Preface

AI-maintained codebases face a specific risk: two functions implementing the same capability can silently diverge, because static checkers cannot detect redundancy. This plugin aims to intervene during the code-writing planning stage (before file creation), deterministically identify existing implementations, and force the agent to reuse or extract code instead of creating a direct copy.

Core Features

The plugin provides the following capabilities:

  • Deterministic retrieval (no LLM): query coverage based on function names, docstrings, and string literals, using IDF weighting.
  • Pre-write reuse firewall: runs before the agent writes new code to detect overlap.
  • Code audit capability channel integration: acts as an Auto_code_audit capability channel.
  • Hash-locked candidate detection: detects files locked by SHA256.
  • Top-K candidate retrieval: returns the highest-scoring matches.

Prerequisites and Installation

The plugin depends on an Auto_code_audit checkout and a Python 3.10+ interpreter.

  1. Install the plugin:
dsh plugin add github:keyiadiannao/dsh-code-reuse-firewall#master
  1. Configure the plugin. In the DSH configuration file, set auditRoot to point to the Auto_code_audit checkout:
- id: dsh-code-reuse-firewall
  config:
    auditRoot: 'D:/path/to/Auto_code_audit'
    pythonPath: 'python'
    maxK: 5
    minScore: 0.1
    timeoutMs: 30000

Usage

The agent calls reuse_check before writing new code. The prompt should describe the intent.

Example: request to implement “read from a JSON config and support environment variable overrides”.

Invocation Example:

Invoke reuse_check: I want to implement “read from a JSON config and support environment variable overrides”. The root directory is D:/project/src. Check whether there is an existing implementation that can be reused.

Output Example:
The tool returns the top K candidates, including paths, scores, and evidence grouped by channel:

Existing implementations overlapping "load a JSON config with env overrides":
  [0.72] config.py:load_config  (src/config.py) (name=0.72 doc=0.10 literal=0.00)
  [0.51] util.py:ConfigLoader.load  (src/util.py) (name=0.51 doc=0.00 literal=0.00)

If a candidate is located in a file locked by SHA256, the 🔒 LOCKED marker is shown:

  [0.32] lib/protocol.py:_split_hash_payload  (lib/protocol.py) (name=0.32) 🔒 LOCKED by configs/generation_b_training_compatibility.json

⚠ 1 candidate(s) are in hash-locked files: REUSE by import, do not copy-and-modify their implementation (editing invalidates frozen results).

Notes

  • Nature of Evidence: Retrieval results are suggestive evidence, not a defect verdict. The agent must decide whether to reuse, extract, or write new code, and must not delete or rewrite existing code based solely on retrieval results.
  • Signal Strength: Because reuse_check runs before the code exists, structural matching signals are unavailable. It relies on names, docstrings, and string literals. Natural-language queries work best with English keywords; pure Chinese descriptions match English code poorly.
  • Hash Locking: Locked files (defined by SHA256 in frozen_results or configs) are marked with 🔒 LOCKED. Editing these files invalidates the frozen results they reference. The correct approach is to import the code, rather than copy and modify the implementation.
  • Current Limitations: Detection of structurally similar code (the strongest signal) requires the code to actually exist; the plugin currently does not support --file/--base modes for checking specific files or diffs (this is a roadmap item for the future).
  • Dependencies: The plugin requires an Auto_code_audit checkout that includes capability_retrieval.py and a Python 3.10+ interpreter.

Conclusion

This plugin acts as a pre-write gatekeeper to prevent code duplication. By providing a list of candidates based on deterministic algorithms, it enables the agent to make reuse decisions before divergence occurs. For plugin details, see GitHub: https://github.com/keyiadiannao/dsh-code-reuse-firewall.