Ok, so I managed to configure the VLANs on the tunnel; pero your advice, I changed the tunnel name, moved the bridge configuration, and changed the notation. On the main router, I have this now:
config interface 'lnk'
option proto 'gretap'
option ipaddr '192.168.1.254'
option peeraddr '192.168.1.253'
option force_link '1'
config interface 'iot'
option type 'bridge'
option proto 'static'
option ifname '@lnk.4'
option ipaddr '192.168.4.254'
option netmask '255.255.255.0'
And on the wireless extender, I have it configured as:
config interface 'lnk'
option proto 'gretap'
option ipaddr '192.168.1.253'
option peeraddr '192.168.1.254'
option force_link '1'
config interface 'iot'
option type 'bridge'
option proto 'dhcp'
option ifname '@lnk.4'
This works like a charm, I even added a second network to the link, using a different VLAN. Next step will be to use a separate network for the link with a larger MTU, so the MTU on the encapsulated networks can be raised back to 1500 bytes (it's currently at 1280 bytes).