From dbb4bd632b3ba307bb4f111dd61a4c1dd896be42 Mon Sep 17 00:00:00 2001 From: Raimund Andree Date: Sat, 10 Oct 2026 07:33:01 +0000 Subject: [PATCH] chore(memory-bank): say which cleanup branches met real residue The cached-name form of a log-group entry and the profile of an unloaded user did; a bare SID and a loaded profile did not. Every unresolved S-1-5-21-* member of Performance Log Users counts as the probe's. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant --- .memory-bank/techContext.md | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/.memory-bank/techContext.md b/.memory-bank/techContext.md index 29c5837..881aa48 100644 --- a/.memory-bank/techContext.md +++ b/.memory-bank/techContext.md @@ -224,8 +224,9 @@ source: repository and executable evidence (`NtfsLiveSubject` and four digits). In the matrix lab, after an account was deleted and created again with the same name, the remote authorization managers (the client's for the default `-ServerName`, the file server's for its - name) answered for about ten minutes as if it had no groups (`0x100000`), - whichever module version asked, while the Kerberos S4U logon of the oracle, the + name) answered for about ten minutes as if it had no groups (`0x100000`), for + the baseline and for the final candidate alike, while the Kerberos S4U logon of + the oracle, the name resolution, and the local manager were right in the same second. A replay with the baseline and the final candidate alternating failed the baseline in two of three cells and the final candidate in one of three (not counting the warm-up @@ -240,5 +241,8 @@ source: repository and executable evidence deleted domain account as its SID (or as its cached name for a while); deleting a local user removes its entries from the local groups, so only the entries of domain accounts stay orphaned. `Test-MatrixCleanup.ps1` finds the - entries of the account probe in Performance Log Users by either form and its - profiles by their folder `C:\Users\NtfsProbe*`. + entries of the account probe in Performance Log Users by a name with + `NtfsProbe` or by any unresolved `S-1-5-21-…` SID (every such member counts as + the probe's), and its profiles by their folder `C:\Users\NtfsProbe*`. The + cached-name form met real residue in a test; the bare-SID form and a profile + that stays loaded didn't.