[Unit]
Description=Test for PrivateDev=yes
[Service]
ExecStart=/bin/sh -c 'test ! -c /dev/mem'
Type=oneshot
PrivateDevices=yes