pf_nvrule_to_krule
error = pf_nvrule_to_krule(nvlist_get_nvlist(nvl, "rule"),
int pf_nvrule_to_krule(const nvlist_t *, struct pf_krule *);