codex-rs/shell-command/src/parse_command.rs (67 lines):
	- line 121: &shlex_split_safe("git grep TODO src"),
	- line 123: cmd: "git grep TODO src".to_string(),
	- line 124: query: Some("TODO".to_string()),
	- line 129: &shlex_split_safe("git grep -l TODO src"),
	- line 131: cmd: "git grep -l TODO src".to_string(),
	- line 132: query: Some("TODO".to_string()),
	- line 209: let inner = "rg -n \"BUG|FIXME|TODO|XXX|HACK\" -S | head -n 200";
	- line 213: cmd: "rg -n 'BUG|FIXME|TODO|XXX|HACK' -S".to_string(),
	- line 214: query: Some("BUG|FIXME|TODO|XXX|HACK".to_string()),
	- line 282: &shlex_split_safe("rg -l TODO src"),
	- line 284: cmd: "rg -l TODO src".to_string(),
	- line 285: query: Some("TODO".to_string()),
	- line 290: &shlex_split_safe("rg --files-with-matches TODO src"),
	- line 292: cmd: "rg --files-with-matches TODO src".to_string(),
	- line 293: query: Some("TODO".to_string()),
	- line 298: &shlex_split_safe("rg -L TODO src"),
	- line 300: cmd: "rg -L TODO src".to_string(),
	- line 301: query: Some("TODO".to_string()),
	- line 306: &shlex_split_safe("rg --files-without-match TODO src"),
	- line 308: cmd: "rg --files-without-match TODO src".to_string(),
	- line 309: query: Some("TODO".to_string()),
	- line 314: &shlex_split_safe("rga -l TODO src"),
	- line 316: cmd: "rga -l TODO src".to_string(),
	- line 317: query: Some("TODO".to_string()),
	- line 377: let inner = "less -p TODO README.md";
	- line 626: &shlex_split_safe("egrep -R TODO src"),
	- line 628: cmd: "egrep -R TODO src".to_string(),
	- line 629: query: Some("TODO".to_string()),
	- line 634: &shlex_split_safe("fgrep -l TODO src"),
	- line 636: cmd: "fgrep -l TODO src".to_string(),
	- line 637: query: Some("TODO".to_string()),
	- line 646: &shlex_split_safe("grep -l TODO src"),
	- line 648: cmd: "grep -l TODO src".to_string(),
	- line 649: query: Some("TODO".to_string()),
	- line 654: &shlex_split_safe("grep --files-with-matches TODO src"),
	- line 656: cmd: "grep --files-with-matches TODO src".to_string(),
	- line 657: query: Some("TODO".to_string()),
	- line 662: &shlex_split_safe("grep -L TODO src"),
	- line 664: cmd: "grep -L TODO src".to_string(),
	- line 665: query: Some("TODO".to_string()),
	- line 670: &shlex_split_safe("grep --files-without-match TODO src"),
	- line 672: cmd: "grep --files-without-match TODO src".to_string(),
	- line 673: query: Some("TODO".to_string()),
	- line 1091: &shlex_split_safe("grep -R TODO src"),
	- line 1093: cmd: "grep -R TODO src".to_string(),
	- line 1094: query: Some("TODO".to_string()),
	- line 1103: &shlex_split_safe("ag TODO src"),
	- line 1105: cmd: "ag TODO src".to_string(),
	- line 1106: query: Some("TODO".to_string()),
	- line 1111: &shlex_split_safe("ack TODO src"),
	- line 1113: cmd: "ack TODO src".to_string(),
	- line 1114: query: Some("TODO".to_string()),
	- line 1119: &shlex_split_safe("pt TODO src"),
	- line 1121: cmd: "pt TODO src".to_string(),
	- line 1122: query: Some("TODO".to_string()),
	- line 1127: &shlex_split_safe("rga TODO src"),
	- line 1129: cmd: "rga TODO src".to_string(),
	- line 1130: query: Some("TODO".to_string()),
	- line 1139: &shlex_split_safe("ag -l TODO src"),
	- line 1141: cmd: "ag -l TODO src".to_string(),
	- line 1142: query: Some("TODO".to_string()),
	- line 1147: &shlex_split_safe("ack -l TODO src"),
	- line 1149: cmd: "ack -l TODO src".to_string(),
	- line 1150: query: Some("TODO".to_string()),
	- line 1155: &shlex_split_safe("pt -l TODO src"),
	- line 1157: cmd: "pt -l TODO src".to_string(),
	- line 1158: query: Some("TODO".to_string()),


