Comma.ai Panda Board

Use TI TCAN3404-Q1 for each of the three CAN channels.
Why it fits:
  • CAN FD: supports data rates up to 8 Mbps
  • Automotive qualified: AEC-Q100
  • 3.3 V MCU interface: compatible with the STM32H725
  • Wide bus fault protection: ±58 V
  • Low-power standby mode
  • Small VSON package: suitable for the 85 × 50 mm board
Recommended orderable part:
  • TCAN3404DRBRQ1
  • Package: 8-pin VSON/DRB, 3 × 3 mm
  • Quantity: 3
Use one TCAN3404-Q1 per channel, followed by the channel’s common-mode choke and PESD2CAN protection. Verify that the footprint includes the exposed thermal pad and connect it to ground with nearby vias.
Recommand NXP product
I recommend the NXP TJA1044GT/3 for each CAN channel.
  • Automotive AEC-Q100
  • CAN FD up to 5 Mbit/s
  • Designed for direct use with 3.3 V microcontrollers, including STM32H725
  • Standby and wake-up support
  • SO8 package, easier to assemble than VSON
  • Bus fault protection and excellent automotive EMC performance
Use three TJA1044GT/3 transceivers, one per CAN-FD channel. For improved signal integrity on long or highly branched automotive networks, consider the newer NXP TJA1443 CAN SIC transceiver, but it is larger and requires more support/configuration.
Replace and review
Replace transceivers
Compare NXP options
Check footprint fit
Update BOM cost

Refine this doc
Ask about this doc
Board Bring-Up Plan
Safety and prerequisites
This is a bench bring-up plan for the live 12 V automotive STM32H725 board. Do not begin in a vehicle. Use an isolated, current-limited bench supply, fused leads, DMM, oscilloscope with appropriate grounding, ST-LINK, USB isolator where needed, and three known-good CAN-FD peers/analyzer ports. External automotive transient, EMC, thermal, and safety validation remains open.
Record board serial number, assembly revision, populated/DNP termination parts, ambient temperature, instruments, firmware commit, CubeMX/HAL version, and results.
0. Unpowered inspection
  1. Inspect polarity/orientation and soldering of J2, F1, D5, D6, U5, L4, U1, U2/IC1/IC2, USB protection D1, CAN protection D2–D4, and all polarized parts.
  2. Verify no conductive debris and no short between VBAT_RAW, VBAT_FUSED, VBAT_PROT, 3V3, and GND.
  3. Measure resistance 3V3-to-GND and 12V-to-GND; compare against a known-good board after the first unit. Stop for a near-short or unstable charging signature that does not settle.
  4. Confirm intended CAN termination population: R5/R6 channel 1, R7/R8 channel 2, R9/R10 channel 3, each 60.4 Ω split pair with center capacitor C25/C26/C27. The schematic labels these as DNP or assembly-selectable; actual BOM/assembly option must be recorded.
1. Safe first 12 V power-on
  1. Disconnect USB, SWD, and all CAN lines. Keep only J2 grounds (pins 4/5) and J2 pin 16 supply connected.
  2. Set bench supply to 0 V, 100 mA current limit initially. Connect + to J2 pin 16 and − to J2 pins 4/5.
  3. Raise slowly to 6 V while watching current and 3V3. If U5 has not started, do not defeat UVLO; continue only if current is low and stable.
  4. Raise to 12.0 V. Stop immediately for current limit, heating, smoke/odor, oscillating current, reverse polarity indication, or 3V3 outside 3.20–3.40 V.
  5. If stable, increase current limit in steps (250 mA, then only as needed up to the documented design peak of 0.6 A input-equivalent assumptions must be rechecked). Record 12 V input current in reset and running states. A current limit is protection, not an acceptance threshold.
Pass: no abnormal heating; protected input path intact; 3V3 regulates; input current stable and explainable. Failures remain powered off until root-caused.
2. 3V3 voltage, ripple, and sequencing
Measure at U1 decoupling, each transceiver VCC, and U5 output capacitor bank:
  • DC target: 3.3 V; initial acceptance 3.20–3.40 V at room temperature and no external bus loading.
  • Ripple: use a short ground spring and 20 MHz bandwidth limit. Preliminary bench target: ≤50 mVpp steady-state and no sustained oscillation. This is an engineering bring-up target, not an automotive qualification limit.
  • Capture startup waveform, overshoot, settling, and 12 V input current. Require 3V3 to remain below 3.6 V absolute operating concern; investigate any overshoot near device limits.
  • Exercise reset and firmware LED/CAN activity; verify no material droop. Repeat with USB attached and all three CAN transceivers active.
Open: cold crank/dropout, load dump, ISO 7637/16750 pulses, conducted/radiated emissions, and temperature-corner testing require qualified external lab plans and approved limits.
3. SWD and reset
  1. With 12 V stable, connect ST-LINK to J3: pin 1 VTref=3V3, pin 2 SWDIO=PA13, pin 4 SWCLK=PA14, pins 3/5/9 GND, pin 10 NRST.
  2. Confirm VTref before attaching the probe. Do not let the debugger back-power the board.
  3. Use low SWD clock first (100–400 kHz), normal connect; if needed use connect-under-reset.
  4. Read device ID, halt core, mass-erase/program a minimal image, reset, and verify execution by active-low LED walk on PE4/PE3/PE2.
  5. Confirm J3 NRST asserts low and releases to 3V3. Confirm BOOT0 remains low through R14 for normal flash boot.
Pass: repeatable detection, erase/program/verify, reset, and execution over ten power cycles. Keep PA13/PA14 reserved for SWD; PB3 is CAN2_STB, not SWO.
4. USB device enumeration
  1. Keep 12 V bench power present and connect J1 to a current-monitored host through a known-good data cable. Avoid unintended ground loops.
  2. Confirm USB VBUS raw ≈5 V and PA0 divider node USB_VBUS_SENSE ≈2.5 V. Confirm 3V3 remains in range.
  3. Load CubeMX USB_OTG_HS Device_Only/internal-FS firmware with peripheral VBUS sensing disabled (the dedicated OTG VBUS-sense pin is not wired); optionally log PA0 via ADC.
  4. Verify D+/D− continuity behavior without probing that materially loads the pair. Enumerate temporary CDC, record VID/PID, speed (12 Mbit/s FS), descriptors, connect/disconnect behavior, suspend/resume, and 100 reconnect cycles.
  5. Replace temporary descriptors/protocol with the official commaai/panda-compatible implementation and repeat host tests.
Pass: stable enumeration, no overcurrent/back-powering, clean reconnect, no 3V3 disturbance. USB eye/compliance testing remains an external-lab item.
5. CAN-FD controller and transceiver tests
Safe firmware state: U2/IC1/IC2 STB high at reset, then low only after FDCAN initialization. Their SHDN pins are hard-grounded.
5.1 Internal loopback (no bus connection)
For FDCAN1, FDCAN2, FDCAN3 separately:
  1. Keep all physical CAN connections disconnected and transceiver in standby.
  2. Configure internal loopback; transmit standard and extended IDs, DLC 0–8 classic, then legal CAN-FD DLCs through 64 bytes with BRS.
  3. Check payload, ID, timestamp/order, RX FIFO operation, interrupts, overflow handling, and error counters.
  4. Run at least 100,000 frames per controller with zero corruption/loss outside intentional overload tests.
5.2 External bus test
Use one known-good CAN-FD peer and termination only at the two physical ends. Do not enable all on-board split terminations by default.

