mattcasters opened a new issue, #8671: URL: https://github.com/apache/hop/issues/8671
### What would you like to happen? ## What Hop has today Hop already uses Commons VFS everywhere. Extra schemes (S3, Azure, GCS, Drive, Dropbox, MinIO, WebDAV, Databricks) are Hop plugins, not core VFS. There is no first-class SMB provider. Commons VFS still documents a sandbox `smb://` / CIFS provider, but that code sits on **classic JCIFS**, which is **SMB1 only**. Modern Windows has SMB1 off by default, which is why people end up mapping a drive. Hop maintainers already called this out in [discussion #4733](https://github.com/apache/hop/discussions/4733). You do **not** need PutSMB/GetSMB actions. A real VFS provider plus a named connection (same pattern as FTP / WebDAV / MinIO) covers Text File Input/Output, Copy Files, file dialogs, and the VFS File Explorer. ## License constraint (this is the deciding factor) Apache Hop is ALv2 / ASF. Bundled dependencies must be Category A (or allowed Category B). **LGPL 2 / 2.1 / 3 is Category X** and cannot ship in an Apache product. | Library | License | Protocols | Ship in Hop? | |---|---|---|---| | [hierynomus/smbj](https://github.com/hierynomus/smbj) (`com.hierynomus:smbj`) | Apache 2.0 | SMB 2 / 3 | Yes | | Original JCIFS (`jcifs:jcifs`) | LGPL 2.1 | SMB1 only | No | | [jcifs-ng](https://github.com/AgNO3/jcifs-ng) | LGPL 2.1 | SMB1 + SMB2 + some SMB3 | No | | [CodeLibs JCIFS](https://github.com/codelibs/jcifs) (jcifs-ng continuation) | LGPL 2.1 | SMB1 / 2 / 3 | No | smbj’s own deps are also fine for ASF: SLF4J (MIT), Bouncy Castle (MIT-style, Category A), `asn-one` (ALv2), mbassador (MIT). SMB encryption will pull BC, so the plugin would be cryptographic software for export-notice purposes, same as other Hop/ASF components that already use BC. JCIFS-based VFS adapters (Commons VFS sandbox, [vfs-jcifs-ng](https://github.com/IdentityAutomation/vfs-jcifs-ng), vbauer/commons-vfs2-cifs) are useful as **API shape references only**. The wrapper may be ALv2; the runtime library is still LGPL. ## What to build on **Protocol layer:** `com.hierynomus:smbj` (current Central line is 0.15.x). Pure Java client, no OS mount, talks SMB2/3 to Windows and Samba. It does **not** speak SMB1; that is a feature for current servers. **VFS adapter to copy from, not to depend on blindly:** - [mikhasd/commons-vfs2-smb](https://github.com/mikhasd/commons-vfs2-smb) — VFS2 `FileProvider` over smbj, described as production-tested. Not a mature Central artifact; treat as a starting implementation. - [umjammer/commons-vfs2-smb](https://github.com/umjammer/commons-vfs2-smb) — same idea, ALv2, JitPack. Those wrappers implement the Commons VFS types you need (`FileProvider`, `FileObject`, `FileSystem`, name parser). For Hop you still wrap that as a `@VfsPlugin` / `IVfs` module under `plugins/vfs` (or `plugins/tech/smb`) so it gets its own classloader and `lib/` folder. Do not drop `commons-vfs2-sandbox` into Hop. That is the JCIFS/SMB1 path. ## Suggested shape for a Hop plugin 1. **VFS provider** for `smb://host/share/path`. 2. **Named connection metadata** (host, share, domain, user, password/variable, port, SMB dialect min/max, timeout, DFS on/off) exposed as `myShare:///folder/file.csv`, matching FTP/MinIO. 3. Wire `StaticUserAuthenticator` / Hop’s credential store. Do not put passwords in the URI. 4. Capabilities to implement: list, read, write, create/delete, rename, last-modified. Random access if smbj’s file API makes it cheap. 5. Test against Samba in Docker and against a real Windows share with SMB1 disabled. ## Practical caveats - **DFS, Kerberos, and guest/anonymous** need explicit design. smbj does NTLM well; Kerberos is possible but more work than “drop in a jar”. - Connection pooling and session reuse matter. Naive open-per-file-object behavior is what made old JCIFS VFS painful. - UNC (`\\server\share`) will still not be a VFS URI. The user-facing form should be `smb://server/share/...` or `connectionName:///...`. - If someone only needs SMB1 appliances, that is a separate, non-ASF plugin on JCIFS. Do not mix both stacks in the official distribution. **Bottom line:** use **smbj** as the ALv2-compatible SMB2/3 engine, implement (or lift-and-clean) a Commons VFS provider over it, and register it as a Hop VFS plugin with a named connection. Skip JCIFS/jcifs-ng for anything that would ship with Apache Hop. ### Issue Priority Priority: 2 ### Issue Component Component: VFS -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