codex-rs/app-server-protocol/src/protocol/v2/permissions.rs (8 lines):
	- line 79: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 153: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 224: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 321: // TODO(anp): Rename this type to distinguish it from the protocol FileSystemPath.
	- line 328: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 341: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 366: // TODO(anp): Remove this conversion once core permission paths use PathUri.
	- line 478: // TODO(anp): Remove this conversion once core permission paths use PathUri.


codex-rs/sandboxing/src/manager.rs (6 lines):
	- line 122: // TODO(anp): Reconcile these backend copies with the supplied sandbox context
	- line 139: // TODO(viyatb): Evaluate switching this to Option<Arc<NetworkProxy>>
	- line 144: // TODO(anp): Reconcile these backend inputs with the supplied sandbox context
	- line 162: // TODO(anp): Revisit this preparation type once this module's PathUri migration is complete.
	- line 176: // TODO(anp): Move PathUri conversion into the platform sandbox implementations.
	- line 533: // TODO(anp): Keep PathUri through the Windows sandbox wrapper boundary.


codex-rs/core/src/tools/runtimes/zsh_fork/unix_escalation.rs (5 lines):
	- line 120: // TODO(anp): Keep PathUri through the zsh-fork executor boundary.
	- line 125: // TODO(anp): Keep PathUri through the zsh-fork sandbox policy boundary.
	- line 538: // TODO(anp): Reconcile this policy input with TurnEnvironment::sandbox_context
	- line 565: // TODO(anp): Capture these Windows and Landlock settings from
	- line 816: // TODO(anp): Keep PathUri through the execve-wrapper boundary.


codex-rs/protocol/src/protocol.rs (5 lines):
	- line 149: // TODO(anp): Replace `TurnEnvironmentSelection` with `PathUri` once path URIs carry environment
	- line 223: /// TODO: Remove this rollout knob once transcript-tail flushing is always enabled.
	- line 1242: // TODO(mbolin): cwd param should be AbsolutePathBuf.
	- line 2153: // TODO(aibrahim): make this not optional
	- line 2217: // TODO(aibrahim): make this not optional


codex-rs/core/src/session/mod.rs (5 lines):
	- line 560: // TODO(anp) pull startup_warnings out of Config
	- line 700: // TODO (aibrahim): Consolidate config.model and config.model_reasoning_effort into config.collaboration_mode
	- line 2711: // TODO(anp): Migrate request_permissions to support paths from foreign environments.
	- line 2945: // TODO(anp): Migrate request_permissions to support paths from foreign environments.
	- line 3510: // TODO(CDXENT-441): use the step scoped model


codex-rs/core/src/exec.rs (4 lines):
	- line 104: // TODO(anp): Reconcile these launch settings with TurnEnvironment::sandbox_context
	- line 336: // TODO: Should arg0 be set on the ExecRequest that is returned?
	- line 433: // TODO(anp): Keep PathUri through the local process launch boundary.
	- line 437: // TODO(anp): Keep PathUri through the Windows sandbox launch boundary.


codex-rs/tui/src/chatwidget/user_messages.rs (4 lines):
	- line 712: UserInput::Audio { .. } // TODO: Include audio inputs in pending steer comparison.
	- line 713: | UserInput::LocalAudio { .. } // TODO: Include audio inputs in pending steer comparison.
	- line 760: UserInput::Audio { .. } // TODO: Include audio inputs in the user message display.
	- line 761: | UserInput::LocalAudio { .. } // TODO: Include audio inputs in the user message display.


codex-rs/core/src/session/session.rs (4 lines):
	- line 100: // TODO(anp): Reconcile these legacy thread defaults with TurnEnvironment::sandbox_context;
	- line 113: // TODO(pakrym): Remove config from here
	- line 1236: // TODO(anp): Present AGENTS.md discovery errors more clearly to the user.
	- line 1419: // TODO(jif): extract session to share between sub-agents


codex-rs/core/src/agent/control/spawn.rs (3 lines):
	- line 249: options: SpawnAgentOptions, // TODO(jif) drop with new fork.
	- line 737: // TODO(jif) add helper for drain
	- line 954: // TODO(anp) track better message fragment provenance in rollouts.


