(#11563) Return INHERIT_ONLY_ACEs
Previously, when reading a DACL, puppet excluded INHERIT_ONLY_ACEs which are
ACEs set on a directory that only serve to apply permissions to child
containers (dir) and objects (file). In other words, the ACE didn't affect the
permissions of the directory, and wasn't needed to determine the file mode.
However, now we need to be able to roundtrip a security descriptor, e.g. to
only change the owner, but leave other ACEs intact.
This commit modifies puppet to include inherit only aces when reading the
DACL, but continue to exclude them when determining the file mode.