Tailscale spent six months and 19 corrupted databases hunting a bug in SQLite. The race shipped in 2010 with WAL mode, and survived every release until March. Antithesis pointed a generic write-and-checkpoint workload at the same build and caught it in 15 minutes, first run.
SQLite’s own developers could never reproduce it in the lab. They had to patch the source with a test hook to force the race at exactly the right instant.
In today’s indie hacker news:
- 🐛 A 2010 SQLite race corrupted Tailscale’s control plane
- 🐋 DeepSeek shipped its flagship with no announcement page
- 🖼️ Chrome throws away your logo’s detail before rendering
- 🪜 The hiring rebound went 71% to senior titles
- 💾 The AmigaDOS author who kept 1985 on schedule
TOP STORIES
🐛 SIXTEEN YEARS IN THE WAL

Tailscale bought a SQLite support contract and funded a tracing filesystem to find it.
The story: Tailscale’s writeup starts in August 2025, when a pipeline reading its S3 backups threw an error. An integrity check confirmed the backup really was corrupt. Tailscale runs one SQLite file per control plane shard, with a single Go process as the only writer. It had been snapshotting those files to S3 since early 2023 without trouble.
The decisive clue came from a transaction log it built to replay every mutating statement onto the last good backup. Twice, the replay would not run clean. Data that one transaction had committed was invisible to the next. A write that vanished with no error.
The details:
- SQLite documents the WAL-Reset bug as present in every release from 3.7.0, the one that added WAL mode. The fix landed in 3.51.3 in March.
- The first release carrying that fix was withdrawn. Tailscale’s monitor promptly flagged 13 more databases, all false alarms from stale expression indexes.
- Antithesis engineer Carl Sverre had Claude write the workload: concurrent writes and checkpoints, nothing bug-specific. The assertions were plain. No lost committed writes, and the database is not corrupt.
- Canonical modelled the same code paths in TLA+ and cleared dqlite. The checker produced a counter example in 20 states.
- The damage was tailnet and device metadata, never keys or traffic. Devices already online stayed connected, they just stopped learning about changes.
“running boring technology in a non-standard way is a risk.” (Alex Chan, Tailscale)
Why builders care: Two connections on one WAL database, or your own checkpoint loop, and you were exposed. Pin 3.51.3. A scheduled integrity check over your backups is the cheapest corruption detector you can ship this week.
SQLite itself says not to panic. For a stock app on autocheckpoint it rates your odds against SSD failure and cosmic rays.
🐋 SHIP FIRST, ANNOUNCE NEVER

DeepSeek shipped V4 Pro 0813 with no announcement page and no benchmark post.
The story: The OpenRouter listing is where the model turned up on Aug 12. There was no launch post and no benchmark page. Simon Willison had to link there too, because DeepSeek published nothing obvious of its own. The model string deepseek-v4-pro now resolves to the new checkpoint. Anyone already calling it got moved without touching a line of code.
The price is the fun part. DeepSeek’s pricing page lists $0.435 per million input tokens on a cache miss and $0.003625 on a hit. Real traffic on OpenRouter paid a weighted average of $0.03431, because 92.9% of input tokens hit the cache. Output barely moved, at $0.8696 against $0.87 listed.
The details:
- Concurrency is the ceiling nobody reads. Pro is capped at 500 requests against 2500 on Flash, so a launch spike hits the Pro wall first.
- DeepSeek’s own footnote warns of a coming price rise it calls significant. Today’s number is not a number to build on.
- Non-think is not a cheap tier of the same model. On DeepSeek’s numbers, Humanity’s Last Exam falls from 37.7 in Think Max to 7.7 with thinking off.
- The tail is brutal. End-to-end latency runs 10.26s at the median and 253.45s at P99, which breaks any synchronous request path.
- Claude Code sent it 973M tokens on day one, fourth behind Hermes Agent at 3.26B. The API speaks both OpenAI and Anthropic formats, so trying it is a base URL change.
- Open weights are unconfirmed. The MIT-licensed weights on Hugging Face belong to April’s Pro release, not this checkpoint.
“Interestingly I got very different looking pelicans for the three different reasoning levels of low, medium, and high.” (Simon Willison)
Why builders care: On this model, prompt architecture beats model choice as a cost lever. Put the stable system prompt and repo context in a fixed prefix, and keep the variable turn last. Get the ordering wrong and you pay the sticker.
🖼️ THE DECODER ATE YOUR LOGO

A 15px JPEG logo is drawn from one number per 8x8 block.
The story: Guillaume Techer noticed his logo looked thicker in Chrome than in a colleague’s Firefox. Same file, same CSS, 15px on screen. Chrome had decoded it at one eighth scale, and at that ratio each 8x8 block collapses to its constant component. Every gradient and softened edge was discarded before the pixels existed.
The optimization is old and defensible. A 2000x2000 JPEG shown at 20x20 costs roughly 12 MB as a full bitmap. The thing you actually see is about 1.2 KB. libjpeg documents the only supported ratios as M/8, which is why the denominator is always 8.
The details:
- Blink hard-codes it as
g_scale_denominator = 8, under a comment saying JPEG supports no other denominator. - The numerator comes from a memory budget, not from your CSS. Blink sizes the image as width times height times 4 and checks it against a decode limit.
- Two JPEGs out of one export pipeline can take different paths. Blink refuses the downscale unless both dimensions fit a whole number of MCUs, at most 32 pixels each.
- The post was corrected on 12 August after a Hacker News commenter pointed at the resampling filter instead. The author now calls the damage a mix of both.
“Really, the moral here is that you should not use JPEG for icons and the like.” (Guillaume Techer)
Why builders care: The damage only shows on the downscale path. A full-size JPEG can still break in a thumbnail grid. Ship icons and avatars as SVG or PNG and the whole class of bug goes away. If a pixel diff fails in one browser only, suspect the decoder before your code.
🪜 THE LADDER LOST A RUNG

