Solutions?
Either:
Implement native NFSv4 ACLs in Linux filesystems; or
fake it.
We're doing both!
Faking it