DL6ER 1bc0f00d64 webserver: only raise the mbedTLS debug threshold when debug.tls is set
Our civetweb patch defined `MG_CONFIG_MBEDTLS_DEBUG 3` unconditionally, so `mod_mbedtls.inl` called `mbedtls_debug_set_threshold(3)` in every build. mbedTLS formats each message with `vsnprintf()` *before* it reaches `FTL_mbed_debug()`, which then discards it unless `debug.tls` is set - so release builds paid for formatting every message up to level 3 and threw the result away.

The threshold now follows `debug.tls` and is updated whenever the debug flags are (re)loaded, so toggling it at runtime keeps working. Measured on bulk HTTPS transfers, this is around 4% less CPU; under the pathological TLS read loop reported in #3095 the discarded formatting accounted for roughly a third of all samples.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2026-09-19 16:16:20 +02:00
2026-09-19 16:16:01 +02:00
2026-06-08 19:59:53 +02:00
…
…
…

Pi-hole logo
Network-wide ad blocking via your own Linux hardware

FTLDNS logo

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole®'s Web interface.

  • Fast: stats are read directly from memory by coupling our codebase closely with dnsmasq
  • Versatile: upstream changes to dnsmasq can quickly be merged in without much conflict
  • Lightweight: runs smoothly with minimal hardware and software requirements such as Raspberry Pi Zero
  • Interactive: our API can be used to interface with your projects
  • Insightful: stats normally reserved inside of dnsmasq are made available so you can see what's really happening on your network

Official documentation

The official FTLDNS documentation can be found here.

Installation

FTLDNS (pihole-FTL) is automatically installed when installing Pi-hole.

IMPORTANT

FTLDNS will disable any existing installations of dnsmasq. This is because FTLDNS is dnsmasq + Pi-hole's code, so both cannot run simultaneously.

Languages
C 96.7%
Python 1.1%
C++ 1.1%
Shell 0.7%
CMake 0.3%