Commit Graph
100 Commits
Author SHA1 Message Date
Dominik Jain 6707cd9b7e Introduce component-based licensing: Serena GPL-3.0-or-later, SolidLSP MIT
The repository is licensed per component. SolidLSP (src/solidlsp,
test/solidlsp, test/resources) remains MIT-licensed and independently
reusable; the Serena application (src/serena, src/interprompt, scripts,
test/serena, docs) is licensed under GPL-3.0-or-later starting with the v2
licensing transition. The change is not retroactive: all releases and
commits up to v1.7.0 / 74c38a65 (tag mit-final) remain available under MIT.

Since MIT is GPL-compatible, a distribution combining both (such as the
serena-agent package) is as a whole subject to GPL-3.0-or-later, while the
SolidLSP files themselves stay MIT and can be extracted and used separately
under MIT terms. The distribution metadata therefore declares
GPL-3.0-or-later, with both license texts shipped alongside it.

Serena originally began under the GPL (v2) and was switched to MIT in
May 2025 following community requests. We consider that change a mistake;
the substantial changes in v2 make this the appropriate time to revert it.
We want the best version of Serena to remain free.

Changes:
* LICENSE is now the licensing overview; canonical license texts live in
  LICENSES/ (MIT.txt is the previous LICENSE verbatim, GPL-3.0-or-later.txt
  is the unmodified FSF text)
* pyproject.toml declares the PEP 639 license expression
  "GPL-3.0-or-later" and bundles LICENSE and LICENSES/* as license files;
  the deprecated MIT classifier is dropped and flake.nix declares gpl3Plus;
  README has per-component license badges and a License section
* SPDX-License-Identifier headers in all Python sources under src/ and
  scripts/, added by the new idempotent scripts/add_spdx_headers.py, which
  gen_prompt_factory.py also uses to keep the header on the generated
  module; existing third-party notices are preserved
* CLA.md: Contributor License Agreement (contributor retains copyright;
  grants a perpetual, irrevocable license including relicensing under any
  terms, incl. proprietary/commercial; patent grant; authority
  representations), to be enforced repository-wide via cla-assistant.io
* CONTRIBUTING.md, PR template and a new docs page explain the licensing
  boundary and the CLA workflow
2026-09-14 21:33:18 +02:00
Dominik Jain 9f9db76622 Fix document symbol caching for language servers that post-process symbols
Caching happened in the base implementation before subclass overrides could
post-process the result, so an override's work was either never cached or,
if it mutated in place, re-applied to cached output on every hit.

Restructure both symbol caches so that they wrap the subclass logic:
subclasses now post-process via dedicated hooks (`_request_raw_document_symbols`
and `_build_document_symbols_from_raw_symbols`), and the cached value is
the fully processed result. Cache versions are bumped where the cached
content changes as a consequence.
2026-09-06 13:51:53 +02:00
Dominik Jain 7cde558158 Remove test_jetbrains_launch_coordinator 2026-09-06 11:24:20 +02:00
Dominik Jain 801a388c2b Remove unnecessary platform restrictions in language servers
Platform checks in the following language servers are affected:
* Elixir Tools
* Intelephense
* Perl
* TypeScript
* VTS
2026-09-03 18:35:07 +02:00
Dominik Jain 813fd98f4f CLI: Fix project index-file command not using only the relevant language server to index the given file
Resolves #1965
2026-09-02 15:12:16 +02:00
Dr. Dominik Jain c8ef9d358e Merge pull request #1872 from AmirF194/fix/1871-nextflow-scan-flush-flag
fix(nextflow): don't mark workspace scan flushed when both probes fail
2026-09-02 13:46:24 +02:00
Dr. Dominik Jain f41f33c904 Merge branch 'main' into fix/1871-nextflow-scan-flush-flag 2026-09-02 13:06:49 +02:00
Dominik Jain 43ae0211d7 Fix: read_only restriction in project definition was not applied to base tool set when in single-project context
Fixes #1938
2026-08-30 17:37:14 +02:00
Dominik Jain 93ec043105 Updated interprompt sync commit identifiers (push) 2026-08-14 20:50:47 +02:00
Dominik Jain 1814fc9a0f interprompt edbee70392dca692d36d136c47a61513f4a2b222
commit edbee70392dca692d36d136c47a61513f4a2b222
  Author: Dominik Jain <dominik.jain@outlook.com>
  Date:   Fri Aug 14 20:49:45 2026 +0200

