Five deployment setups, the same question each time: assuming the untrusted model is scheming, does the setup hold the control property?