When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
frees the rule with pf_free_rule(), which asserts the rules and config
locks (neither is held) and releases references that
pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
pfr_detach_table() dereference NULL.
Use pf_krule_free(), as the ioctl paths do.
Fixes: e249f5daa41f ("pf: fix memory leak on rule add parse failure")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")