Short answer: On most cPanel servers /tmp is a small loop-mounted file (/usr/tmpDSK) created by /usr/local/cpanel/scripts/securetmp, and /var/tmp shares it. When it fills, find the culprit with du, find with size and age filters and lsof -a +L1 /tmp, delete only old files you have identified, and if the partition is simply too small, set Size, in MB, for the /tmp partition secured by securetmp in WHM Tweak Settings and reboot.
Applies to AlmaLinux 9, cPanel & WHM 11.138, MariaDB 10.11
We ran the checking commands on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138, MariaDB 10.11, three WordPress sites) on 7 October 2026; the values quoted below come from that run. We did not delete files or resize /tmp on the lab; those steps are checked against the cPanel documentation linked below and the securetmp script shipped with 11.138.
Table of Contents
Symptoms of a full /tmp on cPanel
A full /tmp rarely says so directly. Typical signs:
- File uploads fail in WordPress or other PHP apps, for example with “Failed to write file to disk.”
- MariaDB/MySQL errors such as
Errcode: 28 "No space left on device"on files in/tmpor failing large queries and backups. - PHP warnings about failing to write session data, if an app stores sessions in
/tmp. - cPanel backup, update or EasyApache tasks failing while unpacking.
df -hshows/tmpat or near 100% while/still has plenty of space.
Confirm it first, for both space and inodes:
df -h /tmp /var/tmp
df -i /tmp
findmnt /tmp; findmnt /var/tmp
On our lab, findmnt showed both /tmp and /var/tmp on /dev/loop0 (ext4, nosuid,noexec), backed by the file /usr/tmpDSK of about 3.7 GB, giving a 3.4 GB filesystem. Because /var/tmp is the same filesystem, anything written there eats the same space.
How cPanel sets up /tmp (securetmp)
/usr/local/cpanel/scripts/securetmp creates /usr/tmpDSK, formats it, mounts it on /tmp with noexec,nosuid and points /var/tmp at the same mount. It runs at boot from securetmp.service (securetmp --auto --nodaemonize) and its --help lists --auto, install and uninstall. Reading the 11.138 script shows how it sizes the file:
- With no custom size (the default “Use algorithm to determine size”): 5% of the free space on the filesystem that holds
/usr/tmpDSK, at least 512 MB and at most 4 GB. - With a custom size set in Tweak Settings (stored as
securetmp_file_sizein/var/cpanel/cpanel.config): your value in MB, at least 512 MB and at most 90% of the free space. - If the existing
/usr/tmpDSKis the wrong size, the script unmounts/tmpand/var/tmp, deletes the file and builds a new empty one.
That 4 GB cap is why many servers end up with a small /tmp even when the disk is large. Check whether a custom size is set:
grep securetmp_file_size /var/cpanel/cpanel.config
ls -lh /usr/tmpDSK
On our lab the key was present with no value, meaning the algorithm was in use.
Find what fills /tmp
Work from big to small. All of these commands only read; -xdev keeps find and du on the /tmp filesystem.
# Biggest entries at the top level
du -xh --max-depth=1 /tmp 2>/dev/null | sort -rh | head -20
# Biggest single files, with date and owner
find /tmp -xdev -type f -size +50M -printf "%s\t%TY-%Tm-%Td\t%u\t%p\n" 2>/dev/null | sort -rn | head -20
# Which users own the space (files only)
find /tmp -xdev -type f -printf "%u %s\n" 2>/dev/null | awk '{s[$1]+=$2} END {for (u in s) printf "%10.1f MB %s\n", s[u]/1048576, u}' | sort -rn
# Files untouched for more than 7 days
find /tmp -xdev -type f -mtime +7 -printf "%TY-%Tm-%Td %u %p\n" 2>/dev/null | sort | head -50
# Deleted files that are still open (space not freed yet)
lsof -a +L1 /tmp
Our lab was nearly empty (3% used), but the commands still showed the usual suspects: two 34 MB wp_*.tar.gz archives dated 5 October left behind by a WordPress task, and lsof -a +L1 /tmp listed several deleted /tmp/#NN files held open by mariadbd. Those MariaDB entries are its normal temporary files; on a busy server they can be gigabytes and do not show up in du at all, because they are already deleted.
