Enabling RTT console (and logger) appears to corrupt adjacent memory

NCS-3.4.0, on nRF5340, custom board losely based on PAN1783.

No RTT backend, BLE stack works properly:

2026-08-07T05:56:39.031Z <inf> [  0 main] bt_hci_core: HW Platform: Nordic Semiconductor (0x0002)
2026-08-07T05:56:39.031Z <inf> [  0 main] bt_hci_core: HW Variant: nRF53x (0x0003)
2026-08-07T05:56:39.031Z <inf> [  0 main] bt_hci_core: Firmware: Standard Bluetooth controller (0x00) Version 200.12506 Build 888207768
2026-08-07T05:56:39.032Z <inf> [  0 main] bt_hci_core: No ID address. App must call settings_load()
2026-08-07T05:56:39.034Z <inf> [  0 main] bt_hci_core: HCI transport: IPC
2026-08-07T05:56:39.034Z <inf> [  0 main] bt_hci_core: Identity: (REDACTED) (public)
2026-08-07T05:56:39.034Z <inf> [  0 main] bt_hci_core: HCI: version 6.3 (0x11) revision 0x2039, manufacturer 0x0059
2026-08-07T05:56:39.034Z <inf> [  0 main] bt_hci_core: LMP: version 6.3 (0x11) subver 0x2039

RTT enabled, BLE stack reads some garbage:

2026-08-07T06:17:19.030Z <inf> [  0 main] bt_hci_core: HW Platform: Nordic Semiconductor (0x0002)
2026-08-07T06:17:19.030Z <inf> [  0 main] bt_hci_core: HW Variant: nRF53x (0x0003)
2026-08-07T06:17:19.030Z <inf> [  0 main] bt_hci_core: Firmware: Standard Bluetooth controller (0x00) Version 200.12506 Build 888207768
2026-08-07T06:17:19.031Z <inf> [  0 main] bt_hci_core: HCI transport: IPC
2026-08-07T06:17:19.031Z <inf> [  0 main] bt_hci_core: Identity[0]: 00:20:00:00:07:CE (0xc0)
2026-08-07T06:17:19.031Z <inf> [  0 main] bt_hci_core: Identity[1]: 00:00:00:00:00:10 (0x20)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[2]: 01:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[3]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[4]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[5]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[6]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[7]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[8]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[9]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[10]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[11]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[12]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.032Z <inf> [  0 main] bt_hci_core: Identity[13]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[14]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[15]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[16]: 59:20:39:20:39:11 (0x11)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[17]: 00:60:00:00:00:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[18]: 00:00:80:00:20:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[19]: 00:E4:00:00:00:00 (0xc0)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[20]: 00:00:00:22:28:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[21]: F7:00:00:04:00:00 (public)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[22]: 30:00:00:00:0F:FF (0xff)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[23]: 04:80:00:00:7E:79 (0xc0)
2026-08-07T06:17:19.033Z <inf> [  0 main] bt_hci_core: Identity[24]: 00:40:00:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[25]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[26]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[27]: 00:07:23:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[28]: 03:21:55:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[29]: 00:00:00:00:00:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[30]: FD:00:00:00:0D:00 (public)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: Identity[31]: 00:00:00:00:00:00 (0x49)
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: HCI: version 6.3 (0x11) revision 0x2039, manufacturer 0x0059
2026-08-07T06:17:19.034Z <inf> [  0 main] bt_hci_core: LMP: version 6.3 (0x11) subver 0x2039

Printing is done in bt_dev_show_info():

(...)

	for (i = 1; i < bt_dev.id_count; i++) {
		LOG_INF("Identity[%d]: %s", i, bt_addr_le_str(&bt_dev.id_addr[i]));
		
(...)

bt_dev structure with BLE addresses in this case is placed by the linker just after RTT buffer data:

_RTT_SECTION_NAME
                0x20002000                        __rtt_buff_data_start = .
 *(SORT_BY_ALIGNMENT(.rtt_buff_data))
 .rtt_buff_data
                0x20002000     0x1000 modules/segger/libmodules__segger.a(SEGGER_RTT.c.obj)
                0x20002fd0                _SEGGER_RTT
                0x20003000                        __rtt_buff_data_end = ALIGN (0x4)
                0x00001000                        __rtt_buff_data_size = (__rtt_buff_data_end - __rtt_buff_data_start)
 .data.bt_dev   0x20003000      0x158 zephyr/subsys/bluetooth/host/libsubsys__bluetooth__host.a(hci_core.c.obj)
                0x20003000                bt_dev

Is SEGGER RTT driver broken - writing outside its memory buffer or sth?

Relevant prj.conf snippet:

CONFIG_USE_SEGGER_RTT=y
CONFIG_RTT_CONSOLE=y
CONFIG_SEGGER_RTT_BUFFER_SIZE_UP=4096
CONFIG_SEGGER_RTT_MODE_NO_BLOCK_TRIM=n
CONFIG_SEGGER_RTT_MAX_NUM_UP_BUFFERS=1
CONFIG_SEGGER_RTT_MAX_NUM_DOWN_BUFFERS=0

CONFIG_LOG=y
CONFIG_LOG_RATELIMIT=n
CONFIG_LOG_RATELIMIT_FALLBACK_LOG=y
CONFIG_LOG_BUFFER_SIZE=4096
CONFIG_LOG_THREAD_ID_PREFIX=y
CONFIG_LOG_TIMESTAMP_USE_REALTIME=y
CONFIG_LOG_OUTPUT_FORMAT_CUSTOM_TIMESTAMP=y

Related