Hello, I made a test where I specified an empty field for --tpm2-pcrs instead of default 7 and the luks partition is decrypted with the tpm.
I also made some test with other PCR values (1, 0) and it fails. It seems to be related to the PCR binding and linux-image-6.7.7-amd64 since this problem does not come up with previous versions (linux-image-6.6.15-amd64 and earlier) "Luckily", since the problem is not specific to the secure-boot PCR binding, I may be able to git-bisect the problem (i.e. with unsigned kernels). Best regards