eclass: add devicejail user/group, cuse group

The cuse group will have access to /dev/cuse. We will
run device_jail and device_jail_fs as the device_jail
user in order to make sure we don't have root daemons
running around.

TEST=build_packages, check /build/board