      Sync reframer

        commit 8f0e933cca9481a57ccabf1ef9419815274cdfa1
        Author: Dominik Jain <dominik.jain@outlook.com>
        Date:   Fri Aug 14 19:56:51 2026 +0200

            Allow to configure name of generated class

        reframer/interprompt/prompt_factory.py

        commit 7eb3472cec8179a19e1f127ecbdeadf50becab01
        Author: Dominik Jain <dominik.jain@outlook.com>
        Date:   Fri Aug 14 19:48:49 2026 +0200

            Allow to configure interprompt package name and fix imports in generated code (must include PromptList)

        reframer/interprompt/prompt_factory.py

        commit 015781ed2b6b0e2311d9938788403e0b33b19e17
        Author: Dominik Jain <dominik.jain@outlook.com>
        Date:   Fri Aug 14 19:36:07 2026 +0200

            Fix: Language code was read at the wrong level

        reframer/interprompt/multilang_prompt.py

        commit 487e9eed63d435257ee03eda03e668b4e7a73019
        Author: Dominik Jain <dominik.jain@outlook.com>
        Date:   Fri Aug 14 19:08:18 2026 +0200

            Use relative imports

        reframer/interprompt/jinja_template.py

  src/interprompt/jinja_template.py
  src/interprompt/multilang_prompt.py
  src/interprompt/prompt_factory.py
2026-08-14 20:50:47 +02:00
Dominik Jain 3ad624f511 Merge branch 'main' of github.com:oraios/serena 2026-08-14 15:57:04 +02:00
Dominik Jain 36e5e981e7 Updated interprompt sync commit identifiers (pull) 2026-08-14 15:56:20 +02:00
Dominik Jain 17e39c9655 Fix duplicate section 2026-08-14 15:46:51 +02:00
Dominik Jain 25610cb280 Improve docstrings 2026-08-13 13:10:37 +02:00
Dominik Jain 8a4d116c13 Fix: Parallel agents auto-registering projects could overwrite each other's changes
to the global project list in `serena_config.yml`

Fixes #1850
2026-08-13 12:21:45 +02:00
Dominik Jain f1d78a88ce Update docstring of web_dashboard_interface 2026-08-10 19:02:05 +02:00
Dr. Dominik Jain 946ad98178 Merge pull request #1836 from oraios/release-1.7
Release v1.7.0
2026-08-09 20:37:45 +02:00
Dominik Jain 2cb9d87227 Set version to v1.7.1.dev0 2026-08-09 20:14:38 +02:00
Dominik Jain 949a27ef1e Release v1.7.0 2026-08-09 20:14:37 +02:00
Dominik Jain be5cf4e41e Merge remote-tracking branch 'origin/main' into release-1.7 2026-08-09 20:13:17 +02:00
Dr. Dominik Jain 3c8e9854f6 Improve identification of container/low-level symbols (#1834)
This affects results returned for request_containing_symbol,
some tests were adjusted accordingly.
2026-08-09 20:12:51 +02:00
Dominik Jain bad11d825c Update news item 2026-08-09 17:51:16 +02:00
Dominik Jain 140d0b03ee Merge branch 'main' into release-1.7 2026-08-09 17:42:14 +02:00
Dr. Dominik Jain 281e9db2eb Merge pull request #1823 from AmirF194/fix/1818-process-group-cleanup-without-enumeration 2026-08-09 17:37:16 +02:00
Dominik Jain bd86cf840a Introduce ManagedSubprocess to encapsulate subprocess lifecycle management
The knowledge that a process launched with start_new_session=True is its own
group leader (and thus that its PGID equals its PID) was previously held by
StdioLanguageServer, i.e. the consumer had to know how the launcher works in
order to terminate the process correctly.

