You can still verify the contents - the content blobs don’t change after the migration. Not sure if there’s a practical attack one could do but maybe
Um. how do you verify the contents? The history is for the contents you now have, not what might have been
Shallow clones and such would break but you could rehash the local history manually and compare the SHA256 hashes commit by commit, no?
Issue is it would be pretty slow so you'd want it to be a one time thing.
The contents of the files don’t change, only the Merkle tree. You can verify that the content blobs all have the same sha1 by literally rehashing. Then you can verify that the contents of the clone are the same. That doesn’t stop history corruption, but it does prevent malicious injection into the current state of the tree before the migration.