Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

strcpy copies a complete null-terminated string, including its terminating ; the destination must have room for the entire string and terminator. strncpy copies at most a specified number of bytes, but it may leave the destination without a terminator and may pad it with extra null bytes. So strncpy is not a drop-in safe replacement for strcpy.

How do strcpy and strncpy differ?

Function What it copies Null termination Behavior when the source is shorter than the limit Main risk
strcpy The complete source string, including its terminating null byte, as specified by The Open Group Base Specifications. Copies the source terminator. The source must itself be a valid null-terminated string. Not applicable; it copies through the source terminator. If the destination cannot hold the source and terminator, writing past its bounds can cause undefined behavior.
strncpy At most the specified count of bytes. Does not guarantee a terminator when the source has at least that many non-null bytes, as explained by SEI CERT C. Fills the remaining bytes up to the count with null bytes, according to the GNU C Library manual. May silently truncate data or produce a destination that is not a C string.

The Open Group also specifies that copying between overlapping objects has undefined behavior for strcpy. Neither function should be used when the source and destination overlap.

What does strcpy do?

strcpy(dst, src) copies bytes from src through its first null byte into dst. The destination therefore needs space for every byte before the source terminator, plus the terminator itself. The function returns dst; that return value does not report whether the copy fit or signal an error.

Use strcpy only when the source is known to be null-terminated and the destination capacity has already been proven sufficient. If either condition is unknown, the function cannot make the operation safe for you.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does strncpy do?

strncpy(dst, src, n) writes up to n bytes. Its behavior depends on the source length:

  • If the source terminates before n bytes, strncpy copies the terminator and pads the rest of the n-byte region with null bytes.
  • If the source has at least n non-null bytes, the function copies only those bytes and does not append a terminator. The destination is then not necessarily a C string.

That padding is part of the function’s fixed-width behavior, not a general-purpose safety feature. It can also mean extra writes when n is much larger than the actual source string.

Why is strncpy not a safe substitute?

A bounded count prevents strncpy from copying more than that count, but it does not by itself ensure the result is a usable, terminated string. A common pattern such as strncpy(dst, src, sizeof dst) can fill the entire destination without a terminating null byte when the source is too long. Later code that treats dst as a C string may then read beyond its bounds.

It can also truncate input without making that loss obvious to the caller. SEI CERT C warns that unintentional truncation loses data and can, in some cases, lead to software vulnerabilities. A length limit is useful only when the program also defines what should happen if the input exceeds it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you choose?

  • Use strcpy when the source is valid and its length is known to fit in the destination, including room for the terminator.
  • Reject the input when exceeding the destination capacity is an error. Check the length before copying and report or handle an oversized value.
  • Allocate enough storage when the full input must be preserved but its length varies. Account for the terminator and allocation-size limits.
  • Truncate only deliberately when losing excess characters is acceptable. Detect that truncation occurred, ensure the resulting string is terminated, and communicate or otherwise handle the loss as the program requires.
  • Use fixed-width padding only when the format requires it. That is a narrower use case for strncpy than ordinary string copying.

There is no single replacement that is best on every platform and for every policy. CERT discusses alternatives such as snprintf, but check the API’s behavior and availability on your target platform, and decide explicitly whether too-long input should be rejected, preserved through allocation, or truncated.

Best Value

Practical checks before copying

  • Confirm that the source is terminated within the memory region you are allowed to read.
  • Know the destination’s actual capacity, not just a count copied from a different object.
  • Include space for the terminating null byte whenever the result must be a C string.
  • Choose and implement an explicit policy for oversized input; do not let a bounded copy silently decide it.
  • Do not rely on either function for overlapping source and destination regions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.