- I wrote unit tests for every single one of those functions to confirm/validate the behavior.
- Then I deleted all 900 lines of code and committed it.
- Then I wrote code to make the unit tests pass again.
It was painful but that kept it tightly scoped and I could "prove" the behavior hadn't changed AND that I didn't use the original code.
There's an argument that the unit tests could be a "derivative work" but they were not part of the original system, did not change or add functionality to the system, and did not impact its performance so we discounted that concern.
The more pressing was that - as an open source project - and the guy doing the audit, I had reviewed the GPL implementation and had access to it at any time. What helped me there is that I made a point of using more modern language constructs and patterns which improved the performance of those functions by 30-90% and I resolved a number of buggy edge cases and other problems so it was clearly "substantially different" in implementation.
This was never tested in a lawsuit and do NOT take the above as a definitive solution.