core:encoding/base64 currently decodes leniently: it infers padding from the
last one or two bytes, accepts missing/extra/interior padding, and does not
check the trailing padding bits required by RFC 4648 Section 3.5.
Go exposes canonical decoding as `Encoding.Strict()`; Odin has no equivalent,
so downstream ports (e.g. age) have to reimplement base64 from scratch.
This adds opt-in strict decoding through a `Decode_Options` bit set.
Existing calls and behavior are unchanged.
It was leaky and required a substantial number of `loc := #caller_location` additions to parts of the core library to make it easier to track down how and where it leaked.
The tests now run fine multi-threaded.