A tool to flash Sonix MCUs in recent Convoy drivers

Hi, everyone!

Here is something I’ve been slowly working on recently: a tool to flash Sonix MCUs in recent Convoy drivers.

As you probably know, recent Convoy drivers contain SN8F57xx microcontrollers instead of the old ATtiny13. The only way to program them used to be a 50$ proprietary SN-Link programmer. So I bought one and decided to reverse engineer it to replace with cheaper hardware. Turns out the programming protocol is just single-duplex UART, and you can use a cheap USB-UART dongle! The only catch is that the chip would only listen for a few milliseconds after reset, so a dongle with exposed RTS or DTR signals is recommended for a hardware reset circuit.

But then, it turned out that a lot of Convoy drivers don’t have programming pads. And most of them have their programming pin (SWAT) attached to an RC circuit that interferes with UART signal, so you can’t really program them in-circuit. Here are my research results:

  • 5A 12-group linear driver for S2+: has programming pad, has RC circuit
  • 5A buck driver for S2+: no programming pad, has RC circuit
  • 6A driver for S21E: no programming pad, has RC circuit
  • 6A driver for M26D: no programming pad, has RC circuit
  • 1.5A dual-fuel 12-group driver for T3: no programming pad, has RC circuit
  • 1.5A dual-fuel 4-group driver for T3: no programming pad, has RC circuit
  • 5A dual-fuel driver for T6: has programming pad, no RC circuit

So, the only driver so far that is confirmed to be easily programmable is the 5A dual-fuel driver: it has an exposed programming pad and nothing is interfering with the signal. Sadly, the drivers are read-protected, so the only way to have custom firmware on them is to reverse-engineer the hardware and write firmware from scratch. But it’s a complex driver with both boost and buck circuits and a lot of tiny parts, so the idea of reverse-engineering it is giving me shivers :sweat_smile:

I’ve also ordered a couple of simple 7135 drivers to see whether they can be programmed in-circuit as well. I’ll probably try starting with them first.

So here is a question to the community: are you interested in custom firmware for T6 Convoy drivers? And if someone has already tried to reverse-engineer the driver, I would be very happy to hear about that.

24 Thanks

This is very lit, very well done. I am v interested in new firmware for Convoy drivers. Even if it’s just the 5A T6 driver it’s still 17mm and so fits in lots of other hosts. The simple addition of a medium press to go backwards (and to turbo from moonlight) as found in Bistro or the BLF A6 firmware is sorely lacking, in my view, from the Convoy UI.

Having the ability to flash Bistro onto regularly available, reasonably priced, reasonably efficient drivers would be a real luxury.

1 Thank

In case the firmware development for Sonix Convoys gets anywhere, I just clicked together a small dedicated programmer based on your writeup that directly outputs VIO (selectable between 5V and 3.3V), GND and SWAT. ESD protection on USB datalines, VBUS, SWAT and VIO too, because why not. Wonder if I should add a fuse, too…

EDIT: Just added a fuse. There was still space :smiley:

If people are interested I will push it to github, together with the files to order them at jlcpcb for cheap.

Edit2: found another, the T4 driver. No clue if it has any components attached to that pin though.

10 Thanks

Oh, that’s really nice, thanks! That would definitely be an upgrade over my current breadboard setup :grinning:

I’ve contemplated making something similar once the software part is sorted out, but you were much, much faster! Would definitely try to build one if you publish Gerber files.

Regarding the T4 driver – nice find! I’m pretty confident the pads are connected, but the question is whether there is an RC circuit or not. Sadly it’s hard to judge by the official photos, because the MCU is sandwiched deep between the two boards. I’m not sure why Convoy engineer even bothered with programming pads on the 5A linear driver, since it can’t really be programmed with that capacitor soldered in.

4 Thanks

A port of Bistro is a good idea, thanks!

