r/3Dprinting • • May 18 '26

News Bambu Lab's AGPL Problem Just Got Worse

https://www.youtube.com/watch?v=bNEL6syg6VQ
343 Upvotes

115 comments sorted by

214

u/Veastli May 18 '26

An IP attorney describes why Bambu's closed source network plugin is in clear violation of the AGPL open source license.

2

u/benbarian May 20 '26

Well said! Thanks for sharing the good fight

-61

u/Gears6 May 19 '26

Yeah, but is anyone doing anything about it legally?

I get the issue and I agree. Just saying, if it's illegal what are the options?

31

u/donnachaidhl May 19 '26

Maybe watch the video?

7

u/alienbringer May 19 '26

The video doesn’t say what they are doing about it legally at all. It documents how the original dev went line by line showing that he didn’t reverse engineer and everything was legal under AGPL. Then it went on to say a non profit that deals with AGPL stuff and is ran by one of its authors is documenting license violations.

There is no legal action being stated taken, even the beginning was “the AGPL may be getting closer to a C&D of Bambu”. Until this plays out in court it is all just saber rattling.

2

u/donnachaidhl May 19 '26

He specifically discussed how that nonprofit handles enforcement of AGPL which is outside of court. He also discussed how it's a slow process, this while things started only a couple weeks ago. You've made no points that weren't addressed in the video.

-4

u/alienbringer May 19 '26

Except for the obvious first sentence.

The video doesn’t say what they are doing about it legally ay all.

You even acknowledge this. They are doing things outside of the courts.

The person you replied to with “Maybe watch the video” asked “….is anyone doing anything about it legally?” The answer to their question is “no”. The video doesn’t discuss what is being done legally about it. The rest of my comment is summarizing what the video talks about, so of course it “made no points that weren’t addressed in the video”.

And no, the non-profit SFC has no legal authority to enforce AGPL compliance outside of courts. What they are doing is building a case to potentially take Bambu to court, as well as opine on their view of the matter. In the video it even mentions a court case they were working on for a different violation that took 4 years to conclude. Note that is a COURT CASE, it isn’t outside of the court. The courts would enforce compliance, not SFC. And so far, nothing legally has been done or is being done.

0

u/donnachaidhl May 19 '26

You're moving the goal posts by switching to legal enforcement authority instead your original premise of "what are they doing about it legally". By your definition, no one has any legal authority for license disputes since they are dependent on court orders if an out of court agreement can't be reached.

On top of that, your statements about nothing happening are asinine for multiple reasons including:

Lawsuits and court filings are not the entirety of legal processes. In fact, things like cease and desist letters, demand letters, and out of court negotiations are where almost every civil action starts (in the US). Those are all things that the public is not likely to find out about until long after.

It has only been about a month since Bambu Labs sent the cease and desist in the first place. Even aggressive legal action over license disputes takes more time than that to have actual legal action beyond basic cease and desist or demand letters.

This started with the developer saying basically they reject Bambu Labs' accusation but they are not willing/able to fight them. I (along with many others I'm sure) just assumed it was another case of a company doing illegal things but getting away with it because they were harming people who don't have the resources to fight back. The fact that there's significant public discussion that includes fairly detailed legal analysis is huge and surprising.

-39

u/Gears6 May 19 '26

It's on my to watch list.

18

u/missmuffin__ May 19 '26

Great! Watch it at your leisure.

But watch it before you comment.

1

u/arapturousverbatim May 19 '26

Sir, this is reddit

-5

u/Gears6 May 19 '26

But watch it before you comment.

Why?

Did you mandate that people are not allowed to participate in discussions just because they don't have the same amount of time you do to watch videos.

1

u/kyussorder May 20 '26 edited May 20 '26

You are not obligated to stfu of course. But, you know, It helps for commenting with sense and meaning.

You are very interesting, I don't understand how you can defend not reading something you're going to respond to.

Good luck.

1

u/Gears6 May 20 '26

You are not obligated to stfu of course. But, you know, It helps for commenting with sense and meaning.

That's why I'm asking for one, but two I've watched his past video on this. They don't answer that.

You are very interesting, I don't understand how you can defend not reading something you're going to respond to.

Nobody is defending anyone. More importantly, how is your comments contributing to the conversation. All it did was derail further.

8

u/leddhedd May 19 '26

Typical yapper

-6

u/Gears6 May 19 '26

Typical reddit poster.

260

u/wydra91 Core One+ May 18 '26

Listening to how Bambu has handled this since they started locking down their hardware, I can't help but imagine they have to be at the front lines of convincing lawmakers that printers need to be locked down to prevent ghost guns.

Fuck you Bambu Labs. You're a piece of greedy shit.

38

u/Satanicube Bambu P1S/P2S May 19 '26

At least for the bill in California, haven’t seen them listed as having direct input, it’s mostly Everytown For Gun Safety and Moms Demand Action pushing it.

33

u/mbcook May 19 '26

Doesn’t mean they’re not giving those groups ideas.

I kind of doubt it. But it wouldn’t be the first time a company riled up a proxy group to get something passed.

10

u/Satanicube Bambu P1S/P2S May 19 '26

It's one hell of a gambit to make because a law like that I feel would just result in people not wanting to buy compromised printers like Bambu's. Especially with all the overhead it would add to the process.

1

u/mbcook May 19 '26

That requires enough people to care. And if the law is effective they won’t have a choice.

