WithGroup dropped the group name, so grouped attributes lost their namespace and
could collide with ungrouped fields. Carry the open-group path as a key prefix
and apply it in Handle and WithAttrs; an empty group name stays a no-op per the
slog contract.
Found in cubic review on #7098 (client/internal/pqkem/env.go:139).