> Even though freestart collisions do not directly lead to actual collisions for SHA-1, in our case, the experimental data we obtained in the process enable significantly more accurate projections on the real-world cost of actual collisions for SHA-1, compared to previous projections. Concretely, we estimate the SHA-1 collision cost today (i.e., Fall 2015) between 75K$ and 120K$ renting Amazon EC2 cloud computing over a few months.
So if I understand their estimates correctly, it would cost around $100,000 and several months to create your circular data structure. (Or, somewhat less trivially, compromise Git's SHA1 integrity promise in a still-probably-useless way.)
Exploiting the result will involve some social engineering. Starting with getting one of the colliding objects accepted into the repo you want to attack.
At this point, it's cheaper to generate a SHA1 collision than it will be to fix git not to use SHA1. Which is deeply worrying.
Basic hygiene at this point probably includes only merging git commits from others that are gpg signed (as well as gpg signing as many commits yourself as you can without going mad at the password prompts). Unfortunately, tooling doesn't make this easy, and some things like git format-patch are actively unhelpful by not preserving gpg signatures.
Edit: this is only true of tag signing - with commit signing you GPG-sign the whole commit object.
Edit: Actually, looking at the code (do_sign_commit), git appears to gpg sign the whole commit object.
I think it's in signed tags where git only signs the sha1 being tagged.
So you're correct that GPG-signing commits (but not tags) prevents collisions in commit objects. The problem though is that a commit ultimately contains a SHA-1 hash of a tree object, so now the concern is someone generating colliding tree objects.
Edit: fortunately, the format of tree objects looks pretty rigid. I feel somewhat reassured, but only somewhat.
It doesn't seem so. They still require that the SHA-1 is given different initialization vectors (if you look closely you'll notice IV1 and IV2 are different) so I'm thinking this is what freestart means. Git objects tend to have a stricter format so injecting an initial state may be a bit further out of reach.
What it does mean is that the triviality of a full collision is greatly increased. I'd not trust arbitrary git DAGs anyway... I'd double check but I bet you could forge a pack with some objects that are given invalid content addresses. An integrity check would pick it up but I would also expect most git code to not check that on every operation.