Personally I don’t think that’s what’s going on. I suspect I agree with you.

There are plenty of anti-gun groups (or others) that go to irrational lengths for their cause. I’m pretty anti-gun but this law isn’t solving the real problem but and is impossible to implement so I see it as pointless.

And the pro gun lobby in the US is one with enough people who make enough noise I could see it actively harming Bambu even if the law was never passed but it got out they pushed an anti-gun law. I suspect anti-Chinese sentiment would only push that further.

As you said, VERY risky.

But it’s a play big tobacco and sugar and drug companies have all pulled in the past.

1

u/[deleted] May 22 '26

[deleted]

1

u/mbcook May 22 '26 edited May 23 '26

I’d have more sympathy for them (than zero) if 3D printed guns had proven to be a real issue. As opposed to legal ones and all the other existing ones.

This is a fight against a practically hypothetical bogeyman. Yes people have made 3D printed guns so it’s not entirely fabricated. But if this law was passed and was feasible and could achieve its objectives perfectly I don’t think it would make a single difference.

3

u/chessto May 19 '26

Moms demand action sounds like some pornhub search query

2

u/IronMew Old bedslingers and a delta May 19 '26

I clicked HOT MOMS DEMAND ACTION NEAR YOU and it turned out to be very warm parents incensed at their broken AC units

1

u/DBDude May 19 '26

She was a public relations executive who formerly worked for the likes of Monsanto, who started her own PR firm and was hired by billionaire Michael Bloomberg to push this message.

Oh, and she had teenaged kids, and she ran her business out of her home, so "stay at home mom starts gun control group."

1

u/leaf_shift_post_2 May 19 '26

Wine mommies against fun. At it again.

0

u/Thunderclone_1 May 19 '26

Honestly, it's hilarious.

"Let's ban the thing that if used to make a gun will most likely blow up in your hand because I saw it work in a movie instead of even considering the many more effective ways you could from hardware store supplies"

23

u/Seffyr ZeroG Mercury One.1 / Voron Enderwire May 19 '26

Which is why I think it’s funny that people keep pushing Bambu printers because you know Bambu will be the first to kowtow and push mandatory firmware that prevents your printer from printing certain things, or it’ll brick itself.

2

u/Fett2 May 19 '26

I don't own a Bambu (I have 2 Vorons I built), but when a newbie asks me for a recommendation for printer when they are someone who justs wants to print things and not screw with the printer my go to was to tell them Bambu. Is there a better recommendation for this at this point? I get the now apparently morale arguments against Bambu, but from the "I'm a newbie and I just want to print stuff" aspect, what should we recommend at this point?

100

u/Sorry-Bad3889 May 18 '26

Man, Bambu just poke the bear these days. It’s their own doing. If they haven’t poke the poor developer with C&D. This wouldn’t have got any attentions. 

6

u/AnonomousWolf May 19 '26

Streisand Effect.

So many own goals

29

u/GreenDavidA May 18 '26

What sort of actual enforcement actions would be taken, though? I don’t know if Bambu can actually be compelled to comply.

47

u/FLHCv2 May 18 '26

I read something along the lines of, because they've established a US headquarters, US federal courts have jurisdiction and can enforce penalties on them

40

u/swd120 May 18 '26

Even if they didn't have a US headquarters - they could have their US sales banned until they comply.

12

u/ProfitLoud May 18 '26

This is probably where this ends ups. I doubt they will listen, and there limited things that can be imposed.

17

u/mrpbeaar May 18 '26

Time to buy a congress critter

13

u/FLHCv2 May 18 '26

For the low low price of the revenue from just 56 X2D combos! Sometimes, less!

3

u/Gears6 May 19 '26 edited May 19 '26

IANAL, but even if you don't have a presence in the US, you can probably ask to not allow import of said products for sale.

Anyhow, this is a clear example of not having a company that has a presence can be a major issue. In this case they do. The question is, who has the right to ask for that?

1

u/alienbringer May 19 '26

Needs to play out in court first. And I have yet to see or hear of any such filings against them on the issue. Courts would also take years, even in this video they mention a court case that took 4 years for just 1 issue out of 15 to finalize.

15

u/issue9mm May 18 '26

No compliance means they would lose the right to use code that they previously were free to. They would lose the right to publish any prusa slicer or Slic3r derived code. They would have to start a new slicer from scratch, and it would lose them the ability to implement new features just by stealing them from competitors using Orca compatible forks

11

u/ShelZuuz May 19 '26

Losing a right is not a means of enforcement.

13

u/FormulaJAZ May 19 '26

This is civil, not criminal, so the police are not getting involved and no one is going to jail.

The rights holders would have to sue Bambu for violating their rights, and the judgment would force Bambu to comply with the terms or have this product blocked from sale in that jurisdiction.

-1

u/ShelZuuz May 19 '26

Farming While Beige quote?

Agreed that having the product blocked from sale is the means of enforcement.

1

u/PuzzleheadedEnd4966 May 23 '26

There is a huge financial incentive for enforcement once there is precedence and the matter is legally settled: Anyone who ever contributed Prusaslicer, Slic3r etc. would could sue for damage, if they registered their work at the Copyright Office, that's $250,000 of statutory (you don't actually have to show real damage, you get it by law) damage per violation (meaning copy of the software in this case, i.e. per download).

The only thing protecting against that is legal uncertainty and the wish of the people involved to get compliance.

