The comment talks about upstream development steps and doesn't make
sense for users. We used special '## ' syntax to strip it out during
build, but it got inadvertently reformatted as a normal comment
in
3982becc92197b920d86f03c3c52ae085e26ca60.
TasksMax=16384
{{SERVICE_WATCHDOG}}
-# Enforce a strict device policy, similar to the one nspawn configures when it
-# allocates its own scope unit. Make sure to keep these policies in sync if you
-# change them!
+{# Enforce a strict device policy, similar to the one nspawn configures when it
+ # allocates its own scope unit. Make sure to keep these policies in sync if you
+ # change them! #}
DevicePolicy=closed
DeviceAllow=/dev/net/tun rwm
DeviceAllow=char-pts rw