[Unit]
Description=Test CAP_MKNOD capability for PrivateDevices=no

[Service]
PrivateDevices=no
ExecStart=/bin/sh -x -c 'capsh --print | grep cap_mknod'
Type=oneshot