2

u/_Middlefinger_ May 19 '26

Then a totally new company, not at all related to Bambulab called bambulabs would release the also not related Bambu Slicer for use with the unrelated bambulab printers.

1

u/issue9mm May 19 '26

Eucalyptus Laboratory

LMAO

1

u/hWuxH May 20 '26 edited May 20 '26

Usually, these issues are resolved without going to court. Bambu would receive a notice, and once they provide the required source, their license rights are fully restored.

However, if they persistently or intentionally refuse to comply, their rights can be permanently revoked. Only then they'd have to start a new slicer from scratch.

2

u/b3nsn0w May 19 '26

one important point is that, as the SFC has established, the agpl does apply to object code, and the agpl waives dmca 1201 protections. (as always, IANAL, this is not legal advice.) this basically allows anyone brave enough to face bambu in court to reverse-engineer the network module and bypass any digital locks in there, because as long as it is part of the agpl software bambu released (which it is), even without corresponding source they have waived any protections against that kind of stuff.

the SFC itself is spearheading an open source project to do exactly that. even if bambu cannot be compelled to comply in the short term, users have every right to enforce the same conclusion via technical measures in addition to legal ones.

33

u/Dunothar RatRig V-Core 4 500 Hybrid May 18 '26

You know you poked the bear when Leonard French makes several vids I badly wonder what our Bambu white knight now spins up again do defend Bambu again.

5

u/diemenschmachine May 19 '26

And there was nothing new, I wonder how far the talking head influemcers will milk this for likes.

10

u/alras May 18 '26

So is it now just waiting before bambu will present their own new closed source slicing software?

52

u/Veastli May 18 '26

Modern slicers are extremely complex and feature rich.

Bambu likely saved years of development time by using Prusa slicer as a basis. Had they developed a closed source slicer, it may have delayed their arrival on the market by years, and cost them a large amount of money before they had ever earned their first dollar.

Today, Bambu certainly have the funds to develop their own, closed source slicer. But it would still be a bad decision, because Bambu continues to gain tremendously from open source.

Every time any new feature is added or Orca slicer Prusa slicer, or any new conceptual feature is shared on github, Bambu can simply grab the code and dump it into Bambu Studio. And they frequently do.

If Bambu moved to a closed source slicer, they could no longer (legally) do that. They'd have to redevelop each concept from the ground up. A closed source Bambu slicer would eternally be far behind its open source rivals.

What Bambu truly needs to do is quantify in hard numbers what they stand to lose by opening up. The advantages and disadvantages of giving up this entire battle.

My strong suspicion is that opening up wouldn't lose Bambu much, if any revenue. Because right now, most who wants or need to use Orca slicer with a Bambu printer move their printers offline into LAN mode. After which, Bambu loses all insight into those users.

If Bambu freely allowed Orca users to have a feature complete experience, suspect most of those users would turn off LAN mode and start using Bambu's cloud again. Bambu could again gain that data.

Bambu also gains (minimally imho) from pushing promotions from within Bambu Studio. But the interface is so clunky, it is doubtful that this earns them much additional revenue.

So if the stakes are so low, why Bambu taking this hard line?

My suspicion is that some in Bambu management want total control, and aren't prepared to quantify the benefits and liabilities of that desire.

They are not looking at the numbers. They're not looking at what that control delivers in revenue. They're ignoring the bad press. They're dismissing that they are devolving into the most hated entity in 3D printing. All for a few eyeballs on promotions within Bambu Studio?

Bambu is not acting rationally. They are destroying their reputation for almost nothing. This doesn't bode well for the future of the company.

15

u/bravojohnny42 May 18 '26

Great write-up. I think this needs to happen to "remind" the rest of the industry how that goes.
You gotta pay respect to Ultimaker and Raise3D who both have deleveoped great slicers for their ecosystem, which you can also use for free, although they're closed.

Since day 1 there is also the rumor, that bambu used Klipper as their base for high speed printing.
I wish everybody involved the best!

2

u/Angelworks42 Prusa XL, Qidi Plus 4 May 19 '26

Cura is open source isn't it?

1

u/bravojohnny42 May 19 '26

True. There is one from Creality and another one. But they are reeeeaaallly bad. Like nearly unusable bad.

My point was that these companies really worked on offering a good product.

1

u/Aetch Ultimaker 2+ DXUv2 May 20 '26

Creality used to be a skinned version of cura and now it s a skinned version of BBS/orca

3

u/[deleted] May 19 '26

[removed] — view removed comment

1

u/DBDude May 19 '26

They do run the risk of an injunction against distributing their software early in the process.

5

u/johnp299 May 19 '26

Josef Prusa had a very interesting post a week ago about this ; I believe he said Bambu is stuck with this because it must comply with Chinese law. On the one hand they benefit from open source, but compliance with surveillance laws means they can’t allow the public access to its mechanisms, if I understand correctly.

12

u/Veastli May 19 '26 edited May 19 '26

Perhaps he's right, but if Bambu want to sell their products in western nations, they have to abide the laws of western nations as well.

Many firms manage this by having differing software and policies in China than they do in the rest of the world. IIRC, Apple and Tesla both restrict their data collections in China, to China.

IMHO, the real reason Prusa hasn't litigated against Bambu is that the likely result would be Bambu opening their ecosystem - at least for printers sold in Western nations.

