macOS uses opendirectory for users and groups, which supports nested groups and groups with synthesized membership. This means that asking for a group's users isn't sufficient to test for group membership. With this change, groups like `@localaccounts` or `@_developer` will work in `trusted-users` and `allowed-users`. Fixes https://github.com/NixOS/nix/issues/5885 Change-Id: I3b0783ce7cec303de5aba32c8e5ac0f976112c72