Using ACLs, is it possible to make it so that all new files below a particular dir are created with the execute bit set? While the umask can be overridden by setting the default ACL, it seems the execute bit won't take.