3 Thanks

I’ve had a little look at the spare drivers I’ve got and I think I’ve found two that fit the bill. I just had a little poke around with the multimeter and presumably if the programming pin isn’t connected to any resistors or capacitors nearby then its fine? Connected areas have the little red dot

Programming pad, no RC circuit:
3V 6A 20mm linear driver (V20 on PCB)


12V 2.5A 22mm boost (for GT FC40)


Programming pad, RC circuit (I think):
6V 4A 17mm boost. The 6V 2A 17mm “B35AM” driver is connected the same


I’m not 100% sure what it does but I’m guessing this is the RC circuit previously mentioned.

No prog pad:
3V 8A 20mm buck
6V 8A 22mm boost, it has a tiny pad almost underneath the corner of the MCU but I don’t think it’s connected to the programming pin

3 Thanks

Got myself a couple of simple 7135 drivers from Convoy: discovered that they use Sonix chip as well (SN8F5701), and SWAT pin is not connected to anything. They can be flashed by soldering a wire to pin 6 of the MCU. I’ve decided to use these drivers as training wheels – they are easy to reverse-engineer, and similar to hardware that Bistro firmware currently supports.

Here are some high-res scans of the driver.

With parts:

With no parts:

And here is the reverse-engineered schematic:

The chip has no markings, but is detected by SN8Flash as SN8F5701 series:

Now, it’s time to try writing some code.

9 Thanks

Started working on firmware, faced the first obstacle: Bistro UI uses short clicks (< 1.0s) and medium clicks (1.0s to 4.0s). But the RC constant of R2*C2 is not enough to track delays this long, the voltage falls below ADC resolution in one second:

This is not the end of the word, as it can be fixed by soldering an additional capacitor between MCU pins 7 and 8. But now I wonder whether the 5A dual-fuel driver has the same flaw – if that’s the case, it can’t be fixed this easily, as all components there are tiny.

1 Thank

I just released the flashing dongle files, the release folder contains Gerber, BOM and position files that can be ordered from jlcpcb directly. Other fabs will be able to manufacture these PCBs too if you want to assemble manually, but the assembly files are specific for JLC.

If anyone ends up ordering these boards, please report back that they work so I can mark it as “tested” in the github repository!

2 Thanks

Thank you! I’ve ordered some PCBs to test, but it is going to take 3-4 weeks for them to arrive.

1 Thank

I’m exited about the possibility alternative firmware for Convoy drivers. Something like Bistro would be great, even without the medium-press functions.

Unfortunately I don’t have the skills to contribute to the either the software or hardware myself.

Spent an evening porting Bistro code from ATtiny to SN8F5701. Basic stuff already works – I can switch modes and go through setup menus. But there is still a lot of work to do: I have to figure out thermal protection, re-calculate all calibration values and then spend a while debugging it in a real light.

5 Thanks

Has anyone tested the flasher yet? I’m really interested in this project and would like to help once I get the stuff needed for flashing.

I’ve tried experimenting with wiring an Attiny25 onto the 5A buck, mode changes does work but its not really feasible since that sonix chip is so small there’s not enough room to fit. The buck circuit only needed PWM (pin 5) and EN (pin 10) to work with the Attiny25.

Bistro + buck driver would be soooo good!

4 Thanks

Well, it works for me, but I guess it doesn’t count :sweat_smile:

The biggest issue with 5A buck is that you’ll have to desolder the chip to flash it, so my current plan is to start with drivers that don’t require this.

2 Thanks

Oh that’s good! I’ll order the flasher from JLCPCB then.

Have you made any more progress with porting bistro?

I have asked Simon about releasing the firmware but he says the developer of it will not allow it.

Not exactly that, but long tap will return to the first level in the group in T6.

Any tap is a turn-off. The driver “measures” the longevity of being off. If it’s short enough the driver proceeds to the next mode, otherwise it performs ordinary turn-on.

2 Thanks

Oh, sorry, you meant the hardware dongle, right? Haven’t received the parts yet. I initially thought you meant the software part.

Sorry, was overwhelmed by my day work :frowning: I have some code that kinda works, but would like to calibrate and re-check it before releasing.

Is any of you who ordered my flashing tool from EU? If so, I’d buy one off you (MOQ is 5 anyway, right?)