matches strings matched by both and z3.Complement(r) matches any string except those matched by r They are otherwise rejected by default: if a role has a constraint over the location label, and a node doesn’t provide any value for the location label, the role will not allow access to the node regardless of any of the other constraints or labels. The reason is quite funny: if you have a large set of constraints over what strings need to be in a set, the solver will just use the set containing all strings!