> 1. Should we make the owner aclitem NEVER appear in the acl list? ie.
> when we do the first grant on an object, we don't put in a default acl
> for the owner. Instead we special case the aclcheck to always allow the
> owner full privilieges? Also, if the first grant was 'select' for the
> 'other' user, and then we changed the owner to the 'other' user, should
> we erase the 'other' user's aclitem?
I forgot to mention - under this schema grants/revokes to the owner
become no-ops.
Chris