Steps to re-produce:
1. enable Sentry HDFS permissions sync
2. Create a sentry role or using existing role
3. Provide SELECT grant on a database/table for this role and SAVE
4. Check hdfs sync :
$ hadoop fs -getfacl /user/hive/warehouse/somedatabase.db/
4. Elevate role's permission created in step 2 from SELECT to ALL and 'SAVE'
5. Check hdfs sync :
Expected Result: Privileges should change to group:user_group1:rwx
Actual Result: group:user_group1:-wx
Same issue is happening when changing permission from ALL to SELECT, it doesn't show any privileges for that group.