Repository navigation
[Bug][Windows Desktop 0.2.0-rc.2] Generic transport failure persists across reinstall/reset due to Node CA, stale state, and Electron UI cache #9266
Unanswered
shinji00222
asked this question in
Q&A
Replies: 1 comment
中文\n\n更新:我现在确认 DSH 已恢复可用。Windows 上通过稳定启动入口让 Electron/Node 使用系统 CA 后,新会话可以正常收到回复;之前的 Node 直连请求在未启用该选项时出现 SELF_SIGNED_CERT_IN_CHAIN,启用后 API 和模型请求返回成功。\n\n建议 Windows 桌面版在启动 host 时自动启用 Node 系统 CA(--use-system-ca),并保留已有的 NODE_OPTIONS;同时确保重启时旧的单实例进程退出,避免新环境变量没有进入实际处理请求的进程。若仍失败,详细诊断信息最好能显示脱敏后的底层传输错误,方便区分证书、代理和会话状态问题。\n\n## English\n\nUpdate: I can confirm DSH is working again. On Windows, launching Electron/Node with the system CA enabled through a stable launcher allowed fresh sessions to receive replies. Previously, Node requests failed with SELF_SIGNED_CERT_IN_CHAIN without this option; with it enabled, the API and model requests succeeded.\n\nSuggested Windows desktop fix: enable Node’s system CA (--use-system-ca) when starting the host while preserving existing NODE_OPTIONS. Also ensure any old single-instance process exits on restart so the new environment reaches the process handling requests. If failures persist, detailed diagnostics should expose a sanitized underlying transport error to distinguish certificate, proxy, and session-state issues. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
On Windows Desktop
0.2.0-rc.2,DeepSeek Messages transport failedcan become very hard to recover from in a normal proxy / TLS-inspection environment.The same DeepSeek API key and
deepseek-flashrequest work outside the desktop app, but the desktop UI may still keep failing until all of these are handled together:%USERPROFILE%\.dsh;NODE_OPTIONS=--use-system-ca;%APPDATA%\@deepseek-ai\dsh-desktop, which is not reset by reinstalling the app or moving%USERPROFILE%\.dsh.This makes the visible error look like a generic model transport failure, while the real cause is hidden in the desktop host / runtime state.
Environment
CurrentBuild=26200)0.2.0-rc.2HTTP_PROXY/HTTPS_PROXY/ALL_PROXY-> local proxy port)NO_PROXYwas configured forlocalhost,127.0.0.1,::1,deepseek.com,.deepseek.com,api.deepseek.comSELF_SIGNED_CERT_IN_CHAINreproductionWhat I observed
The desktop UI repeatedly showed:
Reinstalling the desktop app did not fix it, because the failing state survived in user data.
After a clean
%USERPROFILE%\.dshreset, the app still did not fully recover until the desktop UI data directory was also reset.Checks that passed
The key and provider were not the root issue:
GET https://api.deepseek.com/modelswith the configured key returned200.deepseek-flashchat completion with the same key returned200.{ "provider": "deepseek-official", "model": "deepseek-flash", "reasoningEffort": "high" }127.0.0.1:19387.%USERPROFILE%\.dshshowed no staledeepseek-v4-pro/deepseek-v4-flashstrings.Recovery steps that were required
The desktop app only became recoverable after doing all of the following:
%USERPROFILE%\.dsh.%USERPROFILE%\.dsh.DeepSeek Harness.exeprocesses. Otherwise Electron single-instance behavior can reuse the old process and the new environment does not take effect.After that directory was regenerated, the desktop app started again with a fresh UI state.
Why this feels like a product bug
I understand that the local machine has a proxy / TLS-inspection environment, so a Node CA issue is plausible. But the desktop app currently makes the failure much harder to diagnose than it needs to be:
DeepSeek Messages transport failed.SELF_SIGNED_CERT_IN_CHAIN, proxy failure, stale model selection, or host process reuse.%USERPROFILE%\.dshor%APPDATA%\@deepseek-ai\dsh-desktop.%USERPROFILE%\.dshalone still leaves Electron UI/local-storage state behind.NODE_OPTIONS=--use-system-camay not apply.Suggested improvements
SELF_SIGNED_CERT_IN_CHAIN/ certificate validation failures and show an actionable message in the UI.%USERPROFILE%\.dsh%APPDATA%\@deepseek-ai\dsh-desktopDeepSeek Messages transport failed.I can provide more sanitized diagnostics if needed, but I intentionally omitted API keys and full personal paths here.
All reactions