org.bouncycastle.openpgp.api.DoubleBufferedInputStream, which no class in the library referenced and whose read() returned the buffered byte unmasked so that every byte from 0x80 upwards came back negative and 0xFF came back as the -1 a caller reads as end of stream, has been removed along with its test rather than repaired, its withholding also being one read of the underlying stream rather than the configured buffer size, and OpenPGPMessageInputStream now documents that what is read from it is not covered by an integrity check until close() has returned, relates to github #2424.
D
David Hook committed
76020c6ba9133a885bb5eecc83faa0eba5359d32
Parent: b2f6375