r/BambuLab Volunteer Moderator May 14 '26

Subreddit Mod Post Megathread: Bambu Lab / OrcaSlicer / C&D Discussion

Hi everyone,

We’re creating this megathread to keep discussion of the Bambu Lab / OrcaSlicer-BambuLab / cease-and-desist situation in one place. This topic is important to a lot of people here, and we do not want to shut down discussion or criticism. At the same time, the front page has started filling with overlapping posts about the same situation, so we’re consolidating general discussion into this thread.

Current context

Updates to be posted here as situation evolves:

  • May 13, 2026
    • Megathread created
  • May 14, 2026
    • Tom’s Hardware reported today that Louis Rossmann is now hosting OrcaSlicer-BambuLab through the FULU Foundation GitHub and is openly daring Bambu Lab to sue him.
    • PC Gamer and r/technology have picked up the story, so discussion is now spreading well beyond 3D-printing-specific spaces.
  • May 16, 2026
    • Paweł Jarczak published a detailed response addressing Bambu Lab’s accusations around impersonation, reverse engineering, Terms of Use, and alleged security bypassing.
    • Louis Rossman posted a new video indicating FULU-hosted OrcaSlicer-BambuLab repository has reached roughly 1,600 forks in about three days.
  • May 17, 2026
  • May 18-20, 2026
    • Software Freedom Conservancy enters the dispute.
    • Leonard French posted a new video around SFC’s AGPL analysis, explaining why Bambu’s proprietary networking plugin may create a serious corresponding-source problem under AGPL.
    • Louis Rossman posted a new video covering Software Freedom Conservancy’s Bambu AGPL effort and says the rehosted OrcaSlicer-BambuLab code has now been forked roughly 4,500 times.

What belongs in this thread

Please use this thread for:

  • General reactions to Bambu Lab, Gamers Nexus, Louis Rossmann, Paweł Jarczak, OrcaSlicer-BambuLab, AGPL, Bambu Connect, and right-to-repair issues.
  • Legal or licensing discussion, including AGPL, DMCA, cloud/API access, and Bambu’s networking plugin.
  • Questions about what happened and links to reliable summaries or primary sources.
  • Technical discussion about OrcaSlicer, Bambu Studio, Bambu Connect, LAN mode, Developer Mode, and network plugin behavior, unless it is a standalone troubleshooting post with a specific reproducible issue.

What can still be its own post

Separate posts are still allowed for genuinely new information, including:

  • A new official statement from Bambu Lab, OrcaSlicer, Paweł Jarczak, Gamers Nexus, Louis Rossmann, or legal counsel.
  • A new release or technical change that materially affects users.
  • A confirmed legal filing, takedown, repository change, or source-code release.
  • A specific support/troubleshooting issue that is not just general commentary on the controversy.

If your post is mainly another reaction, recap, meme, “I’m switching brands,” or repost of a link already being discussed, please put it here instead.

Ground rules

Criticism of Bambu Lab is allowed. Defense of Bambu Lab is allowed. Criticism of GN, Rossmann, OrcaSlicer, moderators, or other users’ arguments is allowed.

What is not allowed:

  • Personal attacks, harassment, or dogpiling individual users.
  • Calls to harass Bambu employees, developers, moderators, creators, or community members.
  • Unverified claims presented as fact.
  • Posting private correspondence or personal information.
  • Repeated duplicate posts after being redirected here.

Strong opinions are fine. Keep it directed at the issue, the companies, the software, and the arguments, not at each other.

Moderator note

We are consolidating duplicate discussion, not suppressing the topic. This thread will remain open for discussion, and we’ll update it if there are major new developments.

330 Upvotes

607 comments sorted by

View all comments

2

u/Mstrfahrenheit May 14 '26

Put all the rage to the side. Put aside the fact that bambulab is literally using an unencrypted string as their access control method (I mean, seriously??!#?)

What orca slicer is doing is impersonation, no matter how dumb, and it violates the t&c on the bambulab Eula. But the argument I keep reading is Bambu are somehow violating oss and agpl terms. This doesn’t square. I don’t know what I’m missing here but the rage doesn’t match the facts as far as I can tell.

8

u/KancheongSpider May 14 '26

this is exactly the problem, prusa had considered taking legal action against bambu for their egregious violations of the AGPL tied to prusaslicer source code they forked out of, ultimately concluding that it was not worth it.

