Tp-Note v1.27.3 -- Nested Projects, One Configuration Chain

Project configuration files can now cascade. Until this release, every
tpnote.toml found while searching upward from a note's directory lived in
isolation -- each one either was the whole story or replaced whatever came
before it. Now a project configuration file can opt in to inherit the one
above it, chaining across as many nested directories as you like, while a
separate setting decides independently where the document root itself
sits.

Picture a consultancy that keeps every client engagement under
~/clients/. A single tpnote.toml at the top defines the firm's house
templates and note scheme once. Each client folder below it --
~/clients/acme/, ~/clients/initech/ -- adds a one-line tpnote.toml that
sets merge_parent_config = true to inherit those house defaults, while
is_root_path_marker (true by default) still fixes its own document root,
so the viewer never wanders out of one client's notes into another's.
Change the house template once at the top and every client engagement
picks it up automatically; override a single field inside one client's
folder and only that client sees the difference. See the man page's
CUSTOMIZATION section for the full mechanics, worked through with a
similar nested-directory example.

Breaking changes:
- TPNOTE_CONFIG now overrides the user configuration file path instead of
  adding an extra merge layer between /etc and the user config. Previously
  an existing ~/.config/tpnote/tpnote.toml could silently win over an
  explicitly set TPNOTE_CONFIG; now only one of the two is ever read.
- Removed the old behavior of renaming/disabling the configuration file
  after a load or version-mismatch error. An incompatible or invalid
  configuration file is now skipped (or, for the whole file, ignored) and
  Tp-Note continues with the rest of the merged configuration -- the file
  itself is left untouched on disk.
- tpnote-lib: Context::from() and WorkflowBuilder::new() now require an
  explicit root_path: PathBuf argument; the library no longer discovers
  its own document root. Update call sites accordingly.

Security:
- A project configuration file (a tpnote.toml found by searching upward
  from the note's directory) can no longer set [app_args] -- the editor,
  editor console, and browser launch commands. Such a file can live in a
  directory you do not control (a cloned repository, an extracted
  archive, a synced folder), and those settings reach Command::new() with
  no sanitization, so merely opening a note below one could previously
  launch an attacker-chosen program. Tp-Note now always strips
  [app_args] from a project configuration file before merging it and
  logs a warning (exit status 5); every other setting in the file still
  applies normally. System and user configuration files, and a --config
  override, are unaffected.

Features:
- A project configuration file can now set the two root-level variables
  is_root_path_marker (default true) and merge_parent_config (default
  false), letting a project chain multiple configuration files across
  nested directories and/or move the document root independently of how
  far the configuration search extends. Being root-level variables, they
  must appear before the file's first [table] header. See the man page's
  CUSTOMIZATION section for worked examples.
- A single bad configuration file no longer discards the whole merged
  configuration: only that file is skipped, with the rest of the chain
  (defaults, /etc, user config, other project configuration files) still
  applied.

Exit status:
- Exit status 5 is now returned whenever any sourced configuration file
  was invalid, unreadable, skipped, or below the minimum required version
  -- in addition to the existing case of `--config-defaults` failing to
  write. Tp-Note still runs to completion in this case (editor, viewer,
  export all still happen); exit status 1 (note processing failure) takes
  precedence over 5 if both occur.

Fixes:
- `--version`'s searched_config_file_paths now lists every directory
  actually walked while searching for a project configuration file,
  including ones where none was found, instead of silently omitting them
  and looking complete when it wasn't. sourced_config_files is unchanged
  (still only the files that actually got merged).
- A typo inside a config table (e.g. `[arg_default] yscheme` instead of
  `scheme`, or `[viewer] xsame_user_policy` instead of
  `same_user_policy`) was silently ignored. Unknown fields nested inside
  a config table are now rejected the same way an unrecognized top-level
  key already was: skip-with-warning / exit status 5.

Performance:
- The upward project configuration file search now runs at most once per
  process instead of being repeated for the same directory.

Docs:
- Rewrote the man page's CUSTOMIZATION section with worked examples for
  the new project configuration file chain, and its Security note to
  describe the [app_args] restriction above.
- Updated the README's "Upgrading" section and the manual's
  troubleshooting section to describe the current skip-and-continue
  behavior instead of the removed rename-and-disable behavior.
- Added Weasyprint per-note page layout and page-break examples to the
  man page.

Dependencies:
- Update tpnote-lib to 0.47.0.
- Routine dependency refresh: thiserror 2.0.20 -> 2.0.21, wl-clipboard-rs
  0.9.3 -> 0.9.4, notify-rust 4.18.0 -> 4.18.1, yoke-derive 0.8.3 ->
  0.8.4, and other transitive patch/minor bumps.