Thanks for pointing me in that direction. While I found that
Network -> Interfaces -> 0/1 (edit) shows interface mode = route
I also found while I was there that I still had a legacy secondary IP of 1.2.3.4/28, and once I remove it, my routing works, so thanks for the help!
The reason I had a secondary IP on 0/1 DMZ is that I was trying to use both 192.168.5.0/24 and 1.2.3.4/28 on that same interface, but was also trying to use 1.2.3.4/28 NAT'ed to Trust, which was, um, problematic (possibly due to lack of understanding on my part).
I have since gotten a new separate public subnet of 5.6.7.8/28 from the upstream provider, I have started a separate thread to ask whether it is possible to route without NAT to 0/1 DMZ as a secondary IP/subnet while NAT'ing on 0/1 DMZ to 192.168.5.0 as well, or should I be thinking about this differently?