concatenate strings

You're viewing an older version of this page (#3283). View the current version.

View versions (3)

NAME

<span class="Nm" id="strcat">strcat</span>

INTERFACE

#include <string.h> char strcat ( char * restrict s, const char * restrict append ) char strncat ( char * restrict s, const char * restrict append, size_t count )

DESCRIPTION

The strcat and strncat functions append a copy of the null-terminated string &#92;c append to the end of the null-terminated string &#92;c s, then add a terminating '<span class="Qlq">\\0</span>'. The string &#92;c s must have sufficient space to hold the result. &#92;n &#92;n The strncat function appends not more than &#92;c count characters from &#92;c append, and then adds a terminating '<span class="Qlq">\\0</span>'.

RETURN VALUES

The strcat and strncat functions return the pointer &#92;c s.

SECURITY CONSIDERATIONS

The strcat function is easily misused in a manner which enables malicious users to arbitrarily change a running program's functionality through a buffer overflow attack. (See the FSA.) &#92;n &#92;n Avoid using strcat . Instead, use strncat or strlcat and ensure that no more characters are copied to the destination buffer than it can hold. &#92;n &#92;n Note that strncat can also be problematic. It may be a security concern for a string to be truncated at all. Since the truncated string will not be as long as the original, it may refer to a completely different resource and usage of the truncated resource could result in very incorrect behavior. Example:

void
foo(const char *arbitrary_string)
{
	char onstack[8] = "";

#if defined(BAD)
	/*
	 * This first strcat is bad behavior.  Do not use strcat!
	 */
	(void)strcat(onstack, arbitrary_string);	/* BAD! */
#elif defined(BETTER)
	/*
	 * The following two lines demonstrate better use of
	 * strncat().
	 */
	(void)strncat(onstack, arbitrary_string,
	    sizeof(onstack) - strlen(onstack) - 1);
#elif defined(BEST)
	/*
	 * These lines are even more robust due to testing for
	 * truncation.
	 */
	if (strlen(arbitrary_string) + 1 >
	    sizeof(onstack) - strlen(onstack))
		err(1, "onstack would be truncated");
	(void)strncat(onstack, arbitrary_string,
	    sizeof(onstack) - strlen(onstack) - 1);
#endif
}

SEE ALSO

reference:bcopy (3) , reference:memccpy (3) , memcpy (3) , memmove (3) , strcpy (3) , reference:strlcat (3) , reference:strlcpy (3)

STANDARDS

The strcat and strncat functions conform to