# Suricata 8.0 dynamic alproto can not be disabled

**URL:** <https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059>\
**Category:** Developers\
**Tags:** suricata\
**Created:** [October 15, 2025, 5:55am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059 "2025-10-15T05:55:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![liheng562653799](https://avatars.discourse-cdn.com/v4/letter/l/f19dbf/32.png) [@liheng562653799](https://forum.suricata.io/u/liheng562653799)\
**Post date:** [October 15, 2025, 5:55am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059/1 "2025-10-15T05:55:40Z")

</div>

**Outputing:**  
[35686] Notice: suricata: This is znsm version 8.0.0 RELEASE running in SYSTEM mode  
[35686] Info: cpu: CPUs/cores online: 16  
[35686] Info: dpdk: Setting IPS mode  
[35686] Warning: runmodes: disabling livedev.use-for-tracking with IPS mode. See ticket #6726.  
[35686] Info: exception-policy: master exception-policy set to: auto  
[35686] Info: app-layer-ftp: Parser disabled for ftp protocol. Protocol detection still on.  
[35686] Info: app-layer-smtp: Parser disabled for smtp protocol. Protocol detection still on.  
ERROR: incomplete app-layer registration  
AppLayer protocol snmp ipproto 6

- option flags 214
- first\_data\_dir db  
Mandatory:
- Parser[0] (nil) Parser[1] 0x3f1
- StateAlloc 0x380 StateFree 0x38000
- StateGetTx (nil) StateGetTxCnt (nil) StateTransactionFree 0xa9172f1d
- GetTxData (nil)
- GetStateData (nil)
- StateGetProgress 0x100000000  
Optional:
- LocalStorageAlloc 0x3000000000 LocalStorageFree (nil)
- StateGetEventInfo 0x2000000000 StateGetEventInfoById 0x20

**Problem:**  
When snmp is disabled, suricata 8.0 exits dule to func call chain“ValidateParsers→ValidateParser→ValidateParserProto”.

**Reason:**  
Source code shows that though a dynamic alproto’s AppProtoEnum is asigned(which lead to increament of variable g\_alproto\_max) by AppProtoNewProtoFromString, alp\_ctx.ctxs won’t be reallocated until func call chain“AppLayerRegisterParser→AppLayerParserRegisterStateFuncs“ which implies that the dynamic alproto is enabled. The func “ValidateParsers“ validates all g\_alproto\_max ctxs, access ctx[g\_alproto\_max-1] which is not reallocated.

**Solution:**  
I found that to modify validator(like ValidateParsers) is not a good idea, beacause other code will access ctx[g\_alproto\_max-1]. So I add a func named AppLayerParserReallocCtx in app-layer-parser.c, add called in func AppProtoRegisterProtoString.

**New Function:**  
int AppLayerParserReallocCtx(AppProto alproto)  
{  
if (alp\_ctx.ctxs\_len \<= alproto) {  
// Realloc alp\_ctx.ctxs, so that dynamic alproto can be treated as real/normal ones.  
// In case we need to turn off dynamic alproto.  
void \*tmp = SCRealloc(alp\_ctx.ctxs,  
sizeof(AppLayerParserProtoCtx[FLOW\_PROTO\_MAX]) \* (alp\_ctx.ctxs\_len + ARRAY\_CAP\_STEP));  
if (unlikely(tmp == NULL)) {  
FatalError(“Unable to realloc alp\_ctx.ctxs.”);  
}  
alp\_ctx.ctxs = tmp;  
memset(&alp\_ctx.ctxs[alp\_ctx.ctxs\_len], 0, sizeof(AppLayerParserProtoCtx[FLOW\_PROTO\_MAX]) \* ARRAY\_CAP\_STEP);  
alp\_ctx.ctxs\_len += ARRAY\_CAP\_STEP;  
}

```auto
return 0;

```

}

---

<div class="post-metadata">

**Author:** ![sbhardwaj](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/sbhardwaj/32/10_2.png) [@sbhardwaj](https://forum.suricata.io/u/sbhardwaj)\
**Post date:** [October 15, 2025, 6:17am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059/2 "2025-10-15T06:17:04Z")

</div>

Hi! SNMP was particularly broken and was fixed in the latest point release `8.0.1`. See the tracking ticket: [Bug #7820: app-layer/snmp: internal error if app-layer is disabled - Suricata - Open Information Security Foundation](https://redmine.openinfosecfoundation.org/issues/7820)

If you see this for any other protocol as well, please feel free to report.

We happily accept code contributions for any betterment but that should come via GitHub. [GitHub - OISF/suricata: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.](https://github.com/oisf/suricata)

---

<div class="post-metadata">

**Author:** ![liheng562653799](https://avatars.discourse-cdn.com/v4/letter/l/f19dbf/32.png) [@liheng562653799](https://forum.suricata.io/u/liheng562653799)\
**Post date:** [October 15, 2025, 7:06am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059/3 "2025-10-15T07:06:22Z")

</div>

I just had tested the fix. When snmp app-layer configuration is “enabled: no“, the problem is resulved. but when “enabled: detection-only“, The problem still exists. Beacause ctxs is not reallocaged when the configuration is “enabled: detection-only“.

---

<div class="post-metadata">

**Author:** ![sbhardwaj](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/sbhardwaj/32/10_2.png) [@sbhardwaj](https://forum.suricata.io/u/sbhardwaj)\
**Post date:** [October 15, 2025, 7:16am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059/4 "2025-10-15T07:16:04Z")

</div>

Indeed. I can confirm `detection-only` is buggy. Could you please create a ticket for this on our Redmine? [https://redmine.openinfosecfoundation.org](https://redmine.openinfosecfoundation.org)

Patches are welcome on Github!

---

<div class="post-metadata">

**Author:** ![liheng562653799](https://avatars.discourse-cdn.com/v4/letter/l/f19dbf/32.png) [@liheng562653799](https://forum.suricata.io/u/liheng562653799)\
**Post date:** [October 15, 2025, 8:25am UTC](https://forum.suricata.io/t/suricata-8-0-dynamic-alproto-can-not-be-disabled/6059/5 "2025-10-15T08:25:29Z")

</div>

I had just create a ticket, [Bug #8000: suricata 8.0 dynamic alproto can not be disabled](https://redmine.openinfosecfoundation.org/issues/8000)
