Ilia, thank you for responding so quickly. Reach rules are not supported yet. I'm assuming you mean rich rules? This is not the case. The trusted zone is empty with no services or ports defined. It has a default target "ACCEPT". The zone is disabled by default but becomes active once you add a source ip. Because of this, the statement that there are no open ports or services on that zone is also false because all traffic is accepted from the source address once it is defined.
Several FirewallD module bugs/inconsistencies