codex-rs/app-server-protocol/src/protocol/v2/realtime.rs (3 lines):
	- line 208: /// TODO: Remove this rollout knob once transcript-tail flushing is always enabled.
	- line 211: // TODO: Remove this experiment-only delivery path after response-item testing is complete.
	- line 215: // TODO: Remove this experiment-only prefix with `codex_responses_as_items`.


codex-rs/core/src/safety.rs (3 lines):
	- line 44: // TODO(ragona): I'm not sure this is actually correct? I believe in this case
	- line 131: // TODO(anp): Make filesystem sandbox policies operate on PathUri.
	- line 155: // TODO(anp): Make sandbox policy path checks accept PathUri without host projection.


codex-rs/tui/src/bottom_pane/request_user_input/mod.rs (3 lines):
	- line 1239: // TODO: Emit interrupted request_user_input results (including committed answers)
	- line 1474: // TODO: Emit interrupted request_user_input results (including committed answers)
	- line 1485: // TODO: Emit interrupted request_user_input results (including committed answers)


codex-rs/protocol/src/error.rs (3 lines):
	- line 282: // TODO(anp): Remove this compatibility macro once callers construct
	- line 297: // TODO(anp): Remove this compatibility macro once callers construct
	- line 353: // TODO(anp): Remove this compatibility constructor once callers construct


codex-rs/rmcp-client/src/oauth/refresh_transaction.rs (2 lines):
	- line 237: // TODO: Add a bounded persistence retry only if telemetry shows this is common; never
	- line 301: // TODO(stevenlee): Add an RMCP adoption API that atomically updates credentials, client ID,


codex-rs/app-server/src/request_processors/initialize_processor.rs (2 lines):
	- line 63: // TODO(maxj): Revisit capability scoping for `experimental_api_enabled`.
	- line 123: // TODO(owen): Once we remove support for CODEX_INTERNAL_ORIGINATOR_OVERRIDE,


codex-rs/shell-escalation/src/unix/escalate_client.rs (2 lines):
	- line 20: // TODO: we should defensively require only calling this once, since AsyncSocket will take ownership of the fd.
	- line 79: // TODO: also forward signals over the super-exec socket


codex-rs/mcp-server/src/codex_tool_runner.rs (2 lines):
	- line 262: // TODO: forward elicitation requests to the client?
	- line 313: // TODO: think how we want to support this in the MCP


codex-rs/windows-sandbox-rs/src/unified_exec/tests.rs (2 lines):
	- line 1039: #[ignore = "TODO: legacy ConPTY cmd.exe exits with STATUS_DLL_INIT_FAILED in CI"]
	- line 1090: #[ignore = "TODO: legacy ConPTY cmd.exe exits with STATUS_DLL_INIT_FAILED in CI"]


codex-rs/tui/src/insert_history.rs (2 lines):
	- line 357: // TODO(nornagon): is this supported on Windows?
	- line 377: // TODO(nornagon): is this supported on Windows?


codex-rs/analytics/src/events.rs (2 lines):
	- line 476: // TODO(rhan-oai): plumb nested Guardian review session tool-call counts.
	- line 1015: // TODO(rhan-oai): Populate once queued/default submission type is plumbed from


codex-rs/tui/src/chatwidget/protocol_requests.rs (2 lines):
	- line 37: // TODO(anp): Remove this native-path localization error path once core permission
	- line 79: // TODO(anp): Remove this native-path localization error path once core permission paths


codex-rs/codex-mcp/src/rmcp_client.rs (2 lines):
	- line 1057: startup_timeout: Option<Duration>, // TODO: cancel_token should handle this.
	- line 1111: // TODO(starr): Unify local stdio MCP launch with


codex-rs/core/src/session/step_settings.rs (2 lines):
	- line 146: // TODO: Revisit the split with StepSettings::validate, which does not
	- line 270: // TODO(aibrahim): Remove once v2 clients no longer send the legacy


codex-rs/core/src/tasks/user_shell.rs (2 lines):
	- line 122: // TODO(ccunningham): After TurnStarted, emit model-visible turn context diffs for
	- line 155: // TODO(anp): Migrate user-shell events and execution plumbing to PathUri so this local-only


codex-rs/core/src/tools/handlers/unified_exec/exec_command.rs (2 lines):
	- line 249: // TODO(anp): Resolve requested shells in remote environments instead of restricting
	- line 304: // TODO(anp): Make permission matching operate on PathUri for remote environments.


