
Differences between revisions 1 and 77 (spanning 76 versions)
Revision 1 as of 2017-09-22 14:22:38
Size: 2485
Editor: ahasenack
Comment: template
Revision 77 as of 2018-08-28 17:04:58
Size: 21855
Editor: ahasenack
Deletions are marked like this. Additions are marked like this.
Line 1: Line 1:
## page was copied from AndreasHasenack/UbuntuServerDevApplication
Line 4: Line 5:
'''Please do not edit this page. It is a template to be used by people applying as an Ubuntu developer.'''

Head over to instead and make use of this template.

'''I, <YOUR NAME>, apply for <universe-contributor|MOTU|core-dev|upload rights for package(s) <X>>.'''

|| '''Name''' || <YOUR NAME> ||
|| '''Launchpad Page''' || <link to your launchpad page> ||
|| '''Wiki Page''' || <link to your Wiki page> ||


'''I, Andreas Hasenack, apply for Ubuntu Core Developer'''

|| '''Name''' || Andreas Hasenack ||
|| '''Launchpad Page''' || ||
|| '''Wiki Page''' || ||
Line 20: Line 15:
''Tell us a bit about yourself.'' I graduated in Electrical Engineering. Worked for a few years in a company in the aerospace industry, but in the civilian area, in a project about installing "black boxes" in trucks and buses to monitor several driving and engine parameters. I then came in contact with a customer who had a nice "intranet" (that's what it was called back then), with internal web sites and a big database backend (oracle). We had to do some development for them, but didn't have access to Oracle, and someone told me that I should try this thing called "linux", "postgresql" and "apache". I did, then installed it at home, and never looked back.

In 1998 I took a post-grad specialization course in the University (a degree higher than graduation, but below masters) in computer networks and went to work for Conectiva, the Brazilian Linux distribution, later renamed to Mandriva, where I stayed until 2008 doing lots of packaging work (RPM) and consulting for enterprise customers in the server area. My main area of expertise was email, authentication (kerberos, pam) and LDAP, and I also spent about half the time working in Conectiva's security team and doing security updates for the distro.
Line 26: Line 23:
In 2008 I applied for a job in the Landscape team (, and got hired as a QA engineer. I had never done any Debian packaging before, just had some ideas about how it worked, had grabbed a few packages here and there to inspect them, looked at patches, etc. apt-get wasn't a stranger, since Conectiva developed apt-rpm back in the day, and the concept of dependency resolution is the same everywhere.

Landscape has a client component, and that means a Debian package that gets installed on machines. It obviously needs to be QA'ed. So that's how I got exposed to Debian packaging "for real" that time.

In April 2017 I started working in the Ubuntu Server Team. That got me back in touch with my "Linux roots" (no pun intended) and immediately I started looking into my old friends kerberos, ldap, samba, etc and searching for bugs to fix. It is in the Ubuntu Server Team that I got introduced to the Debian Merge process, and how this team is looking into improving that process via the [[UbuntuDevelopment/Merging/GitWorkflow|Git Ubuntu tooling]].
Line 27: Line 30:

=== DEP8 tests I added ===
 * [[|Bug #1696823]]
 * Branch: [[|samba-extra-dep8-1696823]]
 * upstreamed to debian:

 * Merge proposal:
 * Pushed to Debian via

 * Pushed to Debian first:

=== FTBFS fixes I uploaded ===
 * ocfs2-tools:
 * squid3 (during gcc7 migration):
 * libcloud, which I hit after doing strongswan and paramiko uploads:
  * fixes were submitted upstream and accepted

=== Cooperation with debian and/or upstream ===
 * please add dep8 tests. There is no salsa repository yet for autofs, so I just attached a debdiff.

 * Pushed up a small DEP8 fix:

 * DEP8 tests:
 * Drop deprecated syslog options from default smb.conf
 * logrotate: only try to reload the services if they are running

 * tests that failed with -Wl,-Bsymbolic-functions enabled (default in ubuntu):
  * mailing list thread:
  * Resulted in upstream
 * Create the secrets directory used by sssd-secrets

squid4 dep8 fixes pushed to debian. Debian had adopted most of our DEP8 tests previously, but they never passed in their infrastructure (

 * I opened it against bind, but it should have been bind9. Debian merged the fix into the right repository.

