Author Topic: $0.11 PY32F002A: Cortex-M0+ MCU, actually a PY32F030! 32/4KB, 48MHz, PLL, DMA...  (Read 192220 times)

0 Members and 13 Guests are viewing this topic.

Offline U6emp

  • Newbie
  • Posts: 3
  • Country: kg
Hello!
Maybe someone had communication with PY32F002B?
The situation is as follows, this chip is used in the PC211 cartridge.
I can't reach it either via SWD or via UART. If I pull nRST to GND  then via SWD:

Switching out of dormant state into SWD
DP DPIDR 0x0bc11477 (v1 MINDP rev0) designer 0x43b partno 0xbc
AP   0: IDR=04770031 CFG=00000000 BASE=e00ff000 CSW=e3000040 (AHB3-AP var3 rev0)
remote_v4_adiv5_mem_read_bytes error around 0xe000edf0
Halt via DHCSR(000d0744): failure after 2510ms
Try again with longer timeout or connect under reset
adiv5: Failed to prepare AP, results may be unpredictable
remote_v4_adiv5_mem_read_bytes error around 0xe00ffff0
Error reading CIDR on AP0: 2
No target found

Is it possible to reset via ISP?
Best regards!
« Last Edit: August 30, 2025, 02:06:05 pm by U6emp »
 
The following users thanked this post: ago58

Offline DavidAlfaTopic starter

  • Super Contributor
  • ***
  • Posts: 6924
  • Country: es
It won't connect with reset active.
The code probably disables SWD interface, so you have only few micro seconds to establish the connection after releasing nRST, which is very difficult with a PC programmer, probably only dedicated programmers can do this.

However, did you try with BOOT0=1 ?
This will boot into SRAM, which contains nothing, so it should keep the SWD active.
Keep in mind not all PY32F002x devices have this pin... In that case, it's pretty much a dead end.

What are you trying to do? Repurpose the mcu? Just buy a new one, it costs cents...
« Last Edit: August 31, 2025, 12:24:01 pm by DavidAlfa »
Hantek DSO2x1x            Drive        FAQ          DON'T BUY HANTEK! (Aka HALF-MADE)
Stm32 Soldering FW      Forum      Github      Donate
 

Offline U6emp

  • Newbie
  • Posts: 3
  • Country: kg
RE:
In that case, it's pretty much a dead end.
What are you trying to do?
Repurpose the mcu? Just buy a new one, it costs cents...

I have no problems with the purchase, I am trying to analyze how effective the protective measures were that China used )))

Connect via blackmagic probe:
Switching out of dormant state into SWD
DP DPIDR 0x0bc11477 (v1 MINDP rev0) designer 0x43b partno 0xbc
AP   0: IDR=04770031 CFG=00000000 BASE=e00ff000 CSW=e3000040 (AHB3-AP var3 rev0)
Halt via DHCSR(02000001): failure after 2002ms
Try again with longer timeout or connect under reset
adiv5: Failed to prepare AP, results may be unpredictable
ROM Table: BASE=0xe00ff000 SYSMEM=1, Manufacturer 43b Partno 4c0 (PIDR = 0x04000bb4c0)
0 0x0e000e000: Generic IP component - Cortex-M0 SCS (System Control Space) (PIDR = 0x04000bb008 DEVTYPE = 0x00 ARCHID = 0x0000)
-> cortexm_probe
CPUID 0x410cc601 (M0+ var 0 rev 1)
remote_v3_adiv5_mem_read_bytes error around 0x1fff0ffc
remote_v3_adiv5_mem_read_bytes error around 0xe00ff004
ROM Table: END
remote_v3_adiv5_mem_write_bytes error around 0xe000edf0
***  1   PY32Fxxx M0+
remote_v3_adiv5_mem_write_bytes error around 0xe000edf0
remote_v3_adiv5_mem_read_bytes error around 0xe000edf0
Can not attach to target 1

My Zoo!
« Last Edit: August 31, 2025, 02:36:31 pm by U6emp »
 

Offline IOsetting

  • Regular Contributor
  • *
  • Posts: 77
  • Country: cn
RE:
In that case, it's pretty much a dead end.
What are you trying to do?
Repurpose the mcu? Just buy a new one, it costs cents...

