[proxy] Stream responses and bound waits with an idle timeout.
Rewrite the proxy to relay upstream responses incrementally:
each chunked SSE frame reaches the client as it arrives instead
of being buffered, and every network wait — connect, response
headers, and gaps mid-stream — is bounded by an idle timeout
(CLAUDE_PROXY_TIMEOUT, default 60 s). A mid-stream expiry emits
a typed SSE error and aborts the relay.
DeepSeek reasoning models default to thinking on, which stalls
non-streaming requests, so such requests now get thinking:disabled
injected unless they set a thinking field themselves; streaming
and explicit-thinking requests pass through untouched. This
replaces the old safety-classifier sniffing.
Log one line per event with a per-request id, so a single request
can be traced with grep 'req=<id>'. Handle portless https
upstreams (scheme-default port and Host header) and give the
Shepherd service a SIGTERM stop with a paced respawn that
survives the port overlap during guix home reconfigure.
Rework the tests around a deterministic fake upstream that can
stream with gaps and stall: assert incremental relaying,
thinking injection, 504 on stalled headers, the mid-stream typed
error, log traceability, and error passthrough. Add a TLS twin
pair — an HTTPS fake on 127.0.0.1:443 behind a self-signed test
certificate and a proxy on portless https://127.0.0.1 — to guard
scheme-default-port and TLS record handling. vps-base.scm now
builds its test services from claude-proxy-test-os-services
instead of duplicating the wrapper.