# /tmp Full on cPanel: Find What Fills It and Clean Up Safely

Source: https://srvscripts.com/guides/cpanel-tmp-full-cleanup/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** On most cPanel servers `/tmp` is a small loop-mounted file (`/usr/tmpDSK`) created by `/usr/local/cpanel/scripts/securetmp`, and `/var/tmp` shares it. When it fills, find the culprit with `du`, `find` with size and age filters and `lsof -a +L1 /tmp`, delete only old files you have identified, and if the partition is simply too small, set **Size, in MB, for the /tmp partition secured by securetmp** in WHM Tweak Settings and reboot.

We ran the checking commands on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138, MariaDB 10.11, three WordPress sites) on 7 October 2026; the values quoted below come from that run. We did not delete files or resize `/tmp` on the lab; those steps are checked against the cPanel documentation linked below and the `securetmp` script shipped with 11.138.

## Symptoms of a full /tmp on cPanel

A full `/tmp` rarely says so directly. Typical signs:

- File uploads fail in WordPress or other PHP apps, for example with “Failed to write file to disk.”

- MariaDB/MySQL errors such as `Errcode: 28 "No space left on device"` on files in `/tmp` or failing large queries and backups.

- PHP warnings about failing to write session data, if an app stores sessions in `/tmp`.

- cPanel backup, update or EasyApache tasks failing while unpacking.

- `df -h` shows `/tmp` at or near 100% while `/` still has plenty of space.

Confirm it first, for both space and inodes:

```
df -h /tmp /var/tmp
df -i /tmp
findmnt /tmp; findmnt /var/tmp
```

On our lab, `findmnt` showed both `/tmp` and `/var/tmp` on `/dev/loop0` (ext4, `nosuid,noexec`), backed by the file `/usr/tmpDSK` of about 3.7 GB, giving a 3.4 GB filesystem. Because `/var/tmp` is the same filesystem, anything written there eats the same space.

## How cPanel sets up /tmp (securetmp)

`/usr/local/cpanel/scripts/securetmp` creates `/usr/tmpDSK`, formats it, mounts it on `/tmp` with `noexec,nosuid` and points `/var/tmp` at the same mount. It runs at boot from `securetmp.service` (`securetmp --auto --nodaemonize`) and its `--help` lists `--auto`, `install` and `uninstall`. Reading the 11.138 script shows how it sizes the file:

- With no custom size (the default “Use algorithm to determine size”): 5% of the free space on the filesystem that holds `/usr/tmpDSK`, at least 512 MB and at most 4 GB.

- With a custom size set in Tweak Settings (stored as `securetmp_file_size` in `/var/cpanel/cpanel.config`): your value in MB, at least 512 MB and at most 90% of the free space.

- If the existing `/usr/tmpDSK` is the wrong size, the script unmounts `/tmp` and `/var/tmp`, deletes the file and builds a new empty one.

That 4 GB cap is why many servers end up with a small `/tmp` even when the disk is large. Check whether a custom size is set:

```
grep securetmp_file_size /var/cpanel/cpanel.config
ls -lh /usr/tmpDSK
```

On our lab the key was present with no value, meaning the algorithm was in use.

## Find what fills /tmp

Work from big to small. All of these commands only read; `-xdev` keeps `find` and `du` on the `/tmp` filesystem.

```
# Biggest entries at the top level
du -xh --max-depth=1 /tmp 2>/dev/null | sort -rh | head -20

# Biggest single files, with date and owner
find /tmp -xdev -type f -size +50M -printf "%s\t%TY-%Tm-%Td\t%u\t%p\n" 2>/dev/null | sort -rn | head -20

# Which users own the space (files only)
find /tmp -xdev -type f -printf "%u %s\n" 2>/dev/null | awk '{s[$1]+=$2} END {for (u in s) printf "%10.1f MB  %s\n", s[u]/1048576, u}' | sort -rn

# Files untouched for more than 7 days
find /tmp -xdev -type f -mtime +7 -printf "%TY-%Tm-%Td %u %p\n" 2>/dev/null | sort | head -50

# Deleted files that are still open (space not freed yet)
lsof -a +L1 /tmp
```

Our lab was nearly empty (3% used), but the commands still showed the usual suspects: two 34 MB `wp_*.tar.gz` archives dated 5 October left behind by a WordPress task, and `lsof -a +L1 /tmp` listed several deleted `/tmp/#NN` files held open by `mariadbd`. Those MariaDB entries are its normal temporary files; on a busy server they can be gigabytes and do not show up in `du` at all, because they are already deleted.

