Emergency server help: get in touch

“Cannot Manage PHP Versions When CageFS Is Disabled”: PHP Selector Fix

Fix "Cannot manage PHP versions when CageFS is disabled" and related CloudLinux PHP Selector errors on cPanel and DirectAdmin.

Published 6 min read

Short answer: CloudLinux PHP Selector only works for users who are inside CageFS. The error “Cannot manage PHP versions when CageFS is disabled” means CageFS is off for that account, for the whole server, or the user is excluded (on DirectAdmin, admin-level users are excluded automatically). Check with cagefsctl --cagefs-status and cagefsctl --user-status bob, enable it with cagefsctl --enable bob, and on cPanel make sure the system PHP is an ea-php version, the domain uses “Inherited” in MultiPHP Manager, and PHP-FPM is off for that domain.

Commands checked against the official CloudLinux documentation and knowledge base (linked below) on 6 October 2026; not yet run on our lab servers (our labs run AlmaLinux without CloudLinux).

Why PHP Selector needs CageFS

PHP Selector gives each user their own choice of alt-php version and modules. It does that by changing what the user sees inside their CageFS jail. A user outside CageFS sees the real system PHP, so there is nothing for the selector to switch. That is why the panel refuses with:

Cannot manage PHP versions when CageFS is disabled

The fix is always to get the user into CageFS, and then to make sure nothing else (MultiPHP, PHP-FPM, the wrong handler) overrides the selector.

Step 1: check CageFS for the server and the user

cagefsctl --cagefs-status          # enabled or disabled for the server
cagefsctl --display-user-mode      # "Enable All" or "Disable All"
cagefsctl --user-status bob        # enabled or disabled for this user
cagefsctl --list-disabled          # users excluded in "Enable All" mode
cagefsctl --list-enabled           # users included in "Disable All" mode

The mode matters. In Enable All mode every user is caged except those listed in /etc/cagefs/users.disabled. In Disable All mode nobody is caged except those in /etc/cagefs/users.enabled, so new accounts are left out unless you add them. Many servers that show this error for new accounts are simply in Disable All mode.

Step 2: enable CageFS for the user

cagefsctl --enable bob
cagefsctl --user-status bob

If CageFS has never been set up on the server, initialise it first. This builds the CageFS skeleton and can take a while on a busy server:

cagefsctl --init
cagefsctl --enable-all     # switch to "Enable All" mode, keeping users.disabled

--enable-all puts every account into CageFS at once. Users who rely on tools only visible outside the jail (custom binaries, cron scripts calling system paths) can break. Try it on a test account first and check cron jobs afterwards.

DirectAdmin: admin users are excluded automatically

CloudLinux documents a DirectAdmin case where CageFS is enabled, the user is not in the disabled list, and the error still appears. The cause: the user was added as a DirectAdmin admin, and DirectAdmin admins are excluded from CageFS through /etc/cagefs/exclude/directadmin.admins.

grep -n "^bob$" /etc/cagefs/exclude/directadmin.admins
# remove the user from that file, then:
cagefsctl --enable bob

Better still, do not host customer sites under an admin account. Create a normal user for the sites, and keep admin accounts for administration only.

cPanel: MultiPHP and PHP-FPM can override the selector

On cPanel, CloudLinux’s integration notes list conditions that must all be true for PHP Selector to take effect:

  • LVE Manager, CageFS and alt-php packages are installed.
  • In WHM MultiPHP Manager, the System PHP Version is an ea-phpXX version, not alt-phpXX.
  • The domain’s PHP version in MultiPHP Manager is Inherited. A specific version set there has higher priority than PHP Selector.
  • PHP-FPM is off for the domain. CloudLinux says PHP Selector is not compatible with it.
  • The Apache PHP handler supports the selector. CloudLinux recommends mod_lsapi.

