rule0401: report only if acl os identifier=* and allow write or delete rule0604: fix when user is default rul0406: new rule