LLMClient.stream now guarantees, for native protocol routes and the
synthetic AI SDK route alike: a successful stream emits exactly one
terminal finish event and nothing after it. EOF before finish means the
provider stream was truncated (proxy cut, silent drop) and fails as
LLM.MalformedResponse instead of letting a partial response settle as
complete; output after finish also fails. Enforcement applies after
protocol parsing so stream.onHalt flushes remain subject to it, with
per-subscription state.