Issues ====== - `_apply_ir_rule` applies `ir.rule` of the current model and also `ir.rule` from the inherited model (via inherits). But `check_access_rule` doesn't check the later one. - `_flush_search` doesn't flush fields coming from the `ir.rule` of the inherited model (via inherits). Then the filtering done by `_apply_ir_rule` may be inconsistent with cached values. Changes ======= Because of https://github.com/odoo/odoo/blob/6ddcb448612f5d784c8e9ebb90f19077e65be3e1/odoo/osv/expression.py#L1073-L1073, and https://github.com/odoo/odoo/blob/00e86b1552d1e5541a8dbf9411de5cfdb8990cc4/odoo/fields.py#L2895 leaf like `('<many2one_delegate>', 'any', [<sub-domain>])`, will be translated in the same way as `_inherits_join_add` does. We can remove `_inherits_join_add` and its usage in `_apply_ir_rule` and change `ir.rule._compute_domain` to also return the inherited (via inherits) `ir.rule` domain (with the new 'any' operator). Since `_compute_domain` is used by `_apply_ir_rule` and `_filter_access_rules_python`, everything is consistent. Also fix `BaseModel._flush_search` to take in account 'any'/'not any' operators (compulsory in order to flush correctly new domain from `ir.rule._compute_domain` generated). Part-of: odoo/odoo#125916