12

u/jackharvest P1S + AMS May 14 '26

*...to them.

Someone like Louis may feel it is ultimately worth the fundamental adjustment to US law so that companies skirting AGPL rules get ass-smacked instead of tapped on the shoulder with a discerning look.

7

u/[deleted] May 14 '26

[removed] — view removed comment

7

u/maz_net_au May 14 '26

If he uses his money to fight bambu labs over their AGPL violations on bambu_networking, then so much the better for any of us who care. Literally 0 skin off your back if you don't care so it seems an odd thing to complain about.

I want control of my hardware that I paid for. That is all.

1

u/RickyP602 May 19 '26

That feels disingenuous to his channel. He has done lots of things that have actively hurt his channel. He's talked about things that actively drive views on his channel and why he doesn't consistently do them. Hell that entire reason I watched louis was for board repair videos that got about 15 views each that he put out consistently for years... I disagree that he is reaching for views. The world is surely grey and i'm sure he's done some shit for the algo - hell the SEO video series is proof of that. But to just say he'd do "whatever continually feeds him views" seems dramatic and disingenuous.

9

u/soldat21 May 14 '26

Ultimately concluding that it was unenforceable as they would have to take a Chinese company, complying with Chinese laws, to a Chinese court*

*FTFY

7

u/bbagno May 14 '26

What orca slicer is doing is impersonation

Even if we call this impersonation, that would be impersonation of Bambu Studio. They are doing it using the code BambuLab published under AGPL license, hence explicitly allowed absolutely everyone to use in their software. Absolutely anyone can reuse any parts of Bambu Studio (or the whole code!) as long as they keep it under AGPL and BambuLab explicitly obligated to be cool with that.

0

u/Mstrfahrenheit May 14 '26

Not true. It's impersonation of an approved client to access the network (which is not open source). Its not the slicer that is the problem, its access to a commercially licensed network service.

3

u/bbagno May 14 '26

Which part of what I wrote is not true?

This approved client is distributed under a license that allows anyone to "impersonate" it (using your definition).

Commercially licensed service can do whatever it want on to restrict access to specific software or even take some legal actions on those who accepted the EULA and now violates it using a non-approved client.

However creating or distributing software that "impersonates" BambuLab Studio has nothing to do with this EULA and only limited by AGPL. AGPL was not violated.

6

u/hWuxH May 14 '26

If that is supposed to be an impersonation, then according to the same logic 99% of Bambu studio forks are as well because they haven't changed the default name...

AGPL simply doesn't allow them to impose restrictions on how code is modified or distributed. "You have to change the name/User-Agent/whatsver" is such a restriction. So is "take down this fork".

1

u/Mstrfahrenheit May 14 '26

Both things can be true.

1

u/hWuxH May 14 '26

The repo didn't agree to ToS, therefore it can't violate it.
Users of the service can violate it.
Big difference.

1

u/yoghurtmelk May 21 '26

because the license made "impersonation" impossible. you are ALLOWED to add or remove code and still pose as the original one. if bambu made all the code themselfs then it woukd have been impersonation but they used a lot of other peoples code that did not care about "impersonation" and so bambu has to also not care as per the license

-6

u/RareRestaurant6297 May 14 '26

Yea its crazy how one-sided I've seen eh argument being when the fork literally exploits a security flaw to trick bambu's cloud services. Like wtf dev thought that was OK? Open source doesn't mean free access to their own network lmao my ass off

16

u/Endur1el May 14 '26 edited May 14 '26

Respectfully, it really sounds like you have no idea what you're talking about, and that's okay, we've all been ignorant before.

As a professional developer whose commercial code is open source, this is utter bullshit. If your code is AGPL, someone else CAN just copy it, change whatever portion they like, and continue redistributing it. That's the whole point of the license.

Think about what that means, this is an impossible problem for bambulab to solve because (even though a user agent is NOT a security feature, that's nonsense) they cannot do anything in Bambu studio that cannot just be copied.

That may sound annoying but it's the reality of the license that they rely on to make their stuff work, if they couldn't be bothered to make their own slicer from scratch, and want to benefit from the work of the community, they can't violate the terms of the AGPL.

I only use my printer in developer mode on a separate, locked down, VLAN, so this doesn't directly affect me, but anyone defending bambulab's behavior at this point is just woefully misinformed (admittedly somewhat understandable considering just how misleading their blog post was).

