Until then, LD_PRELOAD is your friend (assuming you build with semantic interposition).
How taboo is it to just patch glibc and maintain it your own repo? Or even make it public.
However, as someone who does this type of exploitation for fun and has a little bit of experience with heap attacks, I doubt the canaries are particularly effective at stopping exploits, and the README basically admits this as well.