Add policy-readers group

The access to the device policy files in /var/lib/whitelist is now gated by the
policy-readers group which is composed of the chronos user and the other daemons
needing access to the device policy.

TEST=see both u2fd and chrome can access the device policies.