Software postings are climbing again, and 71% of the gain went to senior titles.
The story: Florian Herrengt argued on 11 August that AI is removing the middle class of software engineering. His mechanism is simple. AI took the speed limit off bad decisions, and to an untrained eye the output works. Pull the branch, run it, and you get something functional.
The data he doesn’t cite says something compatible. Indeed Hiring Lab counted the net increase in US software postings from May 2025 to May 2026. Senior roles took 71% of it, and AI-titled roles 37%. The two categories overlap, so they don’t add up.
The details:
- The rebound is real but shallow. US software postings are up almost 15% since Claude Code launched in late February 2025. Postings overall fell 7% over the same window.
- The baseline is the catch. Software postings still sit about 27.5% below February 2020, while postings overall are back to that mark.
- Indeed stamps its own caveat on the timing. Correlation is not causation, and it calls the relationship uncontrolled.
- Neither source breaks out what happened to junior postings. Both only report where the net increase landed.
- It is not a US-only pattern. The software share of postings is rising across most large developed economies Indeed looked at, with Germany still falling.
“At some point, someone still has to know what is going on. And that’s the most valuable person on the team.” (Florian Herrengt)
Why builders care: If you sell dev work, the growing demand is review and architecture, not implementation volume. The same asymmetry runs through your own product. An agent adds tables in ten minutes, and you own the migration. That bill arrives later, and only once paying users have rows in them.
💾 THE BACKUP PLAN THAT SHIPPED

Tim King, who turned a Cambridge operating system into AmigaDOS, has died.
The story: amiga-news published the obituary on 11 August, with the death confirmed by King’s family. He died at the end of July. He took his Cambridge PhD in 1979. In 1984 he joined MetaComCo as director of research and development, carrying a 68000 port of TRIPOS.
Commodore had bought Amiga Corporation and inherited an unfinished machine. Exec handled multitasking and Intuition handled the GUI, but nothing handled the disks. Per GenerationAmiga’s account, the TRIPOS port already ran on the Motorola 68000. Commodore adapted it rather than finish its own. The Amiga 1000 shipped in July 1985 with AmigaDOS inside.
The details:
- The debt shipped with it. AmigaDOS was written largely in BCPL while the rest of the machine moved to C and assembly.
- Commodore did not unwind that until AmigaOS 2.x, and TRIPOS code lived on in dos.library until v36.
- AmigaDOS gave the machine named devices instead of drive letters, so people typed SYS:, RAM: and DF0: for years.
- He kept going. Perihelion built Helios for transputers from 1986. UK Online launched in 1994 on Olivetti money and sold to EasyNet two years later.
- The only long interview with him runs 1:24:40, filmed alongside his wife Jessica and published in 2022.
“I had never heard this name until now, but I owe Dr. Tim King a significant part of my career.” (Cockbrand, Hacker News)
Why builders care: This is the build-versus-adapt call with the receipts on both sides. Boring code that already runs on your target hardware wins the deadline. The interest shows up in the rewrite, years later, long after the launch it saved.
TRENDING TODAY
- 🌑 2026 Eclipse Webcams - One page of webcams aimed at the 2026 eclipse, which is the whole product. It pulled 460 points against 124 comments, so most people opened it and left happy. Somebody shipped the obvious thing first.
- 🎭 Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot - Scanners are wearing AI crawler user agents. An allowlist for ClaudeBot is now an attack surface. It drew 242 points against 183 comments. Go check what you let through on user agent alone.
DRAMA
🏳️ META WON THE ARMS RACE
uBlock Origin is giving up the fight to keep ads off Facebook.
The writeup says the project is stepping back from chasing Facebook’s ads. It landed at 344 points against 463 comments, the rare thread where the argument outweighs the link. An open source filter list against a company that can rewrite its own markup on any schedule it likes. The surprise is that it lasted this long.
Why builders care: Any product whose core loop matches someone else’s HTML is running on borrowed time. Price that in before the roadmap depends on it.
STACK OF THE DAY
🧮 Woxi
Woxi is an open source reimplementation of Mathematica and the Wolfram Language. It pulled 264 points against 40 comments on Show HN, the shape of a launch people liked on sight. If you have ever priced a Wolfram licence, you know exactly why someone built this. Symbolic math inside your own product, with no per-seat conversation. That is a small door into a lot of ideas.
Not sponsored. We just feature tools builders would actually use.
BOOKMARKED TODAY
- 🐟 Thanks to social media, canned sardines are a scarcity on the supermarket shelf - A demand shock with no launch. It drew 65 points against 87 comments, all from people posting. If you have ever wanted a viral moment, this is what one does to a supply chain.
- 📐 What sort of maths are LLMs good at? - The question in the title, taken seriously. It pulled 242 points against 137 comments, so the answer is contested. Useful if you are deciding what to hand a model and what to check yourself.
- 📚 Principia Mathematica is modern and insightful - The title is the whole argument. It picked up 77 points against 30 comments inside an hour of posting. File it under the ones you actually read on a Sunday.
That’s the board for today. Go build something.
Work from any WiFi like it's your home network. NordVPN's Meshnet runs a free private mesh between your laptop, dev box, and home server. SSH from a cafe without exposing a port, the way you'd use Tailscale. The paid VPN on top lets you test geo-fenced Stripe checkouts or feature flags from any country.
We get a cut if you sign up. Only added for tools we use ourselves.
Curated by AI, built by a human.