ManagedSubprocess now owns the process group ID alongside the Popen instance,
deriving it at construction time, and provides the termination logic; the
launcher returns instances of it. StdioLanguageServer merely holds one and
accesses the process through its interface.

LanguageServerSubprocessLauncher now returns ManagedSubprocess instances and
is renamed to ManagedSubprocessLauncher accordingly.
2026-08-09 17:09:57 +02:00
Dominik Jain e663ccb584 Add news item for v1.7.0 release 2026-08-09 13:54:14 +02:00
Dominik Jain b030baf544 Add 'Security' section to changelog 2026-08-09 13:54:03 +02:00
Dominik Jain 600dda1fdf Use <code> tag for commands in news 2026-08-09 13:53:54 +02:00
Dominik Jain d3441d3e23 Merge remote-tracking branch 'origin/main' into release-1.7
Conflicts:
  CHANGELOG.md
2026-08-09 13:53:19 +02:00
Dominik Jain c3f5aab59e Improve project health-check : Disable symbol groupers, remove flawed pattern search test
Resolves #1826
2026-08-09 13:48:41 +02:00
Dominik Jain 430fc62e72 Improve tray manager handling, particularly on macOS #1825
* On shutdown, message tray manager before lengthy project shutdown
* When dead ports are found, explicitly update the menu
2026-08-08 22:17:29 +02:00
Dr. Dominik Jain 9f9700a503 Merge pull request #1827 from oraios/memory-cleanup 2026-08-08 21:51:41 +02:00
Dominik Jain b2de2c8f97 Improve instructions on prompt templates, adding link to new docs section
Improve other docstrings in templates and add missing key `fixed_tools`
2026-08-08 21:50:13 +02:00
Dominik Jain c9fa15741e Add documentation on prompt templating in Serena 2026-08-08 17:57:21 +02:00
Dominik Jain 69d14891ca Minor refactoring: Rename _format_prompt to _render_prompt, adding docstring 2026-08-08 17:48:37 +02:00
Dominik Jain bb06ed05dd Support embed_memory function in prompt templates
Apply it in Serena's own project prompt
2026-08-08 17:43:13 +02:00
Dominik Jain 91ebba1c8c Merge remote-tracking branch 'origin/Main' into memory-cleanup 2026-08-08 17:18:05 +02:00
Dominik Jain ed401769b5 ProjectServer: Use general headless mode config overrides 2026-08-08 16:57:40 +02:00
Dr. Dominik Jain f90d488309 Merge pull request #1828 from oraios/prompt-tags 2026-08-08 16:53:39 +02:00
Dominik Jain d3a8e9b565 Improve project activation message 2026-08-08 16:49:42 +02:00
Dominik Jain 548aea28a6 Allow project initial prompt & newly activated dynamic mode prompts to use templating/variables
Add helper method _format_prompt_tag
2026-08-08 16:47:03 +02:00
Dominik Jain 0968bae6eb Enclose sub-prompts in tags 2026-08-08 16:43:46 +02:00
Dominik Jain 07d49be110 Clean up memories and move system prompt info to critical_info memory 2026-08-08 13:35:19 +02:00
Dominik Jain 52c3165d1d Add more concrete instructions on test strategy in system prompt 2026-08-08 13:05:09 +02:00
Dominik Jain c7af2c09ef SerenaDashboardTrayManager: Configure trusted hosts (local hosts only) 2026-08-05 21:36:03 +02:00
Dominik Jain df24c3151f Clarify responsibilities when exposing network services 2026-08-05 21:31:59 +02:00
Dominik Jain 7aa24b8dad ProjectServer: Configure trusted hosts for localhost case 2026-08-05 21:28:17 +02:00
Dominik Jain de8eaac089 Merge branch 'jinja' into release-1.7 2026-08-05 14:15:05 +02:00
Dominik Jain 81fb5203f9 Use sandboxed environment for jinja2 template rendering
This prevents attackers from exploiting jinja's code execution mechanisms
via custom prompts (e.g. mode inclusion from local file)
2026-08-05 14:14:56 +02:00
Dominik Jain b8fd8a936a Allow project prompt to use templating 2026-08-05 14:12:10 +02:00
Dr. Dominik Jain 9558366327 Merge pull request #1808 from rr-develop/fix/kotlin-ls-refresh-request-handlers 2026-08-05 13:50:53 +02:00
Dr. Dominik Jain df5ab4f607 Merge pull request #1781 from oraios/test-uv-python-compat
Test Python version compatibility in CI
2026-08-05 12:00:32 +02:00
Dr. Dominik Jain e2a344a8da Merge pull request #1791 from caost/fix/macos-tray-dock-icon 2026-08-05 11:51:48 +02:00
Dominik Jain 16692df979 Use TRAY_MANAGER as new default dashboard interface on macOS 2026-08-05 11:51:13 +02:00
Dominik Jain e6b3852117 More liberal handling of ignored paths in file access tools
- Tools that explicitly target a single file (`create_text_file`, `read_file`, `replace_content`) no longer
   consider ignored paths in general, i.e. all files can be accessed.
   When a path is explicitly accessed, we should not try to prevent it; the agent is assumed to have a good reason
    for doing so.
 - Tools that traverse a subtree of the project (`list_dir`, `find_file`, `search_for_pattern`) now all have an
   option `skip_ignored_files` (whether to skip ignored sub-paths).
   Note that if the base path is itself ignored, ignored paths cannot be considered.