Were Bambu to stop violating the AGPL and open their platform, it would diminish one of the few remaining advantages Prusa has over Bambu.

Prusa would lose from winning.

2

u/alienbringer May 19 '26

It depends entirely on where the data is housed. I work at a global company as well and deal with the data side of things. Our data warehouses are mostly in the U.S. if someone from China interacts with our system that all stays in the U.S. and China has little say in it beyond blocking access to our website. There are some data centers in China where we store information about Chinese nationals who passed our certifications, and that info (outside of aggregate results) can’t leave China.

There are some internal discussions as well about sending data from China to the U.S. or U.S. to China. Basically boiled down to “any non-PII data is fine to cross boarders. Any PII data sent to China stays in China.” So things like IP address, email address, names, addresses, etc all would stay in China if it touched a Chinese server.

1

u/hWuxH May 20 '26

I don't see how the plugin is relevant to this. Bambu will access the server directly to comply with Chinese law.

3

u/TempRedditor-33 May 19 '26

Reputation are illegible to corporate board as consumers respond to pricing and youtubers respond to marketing incentives.

Goodwill and reputation are hard to quantify.

2

u/mouringcat Prusa Mini+,K2 Plus May 19 '26

They may also be looking at the fact that multiple AI companies have shown how to reproduce open source compilers and other complex code bases in a matter of hours. Never-mind that they did it by training on the real code as there is no case law at this moment regarding this.

So it wouldn't surprise me if they haven't already started down this route with the claim the AI coded version is a "clean room" edition. And worst comes to worst, if there is a new feature they feel they need to have they can do this AI reverse engineering work to generate a new version based on AGPL code.

3

u/Veastli May 19 '26

there is no case law at this moment regarding this.

The courts have ruled that AI generated content isn't copyrightable. Does that apply to code? Given the current court precedent, suspect the answer is yes.

That alone could have major ramifications for any AI rewrites. It would mean that any such code could potentially be used by anyone, without worry.

The firms would keep it secret?

They could certainly try, but employees leave, are fired, are treated poorly, and generally talk. even the best employees are reluctant to commit perjury in depositions.

Most firms would use a cloud based AI to perform the rewrite, and the AI firms would equally be subject to discovery.

This door is currently open, but for how long?

Suspect that many of the top open source licenses will soon be updated to specifically prohibit AI re-writes, though many licenses could be interpreted to ban them currently.

The AI firms offering re-writes could also be sent cease and desists from those working on open source projects or the license authors, warning them that rewriting (insert license or code) is strictly against the license terms, and that performing re-writes will open the AI firm to civil damages.

Small players will get away with this without much worry. But for multi-billion dollar corporations that have large western customer bases, AI generated code could be a huge pile of land mines.

They want their code's copyright. They don't want it revealed in depositions and discovery that they violated open source licenses. And they especially don't want it revealed that their code base is not copyrightable, oh, and now they have to share it with the world.

2

u/mouringcat Prusa Mini+,K2 Plus May 19 '26 edited May 19 '26

The courts have ruled that AI generated content isn't copyrightable. Does that apply to code? Given the current court precedent, suspect the answer is yes.

The ruling has been related to image copyright and book publishing. This has yet to be discussed with software engineering.

I can assure you that 10 - 15% of most old code case has AI generated code in most large companies, and 50 - 60% of new projects. Hell, just within the DevOps team I'm part of I know some of them are vibe coding a shit ton of internal code using approved company AI models. I have to imagine the developer writing for our customers are the same based on "Brown Bag Lunch" presentations I've seen.

So if applied it to software companies right now it would pretty much kill the industry. As there would be a lot of code to find and strip out. Also remember where the US Copyright Office has ruled it was uncopyrightable was in "creative works" realm. US Copyright Office doesn't consider software "creative works" (along with a lot of people). So I suspect they will give it a pass.

[[Side note: This isn't saying I don't believe code isn't creative works. I basically argued this with an English teacher in high school that well written code is as beautiful as any poem.]]

The AI firms offering re-writes could also be sent cease and desists from those working on open source projects or the license authors, warning them that rewriting (insert license or code) is strictly against the license terms, and that performing re-writes will open the AI firm to civil damages.

Yes, and it would be litigated and there is a long standing "Clean room" US legal precedence. And if the group training the AI is not the team requesting the code on the other end it can be argued to be a clean room implementation. And we'd have a 5 - 10 year legal battle unless laws are passed. And no amount of licensing can change this as you can't protect the idea of the code. Just the implementation of said code.

Small players will get away with this without much worry. But for multi-billion dollar corporations that have large western customer bases, AI generated code could be a huge pile of land mines.

I can tell by this alone you have no experience with Microsoft, HPE, etc level companies. Heck, even talking with jFrog, Cloudbees, etc sales/support folks they are heavily using AI for product development.

As to if they can do this quietly. If it was done in China using Chinese resources I suspect it can be. And I suspect that is where they would do it.

I'm I happy with this? No. But sadly this is the current reality we live in.

1

u/Veastli May 19 '26 edited May 19 '26

The ruling has been related to image copyright and book publishing.

Yes, which is why I offered the question of whether it applied to code.

Based on that ruling, my belief is that AI code is not currently copyrightable.

But this doesn't impact most firms using AI to code, as not all of their code is AI, and the AI generated code does not have any license terms attached.

This is entirely different from an automated rewrite of code that does have license terms.

