netfilter: nft_reject_bridge: restrict reject to prerouting and input