  * Add distro banner (our only delta with Debian). Unfortunately rejected, but we tried :)

 * More DEP8 tests for Dovecot

=== Misc ===
 * libvirt apparmor bug investigation and SRU: Apparmor was being called in post manually, not via dh_apparmor, and that missed the cached profiles. The new profile was never applied.
 * MIR: http-parser, for sssd:
 * bug-pattern contribution for a samba bug:
 * NEW packages:
  * ndctl
   * all history showing how the lintian warnings/errors were addressed:
  * pmdk
   * all history showing how the lintian warnings/errors were addressed:
  * bug showing dialog with upstream about pmdk and ndctl:
 * qa-regression-testing:
  * Apache update changed behavior which broke one regression testing test. Made an MP to fix that:

 * backport that became an SRU to bring a new zstd version back into stable releases. *Lots* of testing involved. This included creating a transitional package in bionic.

 * SRU DEP8 investigation and fixes:
  * A normal apache2 SRU that failed DEP8 in xenial, artful, bionic:
  * See comments (artful) and (xenial)
  * new bug filed for libapache2-mod-perl2 DEP8 fixes in xenial: Normally we don't do SRUs with only DEP8 fixes, but this package in particular would always fail during an apache2 SRU, which is more common.

 * britney hints MP for ocfs2-tools:

 * Mini migration for bind9
  * While looking at the reverse dependencies, I missed bind-dyndb-ldap, thinking it was part of bind9, but it's a separate source. Got it sponsored.
  * Then I thought isc-dhcp wasn't needed, because the old bind package with the old soname would still be around. Even tested that scenario, but had to rebuild it as well:
  jul 31 15:44:10 <ahasenack> and upgrading just bind, leaving isc-dhcp without a rebuild, also works:
  * The packages would still not migrate. Looking at the update_output.txt, I found out that debian-installer is a reverse dependency as well. Asked for a rebuild/sponsorship:
  ago 01 14:37:54 <ahasenack> hi, my bind9 upload, which bumped the soname, also needs a debian-installer rebuild (ppa at Would someone sponsor this for me?
  * Summary of rebuilds needed for bind9 to migrate:
  * PPA with my test builds:

 * Bileto usage:
  * I just got access, and used it to run squid-4.x DEP8 tests in all architectures, prior to an actual upload: Since then, I used it for other packages, but abandoned the ticket after I was satisfied with the test results, so I don't have a link for them. I just left the squid4 one open for now.

 * New team member mentoring: walked a new team member (kstenerud) through the SRU process using git-ubuntu: We continued the next day on the DEP8 tests topic:
Line 29: Line 132:
## As a per-package uploader, please give us some insight into the package maintenance and bug situation since you're working on it.
 * Package maintenance for Conectiva/Mandriva: before Canonical, I was doing server package maintenance for [[|Conectiva]] (which later became [[|Mandriva]]) for 8 years. My focus was authentication, authorization and email servers. I also did a lot of security updates and announcements for Conectiva, you may find them in Bugtraq and other security mailing lists from back then (quick [[|google search]]). For Conectiva, I maintained, among others: MIT kerberos and friends (pam-krb5), openldap and friends (pam-ldap, nss-ldap), cyrus-sasl, cyrus-imapd, postfix, samba.

 * openldap dit: I tried to bring my openldap experience to Ubuntu with a small project called OpenLDAP-DIT (, later moved to, but it stalled as I was very much involved in Landscape and that had nothing to do with LDAP. I might resume it someday. At one of the Ubuntu UDSs it was even proposed to become the default DIT that Ubuntu would install and setup (

