What about having rpmbuild dropping privs to buildmeister automagically when run? So that the user doesn't have to care...
It would be adequate to refuse to run as root, perhaps with an override switch for some old kernel packages that insist on being built as root (because they have mknod invocations).