Adicionado ao /etc/pve/openvz/VMID.conf
MOUNT_OPTS="rw,realtime,acl,user_xattr"
fez a coisa. Agora (por exemplo)
setfacl -m u:sshd:rwx ~/tmp
setfacl -m g:ssh:rwx ~/tmp
e depois
getfacl ~/tmp
mostra
# file: root/tmp
# owner: root
# group: root
user::rwx
user:sshd:rwx
group::r-x
group:ssh:rwx
mask::rwx
other::r-x
Então, a ACL está OK