Ok so my Guest network just lost connectivity again, and indeed now I'm seeing traffic from guest IPs showing up on the regular wifi LAN, which again are correctly rejected by the router
brctl show says all is still set up correctly though:
bridge name bridge id STP enabled...