 * Landscape:
  * Landscape Autopilot: automated cloud deployments (openstack) using juju charms
  * automated troubleshooting of failed cloud deployments: together with [[|Ursinha]] and [[|Francis Ginther]] we created a cloud deployment log analyser. Hooked up to our jenkins CI, it would fetch logs from a failed cloud deploy and go over it looking for known issues. We had several signatures for known issues. If one was found, it would annotate the jenkins job so we would know right away why the deployment failed. Furthermore, we could use this to also keep the deployment up if an issue which we want to debug manually comes up. We called this "stop the test". Unfortunately it's a private project in LP ( because it contains samples that have PPPA credentials and other secrets that were hard to remove.
  * Documentation and release notes: all Landscape release notes, including deployment guides, from For example, for the 17.03 release:
 * Ubuntu Server Guide documentation fixes:
  * [[|#1692259]]: slapd service does not automatically start
  * [[|#973981]]: Ubuntu 11.10 help page for kerberos and ldap uses deprecated commands
  * [[|#1038625]]: kerberos: never states to create non-admin user principal
  * [[|#1170876]]: LDAP Private Key Access
  * [[|#1239914]]: ldap installation Server guide implies for default settings that do not happen
  * [[|#1409392]]: 'Kerberos and LDAP' instructions show bad ldap_kerberos_container_dn example
  * [[|#1579209]]: Samba and LDAP is completely out of date
  * [[|#1603540]]: wrong ldif file for altering indexes
Line 32: Line 158:
 * I stopped updating the server guide
 * Create more bug patterns. Experience with triage has showed some patterns in bugs that we can leverage with automation
Line 35: Line 163:
 * Keep adding DEP8 tests to the Ubuntu and Debian packages
 * Reduce the delta with Debian by submitting changes upstream
 * Improve the LTS Server Guide in the areas of Authentication, Authorization and Samba

Line 37: Line 170:
 * Lack of proper DEP3 headers in patches. This sometimes makes it hard to find out why a patch was introduced, or if it can be dropped. There are lintian checks for this already, but they are not enforced on upload. "What's obvious today, may not be obvious 12 months from now."
 * Many SRU bugs I see being accepted lack what I would call proper test cases. In many cases they are way too generic, or do not fulfill this requirement from the SRU template: ''these should allow someone who is not familiar with the affected package to reproduce the bug and verify that the updated package fixes the problem.'' We have to reach some sort of balance here. SRUs are already hard for newcomers, but without a proper test procedure, they are also hard on the members of the SRU team.
 * Communication and coordination in `#ubuntu-release` is a bit ''ad-hoc''. One could argue it's agile, since pings from trusted people on IRC can be quickly acted upon, but if you happen to not know who is and isn't around, or by chance hit the channel when people are on holidays or in a sprint, you can be greeted by a black hole. Maybe there could be a vanguard for the week, or the day?
 * Sites, reports, cron jobs, etc, running all over the place, in all types of domain names. Some look more "official" than others. A few examples:
It feels like someone quickly built a tool to solve an immediate problem, published it under a group account somewhere they had write access to, and that became official because it works and people who need it, know where to find it. I imagine some time ago people thought this would all be part of Launchpad.

 * Lack of ownership of DEP8 failures impeding migration. When a package is uploaded, its DEP8 tests are run (if they exist), and dependent packages also have their tests run. Sometimes, one or more of the latter fails, but since it's a failure in *another* package, it's not always handled by the uploader and it just stays there, or a force-badtest is asked for. There are for sure complex cases, but not always.

 * What's up with packages stuck in proposed migration for dozens of days? Or months? What about a year?
Line 42: Line 194:
Line 46: Line 199:

== Christian Ehrhardt ==
=== General feedback ===
I have accompanied Andreas from him joining the server Team - with an already great technical background and emphasis on testing things before pushing changes - to the clearly core-dev material engineer that he is today - where I'm close to create aliases to sponsor his work.
So far I sponsored 45 uploads of Andreas (see [[*hrhardt*&sponsor_search=name&sponsoree=*hasenack*&sponsoree_search=name|sponsor ship miner]]).
I have seen a great progression of quality over time and it reached a a state where I mostly find style suggestions and similar things, but no actual packaging/Ubuntu issues as part of the upload.
I'd judge the quality of his uploads really high and having seen his improvements over the past I'm sure he can adapt to changes as needed. I appreciate that he has grown as much as being a great resource for reviewing my work recently. Due to that he really has my trust and I'm confident he would be a good Ubuntu Core Dev.

=== Specific Experiences of working together ===
Out of recent memory squid4 comes to my mind, where he nicely carried Ubuntu Delta through a Debian source rename. Worked on extended tests, did well on submitting plenty of things to Debian so that Delta stays maintainable and so on ...

Also the rather complex ndctl (new packaging) and libzstd (was a mess on backward/forward compatibility) cases further increased my confidence.

I'm also proud how he took active responsibility of the samba/sssd/ldap area in Ubuntu-server. He combined his former experience with his eagerness to learn and made this somewhat orphaned area great again - great for Ubuntu and great for our team.

