Do not allow to install S+ apps with cross cert permissions

I.e. permissions and permission groups should stay inside a cert-group
so that there cannot be accidential security bugs in apps.

Test: atest CtsPermissionTestCases
            CtsPermission2TestCases
	    CtsAppSecurityHostTestCases
Fixes: 146211400 (No backport possible, all changes are for S+ apps
only)
Change-Id: I19c2f3e216ea57a9e25c65e276f87425aeb1c038
4 files changed