codex-rs/hooks/src/registry.rs (2 lines):
	- line 61: // TODO: Once legacy `notify` is removed, capture this snapshot in `CommandHookRuntime::new`
	- line 308: // TODO: Remove this legacy-notify-only command builder when `notify` support is removed.


codex-rs/core/src/session/turn_context.rs (2 lines):
	- line 231: // TODO(anp): Reconcile this parallel turn snapshot with TurnEnvironment::sandbox_context
	- line 923: // TODO(anp): Migrate per-turn config and legacy TurnContext cwd consumers to PathUri so


codex-rs/app-server-protocol/src/protocol/v2/mcp.rs (2 lines):
	- line 394: // TODO: When core can correlate an elicitation with an MCP tool call, expose the associated
	- line 758: // TODO(victor): Deprecate once migrated to `openai/elicitation/create`.


codex-rs/core/src/thread_manager.rs (2 lines):
	- line 164: // TODO(ccunningham): Add an explicit non-interrupting live-turn snapshot once
	- line 1001: // TODO(jif) merge with fork_agent


codex-rs/core/src/exec_policy.rs (2 lines):
	- line 170: // TODO(anp): Reconcile this decision input with TurnEnvironment::sandbox_context
	- line 286: // TODO(anp): Reconcile this approval snapshot with TurnEnvironment::sandbox_context


codex-rs/app-server-protocol/src/protocol/v2/item.rs (1 line):
	- line 1595: // TODO: Avoid hardcoding individual experimental fields here.


codex-rs/app-server-protocol/src/protocol/v2/thread_data.rs (1 line):
	- line 276: // TODO: Remove this compatibility decoder after app-server versions that omitted


codex-rs/app-server/src/request_processors/plugins.rs (1 line):
	- line 674: // TODO(remote plugins): Remove this once remote plugins are ready and vertical plugins are


codex-rs/core/src/tools/handlers/request_permissions.rs (1 line):
	- line 78: // TODO(anp): Migrate request_permissions parsing and permission profiles to PathUri so


codex-rs/models-manager/src/manager.rs (1 line):
	- line 486: // TODO(celia-oai): Include provider identity in cache eligibility so switching


codex-rs/core/src/tools/handlers/apply_patch.rs (1 line):
	- line 338: // TODO(anp): Make permission matching operate on PathUri. Until then, foreign paths skip


codex-rs/exec/src/lib.rs (1 line):
	- line 1417: // TODO(anp) resolve duplicate startup warnings


codex-rs/rmcp-client/src/oauth/resolved_store.rs (1 line):
	- line 151: // TODO(stevenlee): Different processes can still resolve Auto to different stores


codex-rs/exec-server/src/process_sandbox.rs (1 line):
	- line 126: // TODO(jif): Transport permissions before orchestrator-local paths are materialized,


codex-rs/tui/src/windows_sandbox.rs (1 line):
	- line 3: //! TODO: These helpers inspect and modify the TUI host, so they do not support


codex-rs/model-provider-info/src/lib.rs (1 line):
	- line 196: // TODO(celia-oai): Support AWS SigV4 signing for WebSocket


codex-rs/core/src/session/rollout_reconstruction.rs (1 line):
	- line 368: // TODO(ccunningham): if we drop support for None replacement_history compaction items,


codex-rs/tools/src/tool_spec.rs (1 line):
	- line 33: // TODO: Understand why we get an error on web_search although the API docs


codex-rs/tools/src/tool_call.rs (1 line):
	- line 74: // TODO(anp): Replace the marker with callback-scoped environment access.


codex-rs/rollout/src/list.rs (1 line):
	- line 1345: // TODO(jif): sqlite migration phase 1


codex-rs/tui/src/app/thread_routing.rs (1 line):
	- line 320: // TODO(anp): Remove this native-path localization error path once core permission


codex-rs/code-mode/src/remote_session/connection.rs (1 line):
	- line 58: // TODO(anp) make this timeout configurable if 60 seconds is insufficient.


