BZ-B TOOL KIT v3.1.1
====================
STABILIZATION / DEBUG RELEASE

CORE
- Updated product/launcher/current documentation to v3.1.1.
- Standardized exit codes: 0, 1, 10, 20, 30, 40.
- Implemented CompareSnapshot top-level action.
- Added pending-reboot and role awareness to the console header.
- Improved health scoring so ICMP failure is not treated as proof of Internet loss.
- Ensured zero-finding health/MSP audits still create usable evidence artifacts.

SMART DIAGNOSE / SESSIONS
- Corrected stale Smart Diagnose version text.
- Service sessions now save exact pre-snapshot, Smart Diagnose, post-snapshot,
  comparison, and ticket-note paths.
- Ticket-note generation uses the report bound to the service session rather than
  the newest report found on the machine.
- Remediation history now records final transaction status.

REMEDIATION ENGINE
- Removed problematic compressed operator syntax from the v3.1 development build.
- Catalog and engine now agree on explicit risk/rollback declarations.
- Added transaction-specific Windows Update store backup paths.
- Improved Windows Update rollback so partial execution can restore the recorded
  pre-change state without selecting an unrelated global backup.
- Added exact RDP registry and firewall-rule state capture/restore.
- RDP enable now verifies required firewall rules before changing registry state.
- Added automatic best-effort rollback for rollback-capable actions after execution
  or validation failure.
- Strengthened DISM/SFC/native exit-code classification.
- Network stack reset returns REBOOT_REQUIRED after successful reset commands.
- Print spooler queue files are retained as evidence but are not falsely advertised
  as safely restorable print jobs.
- Silent remediation requires -Force.
- Domain trust repair remains credential-gated/interactive.
- Added active-RDP-session protection before RDP disable.
- Added domain-controller guardrails for selected disruptive remediations.

DOMAIN / NETWORK
- Guarded dcdiag.exe so workstation audits do not fail merely because RSAT is absent.
- Added AD DNS SRV testing for domain audit.
- Smart Diagnose/health no longer recommends trust repair while AD SRV/DC discovery DNS is failing.
- Domain audit now maps native DC-discovery/time failures into material diagnostic status while treating supplemental gpresult/dcdiag failures as warnings.
- Network diagnostics prioritize functional DNS and TCP/443 over ICMP.

MIGRATION / SERVER
- PC migration menu now requires/prompts for an explicit package/destination path.
- Added source-profile and target-profile parameters for noninteractive migration import.
- Reworked Server Migration Audit with capability checks, collection issue reporting,
  safer output handling, and explicit exit status.

VALIDATION
- Added Tests\Smoke-Test.ps1 using the native Windows PowerShell AST parser.
- Added JSON/config/catalog/manifest/capability and regression validation.
- Self-test now verifies full release-file coverage by the SHA-256 manifest.
- Added release SHA-256 manifest and Windows VM validation checklist.
