mattcasters opened a new issue, #8671:
URL: https://github.com/apache/hop/issues/8671

   ### What would you like to happen?
   
   ## What Hop has today
   
   Hop already uses Commons VFS everywhere. Extra schemes (S3, Azure, GCS, 
Drive, Dropbox, MinIO, WebDAV, Databricks) are Hop plugins, not core VFS. There 
is no first-class SMB provider.
   
   Commons VFS still documents a sandbox `smb://` / CIFS provider, but that 
code sits on **classic JCIFS**, which is **SMB1 only**. Modern Windows has SMB1 
off by default, which is why people end up mapping a drive. Hop maintainers 
already called this out in [discussion 
#4733](https://github.com/apache/hop/discussions/4733).
   
   You do **not** need PutSMB/GetSMB actions. A real VFS provider plus a named 
connection (same pattern as FTP / WebDAV / MinIO) covers Text File 
Input/Output, Copy Files, file dialogs, and the VFS File Explorer.
   
   ## License constraint (this is the deciding factor)
   
   Apache Hop is ALv2 / ASF. Bundled dependencies must be Category A (or 
allowed Category B). **LGPL 2 / 2.1 / 3 is Category X** and cannot ship in an 
Apache product.
   
   | Library | License | Protocols | Ship in Hop? |
   |---|---|---|---|
   | [hierynomus/smbj](https://github.com/hierynomus/smbj) 
(`com.hierynomus:smbj`) | Apache 2.0 | SMB 2 / 3 | Yes |
   | Original JCIFS (`jcifs:jcifs`) | LGPL 2.1 | SMB1 only | No |
   | [jcifs-ng](https://github.com/AgNO3/jcifs-ng) | LGPL 2.1 | SMB1 + SMB2 + 
some SMB3 | No |
   | [CodeLibs JCIFS](https://github.com/codelibs/jcifs) (jcifs-ng 
continuation) | LGPL 2.1 | SMB1 / 2 / 3 | No |
   
   smbj’s own deps are also fine for ASF: SLF4J (MIT), Bouncy Castle 
(MIT-style, Category A), `asn-one` (ALv2), mbassador (MIT). SMB encryption will 
pull BC, so the plugin would be cryptographic software for export-notice 
purposes, same as other Hop/ASF components that already use BC.
   
   JCIFS-based VFS adapters (Commons VFS sandbox, 
[vfs-jcifs-ng](https://github.com/IdentityAutomation/vfs-jcifs-ng), 
vbauer/commons-vfs2-cifs) are useful as **API shape references only**. The 
wrapper may be ALv2; the runtime library is still LGPL.
   
   ## What to build on
   
   **Protocol layer:** `com.hierynomus:smbj` (current Central line is 0.15.x). 
Pure Java client, no OS mount, talks SMB2/3 to Windows and Samba. It does 
**not** speak SMB1; that is a feature for current servers.
   
   **VFS adapter to copy from, not to depend on blindly:**
   
   - [mikhasd/commons-vfs2-smb](https://github.com/mikhasd/commons-vfs2-smb) — 
VFS2 `FileProvider` over smbj, described as production-tested. Not a mature 
Central artifact; treat as a starting implementation.
   - [umjammer/commons-vfs2-smb](https://github.com/umjammer/commons-vfs2-smb) 
— same idea, ALv2, JitPack.
   
   Those wrappers implement the Commons VFS types you need (`FileProvider`, 
`FileObject`, `FileSystem`, name parser). For Hop you still wrap that as a 
`@VfsPlugin` / `IVfs` module under `plugins/vfs` (or `plugins/tech/smb`) so it 
gets its own classloader and `lib/` folder.
   
   Do not drop `commons-vfs2-sandbox` into Hop. That is the JCIFS/SMB1 path.
   
   ## Suggested shape for a Hop plugin
   
   1. **VFS provider** for `smb://host/share/path`.
   2. **Named connection metadata** (host, share, domain, user, 
password/variable, port, SMB dialect min/max, timeout, DFS on/off) exposed as 
`myShare:///folder/file.csv`, matching FTP/MinIO.
   3. Wire `StaticUserAuthenticator` / Hop’s credential store. Do not put 
passwords in the URI.
   4. Capabilities to implement: list, read, write, create/delete, rename, 
last-modified. Random access if smbj’s file API makes it cheap.
   5. Test against Samba in Docker and against a real Windows share with SMB1 
disabled.
   
   ## Practical caveats
   
   - **DFS, Kerberos, and guest/anonymous** need explicit design. smbj does 
NTLM well; Kerberos is possible but more work than “drop in a jar”.
   - Connection pooling and session reuse matter. Naive open-per-file-object 
behavior is what made old JCIFS VFS painful.
   - UNC (`\\server\share`) will still not be a VFS URI. The user-facing form 
should be `smb://server/share/...` or `connectionName:///...`.
   - If someone only needs SMB1 appliances, that is a separate, non-ASF plugin 
on JCIFS. Do not mix both stacks in the official distribution.
   
   **Bottom line:** use **smbj** as the ALv2-compatible SMB2/3 engine, 
implement (or lift-and-clean) a Commons VFS provider over it, and register it 
as a Hop VFS plugin with a named connection. Skip JCIFS/jcifs-ng for anything 
that would ship with Apache Hop.
   
   ### Issue Priority
   
   Priority: 2
   
   ### Issue Component
   
   Component: VFS


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to