Appearance
The hardware
One board is in service: can-mdv v2. There is a single kind of box to order, to wire and to program, and one series of firmware images for it.
| can-mdv v2 | |
|---|---|
| Hardware ID | 990010058 |
| Microcontroller | STM32U575 @ 160 MHz |
| MUXEN bus | one CAN bus, 500 kbit/s |
| Sensor bus | one LIN bus, 19200 baud |
| Switch drive outputs | 2 |
| Switch position feedback | 1 |
| Current measurement | 1 analog input |
| Software version series | 6.x |
A box reporting a 5.x software version is an earlier board that never went into service. If you meet one, it is not a box to commission — report it rather than trying to update it.
The MUXEN bus
| Speed | 500 kbit/s, fixed — it is not a setting |
| Frames | classic CAN, extended (29-bit) identifiers |
| Sample point | 75 % |
| Termination | the MUXEN bus is terminated at its two physical ends — not at the can-mdv unless the can-mdv is an end |
Ordinary 120 Ω CAN: two wires plus a common ground, 120 Ω at each end of the segment and nowhere else. A bus with one termination too many or one too few may work on the bench with a short cable and fail on the boat; it is worth checking with an ohmmeter (60 Ω across a powered-down, correctly terminated bus).
A can-mdv has only one CAN connector. There is no second CAN side to get the connectors the wrong way round on.
The LIN bus
| Role | the can-mdv is the LIN master |
| Speed | 19200 baud, 8 data bits, no parity, 1 stop bit |
| What goes on it | the battery sensor — see the battery-switch manual |
| Transceiver | switched by the firmware; it is turned off when the box goes to standby |
The LIN transceiver being off is normal in standby and is not a fault. The bus is dead while the box sleeps and comes back when it wakes.
Inputs and outputs
Whatever firmware is loaded, the board carries these:
| Count | What it is | |
|---|---|---|
| Switch drive outputs | 2 | the two coils of a bistable remote battery switch — one pulses it open, the other pulses it closed |
| Switch position feedback | 1 | a contact input, closed to ground when the switch is closed; internal pull-up, no external resistor needed |
| Supply-present input | 1 | tells the box whether the boat's supply is there; internal pull-up |
| CAN power injection output | 1 | supplies the MUXEN bus side from the box, so the bus survives the switch opening |
| Auxiliary power output | 1 | a switched output that follows the power injection |
| Current measurement | 1 | a 12-bit analog input measuring the current the box injects |
| System LED | 1 | the local diagnostic — see Common mistakes |
The current measurement is scaled by a configurable coefficient before it is published. The two switch outputs are not a held state: a coil is driven only until the position feedback says the switch has moved, then released — a bistable switch holds its own position from there. If the switch never reaches the position asked for, the drive stops by itself after a configurable timeout.
Power and mounting
The box is powered from the boat's DC distribution, and is expected to stay powered when the battery switch it drives is open — that is the whole point of the supply-present input and the power injection output. Follow the mechanical and electrical figures on the product data brief for the product ID you are installing; this manual describes behaviour, not ratings.
Memory and firmware slots
The microcontroller's flash is split four ways, and this is why an update cannot leave a box with nothing to run:
| Area | Size | What is in it |
|---|---|---|
| Bootloader | 40 KB | validates and installs firmware; never written over the bus |
| Running firmware | 480 KB | what the box is executing |
| Spare slot | 488 KB | where an upload lands, before anything is installed |
| Settings | 16 KB | every parameter, kept across resets and firmware updates |
Settings survive a firmware update. They do not survive a factory reset — see Common mistakes.
Firmware compatibility
A firmware image is built for one product ID and one board, and is signed with that board's key. An image the bootloader does not recognise is refused before anything is written; the box restarts on the firmware it already had. In practice this means the 6.x image carrying the right product ID, and nothing else. See Loading and updating a firmware.
