golangci-lint v2 with its default linters flags ten unchecked Close
returns (errcheck) that v1.64 did not report: the database and rows
handles in the SQLite store, the MetaServer response body and probe
connection, and the test fixtures.
The TLS retry was gated on hasCerts (cert-file and key-file both set),
so a TLS-only MetaServer with a CA-signed server certificate was never
tried when the caller passed only --ca-file. The tool then reported
AuthRequiredError and recommended the cert flags that would not help.
Run the TLS retry whenever a CA file or client certificates are
provided, and report a distinct reason when the handshake fails with a
CA-only setup.