Well, the problem was that I had made a tunnel on tap0, but OpenVPN was trying to access tap1.

Now I have everything working except broadcasts across the bridge. Point-to-point comms like ping and SSH work fine.