1 2 3 4 5 6 7
[Unit] Description=Test for PrivateDev=yes [Service] ExecStart=/bin/sh -c 'test ! -c /dev/mem' Type=oneshot PrivateDevices=yes