running BM3.8 on NW6.5sp7 (nw6.5sp5 when problem first appeared)

when a change is made to an access rule only the network admin user for
that container gets the change. no other "group" or nds users receive the
change. ACLCheck updates without error. the server does contain the
"master" replica for that partition. I have unloaded and reloaded proxy,
and aclcheck. I updated NW to sp7 and then tried to upgrade BM to 3.9 but
the upgrade won't run. So I am back to trying to get the access rules to
work with BM3.8. Any ideas?