module sendmail-spamc 1.0; require { type spamc_exec_t; type sendmail_t; class file { execute execute_no_trans getattr map open read }; } #============= sendmail_t ============== #!!!! This avc can be allowed using the boolean 'domain_can_mmap_files' allow sendmail_t spamc_exec_t:file map; allow sendmail_t spamc_exec_t:file { execute execute_no_trans getattr open read };