build(cargo): ship an allowlist rather than the whole repository master
There was no `exclude` before, so this is the first statement of what a tarball should carry: `cargo package --list` drops from 249 entries to 136, and 3.9 MB to 2.7 MB. An allowlist rather than a denylist because the two differ only in how they fail — a denylist publishes whatever nobody thought to name, and nothing anywhere announces that it did, whereas an unnamed file here is merely missing, and missing breaks the packaged build where someone will see it. Two config files are the reason this is worth doing, not the byte count. `.cargo/config.toml` sets `rustdocflags = ["-D", "warnings"]`, and cargo reads config from the build's cwd upward — docs.rs builds inside the extracted crate directory, so shipping it would turn any rustdoc warning into a failed docs build. `rust-toolchain.toml` would pin 1.97.1 in someone else's build directory. `docs/` stays: src/docs.rs pulls its five pages in with `#![doc = include_str!(...)]`, so a tarball without them does not compile. `lexicons/` stays as the provenance of the generated bindings, and `brand/` goes, nothing having loaded it since the mark was inlined into src/html/pages.rs. Dropping `tests/` does mean the suite cannot be run from a crates.io tarball — some fixtures are `include_str!`'d from `#[cfg(test)]` code, so test compilation would fail there.