If the system default is an alt-php version, users see this instead:

System default PHP version is alt-php. PHP Selector is disabled. Use cPanel MultiPHP manager instead

Set an ea-php version as the system default in MultiPHP Manager to clear it.

Error textCause (per CloudLinux KB)Fix
Cannot manage PHP versions when CageFS is disabledUser not in CageFS, or excluded as a DirectAdmin admincagefsctl --enable USER; remove from directadmin.admins
User USER not in CageFSSame as aboveSame as above
No selector dir for user USERThe .cl.selector folder is missing from the home directory, often after a migrationcagefsctl --rebuild-alt-php-ini USER, then cagefsctl --force-update && cagefsctl -m USER
Looks like your PHP handler doesn’t support CloudLinux PHP Selectorea-apache24-mod_suexec missing, or mod_ruid2 in useRemove mod_ruid2, install ea-apache24-mod_suexec, restart Apache, cagefsctl --force-update
No alt-php versions shown, empty selector.confBroken alt-php install left /etc/cl.selector/selector.conf emptyyum -y reinstall alt-php??-common alt-php??, then cagefsctl --force-update
System default PHP version is alt-phpSystem PHP set to alt-php in MultiPHP ManagerChoose an ea-php version as the system default

The handler fix from the CloudLinux knowledge base, for cPanel servers running mod_ruid2:

yum remove ea-apache24-mod_ruid2
yum install ea-apache24-mod_suexec
service httpd restart
cagefsctl --force-update

Removing mod_ruid2 changes how Apache runs PHP and files for every site. Check which sites depend on it and take an EasyApache profile backup before you change modules.

Let cldiag check it for you

CloudLinux ships a diagnostic tool that catches most of these misconfigurations:

cldiag --check-phpselector
cldiag --check-suexec
cldiag --all

Fix what it reports, run cagefsctl --force-update if you changed packages, and check the user again.

Check that it worked

cagefsctl --user-status bob
selectorctl --user-current --user=bob
# set a version from the shell to prove the selector works:
selectorctl --set-user-current=8.3 --user=bob
# or with the newer tool:
cloudlinux-selector set --interpreter php --user bob --version 8.3

Then open the PHP Selector page in the user’s panel: the version list should load without the CageFS error, and a phpinfo() page in the user’s site should show the selected alt-php version.

Official documentation: CloudLinux KB: Cannot manage PHP versions when CageFS is disabled · CloudLinux KB: PHP Selector integration with cPanel · CloudLinux: Command-line tools · CloudLinux KB: Common cldiag errors

Related: CloudLinux 10 cPanel: CageFS and LVE Limits, Upgrade Notes · Harden Shared cPanel Server: Secure CageFS and ModSecurity Setup · EasyApache 4 PHP Versions 8.2 to 8.5: Install and Switch · MultiPHP Manager Bulk PHP Version Changes (cPanel 136+) · cPanel PHP Version Audit

See also: CloudLinux LVE Limits Explained: SPEED, PMEM, EP, NPROC, IO · “508 Resource Limit Is Reached”: Find and Fix the Limit

Frequently asked questions

Can PHP Selector work without CageFS?

No. PHP Selector switches PHP inside the CageFS jail, so the user must be in CageFS for it to work.

Why does a new cPanel account get the CageFS error?

The server is probably in “Disable All” mode, where new users are not caged. Enable them with cagefsctl –enable or switch to “Enable All” mode.

Why does a DirectAdmin user with CageFS enabled still get the error?

If the user is a DirectAdmin admin, CloudLinux excludes it through /etc/cagefs/exclude/directadmin.admins. Remove it from that file and enable CageFS again.

Does PHP Selector work with PHP-FPM on cPanel?

No. CloudLinux says PHP Selector is not compatible with PHP-FPM; turn PHP-FPM off for domains that should use it.

How do I fix “No selector dir for user”?

Run cagefsctl –rebuild-alt-php-ini USER, then cagefsctl –force-update and cagefsctl -m USER.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.