Resolves #1805
2026-08-04 10:33:34 +02:00
Dr. Dominik Jain cd04838be9 Merge pull request #1804 from oraios/ls-notify-on-reopen-changed
Fix stale file state in language servers (with files kept open)
2026-08-03 22:22:23 +02:00
Dominik Jain 0720dd92e0 Merge remote-tracking branch 'origin/main' into ls-notify-on-reopen-changed
Conflicts:
	CHANGELOG.md
2026-08-03 22:21:48 +02:00
Dominik Jain 9fc8033ece Introduce DownloadedDependency abstraction with URL-keyed hash database
* Add DownloadedDependency abstraction to facilitate handling of downloaded
  and hash-verified dependencies.
  In CI, missing hashes raise an exception.
  For users, unverified downloads log a warning.
* Add DownloadedDependencyHashDatabase which manages a URL-keyed database
  of sha256 hashes. It can be conveniently updated incrementally through a
  script (src/solidlsp/resources/downloaded_dependency_hashes.json),
  provided that language server implementations provide DownloadedDependency
  instances statically

Applied in EclipseJDTLS:
* Replace the untyped nested-dict runtime dependency descriptors with DownloadedDependency instances
* Move the JDTLS version-pinning constants into DependencyProvider
* Replace the platform dependency dicts with the VSCodeJavaConfig dataclass

Utils:
 * Add FileUtils.ArchiveType to type archive types that were previously plain str
 * Add is_running_in_ci() to ls_utils

Updated memory on adding a language server accordingly.
2026-08-03 01:34:24 +02:00
Dominik Jain 9eb4df2e7b Fix: Change the semantics of file opening (open_file) in the language server
Instead of sending only the didOpen notification if the file is not already open,
the method now ensures that the language server has the (current) contents of the file,
sending the didChange notification in cases where the file is already open but has changed
on disk. This better reflects the actual intention of calling the method.

