This is a problem that has been discussed earlier (see bug 230).
According to the FSSTND, it should be possible to mount /usr read-only.
There are several advantages of doing that. I expect to be able to
configure makewhatis to create /var/catman/.../index.* instead of
(Please no discussion about the FSSTND.)
It uses /var/cache/man in 7.0
Created attachment 153238 [details]