Add policy-readers group

The access to the device policy files in /var/lib/whitelist is now gated by the
policy-readers group which is composed of the chronos user and the other daemons
needing access to the device policy.

TEST=see both u2fd and chrome can access the device policies.

Change-Id: I125e411aea39708e6bb008c03a60f2ff0bf3c416
Commit-Ready: Vincent Palatin <>
Tested-by: Vincent Palatin <>
Reviewed-by: Dan Erat <>
Reviewed-by: Mike Frysinger <>
(cherry picked from commit a75b80538fabec5b1f815d28bfe89d890b7b4f1d)
Reviewed-by: Vincent Palatin <>
Commit-Queue: Vincent Palatin <>
Trybot-Ready: Vincent Palatin <>
1 file changed
tree: 37346de004b61dc501dacd7d1e313d7b42c5b2ff
  1. PRESUBMIT.cfg
  2. eclass/
  3. metadata/
  4. profiles/