This test crashes: <!DOCTYPE html> <script> document.createElementNS("http://www.w3.org/2000/svg", "svg").className.baseVal = ""; </script> because in WebCore/dom/StyledElement.cpp:176 we call attributeData()->clearClass(); when the class name is empty without checking if attributeData exists. Attribute data will not exist on SVG nodes (at least) immediately upon creation. This is Chromium http://code.google.com/p/chromium/issues/detail?id=138552
Created attachment 153855 [details] Patch
Committed r123377: <http://trac.webkit.org/changeset/123377>