Marantz, Roy writes:
This search returns nentries=0 ldapsearch -x -LLL -h 127.0.0.1 -b 'ou=group,dc=nyc,dc=deshaw,dc=com' '(&(objectClass=posixGroup)(memberUid=marantz))' (...) But this search shows at least one object that I think should match
Do you have access controls which prevent search for memberUid?
If that's not the problem: Try to stop slapd, run sbin/slapindex, restart slapd, and see if that helps. You need it if you added 'index memberUid eq' to slapd.conf _after_ adding marantz to that group. Possibly also if you upgraded recently but kept your old database, I'm not sure.