=== Areas of Improvement ===
He was part of seed changing activities but not yet driving a lot on his own. There more work could be done to get a better grip of these as well. I'm convinced that he'll do great and not start pushing crazy things on day one.

== Robie Basak ==

Andreas is a colleague of mine on the Canonical server team. According to the sponsorship miner, I've sponsored only 11 separate uploads for Andreas. I'm surprised; I thought it'd be a lot more. We operate a peer review policy on our team. This means that I see his work on a daily basis. I suppose much of what I review of his work he can already upload himself, or other colleagues sponsor.

However we keep hitting uploads that he cannot do without being a core dev. samba and bind9 are a couple of examples.

Much of my endorsement for Andreas' previous successful server packageset application still applies: "I am continually impressed by Andreas' attention to detail and the general comprehensiveness and correctness of his work upon first review. He doesn't just throw a patch at a sponsor to see if it sticks; by the time he requests review, he typically has done far more extensive investigation and testing than I would do before uploading. He mostly asks all necessary questions in public on Freenode before preparing an upload for sponsorship. I've seen him find tangential edge cases and fix those up as well while working a particular bug."

Andreas understands well what he doesn't know and is appropriately cautious, asking others before committing to an action to make sure that it is correct. I think his overall knowledge of packaging and Ubuntu processes surpassed the bar for core dev a while ago.


I, Andreas Hasenack, apply for Ubuntu Core Developer


Andreas Hasenack

Launchpad Page

Wiki Page

Who I am

I graduated in Electrical Engineering. Worked for a few years in a company in the aerospace industry, but in the civilian area, in a project about installing "black boxes" in trucks and buses to monitor several driving and engine parameters. I then came in contact with a customer who had a nice "intranet" (that's what it was called back then), with internal web sites and a big database backend (oracle). We had to do some development for them, but didn't have access to Oracle, and someone told me that I should try this thing called "linux", "postgresql" and "apache". I did, then installed it at home, and never looked back.

In 1998 I took a post-grad specialization course in the University (a degree higher than graduation, but below masters) in computer networks and went to work for Conectiva, the Brazilian Linux distribution, later renamed to Mandriva, where I stayed until 2008 doing lots of packaging work (RPM) and consulting for enterprise customers in the server area. My main area of expertise was email, authentication (kerberos, pam) and LDAP, and I also spent about half the time working in Conectiva's security team and doing security updates for the distro.

My Ubuntu story

Tell us how and when you got involved, what you liked working on and what you could probably do better.

My involvement

In 2008 I applied for a job in the Landscape team (, and got hired as a QA engineer. I had never done any Debian packaging before, just had some ideas about how it worked, had grabbed a few packages here and there to inspect them, looked at patches, etc. apt-get wasn't a stranger, since Conectiva developed apt-rpm back in the day, and the concept of dependency resolution is the same everywhere.

Landscape has a client component, and that means a Debian package that gets installed on machines. It obviously needs to be QA'ed. So that's how I got exposed to Debian packaging "for real" that time.

In April 2017 I started working in the Ubuntu Server Team. That got me back in touch with my "Linux roots" (no pun intended) and immediately I started looking into my old friends kerberos, ldap, samba, etc and searching for bugs to fix. It is in the Ubuntu Server Team that I got introduced to the Debian Merge process, and how this team is looking into improving that process via the Git Ubuntu tooling.

Examples of my work / Things I'm proud of

DEP8 tests I added




FTBFS fixes I uploaded

Cooperation with debian and/or upstream





squid4 dep8 fixes pushed to debian. Debian had adopted most of our DEP8 tests previously, but they never passed in their infrastructure (





  jul 31 15:44:10 <ahasenack>     and upgrading just bind, leaving isc-dhcp without a rebuild, also works:
  • The packages would still not migrate. Looking at the update_output.txt, I found out that debian-installer is a reverse dependency as well. Asked for a rebuild/sponsorship:

  ago 01 14:37:54 <ahasenack>     hi, my bind9 upload, which bumped the soname, also needs a debian-installer rebuild (ppa at Would someone sponsor this for me?

Areas of work

Let us know what you worked on, with which development teams / developers with whom you cooperated and how it worked out.