## What usually fills /tmp on a cPanel server

| Source | How to recognise it | What to do |
| --- | --- | --- |
| MariaDB/MySQL temporary files | Owner mysql; lsof -a +L1 /tmp shows /tmp/#NN (deleted) held by mariadbd; mysql -NBe "select @@tmpdir" returns /tmp (it did on our lab) | Find the heavy query (mysqladmin processlist). If big sorts and ALTERs are normal, move tmpdir to a larger disk in /etc/my.cnf |
| Stale PHP uploads | Files named php* owned by account users; PHP uses the system temp dir when upload_tmp_dir is not set | Safe to remove when older than a day and not open |
| PHP sessions | Many small sess_* files | cPanel’s EA-PHP stores sessions in /var/cpanel/php/sessions/ea-phpXX (on our lab) and cleans them twice an hour via clean_user_php_sessions. sess_* in /tmp means an app or PHP build with its own session.save_path |
| ClamAV scans | Temporary directories owned by the ClamAV user during scans | Set TemporaryDirectory in clamd.conf to a bigger location; ClamAV’s default is system specific, usually /tmp or /var/tmp |
| Backups, migrations, plugin archives | Large .tar.gz, .zip or .sql files | Check the owning job has finished, then remove |
| Web server work files | /tmp/lshttpd/ on LiteSpeed, systemd-private-* directories | Do not delete; these belong to running services |

MariaDB 11.5 and later can cap temporary space with `max_tmp_session_space_usage` and `max_tmp_total_space_usage`. Our lab ran 10.11, which does not have them.

## Clean up /tmp safely

Never run `rm -rf /tmp/*` on a live server. It deletes sockets and lock files that running services need (MariaDB, LiteSpeed, systemd private dirs) and can break them until restart. Delete only files you identified, with an age filter, and list before you delete.

- List what a cleanup would remove, here regular files untouched for more than 2 days, skipping service directories:`find /tmp /var/tmp -xdev -type f -mtime +2 ! -path "*/systemd-private-*" ! -path "/tmp/lshttpd/*" -printf "%TY-%Tm-%Td %u %s %p\n" | sort | less`

- Check none of them are open: `lsof +D /tmp 2>/dev/null | less`. Anything listed belongs to a running process; leave it.

- Copy anything that might matter (an unfinished backup, a SQL dump) to a location with space before deleting.

- Delete with the same filter, adding `-delete` at the end: `find /tmp /var/tmp -xdev -type f -mtime +2 ! -path "*/systemd-private-*" ! -path "/tmp/lshttpd/*" -delete`

- For a single known pattern, be specific, for example stale PHP uploads older than a day: `find /tmp -xdev -type f -name "php*" -mmin +1440 -print -delete`.

- If the space is held by deleted-but-open files, deleting more will not help. Restart the process that holds them (for MariaDB, at a quiet time) or let the query finish.

AlmaLinux already ages `/tmp` automatically. On our lab `/usr/lib/tmpfiles.d/tmp.conf` contained `q /tmp 1777 root root 10d` and `q /var/tmp 1777 root root 30d`, run daily by `systemd-tmpfiles-clean.timer`. That only removes files older than 10 or 30 days, so it will not save you from a sudden spike, and you should not shorten it without knowing what your applications keep there.

## Resize /tmp the cPanel way

If `/tmp` keeps filling with legitimate data, make it bigger. For cPanel & WHM 130 and newer, cPanel documents this method:

- Log in to WHM as root and open **Home » Server Configuration » Tweak Settings**, **System** tab.

- Find **Size, in MB, for the /tmp partition secured by securetmp**.

- Change it from **Use algorithm to determine size** to the size you want in MB, for example 8192 for 8 GB.

- Click **Save**.

- Reboot the server. The size is applied when `securetmp` runs at boot.

cPanel warns that changing this setting deletes the contents of the /tmp partition. The script removes and recreates `/usr/tmpDSK` when the size differs. Copy anything you need out of `/tmp` and `/var/tmp` first, and make sure the filesystem holding `/usr` has room: the size is capped at 90% of its free space.

Older cPanel versions (128 and earlier) need a manual command-line procedure; cPanel documents it in the same support article, and it does not work in Virtuozzo/OpenVZ containers. If `/tmp` is a real partition or LVM volume instead of `/usr/tmpDSK`, securetmp does not size it; grow it with your normal LVM or partition tools.