This affects the Vue and Svelte language servers, which unlike all other server implementations,
kept files open, which could result in the servers reporting stale information in the
absence of update notifications (external file changes).
2026-08-02 13:11:04 +02:00
Dominik Jain e5c86a3422 request_document_symbols: Improve logging 2026-08-02 13:11:04 +02:00
Dominik Jain fc7a8ec732 Fix: LSPFileBuffer: a stale content hash could be returned if files are kept open
and file contents were not read before trying to retrieve the hash value
2026-08-02 13:11:03 +02:00
Dominik Jain d179e2ba59 Consistently configure the log level in tests 2026-08-02 13:11:03 +02:00
Dominik Jain c958aa0235 Guard actions in __del__ (obj must be initialised) 2026-08-01 15:57:03 +02:00
Dominik Jain 97bc0980a2 Further improve docstring of find symbol tools 2026-07-31 16:06:02 +02:00
Dominik Jain a47df023f5 Report language server status in GetCurrentConfigTool result
Resolves #1782
2026-07-31 16:06:02 +02:00
Dr. Dominik Jain dd12fa032f Merge pull request #1779 from TyceHerrman/agent/rust-analyzer-lightweight
Rust: reduce rust-analyzer memory churn
2026-07-30 10:43:59 +02:00
Dominik Jain 7155dc596b Remove debug code
Fixes #1783
2026-07-30 10:15:31 +02:00
Dominik Jain 1f133f62cf Re-enable cargo.autoreload
autoreload=false was likely to leave project metadata stale after manifest or workspace changes #1779
2026-07-30 00:27:09 +02:00
Dominik Jain 3bd98c746c Use a file with at least 1k characters for health-check 2026-07-29 18:41:26 +02:00
Dominik JainandClaude Opus 5 9237671ed0 CI: check uv sync and the health check on all supported Python versions
The test suite runs on a single interpreter, so nothing covered the rest of the range declared by
`requires-python` (>=3.11, <3.15). The new workflow installs the locked dependency set on each of 3.11-3.14
and then runs `project health-check` against the Python test repo, which catches both a dependency without a
wheel for a given version and any import or startup breakage. It is deliberately Linux-only, to stay within
the cap of 20 concurrent jobs, and deliberately does not cache the venv, since a restored venv would make the
`uv sync` under test a no-op.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 18:36:13 +02:00
Dominik JainandClaude Opus 5 d9efb5ade8 Fix: project health-check always exited with code 0, even when the check failed
The failure paths either returned normally or were swallowed by the catch-all exception handler, so callers
(CI, scripts) could not act on the command's verdict. Failures now raise, and the verdict is reported outside
the checked region -- where a failure to write the report can no longer be mistaken for a failure of the check
itself -- and signalled through the exit code. A FindSymbolTool result without any matches is treated as a
failure rather than a warning.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 18:34:39 +02:00
Dominik Jain e6e25d3f86 Report project activation errors to the client in the system prompt
SerenaAgent now tracks an initial/startup project activation error and appends it
to the system prompt, instead of the failure being visible only in the log.
This applies both to a failed activation of an explicitly given project and to a
failed --project-from-cwd auto-detection.

Also fix the --project-from-cwd help text, which falsely promised a fallback to the CWD
Resolves #1773
2026-07-29 17:39:06 +02:00
Dominik Jain a61765ecc8 Fix: Serena PyPI version check triggered by callback on main thread could delay agent startup
Closes #1774
2026-07-29 15:24:22 +02:00
Dominik Jain 21f4b3fe58 Add section on trusted projects 2026-07-29 13:53:03 +02:00
Dominik Jain 466960b12f Remove unmaintainable parts of security documentation 2026-07-29 13:13:06 +02:00
Dominik Jain 6c1c965370 find_symbol: Change tool description to improve tool search results
in clients that load tools dynamically
2026-07-28 17:50:22 +02:00
Dominik Jain 9a9d07e83d Improve system prompt (OOP principles, etc.) 2026-07-27 13:41:00 +02:00
Dr. Dominik Jain 66b34dc8eb Merge pull request #1750 from AmirF194/fix/1490-kls-pdeathsig
fix(ls): don't orphan the language server process when Serena is killed
2026-07-26 11:38:33 +02:00
Dominik Jain aeb73c789d Move changelog entries to their proper place, rewording 2026-07-26 11:34:42 +02:00
Dominik Jain 33b042ad06 Add script for visualising the memory graph of a project 2026-07-24 22:30:05 +02:00
Dominik Jain 68884f1190 Add callout on security advisories 2026-07-24 19:07:43 +02:00
Dominik Jain cbc7f286b3 Refactoring: Fully internalise the pdeathsig machinery into LanguageServerSubprocessLauncher 2026-07-24 18:19:03 +02:00
Dominik Jain 140ffaf3ff Fix: Tool calls exceeding the timeout blocked the task executor indefinitely;
tasks are now cancelled on timeout and the executor recovers

Previously, Tool.apply_ex issued its task without a timeout, so a hung tool
would block the TaskExecutor's dispatcher thread forever: the caller received
a TimeoutError after tool_timeout, but no further tasks were ever processed.