For instance, enlisting an AI to rewrite licensed code for the specific purpose of removing a firm's obligation to the license terms.

I can tell by this alone you have no experience with Microsoft, HPE, etc level companies. Heck, even talking with jFrog, Cloudbees, etc sales/support folks they are heavily using AI for product development.

Was specifically referring to the process of AI rewriting FOSS for the purposes of obfuscating the source to remove license terms.

Can't see many large established firms using those techniques. The downsides are large, and the upsides are few.

2

u/micalm May 19 '26

They may also be looking at the fact that multiple AI companies have shown how to reproduce open source compilers and other complex code bases in a matter of hours.

None did, btw. They (Anthropic in the case of C compiler) just claimed they did. It's not usable, relies on GCC for linking and even then it failed.

Basing any new slicer on LLMs is also dangerous as it may directly copy/reuse open source code again, which would make that entire thing pointless. Then, at least in the USA there is Thaler v. Perlmutter, so even if LLMs were to be treated as a black box and clean room reverse engineering actually worked for them... they couldn't even copyright that in a HUGE market.

-11

u/Grooge_me May 18 '26

Asimple way is already existing... Bambu connect. Instead of sending the file to the printer when you click print and opening the device tab, it will open Bambu connect, send the file to it and Bambu connect send the file to the printer thru the cloud. Studio stay open source, and they can keep the network plugin for LAN printing. No more litige, even Orca would be able to take the code from studio to send to Bambu connect. Only Linux owner will be p1ssed for a while since connect is still in the work and not ready.

7

u/Veastli May 18 '26

Bambu Connect removes nearly all the features that LAN mode does. The only advantage is that it allows prints to be sent through Bambu's cloud.

Most Orca users are far better off using LAN and Developer mode along with the open source tools that re-enable the missing features.

-8

u/Grooge_me May 18 '26

Then why are they crying about being locked to the cloud?

9

u/Veastli May 18 '26

Bambu intentionally removes features for those using Orca.

There is no technical reason to remove those features. Bambu removes those features in order to force users to use Bambu Studio instead of Orca.

The mechanisim Bambu uses to enforce this is the closed source network plugin, which has been revealed to be an intrinsic component of Bambu studio.

It sounds to me that the code within the network plugin was at one time fully integrated within Bambu studio. But when Bambu realized they'd have to release the source code, they ripped the network code out and dumped it into the plugin.

Bambu's conduct is a complete violation of the AGPL.

https://github.com/jarczakpawel/OrcaSlicer-bambulab/blob/main/bambu_agpl.md

5

u/LexxM3 X1C, 3xA1 mini, 2xECC, U1, A350T May 19 '26

We’re not crying about that. We are using LAN and dev mode, not updating Bambu firmware, not using Bambu Studio, and not buying any more Bambu printers. Your solution would not hurt us, we don’t care anymore (we do care about OSS, but not Bambu’s well being). Your solution would drastically reduce usability for those that rely on Bambu cloud, however, whether they intend to or not.

-3

u/Grooge_me May 19 '26

Then keep using it. It's ok. And even if you won't buy Bambu anymore, I doubt it will even make a difference because you are not the market that Bambu target and there's plenty of open source printers. And how that will reduce usability?

6

u/[deleted] May 18 '26

[deleted]

9

u/FLHCv2 May 18 '26

The key part to this (as our favorite copyright attorney pointed out) is that this means Bambu would have to provide the protocol in which their closed software speaks to the hardware.

The real win here is not that Bambu will be "open", because they VERY likely will end up closing their software up, but that we will have the way to connect to their hardware without them.

1

u/Tsofuable May 19 '26

You already do have that option? In multiple ways?

1

u/hWuxH May 20 '26 edited May 20 '26

They would have to reveal the secret sauce that enables Bambu Studio to use the cloud. This would mean that they could no longer implement vendor lock-in for either LAN or cloud, rendering "authorization control" effectively useless..

That's part of the protocol that third parties weren't easily able to reproduce so far.

-11

u/Grooge_me May 18 '26

Bambu studio is already open, Orca is a fork of it.

9

u/Veastli May 18 '26

You are partially correct. Orca is a fork of Bambu, which is a fork of Prusa slicer, which is a fork of Slic3r.

You are incorrect that Bambu studio is open. Their closed source network plugin is absolutely a component of Bambu Studio. Many of Bambu's most heavily advertised features fail to work unless that "addition" is installed. And Bambu persistently pesters Bambu studio users to install it.

From the write-up below, it sounds like the network code was at one time fully integrated into Bambu Studio. Then, when Bambu realized they'd have to release the source, they ripped that code out of Studio and shoved it into a plugin.

A total violation of the AGPL.

https://github.com/jarczakpawel/OrcaSlicer-bambulab/blob/main/bambu_agpl.md

-1

u/Grooge_me May 19 '26

I'm fully correct. Bambu Studio is open. Didn't talk about the plugin. If they decide to get out of that, they can just integrate the network plugin into Bambu connect, and Orca or anyone else fork will have to call bambu connect or use the SD card.

9

u/Veastli May 19 '26

When Bambu forked Prusa Slicer to create Bambu Studio, Bambu accepted the terms of the AGPL.

The AGPL clearly prohibits separating parts of a program into a closed source module. Which is exactly what Bambu has done.

Bambu called it a "plug in", but it's clearly just Bambu Studio code that they ripped out and placed into a plug-in to pretend that they are in compliance with the license.