codex-rs/windows-sandbox-rs/src/unified_exec/mod.rs (1 line):
	- line 26: // TODO(anp): Reconcile Windows backend and desktop copies with the supplied sandbox


codex-rs/tools/src/responses_api.rs (1 line):
	- line 35: /// TODO: Validation. When strict is set to true, the JSON schema,


codex-rs/core/src/mcp_tool_call.rs (1 line):
	- line 802: // TODO(anp): Build this metadata from the server's captured


codex-rs/message-history/src/lib.rs (1 line):
	- line 119: // TODO: check `text` for sensitive patterns


codex-rs/app-server-protocol/src/protocol/v2/thread.rs (1 line):
	- line 1875: // TODO(aibrahim): make this not optional


codex-rs/tui/src/app/config_persistence.rs (1 line):
	- line 768: // TODO(aibrahim): Remove this and don't use config as a state object.


codex-rs/ext/guardian-v2/src/sync_reviewer/reviewer_config.rs (1 line):
	- line 91: // TODO: Use the parent session's auth when reviewer spawning is wired;


codex-rs/core/src/tasks/mod.rs (1 line):
	- line 655: // TODO(jif): drop this


codex-rs/core/src/environment_selection.rs (1 line):
	- line 909: // TODO(anp): Migrate local-environment consumers to PathUri so this compatibility


codex-rs/app-server/src/request_processors/turn_processor.rs (1 line):
	- line 1692: // TODO: Remove this compatibility hack once Xcode 26.4 ages out.


codex-rs/exec-server/src/client.rs (1 line):
	- line 753: // TODO: Remove after app-server migrates off this call.


codex-rs/core/src/compact_remote_v2_attempt.rs (1 line):
	- line 124: // TODO: Emit this before compaction output validation so malformed completed


codex-rs/core/src/session_prefix.rs (1 line):
	- line 18: // TODO(jif) unify with structured schema


codex-rs/core/src/shell_snapshot.rs (1 line):
	- line 82: // TODO(anp): Migrate shell snapshot creation to accept PathUri and defer native


codex-rs/core/src/tools/runtimes/apply_patch.rs (1 line):
	- line 223: // TODO(iceweasel): Report executor filesystem sandbox backends like process/start so


codex-rs/core/src/guardian/mod.rs (1 line):
	- line 83: /// TODO(sayan): See if we can find a way to model those as StepContext as well without holding


codex-rs/app-server/src/request_processors/account_processor/bedrock_setup.rs (1 line):
	- line 123: // TODO: Validate the selected credentials against Bedrock ListModels once supported.


codex-rs/ext/skills/src/provider.rs (1 line):
	- line 48: // TODO(anp): Replace the marker with callback-scoped environment access.


codex-rs/core/src/connectors.rs (1 line):
	- line 165: // TODO: Wire callers that already own an EnvironmentManager into


codex-rs/core/src/sandboxing/mod.rs (1 line):
	- line 63: // TODO(anp): Reconcile these backend copies with TurnEnvironment::sandbox_context


codex-rs/core-plugins/src/marketplace.rs (1 line):
	- line 160: // TODO: Surface or enforce product gating at the Codex/plugin consumer boundary instead of


codex-rs/core/src/realtime_conversation.rs (1 line):
	- line 1708: // TODO(aibrahim): Remove this temporary fallback once realtime auth no longer


codex-rs/codex-api/src/endpoint/realtime_call.rs (1 line):
	- line 146: // TODO(aibrahim): Align the SIWC route with the API multipart shape and remove this branch.


codex-rs/codex-api/src/endpoint/responses_websocket.rs (1 line):
	- line 186: // TODO (pakrym): is this the right place for timeout?


codex-rs/cloud-tasks/src/util.rs (1 line):
	- line 85: // TODO: pass in cli overrides once cloud tasks properly support them.


codex-rs/tui/src/status/helpers.rs (1 line):
	- line 41: // TODO(anp): Rationalize instruction-source summaries with the TUI's broader foreign-path


codex-rs/app-server-transport/src/transport/remote_control/client_tracker.rs (1 line):
	- line 110: // TODO(ruslan): delete this fallback once all clients are updated to send stream_id.


