World Library  
Flag as Inappropriate
Email this Article

C string handling

Article Id: WHEBN0033691376
Reproduction Date:

Title: C string handling  
Author: World Heritage Encyclopedia
Language: English
Subject: C dynamic memory allocation, C mathematical functions, C programming language, ANSI C, C (programming language)
Publisher: World Heritage Encyclopedia

C string handling

C string handling refers to a group of functions implementing operations on strings in the C standard library. Various operations, such as copying, concatenation, tokenization and searching are supported.

The only support for strings in the C programming language itself is that the compiler will translate a quoted string constant into a null-terminated string, which is stored in static memory. However, the C standard library provides a large number of functions designed to manipulate these null-terminated strings. These functions are so popular and used so often that they are usually considered part of the definition of C.


A string is a contiguous sequence of code units terminated by the first zero code (written '\0' and corresponding to the ASCII null character). In C, there are two types of strings: string, which is sometimes called byte string which uses the type chars as code units (one char is at least 8 bits), and wide string[1] which uses the type wchar_t as code units.

A common misconception is that all char arrays are strings, because string literals are converted to arrays during the compilation (or translation) phase.[2] It is important to remember that a string ends at the first zero code unit. An array or string literal that contains a zero before the last byte therefore contains a string, or possibly several strings, but is not itself a string.[3] Conversely, it is possible to create a char array that is not null-terminated and is thus not a string: char is often used as a small integer when needing to save memory.

The term pointer to a string is used in C to describe a pointer to the initial (lowest-addressed) byte of a string.[1] In C, pointers are used to pass strings to functions. Documentation (including this page) will often use the term string to mean pointer to a string.

The term length of a string is used in C to describe the number of bytes preceding the zero byte.[1] strlen is a standardised function commonly used to determine the length of a string. A common mistake is to not realize that a string uses one more unit of memory than this length, in order to store the zero that ends the string.

Character encodings

Each string ends at the first occurrence of the zero code unit of the appropriate kind (char or wchar_t). Consequently, a byte string can contain non-NUL characters in ASCII or any ASCII extension, but not characters in encodings such as UTF-16 (even though a 16-bit code unit might be nonzero, its high or low byte might be zero). The encodings that can be stored in wide strings are defined by the width of wchar_t. In most implementations, wchar_t is at least 16 bits, and so all 16-bit encodings, such as UCS-2, can be stored. If wchar_t is 32-bits, then 32-bit encodings, such as UTF-32, can be stored.

Variable-width encodings can be used in both byte strings and wide strings. String length and offsets are measured in bytes or wchar_t, not in "characters", which can be confusing to beginning programmers. UTF-8 and Shift JIS are often used in C byte strings, while UTF-16 is often used in C wide strings when wchar_t is 16 bits. Truncating strings with variable length characters using functions like strncpy can produce invalid sequences at the end of the string. This can be unsafe if the truncated parts are interpreted by code that assumes the input is valid.

Support for Unicode literals such as char foo[512] = "φωωβαρ";(UTF-8) or wchar_t foo[512] = L"φωωβαρ"; (UTF-16 or UTF-32) is implementation defined,[4] and may require that the source code be in the same encoding. Some compilers or editors will require entering all non-ASCII characters as \xNN sequences for each byte of UTF-8, and/or \uNNNN for each word of UTF-16.

Overview of functions

Most of the functions that operate on C strings are declared in the string.h header (cstring in C++), while functions that operate on C wide strings are declared in the wchar.h header (cwchar in C++). These headers also contain declarations of functions used for handling memory buffers; the name is thus something of a misnomer.

Functions declared in string.h are extremely popular since, as a part of the C standard library, they are guaranteed to work on any platform which supports C. However, some security issues exist with these functions, such as potential buffer overflows when not used carefully and properly, causing the programmers to prefer safer and possibly less portable variants, out of which some popular ones are listed below. Some of these functions also violate const-correctness by accepting a const string pointer and returning a non-const pointer within the string. To correct this, some have been separated into two overloaded functions in the C++ version of the standard library.

