Yeah, sending SIGKILL to pid1 of a container will insta-kill the whole thing. But the network resource stuff does also include removing iptables rules, so it's not something that you really want to be skipping. It feels like the network resources being cleaned up should be a background job rather than blocking the kill (after all, it's not critical to stopping the container and most resources will be freed by the network namespace dying). Also (if you're not already aware of this), you should note that if you use "docker exec" or share pid namespaces between containers, this trick will no longer work because your saved pid is not the pid1 of the namespace (runc has a "kill everything in the container" mode to work around this -- so I'd suggest using "runc kill SIGKILL" rather than doing it manually but it's probably not that important).
Have you opened a bug report in Docker upstream to see if they can improve the situation (perhaps by putting networking cleanup jobs to a background goroutine)?