Changes:
- Tool.apply_ex now passes the configured tool timeout to issue_task, bounding
  the dispatcher's wait as well as the caller's.
- TaskExecutor.Task.result gained cancel_on_timeout (default True): on timeout,
  the task is cancelled, preventing execution of tasks still waiting in the
  queue and discarding the result of tasks already running.
- Task.wait_until_done no longer takes a timeout parameter; it uses the task's
  own timeout and returns whether the task completed. The dispatcher logs a
  warning and continues with the next task if the timeout was reached.
- TaskExecutor.execute_task now propagates its timeout to result() instead of
  waiting indefinitely, thus also benefiting from cancel-on-timeout.
- Corrected the docstring of Task.result to match the actual semantics.
2026-07-24 13:23:06 +02:00
Dr. Dominik Jain 05468d9685 Merge pull request #1734 from arimu1/fix/1732-glob-match-single-asterisk
fix(util): ensure bare * and ? in non-** glob patterns do not match /
2026-07-23 23:32:54 +02:00
Dominik Jain 5b5f8332ce Add subprocess_run util function (to replace direct calls of subprocess.run) 2026-07-23 23:13:09 +02:00
Dominik Jain ad2598e9f3 Move helper functions into GlobMatcher 2026-07-23 22:48:27 +02:00
Dominik Jain 954d8554fd Make GlobMatcher with cached regex patterns the only glob matching mechanism 2026-07-23 22:48:27 +02:00
Dominik Jain 7033e90306 Unify glob matching to always use regex translation 2026-07-23 15:28:48 +02:00
Dominik Jain 33125287dc Remove obsolete glob pattern support in search_text, removing duplicate glob translation 2026-07-23 14:33:06 +02:00
Dominik Jain 5e8662b283 JetBrainsFindSymbolTool: Disallow wildcard-only search, delegating to overview tool if file
Resolves oraios/serena-jetbrains-plugin-public#8
2026-07-23 13:50:38 +02:00
Dr. Dominik Jain 5e745aabf5 Merge pull request #1739 from oraios/refactor-language-enum
Refactoring: Language vs language server semantics
2026-07-22 21:44:27 +02:00
Dominik Jain 4f8f9b3fc8 Refactoring: Rename ProjectConfig.languages to language_servers 2026-07-22 21:41:00 +02:00
Dominik Jain d2cf18ddcb Refactoring: Rename Language to LanguageServerId
This resolves a long-standing naming issue in Serena & SolidLSP.
2026-07-22 20:55:36 +02:00
Dr. Dominik Jain ef0e218fb1 Allow language server priorities to be configured in serena_config.yml (#1736) 2026-07-22 17:26:56 +02:00
Dominik Jain 2c10e25c97 Set version to v1.6.2.dev0 2026-07-21 17:34:25 +02:00
Dominik Jain bcac0969fb Release v1.6.1 2026-07-21 17:34:25 +02:00
Dominik Jain 4c82b2bf19 Dashboard: indicate when a newer Serena version is available 2026-07-21 14:51:32 +02:00
Dr. Dominik Jain 4903da5ac0 Merge pull request #1524 from BinarySo1o/fix/ts-coverage-dirname-ignore
TypeScript: stop hard-ignoring source directories named `coverage`
2026-07-21 13:30:50 +02:00
Dr. Dominik Jain 0c96c39a90 Merge branch 'main' into fix/ts-coverage-dirname-ignore 2026-07-21 13:29:54 +02:00
Dr. Dominik Jain 9b710a7193 Merge pull request #1731 from oraios/fup-ls-file-system-sync
F'up: LS file system sync
2026-07-21 13:27:42 +02:00