Table


ChannelMCU/transceiverVehicle connector pinsTermination parts
CAN1FDCAN1 PD0/PD1 → U2J2 6 (H), 14 (L)R5/R6, C25
CAN2FDCAN2 PB5/PB6 → IC1J2 3 (H), 11 (L)R7/R8, C26
CAN3FDCAN3 PD12/PD13 → IC2J2 1 (H), 9 (L)R9/R10, C27
For each channel:
  1. With power off, verify H/L continuity and no H/L-to-ground short. Verify total bus resistance: approximately 60 Ω only when two 120 Ω ends are present; approximately 120 Ω with one end. Split pairs total 120.8 Ω nominal when populated.
  2. Power on, release only that channel from standby, and test classic CAN at a conservative rate first.
  3. Test bidirectional CAN-FD at required nominal/data rates, including BRS, all legal DLCs, standard/extended IDs, arbitration, saturation, and long-run error counters.
  4. Scope CANH/CANL common-mode and differential waveforms at both ends. Check ringing, recessive level, symmetry, and error frames.
  5. Assert/deassert STB during idle only; verify no dominant glitch and that RX/TX resumes.
  6. Repeat with all three buses active and USB traffic running. Confirm no cross-channel corruption or supply droop.
Pass: zero unexplained bus-off, protocol errors, or payload corruption in the defined run; correct connector mapping; error counters remain bounded. Final rates, sample points, harness lengths, and acceptance counts must come from system requirements/panda compatibility tests.
6. Fault-oriented bench checks
Perform only with current limiting and approved fixtures:
  • Open CANH/CANL, swapped pair, missing/excess termination, disconnected ground, and connector insertion/removal while idle.
  • One channel bus-off while other two and USB remain operational; verify controlled recovery and logged diagnostic.
  • Brownout/reset cycling; verify all STB outputs return high and LEDs do not imply a safe state before firmware validation.
  • Regulator thermal scan at idle and worst-case communication load.
Do not perform battery pulse, short-to-battery, short-to-ground, reverse battery beyond approved fixture ratings, or thermal chamber testing until a reviewed lab procedure exists.
7. Release evidence and open gates
Archive plots, current logs, SWD transcript, USB enumeration logs, CAN analyzer captures, firmware commit, and pass/fail matrix. Open gates: HARA and ASIL determination, safety concept, external EMC/ESD/transient lab testing, environmental/thermal qualification, connector/harness validation, production test limits, and qualification status of D5/D6.
  • Safety and prerequisites

  • 0. Unpowered inspection

  • 1. Safe first 12 V power-on

  • 2. 3V3 voltage, ripple, and sequencing

  • 3. SWD and reset

  • 4. USB device enumeration

  • 5. CAN-FD controller and transceiver tests

  • 5.1 Internal loopback (no bus connection)

  • 5.2 External bus test

  • 6. Fault-oriented bench checks

  • 7. Release evidence and open gates

Assets

Assets are files uploaded to this project which can be used in various ways.

Red Panda Compatible CAN-FD Interface thumbnail
Automotive USB-C interface based on STM32H725 with three CAN-FD channels, Red Panda-compatible firmware behavior, harness connector, power protection, and connector placement.

Properties

Pricing & Availability

Distributor

Qty 1

Arrow

$15.46–$19.69

Digi-Key

$2.72–$2.92

HQonline

$2.56–$2.73

LCSC

$18.44–$19.00

Mouser

$28.64

TME

$18.00

Verical

$11.09–$22.32

Controls