Features:
+* shutdown: don't read-only mount anything when running in container
+
* nspawn: --read-only is not applied recursively to submounts
* MountFlags=shared acts as MountFlags=slave right now.
- resource control in systemd
- inhibiting
- testing with Harald's awesome test kit
+ - restart
* allow port=0 in .socket units