## Check that it worked

- `df -h /tmp /var/tmp` shows free space, and `df -i /tmp` shows free inodes.

- `lsof -a +L1 /tmp` no longer lists large deleted files.

- After a resize and reboot: `findmnt /tmp` still shows the loop device with `noexec,nosuid`, `ls -lh /usr/tmpDSK` matches the new size, and `grep securetmp_file_size /var/cpanel/cpanel.config` shows your value.

- Upload a test file through a WordPress site and run a large export or backup that failed before.

- Watch it for a few days: `df -h /tmp` from cron, or our [Disk and Inode Alert](/scripts/disk-inode-alert/) script, catches the next spike before users do.

## Common problems

- **`du` says /tmp is small but `df` says full.** Deleted files are still open. Use `lsof -a +L1 /tmp` and restart the holding process.

- **/tmp is full of inodes, not bytes.** `df -i /tmp` at 100% means millions of tiny files, usually sessions or cache files. Find the directory with `find /tmp -xdev -type f | cut -d/ -f2-3 | sort | uniq -c | sort -rn | head`.

- **The new size did not apply.** You saved the Tweak Setting but did not reboot, or the filesystem with `/usr` did not have enough free space, so the script capped the size.

- **A site breaks after cleanup.** You probably removed a socket or lock file. Restart the affected service (MariaDB, LiteSpeed, PHP-FPM), which recreates it.

- **/tmp fills again within hours.** One job is writing large temp files. Watch it live with `watch -n 10 "du -xsh /tmp; ls -lt /tmp | head"` and fix the job, or move its temp directory (MariaDB `tmpdir`, ClamAV `TemporaryDirectory`, PHP `upload_tmp_dir`) to a bigger disk.

- **The whole disk is full, not just /tmp.** See [cPanel Disk Full: Safe Cleanup](/guides/cpanel-disk-full-cleanup/) instead.

**Official documentation:** [cPanel: increase the cPanel-generated /tmp filesystem](https://support.cpanel.net/hc/en-us/articles/360063263733) · [cPanel: Tweak Settings](https://docs.cpanel.net/whm/server-configuration/tweak-settings/) · [systemd tmpfiles.d](https://www.freedesktop.org/software/systemd/man/latest/tmpfiles.d.html) · [PHP: upload_tmp_dir and core ini settings](https://www.php.net/manual/en/ini.core.php)

**Related:** [cPanel Disk Full: Safe Cleanup of Logs, Backups and Mail](/guides/cpanel-disk-full-cleanup/) · [cPanel Inode Usage: Find What Uses Inodes and Fix It](/guides/cpanel-inode-usage-find-files/) · [Disk full on a production server: recovery runbook](/guides/runbook-disk-full/) · [Disk and Inode Alert](/scripts/disk-inode-alert/) · [cPanel Disk Usage Report](/scripts/cpanel-disk-usage-report/)

**See also:** [cPanel Disk Full: Safe Cleanup of Logs, Backups and Mail](/guides/cpanel-disk-full-cleanup/) · [cPanel Inode Usage: Find What Uses Inodes and Fix It](/guides/cpanel-inode-usage-find-files/) · [Disk full on a production server: recovery runbook](/guides/runbook-disk-full/)

## Frequently asked questions

### Is it safe to delete everything in /tmp on cPanel?

No. Running services keep sockets, lock files and private directories there. Delete only regular files you have identified, older than a day or two, that no process has open.

### Why is /tmp only a few GB on a big server?

When no custom size is set, cPanel’s securetmp sizes /usr/tmpDSK at 5% of free space with a 4 GB maximum. Set a custom size in WHM Tweak Settings to go beyond that.

### Does resizing /tmp in WHM need a reboot?

Yes. cPanel documents that you must reboot for the new size to apply, and that changing the setting deletes the current contents of /tmp.

### Why is /var/tmp full too?

On cPanel servers /var/tmp is mounted from the same /usr/tmpDSK file as /tmp, so they share one filesystem and fill together.

### Why does du show less than df on /tmp?

df counts space used by deleted files that are still open, du does not. lsof -a +L1 /tmp lists them; the space is freed when the process closes them or restarts.

### Can I move MySQL temporary files off /tmp?

Yes. Set tmpdir in the [mysqld] section of /etc/my.cnf to a directory on a larger disk owned by the mysql user, then restart MariaDB at a quiet time.
