if anyone's interested in trying something different;
Atmosphere with embedded patches, and a trimmed down, non-configurable version of sys-patch built into atmosphere, which sole purpose is to add FS patches so that both hekate and fusee.bin booters can use it.
this version of sys-patch does
not have an overlay, or logs.
it also forces dns mitm of 127.0.0 for all *nintendo* domains (in addition to whatever configuration any other user may provide)
essentially, atmosphere with all patches built in.
https://github.com/borntohonk/Atmosphere/commit/ba7284945f70cb8c7cc03f855ac36b18bdcad774
https://github.com/borntohonk/Atmosphere/releases/tag/1.10.2+
https://github.com/borntohonk/Atmosphere/releases/tag/1.9.5+
what needs testing is really just that your regular games work (those should work, as embedded ES patches already been tested to work before), and if possible, someone who has forwarders compatible with latest atmosphere (1.10+) (what needs testing basically is the embedded sys-patch for the FS patches)
before testing, kindly rename atmosphere folder to atmosphere-backup and only use this version with nothing extra while testing.
boot with hekate pkg3 method, or fusee.bin, doesn't matter which, but if hekate, don't have patches.ini or kip1patch=nosigchk line
(not compatible with 22.0.0 just yet - will wait for homebrew fix before rebasing for that)
pros:
version of atmosphere, if maintained, will always have the correct patches for a firmware version
edit:
i added a "1.9.5" atmosphere version, which is 1.10.2 bundled with tls 0x108 hbl, hbmenu and atmosphere itself is compiled with tls 0x108 libnx, and reverting the tls 0x108 restriction commit
(to faster be able to have someone test if tinfoil starts on any firmware, to verify the FS patches are loaded or not)