1. close transient fd 2. use authenticated user name from ticket to avoid forgery 3. use fid not afid in read/write/clunk