Common causes
- session.save_path points to a folder that does not exist
- The PHP user (www-data, nginx or your account user) cannot write to the session folder
- The disk or inode quota is full, so new session files cannot be created
- A Redis or Memcached session handler is configured but the service is down
- Output was sent before session_start(), causing the headers-already-sent variant
- A per-site PHP-FPM pool sets a different save path than the one that exists
How to fix it
- Find the active save path. Check session.save_path and session.save_handler in phpinfo(). The path in the error is the folder PHP is trying to use.
- Create the folder with the right owner. Create it if missing and give it to the PHP user, for example sudo mkdir -p /var/lib/php/sessions && sudo chown www-data:www-data /var/lib/php/sessions && sudo chmod 1733 /var/lib/php/sessions. 1733 lets PHP create files but not list other users' sessions; use 700 for a folder used by a single site.
- Check disk space. Run df -h and df -i. A full disk or inode table stops new session files. Clear old sessions and check that session garbage collection or the system cleanup cron runs.
- Set a per-site path on shared hosting. Point sessions to a private folder outside the web root, for example session.save_path = "/home/user/tmp/sessions" in .user.ini, and create that folder with 700 permissions.
- Fix Redis-backed sessions. If the handler is redis, test the server with redis-cli ping and confirm the save path host and port. Restart Redis or switch back to files while you fix it.
- Start the session before output. If the warning mentions headers already sent, call session_start() at the very top of the script before any echo, HTML or whitespace.
Private session folder for one site (php.ini or .user.ini)
; .user.ini
session.save_handler = files
session.save_path = "/home/user/tmp/sessions"
session.gc_maxlifetime = 1440
# create the folder
mkdir -p /home/user/tmp/sessions && chmod 700 /home/user/tmp/sessions How to stop it happening again
- Keep sessions in a folder only the PHP user can access
- Monitor disk space and inodes on servers with many sessions
- Health-check Redis if it stores sessions
- Call session_start() before any output