rmad: Add rmad-executor user and group

The RMA executor was run as root. After discussion with security team,
it's better to run as a non-root "rmad-executor" user with CAP_SYS_ADMIN
capabilities so it's still allowed to perform most of the root-level
tasks.

BUG=b:243855405
TEST=display-accts.py --lint

Change-Id: Id90c37ce2e6958b1c57907fa4f90d622bd12ee4d
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/overlays/eclass-overlay/+/3861529
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Commit-Queue: Cheng-Han Yang <chenghan@chromium.org>
Tested-by: Cheng-Han Yang <chenghan@chromium.org>
diff --git a/profiles/base/accounts/group/rmad-executor b/profiles/base/accounts/group/rmad-executor
new file mode 100644
index 0000000..d10ded0
--- /dev/null
+++ b/profiles/base/accounts/group/rmad-executor
@@ -0,0 +1,3 @@
+group:rmad-executor
+gid:20195
+users:rmad-executor
diff --git a/profiles/base/accounts/user/rmad-executor b/profiles/base/accounts/user/rmad-executor
new file mode 100644
index 0000000..c4c4353
--- /dev/null
+++ b/profiles/base/accounts/user/rmad-executor
@@ -0,0 +1,6 @@
+user:rmad-executor
+uid:20195
+gid:20195
+gecos:CrOS RMA daemon executor for privileged tasks
+home:/dev/null
+shell:/bin/false