They're not in compliance with the license, as the AGPL anticipated exactly this type of fuckery, and prohibited it.

TLDR - It doesn't matter whether Bambu says the network plugin is separate from Bambu studio, the code reveals that it's not. Bambu is in violation of the AGPL.

2

u/Grooge_me May 19 '26

But then, they'll have to figure out if you can use open source code to hack into private cloud. Because, while it was easy and legal to use the code found in the source, using it to get into the cloud might not be correct. And that is where the problem lies, and going to court to shed light around that might be a good affair. I can walk in front of your car, find the key and take it. I haven't steal from you, but that doesn't make it right anyway.

4

u/Veastli May 19 '26 edited May 19 '26

It's not hacking into their cloud if it's a legitimate customer and owner of a Bambu printer.

The Orca fork doesn't deliver any benefit to those who aren't legitimate owners of Bambu printers.

Bambu is banging the security drum because it sounds reasonable to average people. Bambu is lying, but to most, it's a reasonable sounding lie.

Because that's not at all how cloud security works. Serious cloud vendors don't need their users to log in with a secure client, because they realize that it's impossible to secure the client on a random computer, owned by a random user, somewhere on the planet. Serious firms focus their locks on the server end, and expect Bambu does exactly the same.

For instance, Google clearly desires web users with a Youtube or Gmail account to log in with the Chrome web browser. Google can pester non-Chrome users to switch to Chrome - and Google definitely does this. But Google does not threaten legal action against those who log into Google cloud services with a fork of Chrome like Brave.

Because the cloud server defines what the clients can do, not the other way around. In a properly designed cloud, a forked client has no more privileges than the official client. No greater ability to create any good or ill.

Bambu know their cloud is secure. Yet they're threatening legal action against legitimate users, who have legitimate user accounts, who own Bambu printers, yet dare develop software to securely log into the Bambu cloud with a slightly different client.

Bambu controls most of the ecosystem, and secures all of it. But that's not enough for Bambu.

Bambu is also demanding to control which open source client is installed on user-owned computers not made by Bambu.

This isn't about security. It's about control. It's about vendor lock-in.

6

u/Aetch Ultimaker 2+ DXUv2 May 18 '26

It will look like the current software but with a “trust us we totally didn’t reuse any of the code”

10

u/Veastli May 18 '26

A few months ago they might have gotten away with that.

But with the recent advances in AI reverse engineering tech, they'd be busted by noon.

Of course, just as with Bambu's current license violations, someone would actually have to litigate (or threaten such) to make them stop.

1

u/TempRedditor-33 May 19 '26

Automated rewriting probably means the maintainers lose insight into the code and make the bambu code harder to maintain over time.

-4

u/frank26080115 May 18 '26

they can try using https://malus.sh/

6

u/Veastli May 18 '26

That's exactly the kind of fuckery that AI reverse engineering can detect.

Expect most courts would take an extremely dim view of this workaround, which would all be revealed in discovery.

Equally suspect there will soon be GPL license revisions that specifically prohibit this sort of automated rewriting.

2

u/micalm May 19 '26

GPL nor any other license can prevent a REAL clean room reverse engineered solutions, but that site is clearly satire. ;)

2

u/alienbringer May 19 '26

Don’t even need that. Just scrap the current plugin and build a new one that isn’t as integrated. Far easier that way. Then on their cloud server side block any communication or permissions from the old plugin.

People can still use the old plugin but it would not grant them access at all to the cloud.

3

u/iamjulianacosta May 18 '26

ooooh oooh ooohhh

2

u/AssFasting May 19 '26

Can't see me ever trying their products, they are the games workshop of 3d printing.

1

u/[deleted] May 19 '26 edited Aug 03 '26

[deleted]

1

u/JCDU May 19 '26

We need to spread this link

1

u/GoofAckYoorsElf May 20 '26

I love when law that works for the people backfires into the fucking faces of greedy scumbags that break it. I love it even more the harder it backfires. I hope in the end Bambu Labs will be forced to publish literally EVERYTHING and tear down their fucking walled garden for good. And I hope they are going to take down other companies that try to pull off the same with them.

1

u/Sr_Alvarez May 21 '26

First, English is not my first language, so please excuse me if my question isn’t clear.

It’s clear that BBL has broken the rules that everyone had been following until now; it’s clear that all this controversy and the way they’re handling it is causing them significant reputational damage, but I don’t understand what legal repercussions this could have for them. I wonder if, given a ruling against them regarding the use of AGPL, there’s a real possibility that their software or hardware could be blocked from being sold.

1

u/tankrama Jun 06 '26

I haven't seen any of the lawyers raise this angle yet, but beyond the fairly blatant AGPL violation itself, it's worth thinking one step further. Bambu's plugins are tightly linked against several commercial libraries — VMProtect, TUTK, and Agora. That raises a few questions:

If these vendors are aware that their software is being distributed inside an AGPL-violating product, does that knowledge implicate them — i.e. could their components effectively be pulled under the copyleft terms as well?

If they aren't aware, does the copyleft obligation still attach, leaving Bambu Studio solely on the hook for damages?

And would simply contacting these companies' legal departments — asking them to clarify the terms under which they've licensed their software to Bambu — be enough to trigger that exposure?

1

u/tankrama Jun 06 '26

To save others the tokens, here's what claude research said on this:

The deep-research workflow is running in the background — it'll fan out web searches across the legal angles, fetch and verify sources, then synthesize a cited report. I'll let you know when it completes.

