Hi David,
Please make sure to file this
issue in the Feedback Hub so
the Engineering team gets the data.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Running routine DISM component store maintenance on Windows 11 25H2,
Build 26200.9457 (KB5129195), after KB5124008 (Build 26200.9445).
BUG: DISM /Online /Cleanup-Image /ScanHealth permanently leaks staging
data into C:\Windows\WinSxS\Temp\InFlight on every run. Never reclaimed
by StartComponentCleanup, /ResetBase, RestoreHealth, or
RevertPendingActions + reboot. AnalyzeComponentStore's "Cache and
Temporary Data" never returns to 0 bytes; grew to 1.3 GB before I
traced the cause.
EXACT REPRO (confirmed twice, back-to-back, nothing else in between):
CBS.log indicates the growth occurs during the CheckCsi phase. Each ScanHealth run performs CSI metadata refresh operations and opens 163,386 files:
"Direct SIL provider: Number of files opened: 163386"
"CSI Store Metadata refreshed: True"
163K files get opened/compared and CSI metadata rebuilt, but the
resulting InFlight staging data is never torn down.
ONLY WORKAROUND: stop TrustedInstaller / confirm no TiWorker.exe
running, then takeown /R + icacls /grant Administrators:F /T + delete
InFlight's contents manually. Verified safe - sfc /scannow and
ScanHealth/CheckHealth report clean before and after, same scan
duration.
Expected: ScanHealth should not leave persistent staging data behind.
Cache/Temp should return to ~0 bytes after cleanup, as on prior builds.
Hi David,
Please make sure to file this
issue in the Feedback Hub so
the Engineering team gets the data.
Proposed workaround as powershell script to clean cache until this issue is fixed,
# =========================================================================
# CHECK CBS/TrustedInstaller IS IDLE, THEN TAKE OWNERSHIP AND CLEAR InFlight
# Run this AFTER a reboot, once you've confirmed cache growth (>500MB) persists
# =========================================================================
# --- 1. Confirm TrustedInstaller service is stopped ---
$tiService = Get-Service TrustedInstaller
Write-Host "TrustedInstaller service status: $($tiService.Status)" -ForegroundColor Cyan
if ($tiService.Status -ne 'Stopped') {
Write-Host "TrustedInstaller is still running. Waiting 2 minutes and rechecking..." -ForegroundColor Yellow
Start-Sleep -Seconds 120
$tiService = Get-Service TrustedInstaller
Write-Host "Rechecked status: $($tiService.Status)" -ForegroundColor Cyan
}
# --- 2. Confirm no TiWorker process is active ---
$tiWorker = Get-Process TiWorker -ErrorAction SilentlyContinue
if ($tiWorker) {
Write-Host "TiWorker is still running (PID $($tiWorker.Id), StartTime $($tiWorker.StartTime)). Not safe to proceed." -ForegroundColor Red
return
} else {
Write-Host "TiWorker not running. Confirmed idle." -ForegroundColor Green
}
# --- 3. Only proceed if TrustedInstaller is stopped ---
if ($tiService.Status -eq 'Stopped') {
Write-Host "`nSystem is idle. Proceeding with InFlight cleanup." -ForegroundColor Cyan
# Take ownership of InFlight and everything inside it
takeown /F "C:\Windows\WinSxS\Temp\InFlight" /R /D Y
# Grant Administrators full control
icacls "C:\Windows\WinSxS\Temp\InFlight" /grant Administrators:F /T /C
# Delete contents (folder itself remains, only contents removed)
Get-ChildItem "C:\Windows\WinSxS\Temp\InFlight" -Force | Remove-Item -Recurse -Force -ErrorAction Stop
# Verify
$remaining = Get-ChildItem "C:\Windows\WinSxS\Temp\InFlight" -Recurse -Force -ErrorAction SilentlyContinue |
Measure-Object -Property Length -Sum
Write-Host "`nRemaining size in InFlight: $([math]::Round($remaining.Sum / 1MB, 2)) MB" -ForegroundColor Green
# Confirm system health afterward
Write-Host "`nRunning SFC to confirm nothing was disturbed..." -ForegroundColor Cyan
sfc /scannow
} else {
Write-Host "`nTrustedInstaller still not stopped after wait. Aborting - do not proceed manually until it's idle." -ForegroundColor Red
}