I dragged my #GLiNet routers not currently in use out to boot them up and see if there are any firmware updates, and lo & behold I found another weird bug.
it seems (tentative description) that if "Block Non-VPN Traffic" is enabled, and DNS over TLS is enabled (and maybe other conditions, dunno), after a few months being powered down, the router can't resolve DNS queries and so nothing else works, UNTIL the date & time is manually set and the router is rebooted.
whew. yeah, that sounds about right for GLi stock firmware.