core/utils/trusted_clock library

Classes

ClockSample
A wall-clock reading paired with a monotonic, boot/process-relative reading taken at the same instant — see TrustedClockService for why TrustedClockService.nowMsTrusted needs both together, not just one.
TrustedClockService
A rewind-proof clock that RECOVERS from a suspicious forward jump instead of permanently locking onto it (IDEA-40) — the failure mode utils/clamped_clock.dart's plain watermark clamp has: once a forward jump (deliberate or an honest clock misconfiguration) bumps the watermark to some far-future instant, every time-gated system it backs stays locked until the REAL wall clock naturally catches up to that instant — which, for a big jump, can be months or years.
TrustedTimeSource
Optional seam for a caller-supplied trusted time source (e.g. an NTP round-trip, or a server timestamp from any authenticated request the app already makes) — deliberately not implemented by this package (no network dependency baked in, same reasoning as every other seam here: AnalyticsProvider/CrashReporter/PurchaseSeam).

Enums

ClockJudgement
How a new ClockSample compares to the previously recorded one.

Functions

classifyClockSample({required ClockSample previous, required ClockSample current, Duration normalTolerance = const Duration(seconds: 5), Duration suspiciousJumpThreshold = const Duration(hours: 1)}) → ClockJudgement
Pure classifier — no storage, no singletons — comparing current against the previous recorded sample. Exposed directly (not just through TrustedClockService) so a test can drive the full normal/rewind/jump/reboot matrix without touching StorageService.