I ran "... | mail -s ... aleksey" while running under sysadm_r and I got:
audit(1079685757.727:0): avc: denied { read } for pid=9687 exe=/usr/sbin/sendmail.sendmail name=self dev= ino=2 scontext=aleksey:sysadm_r:sysadm_mail_t tcontext=system_u:object_r:proc_t tclass=lnk_file audit(1079685757.727:0): avc: denied { search } for pid=9687 exe=/usr/sbin/sendmail.sendmail name=9687 dev= ino=634847234 scontext=aleksey:sysadm_r:sysadm_mail_t tcontext=aleksey:sysadm_r:sysadm_mail_t tclass=dir audit(1079685757.751:0): avc: denied { dac_override } for pid=9688 exe=/usr/sbin/sendmail.sendmail capability=1 scontext=system_u:system_r:sendmail_t tcontext=system_u:system_r:sendmail_t tclass=capability
The first one is probably an issue with how the kernel manages /proc - /proc/self IMHO should not be system_u:object_r:proc_t.
-- Aleksey Nogin
Home Page: http://nogin.org/ E-Mail: nogin@xxxxxxxxxxxxxx (office), aleksey@xxxxxxxxx (personal) Office: Jorgensen 70, tel: (626) 395-2907