Mladen, I'm switching the bInheritHandle to FALSE, in apr_procattr_user_set, because this creates an apparently uninteresting handle leak.
Let me know if there was a reason to allow sub-processes to see the actual sa handle describing their parent's access control, as opposed to querying the acl in the normal manner? Be happy to revert if there is an interesting justification :) Bill
