I'm going to be disabling them shortly.
I'm sure there's a more precise way to disable these on only the affected platforms, but they're currently holding the tree closed.
This probably needs triage from the security team...
(In reply to Boris Zbarsky [:bz] (still a bit busy) (if a patch has no decent message, automatic r-) from comment #4) > This probably needs triage from the security team... Thanks for letting me know. I'll have someone look at that.
Francois, Wennie mentioned you might be able to take a look at this one. If not, please let me know!
Here's what I found so far. Tests that fail: https://github.com/w3c/web-platform-tests/blob/master/content-security-policy/blink-contrib/self-doesnt-match-blob.sub.html https://github.com/w3c/web-platform-tests/blob/master/content-security-policy/blink-contrib/star-doesnt-match-blob.sub.html https://github.com/w3c/web-platform-tests/blob/master/content-security-policy/blink-contrib/worker-connect-src-allowed.sub.html https://github.com/w3c/web-platform-tests/blob/master/content-security-policy/blink-contrib/worker-script-src.sub.html I suspect they fail because we lack SecurityPolicyViolationEvent (bug 1302962). I've got too much on this week and next, but I'll try to confirm after that. Tests that are no longer in the upstream repo: testing/web-platform/meta/content-security-policy/frame-ancestors/multiple-frames-meta-ignored.sub.html.ini testing/web-platform/meta/content-security-policy/frame-ancestors/multiple-frames-self-allowed.sub.html.ini testing/web-platform/meta/content-security-policy/frame-ancestors/single-frame-self-allowed.sub.html.ini They have been replaced with new ones, so it's probably not worth looking into these.