If it has to do with a software-sided patching of the OSD (from chip-side) instead of a Hardware-Patch, I assume it has to do with the relpacement cdvd-routine for the OSDSYS.
All this modes works if I choose any boot mode of the chip and at the FMCB screen I hold any shortcut key to OSDSYS, than I get the OSDSYS Hacked. The chip is configured as 'AUTO' to boot any disc, so, if I don't press any key and hold any shortcut key to OSDSYS on FMCB logo, the PS2 die in black screen.
Other option is to manually select on the chip config to boot only PS2 or PS1 or DVD and do the same at the FMCB logo to get to hacked OSDSYS.
Edit: I've changed my FMCB configuration back to standard, so if I set to auto launch OSDSYS this works also if i force the chip to boot PS2/PS1 or DVD.
Nice move TnA, you know something that we dont. ;)