I have no problems with the purchase, I am trying to analyze how effective the protective measures were that China used )))

As David said, the conventional method may not work. 002B has no BOOT0 pin, and the NRST pin can also be turned off in the code, so unless there is a flaw in the chip itself, it is difficult to connect it with SWD. From the perspective of reverse engineering, a feasible way is to analyze the communication between the printer and the cartridge with a logic analyzer, and make a module to simulate this communication process.
 

Offline U6emp

  • Newbie
  • Posts: 3
  • Country: kg
and make a module to simulate this communication process.

Replacing the chip is not the goal, I managed to drain the firmware, you can just print a few pages and look at the counter, which can be made a little bigger )))
From which I managed to drain this PY32f003S18, 64k flash, 8k RAM
I didn't want to throw these chips in the trash, at their price of 10 cents, but maybe somehow use them in the household )))


Another question, what programmer or programmers are needed for Py32CubeProgrammer (PY-Link and PY-Programmer)? When using J-Link Segger 9 and programming OPTR via J-Link, it damaged two chips.

« Last Edit: September 03, 2025, 02:08:32 pm by U6emp »
 

Offline IOsetting

  • Regular Contributor
  • *
  • Posts: 77
  • Country: cn
Another question, what programmer or programmers are needed for Py32CubeProgrammer (PY-Link and PY-Programmer)? When using J-Link Segger 9 and programming OPTR via J-Link, it damaged two chips.
I am a Ubuntu user, I always use the cheap JLink ob(st-link does't work and pyocd too slow), it works perfectly, I never had a problem.
 

Offline Pixie dust

  • Contributor
  • Posts: 16
  • Country: nl
The PY32Fxx family seems to be extended with a new device called MS32C001 This one is scaled down to 18k flash and 1.5k RAM. They claim in volume you can get them for $0.04
The following hardware is not onboard anymore:
1) Comparators
2) DMA channels

As the data sheet is from a later date it seems they did some improvements on the silicon.
The power consumption of the AD converter is now 300uA at full speed. Also can you use now scale the input voltage range of the AD converter to VCC or 2.5V or 2.048V or 1.5V) which is quite handy for low voltage analog signals.
Currently the device is only available in QFN20 and QFN16.
I have no idea why they called it the MS32C001 and not PY32F001 as it is still a flash device which can be re-programmed.
Also strange is that on their official site they do not mention this device at all.
Here a link were I found the documents: https://www.xinlinggo.com/col.jsp?id=111&m530pageno=2&utm_source=chatgpt.com
« Last Edit: July 27, 2026, 04:08:30 am by Pixie dust »
 

Offline IOsetting

  • Regular Contributor
  • *
  • Posts: 77
  • Country: cn
The PY32Fxx family seems to be extended with a new device called MS32C001 This one is scaled down to 18k flash and 1.5k RAM. They claim in volume you can get them for $0.04
The pin definitions and multiplexing are the same as those of the py32f002b by comparing the datasheet, it should be a reduced version of py32f002b with less peripherals. less ram and flash. Possibly, I guess, the peripheral of py32f002b might still be retained. The retail price 0.4CNY/0.055USD is also close to py32f002b (0.5CNY/0.07USD).
« Last Edit: October 09, 2025, 02:31:39 am by IOsetting »
 
The following users thanked this post: Pixie dust

Offline @

  • Contributor
  • Posts: 29
  • Country: ch
What I know about PY32L020 is that it has an extra "deep stop" mode while PY32F002B only has "stop" mode.
The register value for selecting the deep low power regulator is accepted by the PY32F002B. But the feature seems to have been castrated somehow. If you don't wake up every second or so using the LPTIM, the regulator seems to gradually fail to regulate. The internal voltage falls, the LSI frequency gets lower until it stops and the chip can't wake up anymore.

Or am I doing something wrong here? Has someone managed to use the deep stop mode on the PY32F002B? I'm not even concerned about a price difference between F002B and L020, the latter simply isn't readily available.

