https://crrev.com/c/739927 introduced logic to prevent duplicate registrations (i.e. support for excludeList), but it will check *all* devices for duplicates before attempting to register a new credential. This behavior potentially prevents adding a second security key for the same account, which is not what the WebAuthN spec intends [1]:
"""
This member is intended for use by Relying Parties that wish to limit the creation of multiple credentials for the same account on a **single** authenticator. [...]
"""
[1] https://www.w3.org/TR/webauthn/#dom-makepublickeycredentialoptions-excludecredentials
Comment 1 by hongjunchoi@chromium.org
, Feb 16 2018