Some posts are downloads
A photo in a post is a bare filename in an image line. It always has been:

So a file attached to a post is the same line without the exclamation mark:
[Reading notes, 2025](reading-notes.pdf)
A whole line that is nothing but a link, pointing at a bare filename with a known extension, is an attachment. It gets staged through incoming/ like a photo, stored next to the post like a photo, and it never leaves your site.
A line with a URL in it stays what it has always been: a link. The difference is the bare filename — the same rule photos already follow, so there's nothing new to learn.
Rendered as a card, not a link
An attachment renders as a card carrying the label, the extension and the size. The size is there because a download deserves to say what it costs before you commit to it — a 40 MB PDF on a phone on mobile data is a different proposition from a 200 kB one, and the reader should get to make that call.