codex-rs/app-server/src/request_processors/thread_processor.rs (1 line):
	- line 5373: // TODO: Remove this compatibility hack once Xcode 26.4 ages out.


codex-rs/core-plugins/src/manager.rs (1 line):
	- line 2219: // TODO: Remove this legacy remote-sync path once remote plugins have


codex-rs/core/src/unified_exec/process_manager.rs (1 line):
	- line 1264: // TODO(anp): Keep PathUri through the local PTY/process launch boundary.


codex-rs/core/src/tools/runtimes/unified_exec.rs (1 line):
	- line 273: // TODO(anp): Make shell snapshot lookup accept PathUri.


codex-rs/core/src/turn_metadata.rs (1 line):
	- line 120: // TODO(anp): Derive this cached tag from TurnEnvironment::sandbox_context


codex-rs/rmcp-client/src/oauth/refresh_lock.rs (1 line):
	- line 48: // TODO(stevenlee): define that rendezvous before expanding this lock's scope.


codex-rs/core/src/apply_patch.rs (1 line):
	- line 84: // TODO(anp): Carry PathUri through patch protocol events once app-server and rollout


codex-rs/sandboxing/src/spawn.rs (1 line):
	- line 18: // TODO(anp): Reconcile Windows backend and desktop copies with the supplied sandbox


codex-rs/core-plugins/src/loader.rs (1 line):
	- line 354: // TODO(remote plugins): download or update missing local bundles during remote


codex-rs/core/src/tools/events.rs (1 line):
	- line 440: // TODO: We should add a new ToolError variant for user-declined approvals.


codex-rs/exec-server-protocol/src/protocol.rs (1 line):
	- line 87: // TODO: Make this required once all supported exec-server versions return environmentInfo.


codex-rs/mcp-server/src/exec_approval.rs (1 line):
	- line 41: // TODO(mbolin): ExecApprovalResponse does not conform to ElicitResult. See:


codex-rs/protocol/src/approvals.rs (1 line):
	- line 65: // TODO(viyatb): Add websocket protocol variants when managed proxy policy


codex-rs/analytics/src/client.rs (1 line):
	- line 191: //TODO: add a metric for this


codex-rs/apply-patch/src/standalone_executable.rs (1 line):
	- line 68: // TODO(anp): Discover the standalone executable cwd as PathUri directly.


codex-rs/network-proxy/src/proxy.rs (1 line):
	- line 812: // TODO(winston): Materialize policy-checked per-child bundles for readable


codex-rs/protocol/src/plan_tool.rs (1 line):
	- line 6: // Types for the TODO tool arguments matching codex-vscode/todo-mcp/src/main.rs


codex-rs/apply-patch/src/invocation.rs (1 line):
	- line 111: // TODO: make private once we remove tests in lib.rs


codex-rs/core/src/tools/context.rs (1 line):
	- line 61: // TODO(sayan): Remove this compatibility field once handlers use `step_context.turn`.


codex-rs/ext/extension-api/src/contributors/turn_input.rs (1 line):
	- line 14: // TODO(anp): Replace the marker with callback-scoped environment access.


codex-rs/core/src/tools/sandboxing.rs (1 line):
	- line 398: // TODO(anp): Reconcile these attempt settings with TurnEnvironment::sandbox_context


codex-rs/tui/src/app/app_server_requests.rs (1 line):
	- line 124: // TODO(anp): Remove this duplicate validation once core permission paths remain


codex-rs/rmcp-client/src/http_headers.rs (1 line):
	- line 265: // TODO: Follow same-origin redirects once later hops cannot leak helper headers.


codex-rs/core/src/session/turn.rs (1 line):
	- line 168: // TODO(ccunningham): Pre-turn compaction runs before context updates and the


codex-rs/core/src/tools/handlers/extension_tools.rs (1 line):
	- line 180: // TODO(anp): Migrate extension ToolEnvironment and granted-permission lookup to PathUri


codex-rs/tui/src/chatwidget.rs (1 line):
	- line 871: // TODO(anp): Keep this as PathUri once `tui::approval_events::ExecApprovalRequestEvent` and


codex-rs/model-provider/src/provider.rs (1 line):
	- line 185: /// TODO(celia-oai): Make auth manager access internal to this crate so callers


codex-rs/process-hardening/src/lib.rs (1 line):
	- line 121: // TODO(mbolin): Perform the appropriate configuration for Windows.


