Today the exitcode from the nft child process is returned from run(), but nft-helper will then unconditionally call pause(), even if the ruleset was not applied.
Would it not make more sense to terminate the process in this scenario? Then you would get some indication on the host that something went wrong.