(Note that "deep stop" is a term proprietary to Puya, it uses the Arm deep sleep mode but so does regular stop mode. Deep stop mode as opposed to stop mode simply means selecting a different voltage regulator)

A pitfall with using the LPTIM to periodically wake up from stop mode is the need to wait for the ARRM flag reset to propagate to the low-clock domain. The application notes document has details on it.
« Last Edit: November 30, 2025, 07:33:23 pm by @ »
 

Offline IOsetting

  • Regular Contributor
  • *
  • Posts: 77
  • Country: cn
Has someone managed to use the deep stop mode on the PY32F002B?
I tested it before. I have forgot the details. Have you tried this code?
https://github.com/IOsetting/py32f0-template/tree/main/Examples/PY32F002B/LL/PWR/PWR_DeepStop
 

Offline @

  • Contributor
  • Posts: 29
  • Country: ch
I tested it before. I have forgot the details. Have you tried this code?
Yes, thank you IOsetting for that code which I had tried before. As it is it works fine, but if I enable LSI and MCO for it, you can see the frequency drop, slowly at first but within a few seconds it stops completely. Wake-up via EXTI still seems to work.

This seems to match your comments in the LPTIM example:
Code: [Select]
  * - LED blinks every 5 seconds (In low voltage LSI becomes slower and slower, the
  *   interval will be longer than expected)

Code: [Select]
   * Set autoreload value, it must be modified only when LPTIM is enabled
   *
   * 1024 -> 4 seconds
   * 1280 -> 7 seconds
   * 1536 -> 26 seconds
   * 1792 -> never wakeup

So it seems that staying in deep stop for more than about ~3 seconds is not possible when waking up with LPTIM, unless you're ok with the frequency dropping. And even that is probably risky due to tolerances, temperature drift etc.

I'll try to get a 32768Hz crystal to try the LSE.
 

Offline IOsetting

  • Regular Contributor
  • *
  • Posts: 77
  • Country: cn
you are right, using LPTIM with LSI for wakeup from deep stop mode has a time limitation, beyond which the LSI frequency becomes unreliable. LSE might resolve it but it will take 2 extra pins and a bit more power consumption.
 

Offline struberg

  • Newbie
  • Posts: 4
  • Country: at
I have a bunch of py32f002 003 and 030, and they all only supports what puya calls 'sleep mode' and 'stop mode'. Due to puya_stop_mode keeps RAM and Registers powered it still takes around 4.3µA if everything else is off.

The L parts seem to implement the ARM deepsleep mode, ST calls it 'standby mode' where even Registers and RAM are lost (except a special standby register which survives).

My question: anyone got to measure the current consumption in that mode? For reference: if I halt an ATTiny402 it consumes around 135nA.
My application is a battery powered device which sits around for months (potentially years) in shutdown and wakes up on a keypress.
 

Offline @

  • Contributor
  • Posts: 29
  • Country: ch
My question: anyone got to measure the current consumption in that mode? For reference: if I halt an ATTiny402 it consumes around 135nA.
My application is a battery powered device which sits around for months (potentially years) in shutdown and wakes up on a keypress.

The halt mode current is irrelevant if it doesn't need to wake up by itself (i.e. with a timer). Just use a soft latching switch like in Dave's video #262:

Plenty more information if you search for "soft power switch mcu":

https://www.eevblog.com/forum/beginners/circuit-for-low-side-mcu-controlled-soft-power-switch/

https://electronics.stackexchange.com/questions/9015/how-to-implement-a-soft-power-switch-controllable-by-microcontroller

http://www.mosaic-industries.com/embedded-systems/microcontroller-projects/electronic-circuits/push-button-switch-turn-on/microcontroller-latching-on-off

The useful metric for the ATTiny402 is "Standby", which is specced at 0.7uA. In this mode it is able to wake itself with the RTC. Admittedly better than the PY32L020 which consumes 1.7uA.
 

Offline struberg

  • Newbie
  • Posts: 4
  • Country: at
A soft-latch won't help much in my case. The button does not only wake up the mcu but also acts as a data input when running.
Plus adding a dozen components doesn't pay off. Currently the circuit is using a attiny402 and this works fine.
I was just looking into the py32 as a potential replacement.
 

Offline @

  • Contributor
  • Posts: 29
  • Country: ch
A soft-latch won't help much in my case. The button does not only wake up the mcu but also acts as a data input when running.
Ah yes, probably the best link in that case would be: https://circuitcellar.com/resources/quickbits/soft-latching-power-circuits/

The circuits in figure 2 and 3 allow the button press to be detected by the MCU.

