StringCbCatEx (Windows Embedded CE 6.0)


This function is a replacement for strcat.

The size, in bytes, of the destination buffer is provided to the function to ensure that StringCbCatEx does not write past the end of this buffer.

StringCbCatEx adds to the functionality of StringCbCat by returning a pointer to the end of the destination string and by returning the number of bytes left unused in that string.

Flags can also be passed to the function for additional control.


HRESULT StringCbCatEx(
    LPTSTR pszDest,
    size_t cbDest,
    LPCTSTR pszSrc,
    LPTSTR *ppszDestEnd,
    size_t *pcbRemaining,
    DWORD dwFlags


  • pszDest
    [in, out] Pointer to a buffer containing the string that pszSrc is concatenated to, and which contains the entire resultant string.

    The string at pszSrc is added to the end of the string at pszDest.

  • cbDest
    [in] Size of the destination buffer, in bytes.

    This value must consider the length of pszSrc, plus the length of pszDest, plus the terminating null character.

    The maximum number of bytes allowed is STRSAFE_MAX_CCH * sizeof(TCHAR).

  • pszSrc
    [in] Pointer to a buffer containing the source string that is concatenated to the end of pszDest.

    This source string must be null-terminated.

  • ppszDestEnd
    [out] Address of a pointer to the end of pszDest.

    If ppszDestEnd is non-NULL and data is appended to the destination buffer, this points to the terminating null character at the end of the string.

  • pcbRemaining
    [out] Pointer to a variable that indicates the number of unused bytes in pszDest, including those used for the terminating null character.

    If pcbRemaining is NULL, the count is not kept or returned.

  • dwFlags
    [in] One or more of the following values.

    Value Description


    If the function succeeds, the low byte of dwFlags (0) is used to fill the uninitialized portion of pszDest following the terminating null character.


    Treat null string pointers like empty strings (TEXT("")).

    This flag is useful for emulating functions such as lstrcpy.


    If the function fails, the low byte of dwFlags (0) is used to fill the entire pszDest buffer, and the buffer is null-terminated.

    In the case of a STRSAFE_E_INSUFFICIENT_BUFFER failure, any pre-existing or truncated string in the destination buffer is overwritten.


    If the function fails, pszDest is set to an empty string (TEXT("")).

    In the case of a STRSAFE_E_INSUFFICIENT_BUFFER failure, any pre-existing or truncated string in the destination buffer is overwritten.


    If the function fails, pszDest is untouched. Nothing is added to the original contents.

Return Value

This function returns an HRESULT, as opposed to strcat, which returns a pointer.

It is strongly recommended that you use the SUCCEEDED and FAILED macros to test the return value of this function.

Value Description


Source data was present, the strings were fully concatenated without truncation, and the resultant destination buffer is null-terminated.


The value in cbDest is 0 or larger than STRSAFE_MAX_CCH * sizeof(TCHAR), or the destination buffer is full.


The copy operation failed due to insufficient buffer space.

Depending on the value of dwFlags, the destination buffer might contain a truncated, null-terminated version of the intended result.

Where truncation is acceptable, this is not necessarily a failure condition.


StringCbCatEx provides additional processing for proper buffer handling in your code.

Poor buffer handling is implicated in many security issues that involve buffer overruns.

StringCbCatEx always null-terminates a nonzero-length destination buffer.

StringCbCatEx can be used in its generic form, or specifically as StringCbCatExA (for ANSI strings) or StringCbCatExW (for Unicode strings). The form to use is determined by your data.

String data type String literal











StringCbCatEx and its ANSI and Unicode variants are replacements for these functions:

  • strcat
  • wcscat

If the strings pointed to by pszSrc and pszDest overlap, behavior is undefined.

Neither pszSrc nor pszDest should be NULL unless the STRSAFE_IGNORE_NULLS flag is specified; in which case both might be NULL. However, an error due to insufficient space might still be returned even though null values are ignored.


Header strsafe.h
Windows Embedded CE Windows CE 5.0 and later

See Also


StrSafe.h Byte-Count Functions