netfilter: nft_compat: make sure xtables destructors have run