The repository is licensed per component. SolidLSP (src/solidlsp,
test/solidlsp, test/resources) remains MIT-licensed and independently
reusable; the Serena application (src/serena, src/interprompt, scripts,
test/serena, docs) is licensed under GPL-3.0-or-later starting with the v2
licensing transition. The change is not retroactive: all releases and
commits up to v1.7.0 / 74c38a65 (tag mit-final) remain available under MIT.
Since MIT is GPL-compatible, a distribution combining both (such as the
serena-agent package) is as a whole subject to GPL-3.0-or-later, while the
SolidLSP files themselves stay MIT and can be extracted and used separately
under MIT terms. The distribution metadata therefore declares
GPL-3.0-or-later, with both license texts shipped alongside it.
Serena originally began under the GPL (v2) and was switched to MIT in
May 2025 following community requests. We consider that change a mistake;
the substantial changes in v2 make this the appropriate time to revert it.
We want the best version of Serena to remain free.
Changes:
* LICENSE is now the licensing overview; canonical license texts live in
LICENSES/ (MIT.txt is the previous LICENSE verbatim, GPL-3.0-or-later.txt
is the unmodified FSF text)
* pyproject.toml declares the PEP 639 license expression
"GPL-3.0-or-later" and bundles LICENSE and LICENSES/* as license files;
the deprecated MIT classifier is dropped and flake.nix declares gpl3Plus;
README has per-component license badges and a License section
* SPDX-License-Identifier headers in all Python sources under src/ and
scripts/, added by the new idempotent scripts/add_spdx_headers.py, which
gen_prompt_factory.py also uses to keep the header on the generated
module; existing third-party notices are preserved
* CLA.md: Contributor License Agreement (contributor retains copyright;
grants a perpetual, irrevocable license including relicensing under any
terms, incl. proprietary/commercial; patent grant; authority
representations), to be enforced repository-wide via cla-assistant.io
* CONTRIBUTING.md, PR template and a new docs page explain the licensing
boundary and the CLA workflow
Caching happened in the base implementation before subclass overrides could
post-process the result, so an override's work was either never cached or,
if it mutated in place, re-applied to cached output on every hit.
Restructure both symbol caches so that they wrap the subclass logic:
subclasses now post-process via dedicated hooks (`_request_raw_document_symbols`
and `_build_document_symbols_from_raw_symbols`), and the cached value is
the fully processed result. Cache versions are bumped where the cached
content changes as a consequence.
The knowledge that a process launched with start_new_session=True is its own
group leader (and thus that its PGID equals its PID) was previously held by
StdioLanguageServer, i.e. the consumer had to know how the launcher works in
order to terminate the process correctly.
ManagedSubprocess now owns the process group ID alongside the Popen instance,
deriving it at construction time, and provides the termination logic; the
launcher returns instances of it. StdioLanguageServer merely holds one and
accesses the process through its interface.
LanguageServerSubprocessLauncher now returns ManagedSubprocess instances and
is renamed to ManagedSubprocessLauncher accordingly.
- Tools that explicitly target a single file (`create_text_file`, `read_file`, `replace_content`) no longer
consider ignored paths in general, i.e. all files can be accessed.
When a path is explicitly accessed, we should not try to prevent it; the agent is assumed to have a good reason
for doing so.
- Tools that traverse a subtree of the project (`list_dir`, `find_file`, `search_for_pattern`) now all have an
option `skip_ignored_files` (whether to skip ignored sub-paths).
Note that if the base path is itself ignored, ignored paths cannot be considered.
Resolves#1805
* Add DownloadedDependency abstraction to facilitate handling of downloaded
and hash-verified dependencies.
In CI, missing hashes raise an exception.
For users, unverified downloads log a warning.
* Add DownloadedDependencyHashDatabase which manages a URL-keyed database
of sha256 hashes. It can be conveniently updated incrementally through a
script (src/solidlsp/resources/downloaded_dependency_hashes.json),
provided that language server implementations provide DownloadedDependency
instances statically
Applied in EclipseJDTLS:
* Replace the untyped nested-dict runtime dependency descriptors with DownloadedDependency instances
* Move the JDTLS version-pinning constants into DependencyProvider
* Replace the platform dependency dicts with the VSCodeJavaConfig dataclass
Utils:
* Add FileUtils.ArchiveType to type archive types that were previously plain str
* Add is_running_in_ci() to ls_utils
Updated memory on adding a language server accordingly.
Instead of sending only the didOpen notification if the file is not already open,
the method now ensures that the language server has the (current) contents of the file,
sending the didChange notification in cases where the file is already open but has changed
on disk. This better reflects the actual intention of calling the method.
This affects the Vue and Svelte language servers, which unlike all other server implementations,
kept files open, which could result in the servers reporting stale information in the
absence of update notifications (external file changes).
The test suite runs on a single interpreter, so nothing covered the rest of the range declared by
`requires-python` (>=3.11, <3.15). The new workflow installs the locked dependency set on each of 3.11-3.14
and then runs `project health-check` against the Python test repo, which catches both a dependency without a
wheel for a given version and any import or startup breakage. It is deliberately Linux-only, to stay within
the cap of 20 concurrent jobs, and deliberately does not cache the venv, since a restored venv would make the
`uv sync` under test a no-op.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The failure paths either returned normally or were swallowed by the catch-all exception handler, so callers
(CI, scripts) could not act on the command's verdict. Failures now raise, and the verdict is reported outside
the checked region -- where a failure to write the report can no longer be mistaken for a failure of the check
itself -- and signalled through the exit code. A FindSymbolTool result without any matches is treated as a
failure rather than a warning.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
SerenaAgent now tracks an initial/startup project activation error and appends it
to the system prompt, instead of the failure being visible only in the log.
This applies both to a failed activation of an explicitly given project and to a
failed --project-from-cwd auto-detection.
Also fix the --project-from-cwd help text, which falsely promised a fallback to the CWD
Resolves#1773
tasks are now cancelled on timeout and the executor recovers
Previously, Tool.apply_ex issued its task without a timeout, so a hung tool
would block the TaskExecutor's dispatcher thread forever: the caller received
a TimeoutError after tool_timeout, but no further tasks were ever processed.
Changes:
- Tool.apply_ex now passes the configured tool timeout to issue_task, bounding
the dispatcher's wait as well as the caller's.
- TaskExecutor.Task.result gained cancel_on_timeout (default True): on timeout,
the task is cancelled, preventing execution of tasks still waiting in the
queue and discarding the result of tasks already running.
- Task.wait_until_done no longer takes a timeout parameter; it uses the task's
own timeout and returns whether the task completed. The dispatcher logs a
warning and continues with the next task if the timeout was reached.
- TaskExecutor.execute_task now propagates its timeout to result() instead of
waiting indefinitely, thus also benefiting from cancel-on-timeout.
- Corrected the docstring of Task.result to match the actual semantics.