In historical documentation the term "character" was often used instead of "byte" for C strings, which leads many to believe that these functions somehow do not work for UTF-8. In fact all lengths are defined as being in bytes and this is true in all implementations, and these functions work as well with UTF-8 as with single-byte encodings. The BSD documentation has been fixed to make this clear, but POSIX, Linux, and Windows documentation still uses "character" in many places where "byte" or "wchar_t" is the correct term.

Functions for handling memory buffers can process sequences of bytes that include null-byte as part of the data. Names of these functions typically start with mem, as opposite to the str prefix.

Constants and types

Name Notes
NULL Macro expanding to the null pointer constant; that is, a constant representing a pointer value which is guaranteed not to be a valid address of an object in memory.
wchar_t Type used for a code unit in a wide strings, usually either 16 or 32 bits.
wint_t Integer type that can hold any value of a wchar_t as well as the value of the macro WEOF. This type is unchanged by integral promotions. Usually a 32 bit signed value.
mbstate_t Contains all the information about the conversion state required from one call to a function to the other.


Description[note 1]
strcpy[5] wcscpy[6] copies one string to another
strncpy[7] wcsncpy[8] writes exactly n bytes/wchar_t, copying from source or adding nulls
strcat[9] wcscat[10] appends one string to another
strncat[11] wcsncat[12] appends no more than n bytes/wchar_t from one string to another
strxfrm[13] wcsxfrm[14] transforms a string according to the current locale
strlen[15] wcslen[16] returns the length of the string
strcmp[17] wcscmp[18] compares two strings
strncmp[19] wcsncmp[20] compares a specific number of bytes/wchar_t in two strings
strcoll[21] wcscoll[22] compares two strings according to the current locale
strchr[23] wcschr[24] finds the first occurrence of a byte/wchar_t in a string
strrchr[25] wcsrchr[26] finds the last occurrence of a byte/wchar_t in a string
strspn[27] wcsspn[28] finds in a string the first occurrence of a byte/wchar_t not in a set
strcspn[29] wcscspn[30] finds in a string the last occurrence of a byte/wchar_t not in a set
strpbrk[31] wcspbrk[32] finds in a string the first occurrence of a byte/wchar_t in a set
strstr[33] wcsstr[34] finds the first occurrence of a substring in a string
strtok[35] wcstok[36] splits string into tokens
Miscellaneous strerror[37] N/A returns a string containing a message derived from an error code
memset[38] wmemset[39] fills a buffer with a repeated byte/wchar_t
memcpy[40] wmemcpy[41] copies one buffer to another
memmove[42] wmemmove[43] copies one buffer to another, possibly overlapping, buffer
memcmp[44] wmemcmp[45] compares two buffers
memchr[46] wmemchr[47] finds the first occurrence of a byte/wchar_t in a buffer
  1. ^ Here string refers either to byte string or wide string

Multibyte functions

Name Description
mblen[48] returns the number of bytes in the next multibyte character
mbtowc[49] converts the next multibyte character to a wide character
wctomb[50] converts a wide character to its multibyte representation
mbstowcs[51] converts a multibyte string to a wide string
wcstombs[52] converts a wide string to a multibyte string
btowc[53] convert a single-byte character to wide character, if possible
wctob[54] convert a wide character to a single-byte character, if possible
mbsinit[55] checks if a state object represents initial state
mbrlen[56] returns the number of bytes in the next multibyte character, given state
mbrtowc[57] converts the next multibyte character to a wide character, given state
wcrtomb[58] converts a wide character to its multibyte representation, given state
mbsrtowcs[59] converts a multibyte string to a wide string, given state
wcsrtombs[60] converts a wide string to a multibyte string, given state

"state" is used by encodings that rely on history such as shift states. This is not needed by UTF-8 or UTF-32. UTF-16 uses them to keep track of surrogate pairs and to hide the fact that it actually is a multi-word encoding.

