pfr_remove_kentry() returns without removing an entry whose mark is
set. The mark is scratch space for the operations that handle a list
of addresses: each resets it before use and leaves it set on the
entries it kept, so after "pfctl -T replace" or "pfctl -T zero" of an
address the entry stays marked. An address a source limiter put in
its table is then never taken out again when the source falls below
the low-water mark.
Remove the entry whether it is marked or not; nothing else is in the
work queue.
Add a regression test.
Fixes: 461648121230 ("pf: introduce source and state limiters")
Sponsored by: Rubicon Communications, LLC ("Netgate")