What usually fills /tmp on a cPanel server
| Source | How to recognise it | What to do |
|---|---|---|
| MariaDB/MySQL temporary files | Owner mysql; lsof -a +L1 /tmp shows /tmp/#NN (deleted) held by mariadbd; mysql -NBe "select @@tmpdir" returns /tmp (it did on our lab) | Find the heavy query (mysqladmin processlist). If big sorts and ALTERs are normal, move tmpdir to a larger disk in /etc/my.cnf |
| Stale PHP uploads | Files named php* owned by account users; PHP uses the system temp dir when upload_tmp_dir is not set | Safe to remove when older than a day and not open |
| PHP sessions | Many small sess_* files | cPanel’s EA-PHP stores sessions in /var/cpanel/php/sessions/ea-phpXX (on our lab) and cleans them twice an hour via clean_user_php_sessions. sess_* in /tmp means an app or PHP build with its own session.save_path |
| ClamAV scans | Temporary directories owned by the ClamAV user during scans | Set TemporaryDirectory in clamd.conf to a bigger location; ClamAV’s default is system specific, usually /tmp or /var/tmp |
| Backups, migrations, plugin archives | Large .tar.gz, .zip or .sql files | Check the owning job has finished, then remove |
| Web server work files | /tmp/lshttpd/ on LiteSpeed, systemd-private-* directories | Do not delete; these belong to running services |
MariaDB 11.5 and later can cap temporary space with max_tmp_session_space_usage and max_tmp_total_space_usage. Our lab ran 10.11, which does not have them.
Clean up /tmp safely
Never run rm -rf /tmp/* on a live server. It deletes sockets and lock files that running services need (MariaDB, LiteSpeed, systemd private dirs) and can break them until restart. Delete only files you identified, with an age filter, and list before you delete.
- List what a cleanup would remove, here regular files untouched for more than 2 days, skipping service directories:
find /tmp /var/tmp -xdev -type f -mtime +2 ! -path "*/systemd-private-*" ! -path "/tmp/lshttpd/*" -printf "%TY-%Tm-%Td %u %s %p\n" | sort | less - Check none of them are open:
lsof +D /tmp 2>/dev/null | less. Anything listed belongs to a running process; leave it. - Copy anything that might matter (an unfinished backup, a SQL dump) to a location with space before deleting.
- Delete with the same filter, adding
-deleteat the end:find /tmp /var/tmp -xdev -type f -mtime +2 ! -path "*/systemd-private-*" ! -path "/tmp/lshttpd/*" -delete - For a single known pattern, be specific, for example stale PHP uploads older than a day:
find /tmp -xdev -type f -name "php*" -mmin +1440 -print -delete. - If the space is held by deleted-but-open files, deleting more will not help. Restart the process that holds them (for MariaDB, at a quiet time) or let the query finish.
AlmaLinux already ages /tmp automatically. On our lab /usr/lib/tmpfiles.d/tmp.conf contained q /tmp 1777 root root 10d and q /var/tmp 1777 root root 30d, run daily by systemd-tmpfiles-clean.timer. That only removes files older than 10 or 30 days, so it will not save you from a sudden spike, and you should not shorten it without knowing what your applications keep there.
Resize /tmp the cPanel way
If /tmp keeps filling with legitimate data, make it bigger. For cPanel & WHM 130 and newer, cPanel documents this method:
- Log in to WHM as root and open Home » Server Configuration » Tweak Settings, System tab.
- Find Size, in MB, for the /tmp partition secured by securetmp.
- Change it from Use algorithm to determine size to the size you want in MB, for example 8192 for 8 GB.
- Click Save.
- Reboot the server. The size is applied when
securetmpruns at boot.
cPanel warns that changing this setting deletes the contents of the /tmp partition. The script removes and recreates /usr/tmpDSK when the size differs. Copy anything you need out of /tmp and /var/tmp first, and make sure the filesystem holding /usr has room: the size is capped at 90% of its free space.