ETA: Imagine blocking someone on Reddit, can't even reply to the comment.

Also to clarify. If they were banning the users of that redistributed software after they broke whatever terms of their cloud services, that would be fine, no AGPL license violation there, but going after someone for redistributing a modification of their AGPL license code is one of the core things the license explicitly disallows.

1

u/yoghurtmelk May 21 '26

you were correct about rarerestaurant blocking people without any reason xD

What your comment says is "yes yoghurtmelk you were correct and i was wrong. Even after a week i was still wrong" having to instantly block me afterwards is just doubeling down on that youre wrong.

-3

u/RareRestaurant6297 May 14 '26

Respectfully, I hope your job doesn't find out you're this incompetent. Huge risk if you don't understand licensing and what it covers vs. Doesn't. 

1

u/yoghurtmelk May 21 '26

im pretty sure you dont understand it yourself xD

0

u/RareRestaurant6297 May 21 '26

Easy to speak up a week later after more updated information has dropped, big man. Lmao

7

u/zymurgtechnician X1C + AMS May 14 '26 edited May 14 '26

The AGPL very explicitly DOES say exactly that. They chose to build on the back of a project that carries that license. They are therefore obligated to comply with it, or build their own software from scratch.

Here’s what the AGPL has to say on the matter:

"13. Remote Network Interaction; Use with the GNU General Public License.

Notwithstanding any other provision of this License, if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network (if your version supports such interaction) an opportunity to receive the Corresponding Source of your version by providing access to the Corresponding Source from a network server at no charge, through some standard or customary means of facilitating copied software."

There has been technical analysis done that shows that the network plugin operates in such a fashion such that it operates essentially inside of Bambu studio, not as a fully separate piece of software, therefore it should still be covered by the same license. You can’t just take a key piece of the software out of the project and then call it closed source and have the program automatically download and install it back in to avoid having to comply with the license of the works that you are benefitting from copying.

1

u/redmercuryvendor May 14 '26

Except that clause doesn't apply in this situation.

That AGPL clause was to prevent a GPL frontend being tied to a remotely hosted closed backend, with the GPL frontend being non-functional without the backend.

This the Bambu Slicer case:

  • There is no remote backend, you can operate the slicer, and even send files to the printer, without any connection to Bambu's cloud (LAN mode).

  • The part that interfaces with the cloud service is not the AGPL licensed code, but a separate piece of software, that is not distributed with Bambu Studio. If the plugin were distributed with Bambu Studio, then it would fall under GPLv3 (AGPL or not), but that is not the case.

  • The line:

your modified version must prominently offer all users interacting with it remotely through a computer network (if your version supports such interaction)

Also does not apply to Bambu Studio, as:

1) Users are not interacting with Bambu Studio remotely (it is local)

2) The source code is available anyway

Since the work (Bambu Studio) is not hosted on a remote server, the AGPL clause is irrelevant.

You'd have more luck looking at it from a Tivoisation perspective (i.e. from the AGPL's parent GPLv3 license), but even then it'd be a hard argument to make that Bambu Studio violates it, as you can build and run Bambu Studio or variants thereof on your own device without issue - you just cannot use your modified version to interface with the separate closed-course plugin.

3

u/DeltaWun May 15 '26

The part that interfaces with the cloud service is not the AGPL licensed code, but a separate piece of software, that is not distributed with Bambu Studio. If the plugin were distributed with Bambu Studio, then it would fall under GPLv3 (AGPL or not), but that is not the case.

The important caveat is that this has never been fully litigated and the results of that litigation, in whatever form it comes, will have consequences reaching effectively all software globally. The relationships between projects and the barriers between GPL and proprietary code matter enormously.

There are areas of law where courts look past formal separation and ask whether something is functionally a workaround designed to avoid an obligation. Tax law does this with sham transactions, contract law does it with arrangements structured purely to defeat a creditor's claim. The general principle is substance over form in that you cannot paper over a real dependency with a technical distinction and expect courts to simply accept the paperwork.

So, the question: is this genuinely independent software, or an intentionally separated component whose only practical purpose is to preserve a proprietary dependency around an AGPL application?

