Currently, samba-tool ntacl sysvolreset sets the same SD for all objects in sysvol, regardless if it is a file or directory. When looking at a Windows server, the file objects did not have OI/CI set (and this even does not make much sense to use), only the directories have inheritance flags set. This gives trouble when trying to put sysvol on a GPFS share (with NFSv4 ACLs) as GPFS denies the ACL for a file if inheritance rules are set.
Can you please try to reproduce this one with Samba 4.0.0rc6? Thanks!