1 # SPDX-License-Identifier: LGPL-2.1-or-later
3 Description=Test no_new_privs is unset for SystemCallFilter and non-root user
6 ExecStart=sh -x -c 'c=$$(cat /proc/self/status | grep "NoNewPrivs: "); test "$$c" = "NoNewPrivs: 0"'
9 SystemCallFilter=@system-service