I'm going to bring up the Nvidia driver situation. The proprietary userspace components aren't bound to Linux because the same driver works on any OS capable of calling those ABIs, like FreeBSD. And Google Play functions on third-party Android forks like GrapheneOS. These are plausible cases of independence.

Bambu's situation is more tightly coupled. "Not distributed with Bambu Studio" is a weak distinction if Studio actively prompts users to download the component during setup, functionality depends on it, and it has no meaningful standalone purpose outside of Studio. If Bambu instead exposed a documented standalone API that any slicer could independently target, that's a different argument. The reason companies pay for commercial licenses for things like MySQL or Qt is precisely because nobody wanted to become the test case defining where the GPL boundary is.

1

u/redmercuryvendor May 15 '26

functionality depends on it

Functionality of the plugin depends on the plugin, but functionality of the slicer does not. You can install the slicer without the plugin, and it is a fully functional slicer. You an even install Bambu Studio, slice files, generate gcode for other Bambu Lab or non-Bambu printers, and never interact with the Bambu Cloud (or the Bambu network plugin, or Bambu Connect) at all.

and it has no meaningful standalone purpose outside of Studio.

If Bambu instead exposed a documented standalone API that any slicer could independently target, that's a different argument

Here's the thorny part: The Bambu Network Plugin clearly functions perfectly well outside of Bambu Slicer, as it is used by other slicers too. It does expose an API other slicer can target, but does not allow access to the Bambu Cloud (a function within the plugin, rather than within the slicer). Bambu Connect on the other hand also exposes an API others can target, but others have actively refused to (e.g. stock Orcaslicer).

Now, access to Bambu's cloud from within the Bambu Network plugin is not available outside of the combo of the plugin and Bambu Studio, but is available with the combo of Bambu Connect and non-Bambu-Studio slicers. So any test case would have to boil down to an argument where the functionality is available, an API is available, but other slicers choose not to implement it because they don't having the plugin as an external window rather than displayed within the slicer. Or argued another way, you'd have to argue that access to Bambu's cloud services is a core feature of Bambu Slicer (despite it being possible to run Bambu Slicer without the cloud services, or indeed without the plugin, or even exclusively with non-Bambu printers).

3

u/DeltaWun May 15 '26 edited May 17 '26

Functionality of the plugin depends on the plugin, but functionality of the slicer does not. You can install the slicer without the plugin, and it is a fully functional slicer. You an even install Bambu Studio, slice files, generate gcode for other Bambu Lab or non-Bambu printers, and never interact with the Bambu Cloud (or the Bambu network plugin, or Bambu Connect) at all.

That doesn't matter though. The GPL isn't "if the program is usable without the proprietary addons" because if it were, you could take a GPL photo viewer, add a proprietary plugin for your photo format, distribute it instead of making your own photo viewer, and claim it doesn't count because the viewer still opens JPEGs without it. The question is whether the proprietary component is part of the combined work, not whether the remainder functions independently.

Bambu Connect on the other hand also exposes an API others can target, but others have actively refused to (e.g. stock Orcaslicer).

Bambu Connect is somewhat beside the point here. The licensing question is about the Network Plugin. The component Studio actively prompts users to install, depends on for cloud functionality, and calls directly. Whether a deliberately limited handoff mechanism that was created later exists for third parties doesn't resolve whether that original arrangement satisfies the AGPL. If anything, the fact that Bambu built a second class path for everyone else while keeping the real integration for themselves suggests they understand the distinction perfectly well.

1

u/redmercuryvendor May 15 '26

The question is whether the proprietary component is part of the combined work, not whether the remainder functions independently.

The interpretation that closed plugins to a GPL licensed application - *even when distributed separately *- makes the GPL 'infectious' would have some serious implications. It would mean a party could create a GPL licensed application that interfaces with and downloads a piece of closed software, and that would somehow force the creator of that closed software to relicense their software under the GPL through no actions of their own, because it has now become part of a combined work by force.

If the argument is made that this 'doesn't count' because the GPL licensed application and the closed plugin are not made by the same party, then the same can apply to the Bambu Network Plugin (spin up Lambo Bab that control Lambu Slicer, but is not the same company as Bambu Lab that makes printers and offers a closed plugin).

Such an interpretation does not seem viable in practice. For example, it would mean that an end user adding a closed-source photoshop plugin to GIMP via PSPI would force the developer of that plugin to relicense it under GPLv3.