Numeric conversions

Description[note 1]
atof[61] N/A converts a string to a floating-point value
N/A converts a string to an integer (C99)
strtof (C99)[63]
strtold (C99)[65]
wcstof (C99)[66]
wcstold (C99)[68]
converts a string to a floating-point value
converts a string to a signed integer
converts a string to an unsigned integer
  1. ^ Here string refers either to byte string or wide string

The C standard library contains several functions for numeric conversions. The functions that deal with byte strings are defined in the stdlib.h header (cstdlib header in C++). The functions that deal with wide strings are defined in the wchar.h header (cwchar header in C++). Note that the strtoxxx functions are not const-correct, since they accept a const string pointer and return a non-const pointer within the string.

Popular extensions

Name Platform Description
memccpy[73] SVID, POSIX copies up to specified number of bytes between two memory areas, which must not overlap, stopping when a given byte is found.
mempcpy[74] GNU a variant of memcpy returning a pointer to the byte following the last written byte
strcasecmp[75] POSIX, BSD case-insensitive versions of strcmp
strcat_s[76] C (2011) and ISO/IEC WDTR 24731 a variant of strcat that checks the destination buffer size before copying
strcpy_s[77] C (2011) and ISO/IEC WDTR 24731 a variant of strcpy that checks the destination buffer size before copying
strdup[78] POSIX allocates and duplicates a string
strerror_r[79] POSIX 1, GNU a variant of strerror that is thread-safe. GNU version is incompatible with POSIX one.
stricmp[80] Various case-insensitive versions of strcmp
strlcpy[81] BSD a variant of strcpy that truncates the result to fit in the destination buffer[82]
strlcat[83] BSD a variant of strcat that truncates the result to fit in the destination buffer[82]
strsignal[84] POSIX:2008 returns string representation of a signal code. Not thread safe.
strtok_r[85] POSIX a variant of strtok that is thread-safe

Strcat/strcpy replacements

Despite the well-established need to replace strcat and strcpy with functions that do not allow buffer overflows, no accepted standard has arisen. This is partly due to the mistaken belief by many C programmers that strncat and strncpy have the desired behavior; however, neither function was designed for this and the behavior and arguments are non-intuitive and often written incorrectly even by expert programmers.[82]

strcat_s and strcpy_s functions return an error indicator upon buffer overflow, together with setting the output buffer to a zero-length string, which destroys data in the case of strcat_s. These functions attracted considerable criticism because initially they were implemented only on Windows, and at the same time warning messages started to be produced by Microsoft Visual C++, suggesting the programmers to use these functions instead of standard ones. This has been speculated by some to be a Microsoft's attempt to lock developers into its platform.[86][87][88] Although open-source implementations of these functions are available,[89] the absence of these functions from the standard libraries used in Unix-based and Unix-like operating systems is due to the consensus that the design of these functions is incorrect, as they technically prevent buffer overflows but make detecting or recovering from such mistakes impossible . They are part of C11 (Annex K), and are listed in ISO/IEC WDTR 24731.

The more popular strlcat and strlcpy functions have been criticized on the basis that they encourage use of C strings and thus create more problems than they solve.[90][91] Consequently they have not been included in the GNU C library (used by software on Linux), although they are implemented in OpenBSD, FreeBSD, NetBSD, Solaris, Mac OS X, and QNX. The lack of GNU C library support has not stopped various library authors from using it and bundling a replacement, among other SDL, GLib, ffmpeg, rsync, and even internally in the Linux kernel. Open source implementations for these functions are available.[92][93]

