... if you're going to be making a 1:1 copy, you don't need source.
but a verbatim bootloader copy would only work with original satoshilabz firmware and complain about any other (unsigned) release ... but if the copy-cat would be only after income from sales of generic trezor device without intention of providing own firmware, then this could be no issue since it should be compatible.
i had to write it down to think about it, sorry for the spam