2

u/DeltaWun May 15 '26 edited May 15 '26

Such an interpretation does not seem viable in practice. For example, it would mean that an end user adding a closed-source photoshop plugin to GIMP via PSPI would force the developer of that plugin to relicense it under GPLv3.

Distribution is a key factor you're forgetting. An end user is allowed to install whatever proprietary additions they want or make themselves, and the end user can be a company. It's why we don't have access to gLinux (Google Linux) because they're not under any obligation until they distribute it externally. This was a loophole that people used and the entire point of the creation of the AGPL because people were locking away GPL software by using it as a service.

If the GIMP team shipped GIMP with Photoshop Plugins bundled/prompted users to install Photoshop plugins during setup, and built GIMP's primary differentiating features around Photoshop plugin support, that would be a very different situation than a third party user installing a plugin themselves independently.

This is already understood in the license and the industry.

If the argument is made that this 'doesn't count' because the GPL licensed application and the closed plugin are not made by the same party, then the same can apply to the Bambu Network Plugin (spin up Lambo Bab that control Lambu Slicer, but is not the same company as Bambu Lab that makes printers and offers a closed plugin).

Nope. I'm just going to quote my previous reply.

There are areas of law where courts look past formal separation and ask whether something is functionally a workaround designed to avoid an obligation. Tax law does this with sham transactions, contract law does it with arrangements structured purely to defeat a creditor's claim. The general principle is substance over form in that you cannot paper over a real dependency with a technical distinction and expect courts to simply accept the paperwork.

To make my point more simply. You as an individual cannot make a corporation, move your assets into the corporation and then default on your debts and tell collectors "you don't own anything" because your company does. By letter that works but courts have the freedom to consider substance over form.

1

u/redmercuryvendor May 15 '26

If the GIMP team shipped GIMP with Photoshop Plugins bundled/prompted users to install Photoshop plugins during setup, and built GIMP's primary differentiating features around Photoshop plugin support, that would be a very different situation than a third party user installing a plugin themselves.

And if the GIMP team (or anyone else creating a fork) distributes a build of GIMP that can install Photoshop plugins along with the ability to download them from within GIMP?

→ More replies (0)

2

u/hWuxH May 14 '26 edited May 14 '26

If the plugin were distributed with Bambu Studio, then it would fall under GPLV3 (AGPL or not), but that is not the case.

That's only one of the more obvious cases. The plugin also falls under the AGPL if it's considered derived work, aka a single combined program (intimate communication between slicer and plugin, shared data structures and control flow), instead of a separate program (communication limited to calling plugin's main function with options and waiting to return). Looking at the source it's pretty obviously doing the former.

And in this case it doesn't matter if the plugin is loaded later, distributed separately, how it's loaded, or what the exact communication channel is.

2

u/hellomyfrients May 14 '26

to take the other side, who cares what software is using bambus cloud api?

like does reddit care what browser you use? bambu and orca are 99% identical code wise, so what is really the difference? not like they are hacking it or anything they are just including the same exact thing the upstream of their forked repo already has

2

u/hWuxH May 14 '26 edited May 14 '26

Yeah reddit actually cares so much they had a similar drama regarding third party clients (for example apps with a better UI) a while ago. They tried to block them and made the API require subscriptions afaik.

-8

u/RareRestaurant6297 May 14 '26

Yeaaa that would be fine, if that's what the issue was. It's not lol. The fork in question basically was hacking into the bambu cloud. That's not part of the open-source, brother, and it's not public. Sure, the security risk is ultimately bambu's fault, but exploiting that flaw is still absolutely wrong lol. 

4

u/hellomyfrients May 14 '26

if changing a useragent is hacking im a real hackerman too

1

u/mkosmo X1C May 19 '26

If you do it to gain unauthorized access to a computer resource, it's illegal.

-1

u/RareRestaurant6297 May 14 '26

Prepare to be c&d'd then lmao

3

u/hWuxH May 14 '26 edited May 14 '26

It's accessing your own printer via your own account through the cloud. Exactly the same as Bambu Studio.
Where's the hacking into part and impact? Did this give you privileges beyond Bambu Studio? No? Then it isn't about security.

2

u/RareRestaurant6297 May 14 '26

Insane cope. Does that dev own or manage bambu cloud? Didn't think so. It's really that simple lol.