Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
blog.cloudflare.com
blog.cloudflare.com
1. dm-thin operates at 64kb block sizes, but many file systems operate at 4kb block sizes.
2. the point of skip_block_zeroing is to say if we write a 4kb fs block we don't have to zero out the rest of the 60kb dm-thin block (save performance).
why would one do this? perhaps the design was that one isn't exposing the raw block device to the container, only an ext4, xfs or the like fs. In those, the fs also knows what blocks are allocated and if you try to read an unallocated block will probably cheaply return you all 0s (why spend IO time reading something you already know is all 0s, similiar to a quick format).
Therefore, zeroing out the remaining 60kb is also just a waste of IO (ala not using quick format).
However, perhaps someone then decided to use the same provisioning mechanism to enable containers to have block devices (where one can now read the underlying content directly) and boom you have a problem.
or perhaps someone didn't realize the mismatch in dm-thin block size and page size that things are written at.