Tor & SELinux/SuSE 10 (also AppArmor question)

I have SuSE Linux 10, and the latest alpha of Tor. Due to SELinux, I can't run tor as anything but root and have it work correctly. This prompts me to ask the following two related questions:

1. How should I correctly configure SELinux on SuSE to be secure *and* have tor have enough privelages to correctly download all the required dir info, and
2. How can SELinux and/or Novell AppArmor be used to effectively lock down and secure Tor and other potentially dangerous network programs?