Things I could do better

  • I stopped updating the server guide
  • Create more bug patterns. Experience with triage has showed some patterns in bugs that we can leverage with automation

Plans for the future


  • Keep adding DEP8 tests to the Ubuntu and Debian packages
  • Reduce the delta with Debian by submitting changes upstream
  • Improve the LTS Server Guide in the areas of Authentication, Authorization and Samba

What I like least in Ubuntu

Please describe what you like least in Ubuntu and what thoughts do you have about fixing it.

It feels like someone quickly built a tool to solve an immediate problem, published it under a group account somewhere they had write access to, and that became official because it works and people who need it, know where to find it. I imagine some time ago people thought this would all be part of Launchpad.

  • Lack of ownership of DEP8 failures impeding migration. When a package is uploaded, its DEP8 tests are run (if they exist), and dependent packages also have their tests run. Sometimes, one or more of the latter fails, but since it's a failure in *another* package, it's not always handled by the uploader and it just stays there, or a force-badtest is asked for. There are for sure complex cases, but not always.
  • What's up with packages stuck in proposed migration for dozens of days? Or months? What about a year?


If you'd like to comment, but are not the applicant or a sponsor, do it here. Don't forget to sign with @SIG@.


As a sponsor, just copy the template below, fill it out and add it to this section.

Christian Ehrhardt

General feedback

I have accompanied Andreas from him joining the server Team - with an already great technical background and emphasis on testing things before pushing changes - to the clearly core-dev material engineer that he is today - where I'm close to create aliases to sponsor his work. So far I sponsored 45 uploads of Andreas (see sponsor ship miner). I have seen a great progression of quality over time and it reached a a state where I mostly find style suggestions and similar things, but no actual packaging/Ubuntu issues as part of the upload. I'd judge the quality of his uploads really high and having seen his improvements over the past I'm sure he can adapt to changes as needed. I appreciate that he has grown as much as being a great resource for reviewing my work recently. Due to that he really has my trust and I'm confident he would be a good Ubuntu Core Dev.

Specific Experiences of working together

Out of recent memory squid4 comes to my mind, where he nicely carried Ubuntu Delta through a Debian source rename. Worked on extended tests, did well on submitting plenty of things to Debian so that Delta stays maintainable and so on ...

Also the rather complex ndctl (new packaging) and libzstd (was a mess on backward/forward compatibility) cases further increased my confidence.

I'm also proud how he took active responsibility of the samba/sssd/ldap area in Ubuntu-server. He combined his former experience with his eagerness to learn and made this somewhat orphaned area great again - great for Ubuntu and great for our team.

Areas of Improvement

He was part of seed changing activities but not yet driving a lot on his own. There more work could be done to get a better grip of these as well. I'm convinced that he'll do great and not start pushing crazy things on day one.

Robie Basak

Andreas is a colleague of mine on the Canonical server team. According to the sponsorship miner, I've sponsored only 11 separate uploads for Andreas. I'm surprised; I thought it'd be a lot more. We operate a peer review policy on our team. This means that I see his work on a daily basis. I suppose much of what I review of his work he can already upload himself, or other colleagues sponsor.

However we keep hitting uploads that he cannot do without being a core dev. samba and bind9 are a couple of examples.

Much of my endorsement for Andreas' previous successful server packageset application still applies: "I am continually impressed by Andreas' attention to detail and the general comprehensiveness and correctness of his work upon first review. He doesn't just throw a patch at a sponsor to see if it sticks; by the time he requests review, he typically has done far more extensive investigation and testing than I would do before uploading. He mostly asks all necessary questions in public on Freenode before preparing an upload for sponsorship. I've seen him find tangential edge cases and fix those up as well while working a particular bug."

Andreas understands well what he doesn't know and is appropriately cautious, asking others before committing to an action to make sure that it is correct. I think his overall knowledge of packaging and Ubuntu processes surpassed the bar for core dev a while ago.


=== General feedback ===
## Please fill us in on your shared experience. (How many packages did you sponsor? How would you judge the quality? How would you describe the improvements? Do you trust the applicant?)

=== Specific Experiences of working together ===
''Please add good examples of your work together, but also cases that could have handled better.''
## Full list of sponsored packages can be generated here:
=== Areas of Improvement ===

AndreasHasenack/CoredevApplication (last edited 2018-09-23 10:08:31 by ahasenack)