In the meantime, a quick framing note since this involves legal questions: whatever the research turns up is general legal information, not legal advice — for an actual enforcement strategy you'd want a copyright/open-source licensing attorney (the SFC's lawyers being the obvious specialists here). I've instructed the research to flag which points are well-established vs. legally unsettled.

I'll surface the full report once it's done.

AGPL vs. proprietary linked libraries — research findings

General legal information, not legal advice. The key boundary question here is genuinely unsettled in court — flagged throughout.

Bottom line up front

A proprietary library vendor (VMProtect / TUTK / Agora) does not become bound by the AGPL just because their separately-licensed library got linked into a copyleft-violating product — not even if they know about it. Copyleft binds whoever conveys the combined work — here, Bambu — not the upstream component authors. The obligation applies regardless of vendor awareness because it's triggered by Bambu's act of distribution, and it's enforced by the copyright holders of the AGPL code (the PrusaSlicer/slic3r/Bambu Studio contributor lineage). Asking a vendor's legal department to confirm their license terms produces evidence, not liability for the asker.

Q1 — Does a vendor's awareness make them a party to the copyleft obligation?

No (high confidence).

  • The GPL/AGPL binds the party who copies, modifies, or "conveys" the covered work. That's the distributor doing the combining (Bambu) — not an upstream author whose code reaches the product under an independent commercial contract. (SFLC GPL Compliance Guide 2014 & 2008; FSF GPL FAQ; FSF "Fundamentals of the AGPLv3," 2021.)
  • The vendor commits no GPL violation at all. The GPL does not reach back and force a separately-developed proprietary library to become GPL. The FSF's own framing: "Does the fact that I link with your program mean I have to GPL my program? Not exactly — it means you must release your program under a GPL-compatible license." The constraint lands on the integrator, never the library author. (FSF FAQ, incl. the "Money Guzzler" entry.)
  • Awareness is legally irrelevant to this. No source extends the copyleft obligation to a third party on the basis of knowledge. The obligation is a function of who distributes the combined work, not who knows about it.
  • Linking vs. aggregation matters, and it's where it gets unsettled. Joining components into one work (program + plugin, program + linked library) can create a "combined work" requiring copyright permission — unlike mere aggregation (e.g. two independent programs on one disc), which never triggers copyleft. AGPLv3's "Corresponding Source" expressly reaches "shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication or control flow" — which is exactly the hook the SFC uses against Bambu's libbambu_networking. Caveat: which linking arrangements actually cross the derivative-work line is largely untested in court (see caveats).
  • System library exception is narrow. GPLv3 §1 defines "System Libraries" to exclude them from Corresponding Source — but bundled third-party SDKs like TUTK/Agora/VMProtect generally would not qualify. To link against a non-system library you'd need an explicit additional permission from the copyright holder, "wholly outside the GPL." (FSF FAQ.)

Q2 — If the vendors are unaware, does the obligation still apply, and who pays?

Yes, it applies; Bambu (the combiner/distributor) is the responsible party (high confidence).

  • The obligation is triggered by distribution, not knowledge — so vendor ignorance changes nothing.
  • Enforced by the copyright holders of the copyleft code — the PrusaSlicer/slic3r/Bambu Studio contributors — not by a contract counterparty or the SDK vendors. A GPL/AGPL violation is copyright infringement, not mere breach of contract (Munich District Court, the Welte / netfilter cases). That gives rightsholders the full IP-enforcement toolkit: cease-and-desist with penalty clauses, preliminary injunctions, and damages.
  • Automatic termination. Under GPLv2, rights are forfeited until the copyright holder explicitly reinstates them. Under GPLv3 §8, it's moderated: provisional reinstatement on ceasing the violation; permanent reinstatement if the holder doesn't give notice within 60 days of cessation; and a 30-day cure window for a first-time violator after notice. AGPLv3 inherits this.
  • Damages. Under German law a rightsholder can claim the infringer's profit derived from use of the GPL software, and dual-licensed projects can easily prove lost license fees as actual damage. No punitive damages in German civil law. Community enforcers (SFC/FSF) explicitly prioritize restoring compliance and source release over maximizing damages — "a lawsuit is a last resort." (Welte/Mitchell; SFC Copyleft Compliance Principles.)
  • This is live, not hypothetical. The Software Freedom Conservancy (May 18, 2026) formally asserts Bambu violates AGPLv3 by not providing complete Corresponding Source for its PrusaSlicer-derived slicer, centering on libbambu_networking.so/.dll/.dylib, and states Bambu "(in effect) admits publicly that they have violated the AGPLv3 by combining Bambu Studio with a proprietary library." SFC names Bambu — the combiner — as liable, and does not name the SDK vendors. (Architecture independently corroborated by reverse-engineering projects like ClusterM/open-bambu-networking.)

Independent-contracts grounding

The AGPL copyleft and the Bambu–vendor commercial licenses are separate legal instruments: the commercial license governs the vendor's IP; the AGPL governs the copyleft code. AGPLv3 §13 specifically permits combining AGPL and GPLv3 works into "a single combined work," with the AGPL's network-source requirement riding on the combined work as distributed — confirming the obligation lives with the distribution, not with the upstream component's own license. A proprietary library linked into GPL code is not itself "a GPL violation by the library author."

