Add toolchain, lint, CI and contributor config master
Pins the toolchain to 1.97.1 rather than tracking stable: clippy and rustfmt change their output between releases, and with both gating CI a floating channel turns the pipeline red on a tree nobody touched. rustfmt.toml and the [lints] tables were both measured against a baseline before being written, and neither changes the current tree. Unmodified origin/main reports 8 clippy warnings and 19 rustfmt hunks; with this config applied the counts are identical. The prek PR fixes those warnings, after which -D warnings becomes a viable CI gate. deny.toml's allow list is derived from the real dependency graph rather than guessed. It is unverified — cargo-deny is not installed locally, so the file has never been parsed by the tool. It will flag this package until the license PR lands and adds a license field. The pipeline schema was cross-checked against the workflow package's Go structs, docs.tangled.org, and published examples, but no spindle is attached to this repo, so it has never run. The nixery engine is not rustup, so rust-toolchain.toml does not apply in CI and the versions can drift. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>