r4404: check for SEC_ACE_FLAG_INHERIT_ONLY in the "maximum allowed" logic