reconcileWithTrustedSource method
Lets a caller-supplied TrustedTimeSource confirm the CURRENT wall
clock reading is legitimate, immediately re-anchoring the baseline
to it even if the most recent nowMsTrusted call quarantined it as
a ClockJudgement.suspiciousForwardJump. A no-op (never regresses
the baseline) if the confirmed time is behind it, or if
trustedTimeSource is unset or returns null.
Implementation
Future<void> reconcileWithTrustedSource() async {
final source = trustedTimeSource;
if (source == null) return;
final confirmedMs = await source.fetchTrustedNowMs();
if (confirmedMs == null) return;
final storage = StorageService.to;
final storedBaseline = storage.getInt(
StorageKeys.trustedClockBaselineMs,
def: 0,
);
if (confirmedMs <= storedBaseline) return;
// Also re-anchors the "previous sample" reference (not just the
// baseline) to this confirmed point — otherwise the NEXT call would
// still classify against the stale pre-quarantine reference (frozen
// by design, see `nowMsTrusted`'s doc) and could re-quarantine a
// perfectly normal follow-up sample.
final monotonicNow = _sampleNow().monotonicMs;
_persist(
ClockSample(wallMs: confirmedMs, monotonicMs: monotonicNow),
confirmedMs,
);
}