pf_ioctl_addrule() allocates a counter_rate for every rule, whether it
has a max-pkt-rate or not, and pf_krule_free() never frees it.
Free it with the rest of the rule.
Fixes: ff11f1c8c76c ("pf: add a generic packet rate matching filter")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")