This bug stemmed from the discussion in bug 10299. I think that packages shouldn't remove users or groups in postrm scriptlets. Otherwise the system may be left with files with non-existent owner. It may even cause security issues if somebody, at a later time, adds a new user or group with the used-to-be-avahi UID or GID. In this case the new user has full access to the leftover files, e.g. configuration or log files.
This seems reasonable: if we wanted to remove users it should be part of USERADD machinery anyway, not up to individual postrm functions. distcc has the same issue.
In #9262, we had a similar discussion and "unofficially" agreed that we won't delete the existing users/groups from the rootfs. https://bugzilla.yoctoproject.org/show_bug.cgi?id=9262#c2
Fixed in poky: commit 5354a4a315550f71686af17b42818cb1976a7f19 Author: Jussi Kukkonen <jussi.kukkonen@intel.com> Date: Mon Oct 31 15:40:18 2016 +0200 distcc: Don't remove users/groups in postrm There's no way to ensure that files owned by the users aren't left on the system at postrm time: Removing the user would mean those files are now owned by a non-existing user, and later may be owned by a completely unrelated new user. (From OE-Core rev: 776370efb9fa48b82ac991e3d001accd122d611b) Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> commit b1e1c12a3f4d6a06aaf2ed18b1f2a9a7de5f0198 Author: Jussi Kukkonen <jussi.kukkonen@intel.com> Date: Mon Oct 31 15:40:17 2016 +0200 avahi: Don't remove users/groups in postrm There's no way to ensure that files owned by the users aren't left on the system at postrm time: Removing the user would mean those files are now owned by a non-existing user, and later may be owned by a completely unrelated new user. [YOCTO #10442] (From OE-Core rev: c1be2196e7ffb23b7b243ecd8aca1827cbdfa443) Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>