codex-rs/app-server/src/notification_media.rs (1 line):
	- line 176: // TODO(ruslan): Handle oversized results that core has already collapsed into a


codex-rs/core/src/session/review.rs (1 line):
	- line 196: // TODO(ccunningham): Review turns currently rely on `spawn_task` for TurnComplete but do not


codex-rs/tui/src/lib.rs (1 line):
	- line 334: // TODO(jif) delete after 22/11/2026.


codex-rs/exec-server/src/environment.rs (1 line):
	- line 947: // TODO: Remove after app-server migrates off of force_environment_info.


codex-rs/core/src/tools/registry.rs (1 line):
	- line 502: // TODO(anp): Reconcile these tags with TurnEnvironment::sandbox_context


codex-rs/core-plugins/src/executor_hooks.rs (1 line):
	- line 239: // FIXME: Remove this temporary filter once executor plugin hooks can be trusted.


codex-rs/hooks/src/legacy_notify.rs (1 line):
	- line 44: // TODO: Remove this hook and its environment plumbing when legacy `notify` support is removed.


.codex/environments/environment.toml (1 line):
	- line 5: # TODO(anp) make it optional to specify this field


codex-rs/ext/extension-api/src/user_instructions.rs (1 line):
	- line 11: // TODO(anp): Replace the absolute path with a more general instruction-source


codex-rs/app-server/src/bespoke_event_handling.rs (1 line):
	- line 1871: // TODO(anp): Remove this native-path localization error path once core permission paths


codex-rs/tui/src/clipboard_paste.rs (1 line):
	- line 266: // TODO: We'll improve the implementation/unit tests over time, as appropriate.


codex-rs/app-server/src/command_exec.rs (1 line):
	- line 240: // TODO(anp): Keep PathUri through the local command launch boundary.


codex-rs/config/src/state.rs (1 line):
	- line 58: //TODO(gt): Add a macos_ prefix to this field and remove the target_os check.


codex-rs/skills/src/model.rs (1 line):
	- line 65: // TODO: Enforce product gating in Codex skill selection/injection instead of only parsing and


codex-rs/tui/src/chatwidget/streaming.rs (1 line):
	- line 211: // TODO: Replace streamed output with the final plan item text if plan streaming is


codex-rs/exec-server/src/fs_sandbox.rs (1 line):
	- line 465: // TODO(anp): Keep PathUri through the filesystem helper launch boundary.


codex-rs/codex-mcp/src/mcp/mod.rs (1 line):
	- line 159: // TODO(anp): Reconcile this runtime-wide copy with TurnEnvironment::sandbox_context


codex-rs/exec-server/src/server/request_dispatcher.rs (1 line):
	- line 269: // TODO(anp) bound queued request bytes without blocking later responses or cleanup.


codex-rs/tui/src/debug_config.rs (1 line):
	- line 351: // TODO(gt): Expand this debug output with detailed skills and rules display.


codex-rs/hooks/src/engine/mod.rs (1 line):
	- line 77: /// TODO: With CCA, all hooks will be executor-scoped, so user visibility


codex-rs/tui/src/app/thread_settings.rs (1 line):
	- line 156: // TODO(anp): Support Windows sandbox updates through environment configuration;


codex-rs/utils/path-uri/src/lib.rs (1 line):
	- line 230: /// TODO(anp): Once `PathUri` carries an environment identifier, prefer the


codex-rs/core/src/guardian/review_session.rs (1 line):
	- line 1183: // TODO(anp): Migrate guardian review thread settings to a PathUri fallback cwd so foreign


codex-rs/app-server/src/lib.rs (1 line):
	- line 1162: // TODO(jif) handle lag.


codex-rs/windows-sandbox-rs/src/elevated_impl.rs (1 line):
	- line 16: // TODO(anp): Reconcile this private-desktop copy with the supplied sandbox context


codex-rs/core/src/tools/handlers/plan.rs (1 line):
	- line 89: "update_plan is a TODO/checklist tool and is not allowed in Plan mode".to_string(),
