Having very briefly looked into this problem a few years ago, my impression of the primary challenge was that of re-implementing a large OS API surface in a non-infringing way.
I guess there may be ways to do it not really legally by some hacker and then sharing it with others.
Not that I support it, but there are still people who don't see problems with such behavior.