Wssdl – WireShark-Specific Dissector Language
github.com
github.com
It's considerably more flexible, much more elegant, and (in Erlang) battle-tested.
I wrote an Erlang-inspired version of bitstrings for OCaml: https://people.redhat.com/~rjones/bitstring/html/Bitstring.h...
I experimented with a key/value approach on the syntax itself (something like `{ src_port = u16 }` or `{ src_port = 16 }`), which was nicer, but the problem was that, in lua, table literals are unordered. The current approach uses the method syntax (`a:b()`) as a nice workaround, but this mandates the use of parenthesis after the type and other specifiers. This is fine though since a lot of the provided types are parameterized (e.g. `bytes(n)` which takes a number of octets)
In the last dissector I wrote, which was about 1000 lines of Lua, I built a very limited structure definition parser, not completely unlike wssdl. I did it to cut down on the repetitive code needed parse the structures: Typically I parse every field twice: Once to add it to the dissection tree and once to get its value as a Lua-held variable.
I'll definitely be using wssdl in my next dissector!
This is nothing new though: all wireshark plugins must be GPL, since the API itself they rely on is GPL.
EDIT: I'm not entirely correct There are provisions for the network situation ("ASP (application service provider) loophole") I described, but I looks like it's not necessarily the default mode. See [0][1].
[0] https://en.wikipedia.org/wiki/GNU_General_Public_License
[1] https://en.wikipedia.org/wiki/Affero_General_Public_License
As Wikipedia notes, some drafts of the GPLv3 contained such a provision, but this did not make it into the final version.