Older cPanel versions (128 and earlier) need a manual command-line procedure; cPanel documents it in the same support article, and it does not work in Virtuozzo/OpenVZ containers. If /tmp is a real partition or LVM volume instead of /usr/tmpDSK, securetmp does not size it; grow it with your normal LVM or partition tools.
Check that it worked
df -h /tmp /var/tmpshows free space, anddf -i /tmpshows free inodes.lsof -a +L1 /tmpno longer lists large deleted files.- After a resize and reboot:
findmnt /tmpstill shows the loop device withnoexec,nosuid,ls -lh /usr/tmpDSKmatches the new size, andgrep securetmp_file_size /var/cpanel/cpanel.configshows your value. - Upload a test file through a WordPress site and run a large export or backup that failed before.
- Watch it for a few days:
df -h /tmpfrom cron, or our Disk and Inode Alert script, catches the next spike before users do.
Common problems
dusays /tmp is small butdfsays full. Deleted files are still open. Uselsof -a +L1 /tmpand restart the holding process.- /tmp is full of inodes, not bytes.
df -i /tmpat 100% means millions of tiny files, usually sessions or cache files. Find the directory withfind /tmp -xdev -type f | cut -d/ -f2-3 | sort | uniq -c | sort -rn | head. - The new size did not apply. You saved the Tweak Setting but did not reboot, or the filesystem with
/usrdid not have enough free space, so the script capped the size. - A site breaks after cleanup. You probably removed a socket or lock file. Restart the affected service (MariaDB, LiteSpeed, PHP-FPM), which recreates it.
- /tmp fills again within hours. One job is writing large temp files. Watch it live with
watch -n 10 "du -xsh /tmp; ls -lt /tmp | head"and fix the job, or move its temp directory (MariaDBtmpdir, ClamAVTemporaryDirectory, PHPupload_tmp_dir) to a bigger disk. - The whole disk is full, not just /tmp. See cPanel Disk Full: Safe Cleanup instead.
Official documentation: cPanel: increase the cPanel-generated /tmp filesystem · cPanel: Tweak Settings · systemd tmpfiles.d · PHP: upload_tmp_dir and core ini settings
Related: cPanel Disk Full: Safe Cleanup of Logs, Backups and Mail · cPanel Inode Usage: Find What Uses Inodes and Fix It · Disk full on a production server: recovery runbook · Disk and Inode Alert · cPanel Disk Usage Report
See also: cPanel Disk Full: Safe Cleanup of Logs, Backups and Mail · cPanel Inode Usage: Find What Uses Inodes and Fix It · Disk full on a production server: recovery runbook
Frequently asked questions
Is it safe to delete everything in /tmp on cPanel?
No. Running services keep sockets, lock files and private directories there. Delete only regular files you have identified, older than a day or two, that no process has open.
Why is /tmp only a few GB on a big server?
When no custom size is set, cPanel’s securetmp sizes /usr/tmpDSK at 5% of free space with a 4 GB maximum. Set a custom size in WHM Tweak Settings to go beyond that.
Does resizing /tmp in WHM need a reboot?
Yes. cPanel documents that you must reboot for the new size to apply, and that changing the setting deletes the current contents of /tmp.
Why is /var/tmp full too?
On cPanel servers /var/tmp is mounted from the same /usr/tmpDSK file as /tmp, so they share one filesystem and fill together.
Why does du show less than df on /tmp?
df counts space used by deleted files that are still open, du does not. lsof -a +L1 /tmp lists them; the space is freed when the process closes them or restarts.
Can I move MySQL temporary files off /tmp?
Yes. Set tmpdir in the [mysqld] section of /etc/my.cnf to a directory on a larger disk owned by the mysql user, then restart MariaDB at a quiet time.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- AlmaLinux 9, cPanel & WHM 11.138, MariaDB 10.11
- Last full review
- Next review