pf_purge_thread() calls pf_purge_unlinked_rules() in the network
epoch, where sleeping is not allowed, and it takes pf_config_lock, an
sx lock. If a rule is being added at the time, the purge thread
can sleep on the lock, which panics with INVARIANTS.
Fixes: f92d9b1aad73 ("pflow: import from OpenBSD")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")