See also


  1. ^ a b c "The C99 standard draft + TC3". §7.1.1p1. Retrieved 7 January 2011. 
  2. ^ "The C99 standard draft + TC3". §6.4.5p7. Retrieved 7 January 2011. 
  3. ^ "The C99 standard draft + TC3". Section 6.4.5 footnote 66. Retrieved 7 January 2011. 
  4. ^ "The C99 standard draft + TC3". § Translation phases, p1. Retrieved 23 December 2011. 
  5. ^ "strcpy -". 2014-01-02. Retrieved 2014-03-06. 
  6. ^ "wcscpy -". Retrieved 2014-03-06. 
  7. ^ "strncpy -". 2013-10-04. Retrieved 2014-03-06. 
  8. ^ "wcsncpy -". Retrieved 2014-03-06. 
  9. ^ "strcat -". 2013-10-08. Retrieved 2014-03-06. 
  10. ^ "wcscat -". Retrieved 2014-03-06. 
  11. ^ "strncat -". 2013-07-01. Retrieved 2014-03-06. 
  12. ^ "wcsncat -". Retrieved 2014-03-06. 
  13. ^ "strxfrm -". Retrieved 2014-03-06. 
  14. ^ "wcsxfrm -". Retrieved 2014-03-06. 
  15. ^ "strlen -". 2013-12-27. Retrieved 2014-03-06. 
  16. ^ "wcslen -". Retrieved 2014-03-06. 
  17. ^ "strcmp -". Retrieved 2014-03-06. 
  18. ^ "wcscmp -". Retrieved 2014-03-06. 
  19. ^ "strncmp -". Retrieved 2014-03-06. 
  20. ^ "wcsncmp -". Retrieved 2014-03-06. 
  21. ^ "strcoll -". Retrieved 2014-03-06. 
  22. ^ "wcscoll -". Retrieved 2014-03-06. 
  23. ^ "strchr -". 2014-02-23. Retrieved 2014-03-06. 
  24. ^ "wcschr -". Retrieved 2014-03-06. 
  25. ^ "strrchr -". Retrieved 2014-03-06. 
  26. ^ "wcsrchr -". Retrieved 2014-03-06. 
  27. ^ "strspn -". Retrieved 2014-03-06. 
  28. ^ "wcsspn -". Retrieved 2014-03-06. 
  29. ^ "strcspn -". 2013-05-31. Retrieved 2014-03-06. 
  30. ^ "wcscspn -". Retrieved 2014-03-06. 
  31. ^ "strpbrk -". 2013-05-31. Retrieved 2014-03-06. 
  32. ^ "wcspbrk -". Retrieved 2014-03-06. 
  33. ^ "strstr -". 2013-10-16. Retrieved 2014-03-06. 
  34. ^ "wcsstr -". Retrieved 2014-03-06. 
  35. ^ "strtok -". 2013-09-03. Retrieved 2014-03-06. 
  36. ^ "wcstok -". Retrieved 2014-03-06. 
  37. ^ "strerror -". 2013-05-31. Retrieved 2014-03-06. 
  38. ^ "memset -". Retrieved 2014-03-06. 
  39. ^ "wmemset -". Retrieved 2014-03-06. 
  40. ^ "memcpy -". Retrieved 2014-03-06. 
  41. ^ "wmemcpy -". Retrieved 2014-03-06. 
  42. ^ "memmove -". 2014-01-25. Retrieved 2014-03-06. 
  43. ^ "wmemmove -". Retrieved 2014-03-06. 
  44. ^ "memcmp -". Retrieved 2014-03-06. 
  45. ^ "wmemcmp -". Retrieved 2014-03-06. 
  46. ^ "memchr -". Retrieved 2014-03-06. 
  47. ^ "wmemchr -". Retrieved 2014-03-06. 
  48. ^ "mblen -". Retrieved 2014-03-06. 
  49. ^ "mbtowc -". Retrieved 2014-03-06. 
  50. ^ "wctomb -". 2014-02-04. Retrieved 2014-03-06. 
  51. ^ "mbstowcs -". Retrieved 2014-03-06. 
  52. ^ "wcstombs -". Retrieved 2014-03-06. 
  53. ^ "btowc -". Retrieved 2014-03-06. 
  54. ^ "wctob -". Retrieved 2014-03-06. 
  55. ^ "mbsinit -". Retrieved 2014-03-06. 
  56. ^ "mbrlen -". Retrieved 2014-03-06. 
  57. ^ "mbrtowc -". Retrieved 2014-03-06. 
  58. ^ "wcrtomb -". Retrieved 2014-03-06. 
  59. ^ "mbsrtowcs -". Retrieved 2014-03-06. 
  60. ^ "wcsrtombs -". Retrieved 2014-03-06. 
  61. ^ "atof -". 2013-05-31. Retrieved 2014-03-06. 
  62. ^ "atoi, atol, atoll -". 2014-01-18. Retrieved 2014-03-06. 
  63. ^ "strtof, strtod, strtold -". 2014-02-04. Retrieved 2014-03-06. 
  64. ^ "strtof, strtod, strtold -". 2014-02-04. Retrieved 2014-03-06. 
  65. ^ "strtof, strtod, strtold -". 2014-02-04. Retrieved 2014-03-06. 
