I also have an R7800 running r47086 with SFE disabled, QoS enabled and it's all working fine. Maybe you need to nvram erase && reboot and then manually reconfig?
By "WAN access" you mean access to the Internet through your router?
After some more testing, I discovered that if I disable the OpenVPN Server/Daemon, the QoS functions correctly and all clients can access the Internet. So I tried upgrading the firmware to DD-WRT v3.0-r47090 std (07/26/21), with the same result. If either OpenVPN or QoS is enabled, but not both, the respective feature works correctly. If both are enabled, QoS does not work, clients cannot access the Internet and the firewall rules are not applied correctly, however, the OpenVPN server allows outside connections from the Internet.
CVE-2019-14899 Mitigation: Disable
Start Type: WAN Up
Inbound Firewall on TUN: Unchecked
Config as: GUI(server)
Server mode: Router(TUN)
Tunnel Protocol: udp
Encryption Cipher: AES-256-GCM
Hash Algorithm: SHA512
First Data Cipher: AES-256-GCM
Second Data Cipher: AES-256-CBC
Third Data Cipher: AES-128-CBC
Advanced Options: Enable
TLS Cipher: TLS-DHE-RSA-WITH-AES-256-GCM-SHA384
Redirect default Gateway: Disable
Allow Client to Client: Disable
Allow duplicate Clients: Disable
Allow Clients WAN access (internet): Disable
Tunnel MTU setting: 1500
Tunnel UDP Fragment: Blank
Tunnel UDP MSS-Fix: Disable
Use ECDH instead of DH.PEM: Disable
Now that I've upgraded to the DD-WRT v3.0-r47090 std (07/26/21) firmware, should I post here or the new release thread?