Common causes
- A relative path resolved against the wrong working directory
- The file was not uploaded, was renamed, or differs in case on a Linux server
- File or directory permissions do not let the PHP user read or write it
- open_basedir restricts PHP to certain directories
- allow_url_fopen is Off, or the remote URL returned an error
- SELinux blocks the web server from reading the path
How to fix it
- Use paths relative to the current file. Replace require 'config.php'; with require __DIR__ . '/config.php';. Plain relative paths depend on the current working directory and include_path, which differ between web requests, cron and CLI.
- Confirm the file exists. Run ls -l /var/www/html/config.php with the exact path from the message. Check the case of every folder and file name, because Linux paths are case-sensitive.
- Fix permissions. For Permission denied, make files readable by the PHP user, typically 644 for files and 755 for directories, owned by your deploy user or www-data. Writable folders like cache or uploads need write access for that user.
- Check open_basedir and SELinux. If phpinfo() shows open_basedir, the path must be inside one of the listed directories. On RHEL-based systems, run ls -Z and restorecon -Rv /var/www/html if SELinux contexts are wrong.
- Handle remote URLs properly. For file_get_contents('https://...') errors, check allow_url_fopen in phpinfo() and the HTTP status in the message. cURL or an HTTP client like Guzzle gives better error handling and timeouts.
- Restore Composer files. If the missing file is vendor/autoload.php, run composer install in the project root. The vendor folder is usually not committed to Git and must be installed on each server.
Robust include paths
<?php
// Resolves relative to this file, not the working directory
require_once __DIR__ . '/config.php';
require_once __DIR__ . '/../vendor/autoload.php';
$path = __DIR__ . '/cache/data.json';
if (!is_readable($path)) {
throw new RuntimeException("Cannot read $path");
}
$data = file_get_contents($path); How to stop it happening again
- Build every include path from __DIR__ or a defined base path constant
- Run composer install as part of deployment
- Set ownership and permissions in your deploy script instead of by hand
- Check is_readable() or is_writable() before working with runtime files