Repository navigation
Feature Request: Add official support for C2000 Gen 2 and its Expansion Battery (BP2000) #51
Description
Activity
Hi, similar setup to #51 (C2000 Gen 2), but I'm hitting a different, more fundamental issue: my unit's battery ran too low, and now the BMS appears to be in some kind of lockout state — the display shows 0% even though I've verified the individual cells are healthy and balanced (measured externally with a multimeter after charging them separately).
When I try to connect via BLE (both Generic and C1000G2 classes, latest SolixBLE version), the device:
Accepts the connection and GATT service discovery fine
Accepts the notify subscription on 8c850003 fine
But disconnects immediately (BleakError / native BlueZ pairing also fails with AuthenticationCanceled) the instant it receives the stage-0 negotiation write on 8c850002 — it never even sends back an 0801 stage-1 response
This happens 100% consistently across many attempts, with both a stale and a freshly-patched timestamp in NEGOTIATION_COMMAND_0.
I also attempted the OTA firmware update via a modified official app (to bypass the "battery too low to update" check) — the update UI reported "sub-battery updated OK" (nothing connected) but "main unit update failed" at 84%.
Has anyone else encountered this specific BMS-lockout-refuses-all-BLE-sessions behavior? Is there a known recovery procedure (official or otherwise), or a UART command sequence via the internal mainboard↔BMS serial link (RX/TX pins on the BMS connector, 38400 7N1) that's known to clear this kind of fault/lockout state? I can share raw captures. If anyone with a healthy C2000 Gen 2 could do the same tap and share their capture, a byte-level diff would very likely reveal the lockout flag directly
Happy to share full BLE/UART capture logs if useful.
@R-a-K-i C2000G2 support is being worked on under #51, I assume your unit is using an older firmware? Newer firmwares of the G2 class of devices are currently not working due to changes to the authentication mechanism which has been holding up adding support for the C2000G2, progress is being made on it but its slow going.
@flip-dots Thanks! I will contact him.
I have a C2000G2 with BP2000, SolixBLE#50 has support for the expansion battery. But those PR numbers are going to be old, since I am switching the PRs to be easier for @flip-dots to handle/parse.
But disconnects immediately (BleakError / native BlueZ pairing also fails with AuthenticationCanceled) the instant it receives the stage-0 negotiation write on 8c850002 — it never even sends back an 0801 stage-1 response
This is the absolute most recent firmware; it now blocks the unencrypted negotiation. That's why, in my most recent PRs, I am specifically checking the advertisement capability flag for those that provide it, so SolixBLE knows which type of authentication process to use. PR#70
Thank you for the update!
I'm located in Europe and running the latest firmware versions available here:
- SOLIX C2000 Gen 2: v1.2.1.1
- Expansion Battery: v1.9.2.2
The SOLIX C2000 Gen 2 actually works and communicates perfectly fine using the C1000 G2 profile. However, the integration does not recognize or display the expansion battery itself.
It seems the core communication works with this firmware version, but the parameters/entities for the expansion battery are missing.
@R-a-K-i --
I'm located in Europe and running the latest firmware versions available here:
- SOLIX C2000 Gen 2: v1.2.1.1
- Expansion Battery: v1.9.2.2
The SOLIX C2000 Gen 2 actually works and communicates perfectly fine using the C1000 G2 profile. However, the integration does not recognize or display the expansion battery itself.
It seems the core communication works with this firmware version, but the parameters/entities for the expansion battery are missing.
what you are looking for is the C2000G2 code in PR#72 which is waiting for @flip-dots to accept 70 and 71 as well
@jusubbi
take a look at https://www.ti.com/lit/an/sluaa81a/sluaa81a.pdf and https://www.ti.com/lit/an/sluaaq5/sluaaq5.pdf since the battery controllers are TI BQ76952
The MainMCU talks to the BQ over I2C1, not UART, but what you are looking to do is something like:
BQ769x2, 7-bit address 0x08 (write 0x10, read 0x11), I2C-with-CRC, poly 0x07
Send a subcommand: write the 16-bit value little-endian to register 0x3E/0x3F
EXIT_DEEPSLEEP 0x000E (firmware sends this once, then SLEEP_DISABLE,
and checks Control Status bit 2)
SLEEP_DISABLE 0x009A
FET_ENABLE 0x0022 (toggle: only acts when Manufacturing Status FET_EN is clear)
ALL_FETS_ON 0x0096
FET_CONTROL 0x0097 + data byte
I have not tested this myself, since I have not actually removed any feet or screws on my device, only been disassembling the firmware.
