4ab4894f44
The post-stream helper (_deliver_media_from_response) rescanned the already-streamed response and promoted bare local filesystem paths into real uploads via extract_local_files. Since the visible reply was already streamed verbatim, any bare path there is either text the user has seen or stale inspected/tool content — not an attachment request. On Slack this uploaded images from stale inspected content after otherwise clean replies. Post-stream delivery now honors only explicit MEDIA: directives. The non-streaming path in gateway/platforms/base.py keeps its bare-path auto-detect, because that path controls the visible text and strips the path from the reply when it attaches — auto-attach is intentional there. Regression tests: bare image/document paths in a streamed reply produce no upload; explicit MEDIA: tags still deliver. Fixes #20834