More discussion on this forum that I missed the first time around: https://www.eevblog.com/forum/beginners/push-button-power-circuit-for-arduino-trying-to-modify-it-for-12v-input/

But yes, it's a few more simple components than what is needed when the MCU can wake itself from sleep.
« Last Edit: December 17, 2025, 07:21:18 pm by @ »
 

Offline ak0w

  • Newbie
  • Posts: 2
  • Country: tr
Hi all,

One question here, I can't find download link for "PY32CubeProgrammer" in the official website of Puya either in English or Chinese.
I am sure I downloaded it once earlier but can't find the archive file.

Can anybody check it for me please?

Thank you in advance
 

Offline DavidAlfaTopic starter

  • Super Contributor
  • ***
  • Posts: 6924
  • Country: es
I think it's now DFU Tool?
« Last Edit: January 15, 2026, 07:41:53 am by DavidAlfa »
Hantek DSO2x1x            Drive        FAQ          DON'T BUY HANTEK! (Aka HALF-MADE)
Stm32 Soldering FW      Forum      Github      Donate
 
The following users thanked this post: bingo600

Offline corgon

  • Contributor
  • Posts: 43
  • Country: sk
Hi,
I’d like to ask for advice on how to restore the nBOOT bit on the PY32F030.
I switched the nBOOT bit to 0, and as a result I no longer have access to the bootloader via the PY32ISP Tool over USART  :palm:.
The chip can still be programmed without any issues via SWD in KEIL (uVision) using an ST-LINK V2 clone.
How can I set the option bytes back to their original values?

Thank you for any advice.
 

Offline DavidAlfaTopic starter

  • Super Contributor
  • ***
  • Posts: 6924
  • Country: es
Just erase it?
Hantek DSO2x1x            Drive        FAQ          DON'T BUY HANTEK! (Aka HALF-MADE)
Stm32 Soldering FW      Forum      Github      Donate
 

Offline DavidAlfaTopic starter

  • Super Contributor
  • ***
  • Posts: 6924
  • Country: es
You can program it, right?
Then enter the bootloader manually, from the code:

Code: [Select]
typedef struct {
    uint32_t Initial_SP;
    void (*Reset_Handler)(void);
}boot_vectable_t;

boot_vectable_t * BOOTVTAB =  (boot_vectable_t *) 0x1FFF0000;             // PY32 system bootloader base address;

void JumpToBootloader(void) {
  __set_MSP(BOOTVTAB->Initial_SP);                                          // Set the MSP
  BOOTVTAB->Reset_Handler();                                                // Jump to bootloader
}

void main(void){
  JumpToBootloader();
}
« Last Edit: August 16, 2026, 08:17:17 pm by DavidAlfa »
Hantek DSO2x1x            Drive        FAQ          DON'T BUY HANTEK! (Aka HALF-MADE)
Stm32 Soldering FW      Forum      Github      Donate
 
The following users thanked this post: corgon

Offline corgon

  • Contributor
  • Posts: 43
  • Country: sk
Woo Hoo, it works  :-+.
Thank you.
 

Offline ak0w

  • Newbie
  • Posts: 2
  • Country: tr
Hi David,
Thank you, but that is not it. Found it in my external drive. Check the link.

Hi Corgon,
You can use py32cubeprogrammer to program OB. I have checked it with 002B and j-link.


https://drive.google.com/drive/folders/15x-FGZ9v2DObvev4eUiaZ-RR5lAMeuK-?usp=sharing
 

Offline DavidAlfaTopic starter

  • Super Contributor
  • ***
  • Posts: 6924
  • Country: es
Hantek DSO2x1x            Drive        FAQ          DON'T BUY HANTEK! (Aka HALF-MADE)
Stm32 Soldering FW      Forum      Github      Donate
 

Offline josip

  • Regular Contributor
  • *
  • Posts: 176
  • Country: hr
I see in datasheet that VCC is up to 5.5V (and 6.5V absolute maximum). Anyone using it on 5V?

Looking for something to use inside 5V retro devices.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->