I just want to know how slow it will be if we only use scan-and-patch to run the loaded Linux binary.
hmm... int 0x80 will simply generate an exception, and for TLS-related instructions, simply replacing GS: prefix with a privileged one will do the trick too.