Thanks! I will look it.
I managed to download firmware from bms board (GD32F303). Here is the link: https://limewire.com/d/II6ul#KA0cmkX0Tc
@jusubbi, thank you. That provides a couple of things I didn't have, specifically the region below 0x08008000 that isn't included in the OTA files.
Sorry I spam this thread, but I don't know how else I contact you.
I'm still in same situation. OTA update will hangs at 84% after while it goes to 100% and says that, expansion battery updated (I don't even have that) and main failed. I managed to get power from main battery to mainboard by flashing modified firmware to bms:
cat << 'EOF' > patch.py
def patch_firmware(filename):
with open(filename, "rb") as f:
data = bytearray(f.read())
offset = 0x2a0b4
print(f"Ennen patchausta osoitteessa 0x{offset:X}: {data[offset:offset+4].hex()}")
patch_bytes = b'\x00\x20\x70\x47'
for i, b in enumerate(patch_bytes):
data[offset + i] = b
print(f"Jälkeen patchauksen osoitteessa 0x{offset:X}: {data[offset:offset+4].hex()}")
patched_filename = filename.replace(".bin", "_patched.bin")
with open(patched_filename, "wb") as f:
f.write(data)
print(f"Tallennettu patchattu tiedosto nimellä: {patched_filename}")
patch_firmware("firmware.bin")
EOF
python3 patch.py
this will skip some check. it still needs me to start st-util once, then I can close it and power stays. Display still shows 0% and temp shows now -17C. I don't have any I2C usb capable device, so all I do must go througt st-link. I can still do someting in gdb. Also powerbutton can shutdown unit, but not power on. After while bluetooh connection starts to work even device is "off". reset button power on device again. If I want to really shutdown unit, I need first run gdb-multiarch -q firmware_original.elf and then target extended-remote localhost:4242. That drains voltage from mainboard. If I quit from gdb voltage returns to mainboard. Now I flashed back original firmware, so it's stays off.
Sorry I spam this thread, but I don't know how else I contact you.
Fire an email over to me, use jusubbi@kb1ibt.com (I own the whole domain, so it'll just land in a folder filtered for you).
@kb1ibt Thanks! I will mail now and stop spam this thread.
Device Details
Description
Hello! First of all, thank you for this amazing integration.
I am currently using the new Anker SOLIX C2000 Gen 2 with a BP2000 expansion battery. In the integration setup, I selected the "C1000 Gen 2" profile. The main unit works partially with this profile (telemetry like base power and AC/DC toggles are working fine).
However, since the real C1000 Gen 2 hardware does not support expansion batteries, the connected BP2000 battery is currently not detected at all, and no entities are created for it.
I have attached my decrypted debug log from the connection session with the C1000 Gen 2 profile. Hopefully, the raw data provides the necessary structures to implement proper support for the C2000 Gen 2 and its expansion loop.
Thanks a lot for your help!
Debug Log (C1000 Gen 2 Profile)
C1000 Gen 2 Profile.log
Unkown Profile.log
ADDITIONAL UPDATE / ASSUMPTION REGARDING EXPANSION BATTERY
While reviewing the decrypted debug logs, I found a string that likely
represents the connected expansion battery pack.
The hex-encoded value is:
415043444c344530473131363030323131
In the raw decrypted bytes, this serial number is explicitly listed right
next to the expansion battery identifier:
b'\x04\x11APCDL4E0G11600211...A1783_2kWh'