> delete an existing nft rule that uses an nft anonymous set. And an example of the latter operation is an attempt to delete an element from that nft anonymous set after the set gets deleted I'd be very interested to hear how this can be done by an unprivileged user. Try to race set add/removals, sure, but if it depends on the set itself getting deleted, that seems… harder.
on https://bugzilla.redhat.com/show_bug.cgi?id=2196105 a comment suggests that it might only be possible if you have "unprivileged user namespaces" enabled
Which is the default on Ubuntu.