / iCloud coordination
        ↓
cloudd
        ↓
CloudKit
        ↓
Apple

This is important because cloudd may be functioning perfectly while fileproviderd is where the operation gets stuck.

6. Safely restart cloudd

A relatively low-impact test is:

killall cloudd

macOS should automatically relaunch it through launchd.

Then:

pgrep -lf cloudd

You should see a new PID.

I’d do this while watching:

log stream --style compact \
    --predicate 'process == "cloudd"'

This gives you a useful test:

Problem disappears after restarting cloudd → stronger evidence of stale daemon/session/cache state.

Problem remains unchanged → start looking harder at bird, fileproviderd, account state, networking, or the particular CloudKit container.

7. Check whether it is continuously restarting

Run:

while true; do
    date
    pgrep -lf cloudd
    sleep 5
done

The PID should normally remain stable. If you see:

1234 cloudd
1234 cloudd
1234 cloudd
1789 cloudd
1789 cloudd
2142 cloudd

without you killing it, that’s significant. We’d then want to investigate crashes/termination rather than synchronization.

You can check recent logs for termination:

log show --last 1h --style compact \
    --predicate 'process == "cloudd"' |
egrep -i 'crash|abort|terminate|exit|fault'

8. Don’t delete cloudd databases/caches yet

There are various Internet recipes involving deleting things under ~/Library/Caches, ~/Library/Application Support/CloudDocs, CloudKit databases, signing out of iCloud, etc.

I would not do any of those yet.

Given the kind of File Provider/iCloud investigation we’re doing, destroying state too early removes evidence and can trigger a huge resynchronization. We should first establish whether cloudd is actually the failing component.

A diagnostic capture I’d like to see

The most useful next experiment would be to pick one iCloud file that refuses to download, then start:

log stream --style compact --info \
  --predicate 'process == "cloudd" OR
               process == "bird" OR
               process == "fileproviderd"'

Then request Download Now for that single file, wait perhaps 30–60 seconds, and stop logging with Ctrl-C.

Paste that section here. I can separate the noise into the three layers and identify which daemon receives the request, where it progresses, and where the chain stops.

bird – Process

cloudd – Process

EoP