[Unit] Description=Test for PrivateDev=no [Service] ExecStart=/bin/sh -c 'exit $(test -c /dev/mem)' Type=oneshot PrivateDevices=no