codex-rs/tui/src/tui/terminal_stderr.rs (10 lines):
	- line 153: // SAFETY: both output pointers reference valid storage for libc to initialize.
	- line 160: // SAFETY: both fstat calls above returned successfully.
	- line 172: // SAFETY: dup returns a newly owned file descriptor on success.
	- line 177: // SAFETY: saved_stderr is a fresh descriptor returned by dup above.
	- line 180: // SAFETY: both descriptors are valid for the duration of this call.
	- line 194: // SAFETY: saved_stderr was duplicated from stderr and remains owned here.
	- line 226: // SAFETY: dup returns a newly owned file descriptor on success.
	- line 231: // SAFETY: saved_stderr is a fresh descriptor returned by dup above.
	- line 233: // SAFETY: both descriptors are valid for the duration of this call.
	- line 243: // SAFETY: saved_stderr remains owned for the duration of this call.


codex-rs/utils/sleep-inhibitor/src/windows_inhibitor.rs (5 lines):
	- line 70: // SAFETY: `context` points to a valid `REASON_CONTEXT` for the duration
	- line 81: // SAFETY: `handle` is a live power request handle and `request_type` is a
	- line 85: // SAFETY: `handle` was returned by `PowerCreateRequest` and has not
	- line 100: // SAFETY: `self.handle` is the handle owned by this `PowerRequest`, and
	- line 109: // SAFETY: `self.handle` is owned by this struct and closed exactly once


codex-rs/linux-sandbox/src/proxy_routing.rs (5 lines):
	- line 77: // SAFETY: the sandbox helper is single-threaded here, before it forks bridge workers or
	- line 152: // SAFETY: F_GETFD takes only a descriptor, with no pointer arguments;
	- line 158: // SAFETY: the outer helper left this descriptor open across exec, which
	- line 162: // SAFETY: F_SETFD takes integer flags, not a pointer; `control` owns the
	- line 198: // SAFETY: this helper process is single-threaded at this point, and


codex-rs/exec-server/src/sandboxed_file_open.rs (4 lines):
	- line 187: // SAFETY: OpenProcess returns an owned handle or null on failure.
	- line 192: // SAFETY: The successful OpenProcess result is owned by this scope.
	- line 195: // SAFETY: Both process handles remain valid and duplicated receives an owned file handle.
	- line 210: // SAFETY: DuplicateHandle transferred ownership of the new file handle.


codex-rs/linux-sandbox/src/exec_util.rs (4 lines):
	- line 23: // SAFETY: `fd` is an owned descriptor kept alive by `files`.
	- line 34: // SAFETY: `fd` is valid and we are only clearing FD_CLOEXEC.
	- line 60: // SAFETY: `fd` is valid for the duration of the test.
	- line 69: // SAFETY: `fd` is valid for the duration of the test.


codex-rs/utils/pty/src/pty.rs (4 lines):
	- line 470: // SAFETY: proc_pidinfo writes descriptor records into the stack buffer.
	- line 485: // SAFETY: fcntl and close only operate on a descriptor owned by this process.
	- line 501: // SAFETY: proc_pidinfo accepts a null buffer when its size is zero.
	- line 524: // SAFETY: getrlimit writes into the stack-owned resource-limit structure.


codex-rs/diagnostics/src/lib.rs (3 lines):
	- line 112: // SAFETY: the kernel initializes this correctly sized buffer on success.
	- line 133: // SAFETY: querying the system page size does not access caller-owned memory.
	- line 179: // SAFETY: the pseudo-handle is valid and the kernel initializes this


codex-rs/windows-sandbox-rs/src/proc_thread_attr.rs (3 lines):
	- line 51: // SAFETY: `hpc` is the Windows-defined value and size for this attribute.
	- line 65: // SAFETY: `value` points to `self.handle_list`, which remains alive
	- line 78: // SAFETY: `value` points to `self.job_list`, which remains alive while


codex-rs/utils/sleep-inhibitor/src/macos.rs (2 lines):
	- line 76: // SAFETY: `assertion_type_ref` and `assertion_name_ref` are valid `CFStringRef`s and
	- line 96: // SAFETY: `self.id` was returned by `IOPMAssertionCreateWithName` and this `Drop`


codex-rs/tui/src/terminal_probe/windows.rs (2 lines):
	- line 94: // SAFETY: EventType identifies the active INPUT_RECORD union member.
	- line 100: // SAFETY: ReadConsoleInputW populates the UnicodeChar member of KEY_EVENT_RECORD.


codex-rs/linux-sandbox/src/linux_run_main.rs (2 lines):
	- line 201: // SAFETY: capability ABI version 3 uses a [version, pid] header and
	- line 1458: // SAFETY: `read_fd` is a valid owned fd in the parent.


codex-rs/utils/sleep-inhibitor/src/linux_inhibitor.rs (2 lines):
	- line 174: // SAFETY: `getpid` has no preconditions and is safe to call here.
	- line 210: // SAFETY: `pre_exec` must be registered before spawn. The closure only


codex-rs/config/src/loader/mod.rs (2 lines):
	- line 860: // SAFETY: SHGetKnownFolderPath initializes path_ptr with a CoTaskMem-allocated,
	- line 876: // SAFETY: path_ptr is a valid null-terminated UTF-16 string allocated by


codex-rs/linux-sandbox/src/proxy_lifecycle.rs (2 lines):
	- line 200: // SAFETY: F_DUPFD_CLOEXEC takes an integer lower bound, not a pointer;
	- line 213: // SAFETY: F_DUPFD_CLOEXEC returned a new descriptor; the original owner drops here.


codex-rs/utils/pty/src/win/procthreadattr.rs (2 lines):
	- line 74: // SAFETY: `con` is the Windows-defined value and size for this attribute.
	- line 92: // SAFETY: `value` points to `self.job_list`, which remains alive while


codex-rs/bwrap/src/main.rs (1 line):
	- line 25: // SAFETY: We provide a null-terminated argv vector whose pointers remain


codex-rs/linux-sandbox/src/fd_mount.rs (1 line):
	- line 47: // SAFETY: the launcher transferred this live descriptor to this stage,


codex-rs/linux-sandbox/src/launcher.rs (1 line):
	- line 226: // SAFETY: `program` and every entry in `argv_ptrs` are valid C strings for


codex-rs/exec-server/src/regular_file.rs (1 line):
	- line 71: // SAFETY: `file` owns this handle for the duration of the call.


codex-rs/secrets/src/local.rs (1 line):
	- line 372: // SAFETY: `byte` is a valid mutable reference into `bytes`.


codex-rs/exec-server/src/fs_sandbox.rs (1 line):
	- line 477: // SAFETY: Descriptor cleanup only uses fork-safe system calls.


codex-rs/app-server-transport/src/transport/remote_control/mod.rs (1 line):
	- line 94: // SAFETY: app-server calls this synchronously at process startup, before spawning threads.


codex-rs/linux-sandbox/src/bundled_bwrap.rs (1 line):
	- line 61: // SAFETY: `program_cstring` and every entry in `argv_ptrs` are valid C
