Linux's firewall can do port knocking entirely in the kernel:
https://wiki.nftables.org/wiki-nftables/index.php/Port_knock...
That script gets compiled into BPF and uploaded into the kernel once, at boot/ifup time. All the memory is preallocated.
Userspace can be dead/hung/OOM and you can be sure that at least the port knocking won't be why you got locked out.