# github.com/fsnotify/fsnotify@v1.9.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:33.000Z
- Files reviewed: 30
- Findings: 6 low severity findings
- Report: https://security.togoder.click/go/github.com/fsnotify/fsnotify
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/fsnotify/fsnotify@v1.9.0 on Oct 5, 2026. An AI review of 30 source files produced 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Resource limit adjustment

Finding ID: `NPS-8CD06EF8E7BB`

File: `internal/darwin.go:18`

The SetRlimit function raises the process's open file descriptor limit to the system maximum. This is a legitimate system tuning operation common in file-watcher or server applications, not a malicious pattern.

### [low] System information query

Finding ID: `NPS-9BE7D8224F77`

File: `internal/darwin.go:24`

SysctlUint32 calls retrieve kernel.maxfiles and kern.maxfilesperproc system values to cap maxfiles. This is read-only system introspection with no external communication.

### [low] Resource limit modification

Finding ID: `NPS-2B8784A80C6E`

File: `internal/unix.go:16`

SetRlimit() raises the soft limit of RLIMIT_NOFILE to the hard limit. This is a normal system configuration operation, not a security concern.

### [low] Potential regular expression denial of service (ReDoS)

Finding ID: `NPS-A026C032E5DD`

File: `internal/ztest/diff.go`

DiffMatch compiles user-supplied patterns into Go regexps and can match them against arbitrary 'have' input. Although Go's regexp engine is RE2-based and linear-time, complex patterns constructed from the %(..) substitutions (especially %(ANY) mapped to .+?) combined with large inputs can still cause excessive CPU usage. This is test-only code, but callers should be aware that untrusted 'want' patterns are embedded into regexes.

### [low] Regex injection via crafted 'want' pattern

Finding ID: `NPS-C97764D4C924`

File: `internal/ztest/diff.go`

The %(..) replacement in DiffMatch takes the inner text of the pattern and, after QuoteMeta, returns it mostly unescaped (strings.ReplaceAll(m[3:len(m)-2], `\`, ``)). This allows arbitrary regex constructs (except backslash) to be injected, including .*, character classes, anchors, etc. In a test-helper context this is intended behavior, but if 'want' originates from untrusted input it amounts to regex injection. No code execution or data exfiltration occurs.

### [low] Error message leaks raw input

Finding ID: `NPS-0375A2485FEE`

File: `internal/ztest/diff.go`

In applyOpt, when JSON formatting fails the raw 'have'/'want' content is embedded into an error string returned to the caller. This could expose sensitive data present in test fixtures/inputs in logs or CI output. It is a test utility, so exposure is limited, but it is still a minor information-disclosure concern.

## Files reviewed

- `internal/ztest/diff.go` (medium): No malicious patterns (no network, exec, credential harvesting, or persistence) were found; only minor test-time concerns around regex handling and error message content.
- `backend_fen.go` (safe): Cleared by Jev triage; no further analysis needed
- `backend_inotify.go` (safe): This is the legitimate fsnotify Linux inotify implementation; no malicious patterns, exfiltration, or dynamic code execution were found.
- `backend_kqueue.go` (safe): No malicious patterns detected; the code is a legitimate BSD/macOS kqueue-based file system notification backend from the fsnotify library.
- `backend_other.go` (safe): Cleared by Jev triage; no further analysis needed
- `backend_windows.go` (safe): This is the legitimate Windows backend implementation of the fsnotify library using ReadDirectoryChangesW; no malicious patterns, exfiltration, or backdoors were detected.
- `cmd/fsnotify/closewrite.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/fsnotify/dedup.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/fsnotify/file.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/fsnotify/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `cmd/fsnotify/watch.go` (safe): Cleared by Jev triage; no further analysis needed
- `fsnotify.go` (safe): No malicious patterns detected in fsnotify.go; the code is a legitimate cross-platform file system notification library with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `internal/darwin.go` (safe): The code performs legitimate Darwin-specific resource limit tuning and FIFO/device-node creation helpers with no malicious behavior.
- `internal/debug_darwin.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_dragonfly.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_freebsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_kqueue.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_linux.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_netbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_openbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_solaris.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/debug_windows.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/freebsd.go` (safe): No malicious patterns detected
- `internal/internal.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/unix.go` (safe): No malicious patterns detected; code only adjusts file descriptor limits and provides filesystem utility wrappers.
- `internal/unix2.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/windows.go` (safe): No malicious patterns detected; the file contains only Windows-specific stubs and a privilege check using standard library APIs.
- `shared.go` (safe): Cleared by Jev triage; no further analysis needed
- `system_bsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `system_darwin.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
