A full disk makes MySQL 524 refuse writes and PHP fail to save sessions, and Apache 129 cannot even log it. df reports space per filesystem, du finds what used it, and lsof 574 (github.com/lsof-org/lsof (https://github.com/lsof-org/lsof 574 ), 4.99.4 on Ubuntu 26.04 225 ) shows who holds which file. Check df -i too: millions of tiny session files can exhaust inodes with gigabytes free. When df says full but du finds nothing, a process still holds a deleted file, typically a log removed by hand; the kernel frees the blocks only at the last close:
sudo du -xh --max-depth=1 /var 2>/dev/null | sort -h | tail -3
head -c 2G /dev/zero > /var/tmp/ch01-08/app.log
( exec 3>>/var/tmp/ch01-08/app.log; sleep 600 ) & # a "daemon" holding its log open
rm /var/tmp/ch01-08/app.log
df -h --output=used,avail /
lsof -nP +L1 | grep -E 'COMMAND|ch01-08' # open files with a link count of 0
kill $!; sleep 1; df -h --output=used /334M /var/cache 480M /var/lib 980M /var Used Avail 5.1G 951G COMMAND PID USER FD TYPE DEVICE SIZE/OFF NLINK NODE NAME sleep 15362 dev 3w REG 8,64 2147483648 0 92089 /var/tmp/ch01-08/app.log (deleted) Used 3.1G
du -x stays on one filesystem; repeat it a level deeper to reach the culprit. The 2 GB returned only when its holder exited. On a server, reload the service (systemctl reload apache2 reopens its logs), empty live logs with truncate -s 0 rather than rm, and leave rotation to logrotate 1,548 (Log Rotation).