group: Remove root from chronos-access and update comment.

We are putting all chronos-access users (minus chronos) in enforcing
SELinux domains. This isn't practical yet for root, so remove it from
chronos-access.

BUG=b:205301707
TEST=CQ passes

Cq-Depend: chromium:3265864
Change-Id: Ie4c4c06d55a16013684bb01f3cde940338755abe
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/overlays/eclass-overlay/+/3264340
Commit-Queue: Allen Webb <allenwebb@google.com>
Tested-by: Allen Webb <allenwebb@google.com>
Reviewed-by: Mike Frysinger <vapier@chromium.org>
diff --git a/profiles/base/accounts/group/chronos-access b/profiles/base/accounts/group/chronos-access
index 5c0affe..d973a71 100644
--- a/profiles/base/accounts/group/chronos-access
+++ b/profiles/base/accounts/group/chronos-access
@@ -4,4 +4,6 @@
 # mostly system daemons running as a non-chronos user, group permissions
 # to access files/directories owned by chronos.
 # This includes all users accessing opencryptoki database files.
-users:root,vpn,chronos,cros-disks,imageloaderd,crash,dlp,image-burner,spaced
+#
+# Processes running with chronos-access need enforcing SELinux domains.
+users:vpn,chronos,cros-disks,imageloaderd,crash,dlp,image-burner,spaced