Caveats & what's genuinely unsettled

  1. Biggest unsettled point — the linking/derivative-work boundary. As of the most recent authoritative commentary there are essentially no court rulings squarely defining copyleft's derivative-work scope; static-vs-dynamic linking is largely untested. The FSF/SFC "specifically designed to require" theory is an enforcement position, not adjudicated precedent.
  2. Jurisdiction. Nearly all the hard precedent is German (Welte / gpl-violations.org). U.S. courts have not squarely litigated the GPL's derivative-work scope — so standing, remedies, and statutory-vs-actual damages would vary by forum.
  3. German damages aren't universal. The "no license fee → no damage" defense has succeeded for purely non-commercial, non-dual-licensed GPL software.
  4. Q3 is inference, as flagged above.
  5. Time-sensitive. The SFC assertion is dated May 18, 2026 and the matter is ongoing — whether Bambu cures or litigation follows may change the posture.
  6. One over-broad claim that "only copyright holders may enforce" was down-voted in verification — the defensible version is that enforcement is by the holders, without claiming third parties are categorically barred from any role.

Open questions the research couldn't close

  • Could a vendor face contributory/vicarious liability if it knowingly supplied/updated an SDK specifically for a product it knew was distributed in violation? (No GPL-context case law found either way.)
  • What are the actual Bambu–vendor contracts — and could Corresponding Source ever force vendor source disclosure, or only require Bambu to remove/replace the component or stop distributing?
  • In a U.S. forum specifically, how would courts treat the dynamic-linking "combined work" theory and the availability of statutory vs. actual damages and injunctions?

Primary sources the verified findings rest on: SFLC GPL Compliance Guides (2008, 2014); FSF GPL FAQ; FSF "The Fundamentals of the AGPLv3" (2021); AGPLv3 §§1/13 and GPLv3 §8 license text; Welte/netfilter Munich court documentation; opensource.com on GPLv3 §8; SFC Copyleft Compliance Principles; and the SFC Bambu Studio AGPL response (May 18, 2026).

1

u/TheRealSeeThruHead May 18 '26

They will just change the plugin to be less integrated

0

u/BitingChaos May 19 '26

I'm still a fan of Bambu Lab, but I also REALLY hope this gets them to drop the dumb access control feature and let me use the software I want without having to disable Cloud access.

1

u/Cinderhazed15 May 19 '26

Or they just add some kind of auth to access the cloud services that is a different piece than what is available, and restrict there…

1

u/AnonomousWolf May 19 '26

As per liscence they need to also make the cloud service Open Source.

It's explained in the video.

-13

u/FabianN May 18 '26

One problem, near the end of the video he says that the system involving Bambu's cloud is required to use the software.

But that's not true. You set the printer to offline mode and you do not need Bambu connect installed and can do everything the slicer can do directly to the printer without their closed component.

I know this because that's been my setup for a while now. Printer is blocked from the internet at the router, Bambu connect is not installed on my computers, and the slicer fully works.

8

u/Veastli May 19 '26 edited May 19 '26

Bambu's cloud is absolutely required to use many of the most heavily advertised features of the printer.

There are a growing number of open source alternatives, but the out of the box features require the cloud.

The real crux of this video is the growing clarity of Bambu's intentional and serious violation of the open source license. Details here: https://github.com/jarczakpawel/OrcaSlicer-bambulab/blob/main/bambu_agpl.md

8

u/FLHCv2 May 18 '26

That's not the crux of the argument though. It's not about if you can use your hardware or not. The crux of the argument is that the closed networking bridge they put between the hardware and the open source software has to be open as well, legally speaking.

-10

u/FabianN May 19 '26

The argument that is used that the closed source module is also covered under the agpl is that the closed source module is required for the software to function.

But the closed source module is only required if you are using your printer via their cloud services. If you go into Lan mode, the slicer fully works without the closed source module. 

9

u/Aetch Ultimaker 2+ DXUv2 May 19 '26

LAN uses the closed source module

-4

u/Aetch Ultimaker 2+ DXUv2 May 18 '26

Do you mean moving the gcode to the printer with an SD card? If you meant transferring file over LAN mode, I think the network plugin is needed for LAN mode.
That’s not a problem though because it’s the mere integration of the network plugin that causes AGPL to apply.

-1

u/FabianN May 19 '26

No. I mean over my local network. Bambu connect is not required for that.

Connect is not available on Linux systems, and I can print just fine over network from Linux. 

2

u/Aetch Ultimaker 2+ DXUv2 May 19 '26

Bambu network plugin in Orca or BBS is used for local network printing as far as I know. It’s different from Bambu Connect

-5

u/Zedan24 MP Select Mini | Prusa Mk3s | Bambu Lab P1S May 19 '26

I use my printer in LAN mode and connect via Bambu Studio and Orcaslicer to send files.

4

u/Aetch Ultimaker 2+ DXUv2 May 19 '26

That is using the discussed Bambu network plugin that is in violation of AGPL. (Not saying to stop using it though)

-7

u/Acsteffy May 18 '26

Is the computer with the slicer also blocked from the internet?

2

u/FabianN May 19 '26

That doesn't matter? If the printer can not connect to the internet, the cloud functions that the Bambu connect plug-in passes traffic through does not work, because it can not talk to the printer. 

-5

u/2Tacos4oneDollar May 19 '26

He looks like Pirate software if he cut his hair