  66. ^ "wcstof, wcstod, wcstold -". Retrieved 2014-03-06. 
  67. ^ "wcstof, wcstod, wcstold -". Retrieved 2014-03-06. 
  68. ^ "wcstof, wcstod, wcstold -". Retrieved 2014-03-06. 
  69. ^ "strtol, strtoll -". 2014-02-04. Retrieved 2014-03-06. 
  70. ^ "wcstol, wcstoll -". Retrieved 2014-03-06. 
  71. ^ "strtoul, strtoull -". 2014-02-04. Retrieved 2014-03-06. 
  72. ^ "wcstoul, wcstoull -". Retrieved 2014-03-06. 
  73. ^ "memccpy". Retrieved 2014-03-06. 
  74. ^ "mempcpy(3) - Linux manual page". Retrieved 2014-03-06. 
  75. ^ "strcasecmp(3) - Linux manual page". Retrieved 2014-03-06. 
  76. ^ "strcat_s, wcscat_s, _mbscat_s". Retrieved 2014-03-06. 
  77. ^ "strcpy_s, wcscpy_s, _mbscpy_s". Retrieved 2014-03-06. 
  78. ^ "strdup". Retrieved 2014-03-06. 
  79. ^ "strerror(3) - Linux manual page". Retrieved 2014-03-06. 
  80. ^ "String | stricmp()". C Programming Retrieved 2014-03-06. 
  81. ^ "Manual Pages: strlcpy". 2013-09-30. Retrieved 2014-03-06. 
  82. ^ a b c Todd C. Miller; Theo de Raadt (1999). "strlcpy and strlcat – consistent, safe, string copy and concatenation.". USENIX '99. 
  83. ^ "Manual Pages: strlcat". 2013-09-30. Retrieved 2014-03-06. 
  84. ^ "strsignal". Retrieved 2014-03-06. 
  85. ^ "strtok". Retrieved 2014-03-06. 
  86. ^ Danny Kalev. "They're at it again". InformIT. Retrieved 10 November 2011. 
  87. ^ "Security Enhanced CRT, Safer Than Standard Library?". Retrieved 10 November 2011. 
  88. ^ Danny Kalev. "A Tour of C1X, Part II". InformIT. Retrieved 6 April 2012. 
  89. ^ Safe C Library. "The Safe C Library provides bound checking memory and string functions per ISO/IEC TR24731". Sourceforge. Retrieved 6 March 2013. 
  90. ^ libc-alpha mailing list, selected messages from 8 August 2000 thread: 53, 60, 61
  91. ^ The ups and downs of strlcpy();
  92. ^ strlcpy.c
  93. ^ strlcat.c
This article was sourced from Creative Commons Attribution-ShareAlike License; additional terms may apply. World Heritage Encyclopedia content is assembled from numerous content providers, Open Access Publishing, and in compliance with The Fair Access to Science and Technology Research Act (FASTR), Wikimedia Foundation, Inc., Public Library of Science, The Encyclopedia of Life, Open Book Publishers (OBP), PubMed, U.S. National Library of Medicine, National Center for Biotechnology Information, U.S. National Library of Medicine, National Institutes of Health (NIH), U.S. Department of Health & Human Services, and, which sources content from all federal, state, local, tribal, and territorial government publication portals (.gov, .mil, .edu). Funding for and content contributors is made possible from the U.S. Congress, E-Government Act of 2002.
Crowd sourced content that is contributed to World Heritage Encyclopedia is peer reviewed and edited by our editorial staff to ensure quality scholarly research articles.
By using this site, you agree to the Terms of Use and Privacy Policy. World Heritage Encyclopedia™ is a registered trademark of the World Public Library Association, a non-profit organization.

Copyright © World Library Foundation. All rights reserved. eBooks from Project Gutenberg are sponsored by the World Library Foundation,
a 501c(4) Member's Support Non-Profit Organization, and is NOT affiliated with any governmental agency or department.