@Yuki @cks Plus I these days I'd be a bit surprised if anyone, even for embeddeds, couldn't put a whole base system (possibly even including X11) in the / filesystem.
Meanwhile different filesystem for ports could make sense, specially as it's release management is usually a bit different and could warrant some hardening like passing nosuid,nodev to mount.